61 Commits
Author SHA1 Message Date
Ivan Pereira 72ce74541f chore(release): 0.4.0 2026-07-16 16:01:38 +01:00
Ivan Pereira f94c08072e feat(models): add GLM-5.2 and harden reported-model fallback
Perplexity's model fields are inconsistent per model: Claude Sonnet 5 reports the real slug in user_selected_model with display_model "turbo", while GLM-5.2 reports the inverse. Pick whichever field is present and not "turbo", and fall back to the requested model when both are missing or "turbo".

Also add glm_5_2 to KNOWN_MODELS.

Refs #7 (follow-up comment)
2026-07-16 15:59:30 +01:00
Ivan Pereira 11a238a2cb chore(release): 0.3.0 2026-07-14 12:56:19 +01:00
Ivan Pereira 4d9ac2b5dd fix(auth): accept bare session tokens from cookie env vars
parseBrowserAuthInput returns an access-only credential for a bare
__Secure-next-auth.session-token value, which /perplexity-login
--browser accepts but credentialsFromEnvironment rejected because it
required .cookies. Only reject when parsing fails entirely.
2026-07-14 12:54:10 +01:00
Ivan Pereira 17e4267e7f chore: migrate to @earendil-works pi packages
@mariozechner/pi-coding-agent is deprecated in favor of
@earendil-works/pi-coding-agent (github.com/earendil-works/pi).
Import Type from @earendil-works/pi-ai instead of @sinclair/typebox,
which the new ecosystem replaces with plain typebox. Upgrading to
0.80.6 also resolves all 31 open Dependabot alerts from the old
package's transitive dev dependencies.
2026-07-14 12:49:49 +01:00
Ivan Pereira 6158714acf docs: add security policy 2026-07-14 12:42:56 +01:00
Ivan Pereira 3cfe36db0b chore: add dependabot config for npm and github-actions 2026-07-14 12:42:56 +01:00
Ivan Pereira a24b4e5b05 ci: harden workflows against token exfiltration
Disable checkout credential persistence so repository-controlled code
run by npm ci/test cannot read GITHUB_TOKEN from .git/config, and pin
actions to full commit SHAs to guard against mutable-tag supply-chain
attacks.
2026-07-14 12:42:55 +01:00
Ivan Pereira e5f054272d ci: restrict npm publish tags to main 2026-07-14 12:19:06 +01:00
Ivan Pereira 16df0a56c6 test(auth): exercise desktop token extraction on CI 2026-07-14 12:09:24 +01:00
Ivan Pereira 6a8cf7139f chore(release): 0.2.5 2026-07-14 12:07:11 +01:00
Ivan Pereira 5a3a1e82bf docs: backfill changelog and add release verification 2026-07-14 12:06:42 +01:00
Ivan Pereira 838644734f fix: address auth and source handling review findings 2026-07-14 12:06:33 +01:00
Ivan Pereira e6a194bd85 ci: run typecheck and tests before npm publish 2026-07-14 03:26:33 +01:00
Ivan Pereira 5b6bb41c3f refactor: drop dead model/limit plumbing and unused render helper
resolveSearchDefaults no longer accepts a per-call model override and
SearchParams no longer carries limit; neither was reachable from the
tool schema (limit is applied client-side in formatForLLM). Also fold
asPositiveNumber into asPositiveInteger and simplify recency matching.
2026-07-14 03:26:27 +01:00
Ivan Pereira 39d977c403 refactor(auth): route browser paste login through /perplexity-login
The perplexity_search tool no longer prompts for pasted browser
credentials mid-search; /perplexity-login --browser is the single
entry point for that flow. Drop the now-unused promptForBrowserAuth
option and its Cloudflare-challenge fallback from authenticate().
2026-07-14 03:26:00 +01:00
Ivan Pereira f8919e254c refactor(auth): separate browser credential parsing 2026-06-24 17:51:37 +01:00
Ivan Pereira 2b107f13d1 chore(release): 0.2.4 2026-06-24 17:34:14 +01:00
Ivan Pereira 8d889add43 fix(auth): address browser cookie review comments 2026-06-24 17:31:53 +01:00
Ivan Pereira d01cfc86bc feat(auth): add browser cookie login fallback 2026-06-24 17:19:38 +01:00
Ivan Pereira 388235c602 docs(agents): clean project instructions 2026-06-24 16:09:19 +01:00
Ivan Pereira 4a7cf66c42 chore(release): 0.2.3 2026-06-24 15:38:44 +01:00
Ivan Pereira bbb5623f25 refactor(runtime): replace Bun dependency with Node fetch
Run Perplexity search and auth requests through pi's Node runtime instead of
shelling out to Bun. Move development and CI commands to npm, add a Node test
build path, and keep OTP auth fail-fast when Set-Cookie headers are not
available.
2026-06-23 15:51:16 +01:00
Ivan Pereira 142640d96c fix(auth): avoid CSRF challenges during OTP login 2026-06-22 11:33:40 +01:00
Ivan Pereira 4e77f38d5d fix(config): respect configured model 2026-05-11 15:16:42 +01:00
Ivan Pereira 18e38ac89a 0.2.0 2026-03-21 22:26:28 +00:00
Ivan Pereira e1a0a17f04 docs: add CHANGELOG.md 2026-03-21 21:34:17 +00:00
Ivan Pereira 0f301e7f47 fix(test): isolate tests from mock.module cache pollution
mock.module() in index-execute.test.ts permanently poisons Bun's
module cache — mock.restore() does not undo it in Bun 1.3.11.

