Releases: A3Boy/dsh-web-tools
Release list
v0.3.5 — DSH 0.1.7 / 0.2.x compatibility
dsh-web-tools v0.3.5 — DSH 0.1.7 / 0.2.x compatibility
第一个正式发行版本。核心是让插件在 DSH 0.1.7+(含 0.2.x) 上重新可用,并解决设置卡片「点了没反应」的体验问题。
修复的公开问题:#6、#7。
合并的社区贡献:PR #8 — 感谢 @Daltonganger。
兼容性
| DSH 运行时 | 状态 |
|---|---|
0.1.0-rc.6 … 0.1.6 |
支持(旧 settings.register 分支保留) |
0.1.7-rc.2(实测运行) |
支持 |
0.2.0-rc.1 / 0.2.0-rc.2(当前 latest 与 next) |
支持(按源码逐项核对) |
0.2.1-alpha.1(alpha) |
peer 区间允许;未做运行验证 |
peerDependencies 中的 DSH 区间已放宽为 ^0.1.0-rc.6 || ^0.2.0-0。原区间 ^0.1.0-rc.6 在 semver 下无法匹配 0.2.x 的预发布版本,会被 DSH 的激活门禁直接拒绝安装/激活。区间语义测试现在使用真实 semver(带 includePrerelease)作为判定基准。
破坏性变更修复
1. 设置服务(Issue #7 问题一)
DSH 0.1.7 移除了 settings.register(),旧实现导致 readConfig() 静默回退到默认值(defaultProvider = exa),表现为 web_search 报 no usable provider、卡片保存报 namespace is not mounted。
- 以 loader 入口配置为源:
apply(ctx, config)→installConfig(ctx, config) - 0.1.7+ 写入走
ctx.settings.update(ns, patch);旧宿主保留service.register分支 Config标注volatile,并用settings.configure({ auto: false })关闭自动生成的空白表单
2. 会话格式 v4(Issue #6)
注入消息使用退役的 { kind: "plugin" },被格式 v4 准入拒收(format v4 message requires a producer-owned source kind),整轮失败。现改为 plugin:dsh-web-tools。回归测试直接驱动宿主自带 codec 的准入路径。
3. UI 图标改名(Issue #7 问题二)
DSH 0.1.7 把 10 个图标从尺寸后缀(IconSearchOutline16)改为笔画后缀(…Regular)。
原先的做法是把旧名补写到 primitives 命名空间上——这永远不会生效:外壳下发的是已冻结的命名空间(Object.freeze(...)),loader 直接保存该引用,因此非严格模式下的赋值静默失败。18 处图标导入始终是 undefined,React 抛 #130 导致设置卡片白屏。而且它躲过了类型检查:仓库 lockfile 锁定的 primitives 0.1.0-rc.6 仍声明旧名,而 pnpm 按放宽后的区间解析到 0.2.0-rc.2,后者已删除旧名。
现在改为解析而非改写:
compat-icons.ts只保留纯解析核心(别名表 +resolveIcon),不 import primitives 包,因此可在纯 Node 下测试icons.ts是唯一绑定点:优先使用宿主仍提供的旧名,否则由*Regularartwork 加标称尺寸合成,再否则回退到空渲染(未知的将来改名只损失一个图标,不会白屏)- 六个组件改为从
icons.ts取图标,产物中不再从平台命名空间读取任何尺寸后缀名 - 移除
tsdown里那段同样作用于冻结命名空间、从未生效的补丁
体验与性能
DSH 0.1.7 的设置写入是「改 profile patch + Loader 对账」,实测 单次 2.3–2.9 秒(读取仅 11–57 ms),且跑在 hmr.runExclusive() 内与热重载互斥。任何「等写入返回再重绘」的做法都必然迟钝——这是旧版(内存 settings 文档)与现在体感差异的根因,所有插件(含 DSH 自带设置页)都要付这个成本。
- 搜索顺序编辑改为乐观更新:点击即重排,写入在后台进行,失败才回滚并报错
- 未确认的意图会压住读请求:否则 3 秒窗口内任意一次读取都会把旧顺序画回来
- 写入串行化,新意图替换待发送意图,避免并发的多次重排
- 右侧显示「保存中…」,区分「已立刻生效」与「后台仍在持久化」
- Brave 配额持久化合并:原先每次搜索都写一次设置(等于每次搜索触发一次 2.5 秒对账,并占用用户编辑所需的同一把锁),现改为值未变不写、最多每 60 秒合并写一次
其它修复
- 供应商行的响应式 CSS 是死代码:注入的规则针对
.wt-provider-row/.wt-provider-meta,但从未被应用,且SettingsRow没有className属性。窄面板下无法换行,固定 220px 的状态块把「加入搜索顺序」按钮挤出卡片,被overflow: hidden裁掉,用户实际点到的是不可交互的状态文字 mountedref 未在挂载时复位:StrictMode 双调用后永久为false,静默禁用平台状态与配额刷新- 移除失效元数据:
dsh.client.inject与peerDependencies中已停更的dsh-client-runtime(最后发布0.1.1-rc.2,无 0.2.x),以及并非客户端插件的dsh-client-ui-slots CLIENT_EXTERNALS修正为真实的平台模块表:原先允许 4 个并非表键的 specifier(cordis、dsh-client-web-react、dsh-client-schema-form、dsh-client-runtime/client,后三者未发布),又遗漏了两个真实表键(dsh-client-store、dsh-client-ui-dockkit)- SearXNG 反向代理(PR #8):
user:password形式的凭据改走Authorization: Basic头而非api_key查询参数;裸401归类为认证失败
验证
- 345 项测试全部通过(0 失败),
typecheck与build通过,GitHub Actionsbuild-and-test绿 - 产物的
lib/与tsc重新生成的结果逐字节一致 - 类型检查在 primitives
0.2.0-rc.2(已删除旧名)下同样通过——修复前此组合会失败 - 对最新 DSH 线做了跨版本契约核对(逐文件哈希 + 声明比对):
dsh-settings逐字节相同、config-editor.edit()未变、app-boot 的 peer 门禁未变、ctx.web/ctx.credentials接口未变、会话格式仍为 v4 且准入代码逐字节相同、settings.section与客户端模块加载契约未变、web-app/dsh-base 中我们补丁所依赖的tool-web与web入口 id 均保留
