Skip to content

refactor(util): share a browser opener across cli, tui, and core - #51412

Merged
rekram1-node merged 1 commit into
v2from
dependency-audit
Sep 25, 2026
Merged

rekram1-node merged 1 commit into
v2from
dependency-audit

Conversation

@rekram1-node

Copy link
Copy Markdown
Collaborator

Summary

Seven places across cli and tui imported open directly to launch a browser or file manager, each with its own error handling and two of them lazily importing the module by hand. This consolidates them behind a small @opencode/util/open module and makes util the single owner of the dependency.

Changes

  • @opencode/util/open — openUrl(input) parses the target and only launches http:/https: URLs, passing the normalized href to open. openPath(path) covers the working-directory "Open folder" action, which is a filesystem path rather than a URL.
  • Call sites — cli/src/ui/prompt.ts, tui/src/ui/link.tsx, tui/src/routes/session/form.tsx, tui/src/component/dialog-integration.tsx, tui/src/mini/footer.form.tsx, tui/src/app.tsx now use openUrl; tui/src/ui/working-directory-actions.tsx uses openPath. Existing error handling at each site is unchanged.
  • Core MCP OAuth — redirectToAuthorization applies the same http/https check before handing an authorization URL to a client, so every client of the server gets consistent behaviour without reimplementing it.
  • Dependency — open bumped 10.1.2 → 11.0.4, moved from cli/tui into util. A root overrides entry lifts the transitive copies from storybook and lighthouse so the lockfile resolves to exactly one version. open@11 also handles the missing import.meta.url case the bundled binary hits.

Testing

  • packages/util/src/open.test.ts covers the rejection paths for openUrl (unparseable input, file:, javascript:, custom schemes, UNC paths).
  • packages/core/test/mcp-oauth.test.ts adds a case where the authorization server advertises a non-http endpoint and asserts the flow fails with a clear error naming the server.
  • bun run check green; bun typecheck clean in util, cli, tui, core.

Move browser launching into @opencode/util/open so the CLI and TUI stop
importing open directly. openUrl only accepts http and https targets and
openPath handles file manager requests. The core MCP OAuth provider now
applies the same check before handing an authorization URL to a client.

Bump open to 11 and let util own the dependency, with a root override so
the tree resolves to a single copy.
@rekram1-node
rekram1-node merged commit 29ce49d into v2 Sep 25, 2026
10 checks passed
@rekram1-node
rekram1-node deleted the dependency-audit branch September 25, 2026 23:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant