Skip to content

Releases: A3Boy/dsh-web-tools

v0.3.5 — DSH 0.1.7 / 0.2.x compatibility

Choose a tag to compare

@A3Boy A3Boy released this 05 Oct 15:39

dsh-web-tools v0.3.5 — DSH 0.1.7 / 0.2.x compatibility

第一个正式发行版本。核心是让插件在 DSH 0.1.7+(含 0.2.x) 上重新可用,并解决设置卡片「点了没反应」的体验问题。

修复的公开问题:#6、#7。
合并的社区贡献:PR #8 — 感谢 @Daltonganger。

兼容性

DSH 运行时 状态
0.1.0-rc.6 … 0.1.6 支持(旧 settings.register 分支保留)
0.1.7-rc.2(实测运行) 支持
0.2.0-rc.1 / 0.2.0-rc.2(当前 latest 与 next) 支持(按源码逐项核对)
0.2.1-alpha.1(alpha) peer 区间允许;未做运行验证

peerDependencies 中的 DSH 区间已放宽为 ^0.1.0-rc.6 || ^0.2.0-0。原区间 ^0.1.0-rc.6 在 semver 下无法匹配 0.2.x 的预发布版本,会被 DSH 的激活门禁直接拒绝安装/激活。区间语义测试现在使用真实 semver(带 includePrerelease)作为判定基准。

破坏性变更修复

1. 设置服务(Issue #7 问题一)

DSH 0.1.7 移除了 settings.register(),旧实现导致 readConfig() 静默回退到默认值(defaultProvider = exa),表现为 web_search 报 no usable provider、卡片保存报 namespace is not mounted。

  • 以 loader 入口配置为源:apply(ctx, config) → installConfig(ctx, config)
  • 0.1.7+ 写入走 ctx.settings.update(ns, patch);旧宿主保留 service.register 分支
  • Config 标注 volatile,并用 settings.configure({ auto: false }) 关闭自动生成的空白表单

2. 会话格式 v4(Issue #6)

注入消息使用退役的 { kind: "plugin" },被格式 v4 准入拒收(format v4 message requires a producer-owned source kind),整轮失败。现改为 plugin:dsh-web-tools。回归测试直接驱动宿主自带 codec 的准入路径。

3. UI 图标改名(Issue #7 问题二)

DSH 0.1.7 把 10 个图标从尺寸后缀(IconSearchOutline16)改为笔画后缀(…Regular)。

原先的做法是把旧名补写到 primitives 命名空间上——这永远不会生效:外壳下发的是已冻结的命名空间(Object.freeze(...)),loader 直接保存该引用,因此非严格模式下的赋值静默失败。18 处图标导入始终是 undefined,React 抛 #130 导致设置卡片白屏。而且它躲过了类型检查:仓库 lockfile 锁定的 primitives 0.1.0-rc.6 仍声明旧名,而 pnpm 按放宽后的区间解析到 0.2.0-rc.2,后者已删除旧名。

现在改为解析而非改写:

  • compat-icons.ts 只保留纯解析核心(别名表 + resolveIcon),不 import primitives 包,因此可在纯 Node 下测试
  • icons.ts 是唯一绑定点:优先使用宿主仍提供的旧名,否则由 *Regular artwork 加标称尺寸合成,再否则回退到空渲染(未知的将来改名只损失一个图标,不会白屏)
  • 六个组件改为从 icons.ts 取图标,产物中不再从平台命名空间读取任何尺寸后缀名
  • 移除 tsdown 里那段同样作用于冻结命名空间、从未生效的补丁

体验与性能

DSH 0.1.7 的设置写入是「改 profile patch + Loader 对账」,实测 单次 2.3–2.9 秒(读取仅 11–57 ms),且跑在 hmr.runExclusive() 内与热重载互斥。任何「等写入返回再重绘」的做法都必然迟钝——这是旧版(内存 settings 文档)与现在体感差异的根因,所有插件(含 DSH 自带设置页)都要付这个成本。