Use cache-busted dynamic imports (../src/mod.ts?t=${Date.now()}) in
beforeEach for the three affected test files so each test gets a
fresh, unpoisoned module instance.
2026-03-21 21:29:00 +00:00
Ivan Pereira 96a3246d1e fix(search): restore error rendering and safe error handling
- Re-add isError flag to error details so renderPerplexityResult
  shows error styling instead of green success rows
- Use errorMessage() for unknown errors instead of unsafe cast
- Trim whitespace-only PI_PERPLEXITY_MODEL env var values
- Add comment explaining clearToken() on AUTH rejection
2026-03-21 21:28:51 +00:00
Ivan Pereira fcc7613edc fix(config): simplify current model label 2026-03-21 21:02:44 +00:00
Ivan Pereira 041d30651a fix(config): apply defaults to perplexity UI 2026-03-21 20:54:41 +00:00
Ivan Pereira 11c543c0de 0.1.3 2026-02-23 18:07:48 +00:00
Ivan Pereira 89b4ea50d0 Add pi-extension keyword 2026-02-23 18:07:36 +00:00
Ivan Pereira a9007cd69a 0.1.2 2026-02-23 12:58:02 +00:00
Ivan Pereira 6ef681adb1 Fix install commands in README 2026-02-23 12:43:58 +00:00
Ivan Pereira 048ec32a3c Strip v prefix in version check 2026-02-23 12:40:55 +00:00
Ivan Pereira 12dcd11384 Fix tag pattern to match v-prefixed tags 2026-02-23 12:40:43 +00:00
Ivan Pereira ef81cdee18 0.1.1 2026-02-23 12:40:25 +00:00
Ivan Pereira 29723c50e3 Upgrade npm to latest before publish for OIDC support 2026-02-23 12:36:34 +00:00
Ivan Pereira 6737807356 Switch to OIDC trusted publishing, drop NPM_TOKEN 2026-02-23 12:35:44 +00:00
Ivan Pereira 10c2b1cf6b Add npm publish GitHub Actions workflow 2026-02-23 12:32:53 +00:00
Ivan Pereira f375b9bf9c Remove ToS link from disclaimer 2026-02-23 12:22:52 +00:00
Ivan Pereira 66f4fee0a7 Remove architecture doc 2026-02-23 11:16:50 +00:00
Ivan Pereira 45dcfe21d9 Remove project structure from README 2026-02-23 11:16:22 +00:00
Ivan Pereira 3f7fda1e2c Add disclaimer to README 2026-02-23 11:15:18 +00:00
Ivan Pereira 560ff5df75 Rewrite README for GitHub 2026-02-23 11:06:24 +00:00
Ivan Pereira 043c83a722 Add npm publish metadata and MIT license 2026-02-23 11:06:22 +00:00
Ivan Pereira 4a49cbf930 Replace real captured JWE token with fake fixture
The REAL_JWE_TOKEN constant in otp-flow.test.ts contained an actual
token captured from a live Perplexity auth response. Replace with a
structurally valid but non-functional placeholder.
2026-02-23 10:51:40 +00:00
Ivan Pereira a01f0681a0 Document design decisions; update plan to reflect dropped jwt.ts 2026-02-23 10:49:49 +00:00
Ivan Pereira 431a814e9a Add asPositiveInteger helper, use for limit display 2026-02-23 10:49:46 +00:00
Ivan Pereira 56ef5533a3 Standardize ellipsis to … in snippet truncation 2026-02-23 10:49:43 +00:00
Ivan Pereira 909145de94 Remove closure cancel flags from login command
canceledAtEmailPrompt and canceledAtOtpPrompt were closure booleans
set inside prompt callbacks to detect user cancellation after the
fact. Fragile if authenticate ever retries prompts or changes order.

