Hardcode is_incognito: true in the Perplexity request and remove the
toggle surface: the incognito tool parameter, PI_PERPLEXITY_INCOGNITO
env var, config file field, /perplexity-config prompt, and TUI status
indicators. Config and resolveDefaultModel are now model-only.
Supersedes the incognito portion of PR #4.
Co-authored-by: Ivan Pereira <183991+ivanrvpereira@users.noreply.github.com>
parseBrowserAuthInput returns an access-only credential for a bare
__Secure-next-auth.session-token value, which /perplexity-login
--browser accepts but credentialsFromEnvironment rejected because it
required .cookies. Only reject when parsing fails entirely.
resolveSearchDefaults no longer accepts a per-call model override and
SearchParams no longer carries limit; neither was reachable from the
tool schema (limit is applied client-side in formatForLLM). Also fold
asPositiveNumber into asPositiveInteger and simplify recency matching.
The perplexity_search tool no longer prompts for pasted browser
credentials mid-search; /perplexity-login --browser is the single
entry point for that flow. Drop the now-unused promptForBrowserAuth
option and its Cloudflare-challenge fallback from authenticate().
Run Perplexity search and auth requests through pi's Node runtime instead of
shelling out to Bun. Move development and CI commands to npm, add a Node test
build path, and keep OTP auth fail-fast when Set-Cookie headers are not
available.
mock.module() in index-execute.test.ts permanently poisons Bun's
module cache — mock.restore() does not undo it in Bun 1.3.11.
Use cache-busted dynamic imports (../src/mod.ts?t=${Date.now()}) in
beforeEach for the three affected test files so each test gets a
fresh, unpoisoned module instance.
The REAL_JWE_TOKEN constant in otp-flow.test.ts contained an actual
token captured from a live Perplexity auth response. Replace with a
structurally valid but non-functional placeholder.
Enforce 0600 permissions after every auth token write so existing files
with broader modes are corrected.
Add a regression test for the permission hardening path and document the
Bun runtime dependency used by the Node/jiti search subprocess path.
Also declare bun in package dependencies and engines.