  • 搜索顺序编辑改为乐观更新:点击即重排,写入在后台进行,失败才回滚并报错
  • 未确认的意图会压住读请求:否则 3 秒窗口内任意一次读取都会把旧顺序画回来
  • 写入串行化,新意图替换待发送意图,避免并发的多次重排
  • 右侧显示「保存中…」,区分「已立刻生效」与「后台仍在持久化」
  • Brave 配额持久化合并:原先每次搜索都写一次设置(等于每次搜索触发一次 2.5 秒对账,并占用用户编辑所需的同一把锁),现改为值未变不写、最多每 60 秒合并写一次

其它修复

  • 供应商行的响应式 CSS 是死代码:注入的规则针对 .wt-provider-row/.wt-provider-meta,但从未被应用,且 SettingsRow 没有 className 属性。窄面板下无法换行,固定 220px 的状态块把「加入搜索顺序」按钮挤出卡片,被 overflow: hidden 裁掉,用户实际点到的是不可交互的状态文字
  • mounted ref 未在挂载时复位:StrictMode 双调用后永久为 false,静默禁用平台状态与配额刷新
  • 移除失效元数据:dsh.client.inject 与 peerDependencies 中已停更的 dsh-client-runtime(最后发布 0.1.1-rc.2,无 0.2.x),以及并非客户端插件的 dsh-client-ui-slots
  • CLIENT_EXTERNALS 修正为真实的平台模块表:原先允许 4 个并非表键的 specifier(cordis、dsh-client-web-react、dsh-client-schema-form、dsh-client-runtime/client,后三者未发布),又遗漏了两个真实表键(dsh-client-store、dsh-client-ui-dockkit)
  • SearXNG 反向代理(PR #8):user:password 形式的凭据改走 Authorization: Basic 头而非 api_key 查询参数;裸 401 归类为认证失败

验证

  • 345 项测试全部通过(0 失败),typecheck 与 build 通过,GitHub Actions build-and-test 绿
  • 产物的 lib/ 与 tsc 重新生成的结果逐字节一致
  • 类型检查在 primitives 0.2.0-rc.2(已删除旧名)下同样通过——修复前此组合会失败
  • 对最新 DSH 线做了跨版本契约核对(逐文件哈希 + 声明比对):dsh-settings 逐字节相同、config-editor.edit() 未变、app-boot 的 peer 门禁未变、ctx.web/ctx.credentials 接口未变、会话格式仍为 v4 且准入代码逐字节相同、settings.section 与客户端模块加载契约未变、web-app/dsh-base 中我们补丁所依赖的 tool-web 与 web 入口 id 均保留

升级

dsh plugin --profile web update dsh-web-tools

若你之前打过本地临时补丁(例如 issue 中给出的图标别名或 kind 改法),请回退本地补丁。

客户端包由外壳以 immutable 缓存下发、只按 rev(文件 mtime/ctime/size)失效,因此升级后请重启 DSH(不只是刷新页面),再强制刷新浏览器。设置页「连接测试与超时设置」里会显示当前页面实际加载的插件版本,可据此确认是否已生效。

已知限制(非阻塞)

  • 设置写入约 2.5 秒的延迟来自 DSH 的设置架构本身,插件无法绕过(绕开就意味着不持久化)。界面已通过乐观更新消除体感延迟,但「保存中…」提示会短暂出现
  • 若某次重建后文件的 mtime、ctime、size 三者同时不变,外壳不会更新 rev,浏览器会继续使用旧的不可变缓存;正常构建(tsc + tsdown)不会触发这种情况

English summary — First tagged release. Restores the plugin on DSH 0.1.7+ and the 0.2.x line: the settings namespace now originates from the loader entry config and writes through settings.update (fixes the silent exa fallback and namespace is not mounted); Search Mode injects with the producer-owned plugin:dsh-web-tools source kind required by session format v4 (fixes the whole-turn failure); the ten renamed primitives icons are resolved rather than patched onto a frozen namespace, which is why the card could die with React #130 (fixes #6, #7). Peer ranges are widened to ^0.1.0-rc.6 || ^0.2.0-0 so 0.2.x is not refused by the activation gate. Routing edits now paint optimistically because a DSH settings write measures 2.3–2.9s, and Brave quota persistence is coalesced off the search hot path. Also merged is PR #8 (SearXNG HTTP Basic credentials behind a reverse proxy) — thanks @Daltonganger. 345 tests pass; typecheck and build are green in CI; verified against DSH 0.1.7-rc.2 at runtime and audited against 0.2.0-rc.2 source.

