* refactor(app): isolate system clipboard adapters
- Split browser and Tauri clipboard behavior into focused adapters\n- Inject browser clipboard capabilities into unit-testable operations\n- Remove navigator and document mutation from headless clipboard tests
* refactor(app): delegate browser clipboard fallbacks
- Use copy-to-clipboard for modern rich MIME writes and execCommand fallback\n- Keep OpenPencil-specific HTML and plain-text payload construction at the adapter boundary\n- Remove hand-rolled browser capability and selection handling
* test(clipboard): verify rich browser menu round-trip
- Exercise copy from the browser Edit menu under a user gesture\n- Verify text/html and text/plain ClipboardItem formats\n- Paste the system clipboard payload back into the canvas
* refactor(clipboard): reduce adapter surface
- Expose only command dispatch and the injectable system clipboard contract\n- Keep browser and Tauri copy/paste operations private to their adapters\n- Rename the in-memory DataTransfer fallback and share design HTML recognition
* fix(clipboard): harden format and fallback handling
- Require complete OpenPencil or Figma clipboard markers\n- Await browser writes so adapter failures resolve false\n- Write plain-only Tauri payloads as text and reject unrelated clipboard text
* fix(clipboard): reject unrelated current browser data
* fix(clipboard): bind fallbacks to copied selection
- Match cached rich HTML to the current Tauri plain-text fallback\n- Preserve nodes when selection changes during an asynchronous cut\n- Reject unrelated current browser HTML before consulting memory
* fix(clipboard): reuse the shared memory payload type
* fix(clipboard): scan design markers linearly
* fix(clipboard): distinguish unavailable and empty reads
* style(clipboard): use includes for marker closure
* test(clipboard): avoid wall-clock marker assertions
Merges the contributor clipboard fallback fix with maintainer follow-ups for browser cut safety and isolated fallback tests. Selections are preserved when clipboard serialization fails, and clipboard fallback tests no longer depend on host APIs.
Merges the contributor fix with maintainer follow-up coverage. MCP results now treat omitted isError as success, scope detection to mcp__ tools, and preserve generic tool error handling.
* feat(app): make crash recovery configurable
- Add an enabled-by-default persisted recovery preference and General settings control
- Stop recovery writes and remove the active document snapshot when disabled
- Suppress startup recovery discovery while the preference is disabled
- Cover disabled persistence and re-enable behavior
* fix(i18n): translate recovery preferences
* fix(app): serialize recovery disable cleanup
- Block re-enabled persistence until pending snapshot removal completes
- Preserve disable generations so stale cleanup cannot reset newer recovery state
- Display runtime-overridden recovery state in Settings
- Deep-clone nested preferences before updating recovery
- Register the Vite-owned MCP child as a worktree-prefixed Portless sibling service\n- Inject HTTPS and WebSocket automation URLs into the browser instead of assuming port 7600\n- Isolate development socket and discovery files while preserving fixed-port non-Portless flows
- Carry normalized tool-name arrays through app and development JSON configuration
- Serialize the legacy CSV format only at child-process environment boundaries
- Bound, validate, trim, and deduplicate development tool policy input
- Keep New tabs provisional so opening or creating a design reuses the active tab
- Separate recent document, storage, menu, worker, and workspace responsibilities
- Add source-aware recents, responsive files UI, loading states, and localized copy
- Preserve native local Open Recent behavior while supporting remote storage history
- Publish explicit effective tool state while retaining disabled tools for Settings
- Classify filesystem writes as side effects and localize category labels
- Stop failed restarts and return precise development control status codes
- Encapsulate app-global runtime state in a testable service
- Serialize health refresh, start, stop, and restart operations
- Validate health metadata and clean state after failures
- Restart the Vite-managed MCP server with the current authentication, root, and tool settings
- Keep the development control endpoint protected by the local token
- Cover explicit no-auth and configured-root environment propagation
- Open multiple selected design files in separate tabs.\n- Support desktop, File System Access, and fallback pickers.\n- Continue opening later selections when one file fails.