升级
dsh plugin --profile web update dsh-web-tools若你之前打过本地临时补丁(例如 issue 中给出的图标别名或 kind 改法),请回退本地补丁。
客户端包由外壳以 immutable 缓存下发、只按 rev(文件 mtime/ctime/size)失效,因此升级后请重启 DSH(不只是刷新页面),再强制刷新浏览器。设置页「连接测试与超时设置」里会显示当前页面实际加载的插件版本,可据此确认是否已生效。
已知限制(非阻塞)
- 设置写入约 2.5 秒的延迟来自 DSH 的设置架构本身,插件无法绕过(绕开就意味着不持久化)。界面已通过乐观更新消除体感延迟,但「保存中…」提示会短暂出现
- 若某次重建后文件的 mtime、ctime、size 三者同时不变,外壳不会更新
rev,浏览器会继续使用旧的不可变缓存;正常构建(tsc+tsdown)不会触发这种情况
English summary — First tagged release. Restores the plugin on DSH 0.1.7+ and the 0.2.x line: the settings namespace now originates from the loader entry config and writes through settings.update (fixes the silent exa fallback and namespace is not mounted); Search Mode injects with the producer-owned plugin:dsh-web-tools source kind required by session format v4 (fixes the whole-turn failure); the ten renamed primitives icons are resolved rather than patched onto a frozen namespace, which is why the card could die with React #130 (fixes #6, #7). Peer ranges are widened to ^0.1.0-rc.6 || ^0.2.0-0 so 0.2.x is not refused by the activation gate. Routing edits now paint optimistically because a DSH settings write measures 2.3–2.9s, and Brave quota persistence is coalesced off the search hot path. Also merged is PR #8 (SearXNG HTTP Basic credentials behind a reverse proxy) — thanks @Daltonganger. 345 tests pass; typecheck and build are green in CI; verified against DSH 0.1.7-rc.2 at runtime and audited against 0.2.0-rc.2 source.
v0.3.3 - Built-in Generic Fetch Hardening & DNS SSRF Guard
Security & Hardening
- DNS Resolution & Rebinding SSRF Guard: Expanded \etch-security.ts\ to resolve all A and AAAA DNS records prior to connection and across redirects, strictly blocking any host resolving to private/loopback/cloud metadata IP spaces.
- Embedded Userinfo Rejection: Explicitly rejects URLs containing embedded credentials (\user:password@host) with \WEB_INVALID_URL.
- 100% Local Defuddle Extraction: Enforced \useAsync: false\ during Defuddle parsing to strictly guarantee zero third-party external API calls (e.g. FxTwitter).
- Explicit Timeout Enforcement: Added per-attempt timeout budgeting (\DEFAULT_GENERIC_FETCH_TIMEOUT_MS) and accurate \WEB_TIMEOUT\ classification in Generic Fetch.
- Full Test Matrix: Added unit test coverage for DNS rebinding/resolution SSRF, userinfo rejection, and timeout budgeting (303/303 tests passing).
v0.3.2 - Built-in Generic Web Fetch & Fallback
Fixed
- Built-in Generic Web Fetch (Issue #5): Decoupled web_fetch availability from search-only providers (SearXNG, Brave). The plugin now includes a built-in, zero-API-key HTTP fetcher powered by linkedom and Defuddle markdown extraction.
- Resilient Fallback Hierarchy: Fetch requests attempt native provider extraction (Tavily, Exa, Jina, Firecrawl, Parallel) first, cleanly falling back to built-in generic extraction when native providers are unconfigured or fail.
- SSRF & Redirect Security: Built-in HTTP fetcher strictly validates protocols, rejects private/loopback/cloud metadata (169.254.169.254) IP ranges, and performs per-hop SSRF validation across up to 5 manual redirects.