v0.3.3 - Built-in Generic Fetch Hardening & DNS SSRF Guard

Choose a tag to compare

@A3Boy A3Boy released this 03 Sep 03:08

Security & Hardening

  • DNS Resolution & Rebinding SSRF Guard: Expanded \ etch-security.ts\ to resolve all A and AAAA DNS records prior to connection and across redirects, strictly blocking any host resolving to private/loopback/cloud metadata IP spaces.
  • Embedded Userinfo Rejection: Explicitly rejects URLs containing embedded credentials (\user:password@host) with \WEB_INVALID_URL.
  • 100% Local Defuddle Extraction: Enforced \useAsync: false\ during Defuddle parsing to strictly guarantee zero third-party external API calls (e.g. FxTwitter).
  • Explicit Timeout Enforcement: Added per-attempt timeout budgeting (\DEFAULT_GENERIC_FETCH_TIMEOUT_MS) and accurate \WEB_TIMEOUT\ classification in Generic Fetch.
  • Full Test Matrix: Added unit test coverage for DNS rebinding/resolution SSRF, userinfo rejection, and timeout budgeting (303/303 tests passing).

v0.3.2 - Built-in Generic Web Fetch & Fallback

Choose a tag to compare

@A3Boy A3Boy released this 03 Sep 03:01

Fixed

  • Built-in Generic Web Fetch (Issue #5): Decoupled web_fetch availability from search-only providers (SearXNG, Brave). The plugin now includes a built-in, zero-API-key HTTP fetcher powered by linkedom and Defuddle markdown extraction.
  • Resilient Fallback Hierarchy: Fetch requests attempt native provider extraction (Tavily, Exa, Jina, Firecrawl, Parallel) first, cleanly falling back to built-in generic extraction when native providers are unconfigured or fail.
  • SSRF & Redirect Security: Built-in HTTP fetcher strictly validates protocols, rejects private/loopback/cloud metadata (169.254.169.254) IP ranges, and performs per-hop SSRF validation across up to 5 manual redirects.
  • Bounded Stream Protection: Implemented a strict 5 MiB stream reader with graceful truncation and unsupported binary MIME filtering.

dsh-web-tools v0.3.1

Choose a tag to compare

@A3Boy A3Boy released this 01 Sep 02:54

dsh-web-tools v0.3.1

🐛 Bug Fixes & Improvements / 修复与改进

1. 修复自建免 Key SearXNG 无法检索问题 (#4)

  • 修复: 针对自托管免 Key 的 SearXNG 搜索源,修复了在面板未填写 API Key 时由于内部空 Key 检查被错误跳过并提示 no usable provider 的问题。
  • 文档: 在双语 README 的常见问题(FAQ)中新增了「自建 SearXNG 配置与排错」指南,提示用户在 settings.yml 中开启 json 格式支持。

2. 修复 Tavily 时效与日期过滤参数冲突 (#3)

  • 修复: 修复了当使用时效预设(如 this week)时,Tavily 适配器同时发送 time_range 与衍生计算的 start_date / end_date 导致 API 报错的问题。现在存在 preset 时优先发送 time_range,无 preset 时才发送显式起止日期。

3. 插件市场截图配置清单优化

  • 在仓库根目录新增 screenshots.json 规范清单,与 awesome-dsh-plugin 官方市场的最新去中心化截图抓取机制完全对齐。

📦 Installation & Upgrade / 安装与升级

# 升级插件至最新补丁版本
dsh plugin --profile web update dsh-web-tools

🧪 Verification / 验证结果

  • Unit & Integration Tests: 279 / 279 tests passed.
  • Type Checking: Strict TypeScript across Host & Client (0 errors).
  • Build: Production bundle compiles cleanly.

