Skip to content

v1.0.1

Choose a tag to compare

@vaniteav vaniteav released this 14 Jun 01:09
· 24 commits to main since this release

Added

  • Eight browser tools: browser_scroll, browser_key, browser_hover, browser_drag, browser_upload_file, browser_console, browser_network, browser_dialog
  • Capture infrastructure (CaptureState) — console logs, network requests, and dialog handling collected automatically and surviving browser restarts
  • browser_click accepts optional x/y to click by viewport position (no selector) — for strict-CSP and screenshot-driven flows

Changed

  • Custom search providers now require browserExt.trustCustomProviders: true to load — their transforms run arbitrary code, so they stay inert until trusted

Removed

  • Dead code: unused Result<T> and findCacheByUrl()

Fixed

  • browser_back observes same-document pushState (SPA) navigation (waits on popstate, not load)
  • browser_tab_close runs the tab's unload lifecycle (pagehide) before switching
  • fetch_content revalidates every redirect hop (see Security)
  • Firefox/Playwright compatibility for browser_hover, browser_scroll, browser_key, browser_type

Security

  • fetch_content SSRF guard — http/https only; rejects loopback/private/link-local/cloud-metadata IPs on the resolved host and every redirect hop
  • Custom-provider code (new Function) runs only with browserExt.trustCustomProviders: true (off by default)
  • browser_upload_file honors browserExt.allowedUploadRoots when set — symlink-safe, so paths can't escape an allowed root