- Serialize writable-document autosaves and retain only the newest trailing version
- Preserve saves requested while export or persistence is in flight
- Cover file, storage, retry, and recovery scheduling invariants
* refactor(editor): separate canvas view state
- Classify shared and view-local editor state explicitly
- Let canvas surfaces render supplied view state and report their viewport
- Preserve the existing one-canvas behavior by default
* fix(canvas): preserve loading render state
* feat(editor): model split canvas panes
- Add pure recursive split-tree operations with validated sizes
- Add explicit pane registry and independent view-state cloning
- Cap visible panes and cover close and split behavior
* refactor(editor): group state ownership modules
- Move shared and view state into the editor state namespace
- Model the partition with explicit interfaces and default factories
- Derive runtime view keys from the default view object
* feat(editor): model split canvas panes
- Add pure recursive split-tree operations with validated sizes
- Add explicit pane registry and independent view-state cloning
- Cap visible panes and cover close and split behavior
* feat(editor): add split canvas views
- Render recursive pane layouts with Reka UI splitters and pane-local headers
- Route canvas input, selection, viewport state, and close actions to the active pane
- Repaint every canvas during shared document previews and cover split lifecycle in tests
* fix(editor): clean up inactive pane interactions
- Cancel drag, padding preview, and text editing state when pane focus changes
- Remove duplicate changelog entries introduced while updating master
* feat(code): isolate Design JSX execution
- Transform JSX with the existing Sucrase dependency and execute it in a disposable opaque-origin iframe worker
- Block ambient network capabilities and enforce source, timeout, output, depth, and element limits
- Validate that only bounded plain structured data returns to the application
* feat(code): add editable Design JSX
- Add a lazy CodeMirror editor with JSX syntax support, completion, diagnostics, and bounded scrolling
- Convert validated sandbox output into trusted Design JSX helpers before rendering
- Apply or insert JSX as one undoable graph transaction while preserving dirty drafts
* feat(code): localize JSX editor actions
- Add translated-message fallbacks for editing, applying, inserting, and draft state
- Document the editable JSX workflow in the unreleased changelog
* fix(code): satisfy typed sandbox validation
- Keep the sandbox document terminator literal and preserve optional selection handling under type-aware lint
* test(code): resolve sandbox probes through app aliases
* fix(code): bound sandbox results before cloning
- Enforce string, array, object, depth, element, and byte limits inside the disposable worker
- Retain host-side validation as a second structured-data boundary
* fix(code): keep JSX and HTML editing modes separate
- Switch generated Tailwind output back to OpenPencil JSX before editing
- Close the JSX editor when opening HTML/CSS import and avoid stacking both editors
* feat(code): support authored Design JSX programs
- Allow local constants, function components, arrays, conditionals, fragments, and multiple roots
- Preserve replacement positions for multiple selected roots and reject mixed-parent or locked selections
- Cover multi-root undo, redo, and all-or-nothing rollback
* feat(code): add explicit JSX view mode
- Let authors leave CodeMirror without applying a draft
- Keep the editable surface and HTML/CSS importer mutually exclusive
* feat(code): diagnose unknown JSX vocabulary
- Warn on OpenPencil elements and properties that are absent from the canonical schema
- Surface diagnostics inline through CodeMirror lint markers
* test(code): accept WebKit isolation diagnostics
- Cover the sandbox architecture against Playwright WebKit
- Accept engine-specific wording while preserving the same unavailable-window assertion
* refactor(code): consolidate Design JSX vocabulary
- Drive renderer warnings, completion, and diagnostics from one supported-property schema
- Recognize locally declared components and add focused schema and transform tests
- Replace CodeMirror basicSetup with an explicit feature set and remove the umbrella package
* fix(code): support Design JSX variable helpers
* refactor(code): unify JSX sandbox validation
* fix(code): account for complete sandbox output
* fix(code): preserve locked JSX descendants
* fix(code): preserve JSX sibling order
* fix(code): recompute JSX parent layouts
* feat(code): add live code previews
* test(code): centralize graph assertions
* fix(code): harden live preview sessions
* docs: describe live code editing
* fix(code): update editor accessibility labels
* fix(code): use theme-aware error colors
* fix(dev): stop Vite disconnect error loops
* fix(code): clarify live preview status
* fix(ui): avoid tooltip attribute warnings
* test(code): assert semantic preview status
* refactor(code): remove obsolete editor messages
* fix(code): harden preview concurrency and isolation
* fix(code): cancel stale reset previews
