Klipp 0.5.0
Security
- The chat answers only a browser on this machine at
localhost. A page that rebinds its own
name to127.0.0.1, a tunnel and a reverse proxy were let in before, since they connect from
loopback; now the address the request was sent to, and any forwarding headers, count too. chat.allowRemotenow pairs each device once, with a code the dev server prints, instead of
letting anyone on the network in.- Codex is confined to the repository: a permission profile lets it read only the repository,
the system files programs need and its own install, and the commands it runs get only a core
environment. It could read the whole disk before. - Agents no longer get the dev server's whole environment, only what they need to start and log
in.chat.passEnvpasses more by name. - Claude is also denied
.envrc,.dev.vars, Terraform variables and state, keystores,
.pypirc,.netrc,.pgpass,credentials*.jsonand.git/config. - The server files only a ticket the agent proposed in the conversation, once, while it waits on
the user; the browser adds only the page details. Before, it filed any title and body. - A GitHub token goes only to its own host: github.com tokens to github.com, Enterprise tokens
to their host, nothing to GitLab or other remotes. Filed issue addresses must behttps. - Console errors are sent by name and message; objects logged with them are no longer
serialized into the agent's context. - The page context is escaped so it can't close its own tag, and the agent is told to treat it
as data. - Claude's MCP token moved from the command line to a file only you can read.
- A crafted
?klipp=link can no longer put a link in Klipp's bubble.
Added
chat.allowRemotepairing,chat.pairingCodefor a fixed code,chat.passEnvand
chat.maxRuns(four agent runs at once by default).- The ticket card shows the whole ticket and the page details that will be added, before
anyone files it. - HTTP/2 (
server.https) support: requests carry:authorityinstead ofHost. - Files with decorators or import attributes (
withand the olderassert) are stamped; a
file that can't be parsed is reported instead of silently skipped. vite build --ssrwithKLIPP=1stamps the server bundle too, so hydrated markup keeps its
IDs.
Changed
- The Vite peer range is
^5.4.12 || ^6.0.9 || ^7 || ^8: the first releases of 5 and 6 that
check theHostheader. - Escape closes Klipp when focus is in Klipp; on the page, Escape is the page's again.
- On Windows the chat says to run the dev server in WSL, instead of that it can't find the
agent. vite previewserves the chat only for a build made with Klipp.- The manifest no longer includes the absolute repository root.
git statusfor the manifest runs in the background, so a large repository doesn't stall the
dev server.- Self-hosted remotes on a custom port keep the port in permalinks.
Fixed
- A page-tool call that threw left the agent waiting for 30 minutes; it now gets an error.
- A ticket card left over from a turn that ended no longer takes the user's next message.
- A message sent while the previous one was still collecting its element's details could run
alongside it. - Malformed lines from an agent, or malformed MCP requests, could crash the dev server.
- The MCP bridge and running agents are stopped when the dev server closes or restarts.
- More of Klipp's events stop at its own root: pointer and mouse moves, touch moves,
composition, drag and drop.
Install
# npm 12 and later: allow URL dependencies for this project first
npm config set allow-remote root --location=project
npm install -D https://github.com/perara/klipp/releases/download/v0.5.0/klipp-0.5.0.tgz