In the command context both prompt functions are always provided, so
AuthError(NO_TOKEN) unambiguously means the user declined to enter
required input. Check the error code directly instead.
2026-02-23 10:49:39 +00:00
Ivan Pereira 63eb22316a Replace brittle error text detection with isError flag
renderPerplexityResult was pattern-matching content text prefixes
to decide whether to render in error style. This was tightly coupled
to exact message strings in index.ts — a wording change would
silently break the error styling.

Set isError: true in details on every error return path in execute,
and check details.isError in the renderer instead.
2026-02-23 10:49:33 +00:00
Ivan Pereira 2c5b558271 Extract shared Perplexity API constants to src/constants.ts
PERPLEXITY_USER_AGENT and PERPLEXITY_API_VERSION were duplicated
in auth/login.ts and search/client.ts. Centralise both so updates
only need to happen in one place.
2026-02-23 10:49:23 +00:00
Ivan Pereira 76dbc20064 Harden token storage and declare Bun runtime
Enforce 0600 permissions after every auth token write so existing files
with broader modes are corrected.

Add a regression test for the permission hardening path and document the
Bun runtime dependency used by the Node/jiti search subprocess path.
Also declare bun in package dependencies and engines.
2026-02-23 10:47:05 +00:00
Ivan Pereira a3ddb02a65 Add README 2026-02-18 08:06:19 +00:00
Ivan Pereira 501935fe1c Simplify auth and search client, drop local JWT expiry tracking
Auth:
- Remove jwt.ts — stop decoding JWT exp claims locally
- Simplify OTP login: direct token extraction from verify response,
  remove CookieJar, BFS token extraction, session fallback, CF bypass
- Storage: drop expires field, store token-only; clear on 401/403
- Single auth path: try stored token → macOS app → OTP fallback

Search client:
- Remove Cloudflare subprocess fallback (fetchViaBunRuntime)
- Remove streamFromText, isCloudflareChallenge, BunFetchResult
- Simplify SSE fetch to single fetch() call with abort signal
- Let server validate tokens; clear cache on auth errors

Render:
- Extract shared utilities (asString, truncate) to render/util.ts
- Simplify call.ts and result.ts to import from shared module

Tests:
- Remove jwt.test.ts (module deleted)
- Add otp-flow.test.ts for email OTP authentication
- Simplify login and client tests for reduced code paths

Add debug scripts and plan documents.
2026-02-18 08:03:39 +00:00
Ivan Pereira f42531b07c Implement perplexity login/render modules and harden OAuth search flow 2026-02-17 08:25:56 +00:00
Ivan Pereira 39b8ee6b57 Add OTP fallback auth and progress handoff log 2026-02-16 18:51:09 +00:00
Ivan Pereira 86b0c37a08 Add .gitignore, untrack .env and node_modules 2026-02-16 18:44:09 +00:00
Ivan Pereira 47878d9962 Initial commit 2026-02-16 18:42:03 +00:00