Skip to content

Commit 9a1d594

Browse files
committed
Merge main and restore artifact source coverage
2 parents 219dfd6 + 0e9d800 commit 9a1d594

112 files changed

Lines changed: 5321 additions & 474 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"executor": patch
3+
---
4+
5+
Prevent deleted artifacts from briefly reappearing after returning to the artifact gallery.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"executor": patch
3+
---
4+
5+
**Fix: links in generated artifacts (`<a target="_blank">`) did nothing when clicked.** The sandbox iframe deliberately has no `allow-popups`, so the browser blocked the new browsing context and the click went nowhere. A trusted user click is now relayed across the frame boundary to the host's `openLink` capability — guarded by a per-render nonce so generated code cannot forge or observe it — and the host opens only `http`/`https` URLs.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"executor": patch
3+
---
4+
5+
Render artifacts that call integrations or tools with hyphenated slugs.

‎.changeset/cimd-refresh-token.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
---
2+
"@executor-js/api": patch
3+
---
4+
5+
Advertise refresh-token support in OAuth client ID metadata documents.
6+
7+
OAuth providers may reject the `offline_access` scope when the client's
8+
metadata declares only the authorization-code grant. Hosted and local client
9+
metadata now declare both `authorization_code` and `refresh_token`, matching
10+
Executor's dynamic client registration behavior.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"executor": patch
3+
---
4+
5+
Pin CLI browser approval links to `EXECUTOR_WEB_BASE_URL` so a TLS reverse proxy no longer returns an unreachable `http://` URL.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@executor-js/execution": patch
3+
---
4+
5+
Completed MCP execute results now include `toolName` when a script successfully uses exactly one connected tool. Executions that use distinct tools remain unlabeled, and internal call provenance is not exposed in the MCP response.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"executor": patch
3+
---
4+
5+
Return a tool's declared annotations from `tools.schema` and `describe.tool`. Code inside `execute` can now read `requiresApproval`, `approvalDescription` and `mayElicit` without parsing the tool's prose description.

‎.changeset/great-hoops-repeat.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
"@executor-js/plugin-openapi": patch
3+
---
4+
5+
Fetch Google Analytics Data (`analyticsdata`) Discovery from the service's own
6+
host. The central directory does not list the GA4 Data API, so the canonical
7+
`https://www.googleapis.com/discovery/v1/apis/analyticsdata/v1beta/rest` answers
8+
404 and the source fails to import. Same treatment `forms`, `keep` and
9+
`photospicker` already get.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@executor-js/sdk": patch
3+
---
4+
5+
Send HubSpot optional permissions in `optional_scope` for workspace OAuth clients so accounts can connect without optional product features.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@executor-js/plugin-mcp": patch
3+
---
4+
5+
Exclude time spent waiting for elicitation from the MCP tool invocation deadline.

0 commit comments

Comments
 (0)