* feat(acp): add reusable MCP connections
- Store named Streamable HTTP connections separately from model providers
- Keep bearer tokens in the credential manager and resolve them per ACP session
- Add localized settings, validation, documentation, and focused coverage
* test(acp): harden MCP connection workflow
- Label credential inputs and confirm destructive connection removal
- Exercise MCP server delivery through an in-memory ACP session
- Extend the browser smoke test to cover accessible input and confirmation flows
* fix(acp): validate MCP connection lifecycle
- Keep non-browser storage initialization in memory and restore the German model copy
- Reject persisted name collisions and invalid draft IDs
- Preserve connections on credential failures and require credentials before enablement
- Show complete user messages with every image immediately after sending
- Analyze up to four bounded images without adding pixels to Design context
- Organize image handling under the extensible attachment domain
- Route bounded selection renders through the optional Vision model
- Return compact text findings without retaining image data in Design chat history
- Bound MCP and AI image exports by their longest pixel edge
- Serialize recovery cleanup with active snapshot writes
- Preserve version ordering across autosave, restore, and cleanup
- Fall back to memory when IndexedDB operations fail
- Persist debounced FIG snapshots for source-less documents in IndexedDB
- Restore or discard orphaned snapshots from the editor startup dialog
- Clear recovery data after successful saves and explicit tab closure
- Redact and bound provider error details in copied logs
- Avoid repeat toasts after locale changes
- Show reasoning effort only for supported providers
- Report credit and output-limit failures through localized toasts and debug logs
- Persist optional provider-specific reasoning effort on model profiles
- Classify insufficient-credit connection tests and cover failure diagnostics
* fix(tauri): prevent Windows font loading crashes
- Return native font files over binary Tauri IPC instead of JSON byte arrays
- Resolve desktop script fallbacks without parsing large system fonts in JavaScript
* fix(core): restore quality checks
- Use the shared Vector primitive for render-bound offsets
- Remove unsupported SLICE handling from SceneGraph rescaling
- Drop an unused generated-text test binding
* chore: address font fix review
- Place the release note under the Fixed heading
- Name fallback resolution options and use the shared Tauri constant
* fix(storage): polish workspace and connection feedback
- Move Refresh into the Storage Workspace header and keep shell theme actions available outside the editor route
- Split native shell and editor menu listeners behind the app shell
- Replace permanent CORS controls and inline connection results with standard toasts and clearer browser guidance
* fix(app): harden native menu routing
- Dispose menu listeners that finish registering after their Vue scope closes
- Mark shell-owned actions in the shared menu schema instead of duplicating IDs
- Cover route-neutral shell action classification
- Load Prism JSX only after exposing the Prism runtime
- Treat unavailable MCP automation as optional during startup
- Connect the desktop automation bridge only after MCP is ready
- Validate ranged thumbnail payloads and S3 bounds
- Invalidate stale previews and expose loading errors
- Document the public document workspace composable
- Load embedded Figma thumbnails through bounded S3 byte-range requests
- Add a headless Vue workspace composable with lazy previews and refresh lifecycle
- Cache local previews and refresh the workspace after saves and synchronization
- Rename first-party API, RPC, JSON, CORS, SVG, JSX, and related identifiers to preserve acronym casing
- Keep upstream and serialized boundary names unchanged
- Add a lint guardrail and migration notes for exported APIs
- Separate model, connection, and advanced settings
- Resolve capabilities and output limits from provider catalogs
- Keep custom model compatibility declarations explicit
- Centralize design-profile eligibility for the selector, role assignment, fallback, and tests
- Keep built-in provider model selection intact while switching saved custom profiles
- Add localized accessible labeling and constrain long profile names
The chat model chip is a dropdown for built-in providers but a static label
for OpenAI-compatible and custom-model setups, so anyone using a custom
endpoint had to open Settings to change models -- even with several models
already configured.
Add a profile switcher that reassigns the design role from the chat panel.
It lists saved profiles that can use tools, shows the profile name rather
than the raw model ID, and badges the vision-capable ones. It writes the
same assignments.design field the Settings dropdown does, so the two stay in
sync.
Only renders when more than one tools-capable profile exists; a single
profile keeps the existing label. Built-in providers keep ProviderModelSelect
unchanged.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>