dsh-web-tools v0.3.0

Choose a tag to compare

@A3Boy A3Boy released this 26 Aug 04:20

dsh-web-tools v0.3.0

🌟 What's New / 核心更新

🚀 1. Native Chrome / Edge CDP Browser Runtime (Zero Browser Extensions)

  • 架构革新:彻底告别 MV3 浏览器扩展,全面拥抱 Native Edge / Chrome 独立 Profile + CDP(Chrome DevTools Protocol) 本地架构。
  • 纯本地安全:0 外部打包、0 Playwright/Selenium 依赖、Cookie 严格由专用浏览器 Profile 管理,无任何凭证落盘或外传。
  • 无头/交互双模自动切换:日常 Agent 搜索与抓取全程 --headless=new 纯静默后台运行(0 弹窗、不抢占焦点);仅在设置面板主动发起登录时唤起可视化交互窗口。

📕 2. 小红书 (Xiaohongshu) 原生站内搜索、结构化详情与评论抓取

  • 默认原生站内搜索:通过已登录浏览器从真实 /explore 搜索框交互进入,自动去除路由前缀,仅输入纯净关键词。
  • 结构化笔记与评论高保真解析:深度解析 Vue 响应式 __INITIAL_STATE__.note.noteDetailMap,提取正文、发布时间、互动数据(赞/藏/评/图片数),并逐条提取一级评论与已水合的楼中楼回复。
  • 签名 Token 自动恢复:自动保留搜索中的 xsec_token 缓存,即使 Agent 访问无 Token 的简化 URL 也能自动补全签名地址。
  • 登录态稳定保活:双 Cookie(a1 + web_session)+ 真实 /explore 页面状态连续保活验证。

🐦 3. Twitter / X GraphQL Network Capture

  • CDP 网络抓取:通过 CDP 在导航前监听 X Web 客户端的真实 GraphQL 数据流(/SearchTimeline 与 /TweetDetail)。
  • 精准提取与 DOM 兜底:严格按目标推文 ID 提取主推文、长文本(note_tweet 优先)、展开 t.co 短链、提取媒体及互动量;GraphQL 捕获不足或超时时自动无缝降级至 DOM exact-id 补充。

⚡ 4. 8 大 Web Provider 深度能力适配

  • 统一 web_search 与 web_fetch 工具标准接口。
  • 深度适配 Exa、Tavily、Firecrawl、Parallel、Brave、You.com、Jina、SearXNG 的专属搜索分类、时效、分块、软加权(boost_domains)与 Clean Markdown 提取。
  • 多 API Key 轮询、负载均衡、429 智能冷却与确定性 Fallback 容灾。

📦 Installation & Upgrade / 安装与升级

# 升级插件至最新版
dsh plugin --profile web update dsh-web-tools

# 或重新安装
dsh plugin --profile web add github:A3Boy/dsh-web-tools

🧪 Verification / 验证结果

  • Unit & Integration Tests: 278 / 278 tests passed.
  • Type Checking: Strict TypeScript across Host & Client (0 errors).
  • Build: Production bundle compiles cleanly.

dsh-web-tools v0.2.0

Choose a tag to compare

@A3Boy A3Boy released this 22 Aug 15:55
4e319e9

Highlights

  • Refined Web Search settings UI with clearer provider capabilities, routing behavior, usage labels, and denser visual hierarchy.
  • Modernized provider-native search and fetch options, fallback behavior, quota display, and connection diagnostics.
  • Added a silent background update check. Future stable GitHub Releases newer than the installed version appear as an in-plugin update notice.

Update

dsh plugin --profile web update dsh-web-tools

What's Changed

  • feat: dsh-web-tools v0.2.0 by @A3Boy in #2

New Contributors

  • @A3Boy made their first contribution in #2

Full Changelog: https://github.com/A3Boy/dsh-web-tools/commits/v0.2.0