- Bounded Stream Protection: Implemented a strict 5 MiB stream reader with graceful truncation and unsupported binary MIME filtering.
dsh-web-tools v0.3.1
dsh-web-tools v0.3.1
🐛 Bug Fixes & Improvements / 修复与改进
1. 修复自建免 Key SearXNG 无法检索问题 (#4)
- 修复: 针对自托管免 Key 的 SearXNG 搜索源,修复了在面板未填写 API Key 时由于内部空 Key 检查被错误跳过并提示
no usable provider的问题。 - 文档: 在双语 README 的常见问题(FAQ)中新增了「自建 SearXNG 配置与排错」指南,提示用户在
settings.yml中开启json格式支持。
2. 修复 Tavily 时效与日期过滤参数冲突 (#3)
- 修复: 修复了当使用时效预设(如
this week)时,Tavily 适配器同时发送time_range与衍生计算的start_date/end_date导致 API 报错的问题。现在存在 preset 时优先发送time_range,无 preset 时才发送显式起止日期。
3. 插件市场截图配置清单优化
- 在仓库根目录新增
screenshots.json规范清单,与awesome-dsh-plugin官方市场的最新去中心化截图抓取机制完全对齐。
📦 Installation & Upgrade / 安装与升级
# 升级插件至最新补丁版本
dsh plugin --profile web update dsh-web-tools🧪 Verification / 验证结果
- Unit & Integration Tests: 279 / 279 tests passed.
- Type Checking: Strict TypeScript across Host & Client (0 errors).
- Build: Production bundle compiles cleanly.
dsh-web-tools v0.3.0
dsh-web-tools v0.3.0
🌟 What's New / 核心更新
🚀 1. Native Chrome / Edge CDP Browser Runtime (Zero Browser Extensions)
- 架构革新:彻底告别 MV3 浏览器扩展,全面拥抱 Native Edge / Chrome 独立 Profile + CDP(Chrome DevTools Protocol) 本地架构。
- 纯本地安全:0 外部打包、0 Playwright/Selenium 依赖、Cookie 严格由专用浏览器 Profile 管理,无任何凭证落盘或外传。
- 无头/交互双模自动切换:日常 Agent 搜索与抓取全程
--headless=new纯静默后台运行(0 弹窗、不抢占焦点);仅在设置面板主动发起登录时唤起可视化交互窗口。
📕 2. 小红书 (Xiaohongshu) 原生站内搜索、结构化详情与评论抓取
- 默认原生站内搜索:通过已登录浏览器从真实
/explore搜索框交互进入,自动去除路由前缀,仅输入纯净关键词。 - 结构化笔记与评论高保真解析:深度解析 Vue 响应式
__INITIAL_STATE__.note.noteDetailMap,提取正文、发布时间、互动数据(赞/藏/评/图片数),并逐条提取一级评论与已水合的楼中楼回复。 - 签名 Token 自动恢复:自动保留搜索中的
xsec_token缓存,即使 Agent 访问无 Token 的简化 URL 也能自动补全签名地址。 - 登录态稳定保活:双 Cookie(
a1+web_session)+ 真实/explore页面状态连续保活验证。
🐦 3. Twitter / X GraphQL Network Capture
- CDP 网络抓取:通过 CDP 在导航前监听 X Web 客户端的真实 GraphQL 数据流(
/SearchTimeline与/TweetDetail)。 - 精准提取与 DOM 兜底:严格按目标推文 ID 提取主推文、长文本(
note_tweet优先)、展开t.co短链、提取媒体及互动量;GraphQL 捕获不足或超时时自动无缝降级至 DOM exact-id 补充。
⚡ 4. 8 大 Web Provider 深度能力适配
- 统一
web_search与web_fetch工具标准接口。 - 深度适配 Exa、Tavily、Firecrawl、Parallel、Brave、You.com、Jina、SearXNG 的专属搜索分类、时效、分块、软加权(
boost_domains)与 Clean Markdown 提取。 - 多 API Key 轮询、负载均衡、429 智能冷却与确定性 Fallback 容灾。
📦 Installation & Upgrade / 安装与升级
# 升级插件至最新版
dsh plugin --profile web update dsh-web-tools
# 或重新安装
dsh plugin --profile web add github:A3Boy/dsh-web-tools🧪 Verification / 验证结果
- Unit & Integration Tests: 278 / 278 tests passed.
- Type Checking: Strict TypeScript across Host & Client (0 errors).
- Build: Production bundle compiles cleanly.
dsh-web-tools v0.2.0
Highlights
- Refined Web Search settings UI with clearer provider capabilities, routing behavior, usage labels, and denser visual hierarchy.
- Modernized provider-native search and fetch options, fallback behavior, quota display, and connection diagnostics.
- Added a silent background update check. Future stable GitHub Releases newer than the installed version appear as an in-plugin update notice.
Update
dsh plugin --profile web update dsh-web-toolsWhat's Changed
New Contributors
Full Changelog: https://github.com/A3Boy/dsh-web-tools/commits/v0.2.0