Commit Graph
57 Commits
Author SHA1 Message Date
Ivan Pereira a24b4e5b05 ci: harden workflows against token exfiltration
Disable checkout credential persistence so repository-controlled code
run by npm ci/test cannot read GITHUB_TOKEN from .git/config, and pin
actions to full commit SHAs to guard against mutable-tag supply-chain
attacks.
2026-07-14 12:42:55 +01:00
Ivan Pereira e5f054272d ci: restrict npm publish tags to main 2026-07-14 12:19:06 +01:00
Ivan Pereira 16df0a56c6 test(auth): exercise desktop token extraction on CI 2026-07-14 12:09:24 +01:00
Ivan Pereira 6a8cf7139f chore(release): 0.2.5 2026-07-14 12:07:11 +01:00
Ivan Pereira 5a3a1e82bf docs: backfill changelog and add release verification 2026-07-14 12:06:42 +01:00
Ivan Pereira 838644734f fix: address auth and source handling review findings 2026-07-14 12:06:33 +01:00
Ivan Pereira e6a194bd85 ci: run typecheck and tests before npm publish 2026-07-14 03:26:33 +01:00
Ivan Pereira 5b6bb41c3f refactor: drop dead model/limit plumbing and unused render helper
resolveSearchDefaults no longer accepts a per-call model override and
SearchParams no longer carries limit; neither was reachable from the
tool schema (limit is applied client-side in formatForLLM). Also fold
asPositiveNumber into asPositiveInteger and simplify recency matching.
2026-07-14 03:26:27 +01:00
Ivan Pereira 39d977c403 refactor(auth): route browser paste login through /perplexity-login
The perplexity_search tool no longer prompts for pasted browser
credentials mid-search; /perplexity-login --browser is the single
entry point for that flow. Drop the now-unused promptForBrowserAuth
option and its Cloudflare-challenge fallback from authenticate().
2026-07-14 03:26:00 +01:00
Ivan Pereira f8919e254c refactor(auth): separate browser credential parsing 2026-06-24 17:51:37 +01:00
Ivan Pereira 2b107f13d1 chore(release): 0.2.4 2026-06-24 17:34:14 +01:00
Ivan PereiraandGitHub 3e3a110252 Merge pull request #5 from ivanrvpereira/feat/browser-cookie-auth
feat(auth): add browser cookie login fallback
2026-06-24 17:33:04 +01:00
Ivan Pereira 8d889add43 fix(auth): address browser cookie review comments 2026-06-24 17:31:53 +01:00
Ivan Pereira d01cfc86bc feat(auth): add browser cookie login fallback 2026-06-24 17:19:38 +01:00
Ivan Pereira 388235c602 docs(agents): clean project instructions 2026-06-24 16:09:19 +01:00
Ivan Pereira 4a7cf66c42 chore(release): 0.2.3 2026-06-24 15:38:44 +01:00
Ivan Pereira bbb5623f25 refactor(runtime): replace Bun dependency with Node fetch
Run Perplexity search and auth requests through pi's Node runtime instead of
shelling out to Bun. Move development and CI commands to npm, add a Node test
build path, and keep OTP auth fail-fast when Set-Cookie headers are not
available.
2026-06-23 15:51:16 +01:00
Ivan Pereira 142640d96c fix(auth): avoid CSRF challenges during OTP login 2026-06-22 11:33:40 +01:00
Ivan Pereira 4e77f38d5d fix(config): respect configured model 2026-05-11 15:16:42 +01:00
Ivan Pereira 18e38ac89a 0.2.0 2026-03-21 22:26:28 +00:00
Ivan PereiraandGitHub 692d39e618 Merge pull request #3 from ivanrvpereira/issue-2-expose-model-preference
feat: expose model preference and incognito as configurable parameters
2026-03-22 00:25:55 +02:00
Ivan Pereira e1a0a17f04 docs: add CHANGELOG.md 2026-03-21 21:34:17 +00:00
Ivan Pereira 0f301e7f47 fix(test): isolate tests from mock.module cache pollution
mock.module() in index-execute.test.ts permanently poisons Bun's
module cache — mock.restore() does not undo it in Bun 1.3.11.

Use cache-busted dynamic imports (../src/mod.ts?t=${Date.now()}) in
beforeEach for the three affected test files so each test gets a
fresh, unpoisoned module instance.
2026-03-21 21:29:00 +00:00
Ivan Pereira 96a3246d1e fix(search): restore error rendering and safe error handling
- Re-add isError flag to error details so renderPerplexityResult
  shows error styling instead of green success rows
- Use errorMessage() for unknown errors instead of unsafe cast
- Trim whitespace-only PI_PERPLEXITY_MODEL env var values
- Add comment explaining clearToken() on AUTH rejection
2026-03-21 21:28:51 +00:00
Ivan Pereira fcc7613edc fix(config): simplify current model label 2026-03-21 21:02:44 +00:00
Ivan Pereira 041d30651a fix(config): apply defaults to perplexity UI 2026-03-21 20:54:41 +00:00
Ivan Pereira 11c543c0de 0.1.3 2026-02-23 18:07:48 +00:00
Ivan Pereira 89b4ea50d0 Add pi-extension keyword 2026-02-23 18:07:36 +00:00
Ivan Pereira a9007cd69a 0.1.2 2026-02-23 12:58:02 +00:00
Ivan PereiraandGitHub 2d5bf1ef75 Simplify README description for pi extension 2026-02-23 12:49:07 +00:00
Ivan Pereira 6ef681adb1 Fix install commands in README 2026-02-23 12:43:58 +00:00
Ivan Pereira 048ec32a3c Strip v prefix in version check 2026-02-23 12:40:55 +00:00
Ivan Pereira 12dcd11384 Fix tag pattern to match v-prefixed tags 2026-02-23 12:40:43 +00:00
Ivan Pereira ef81cdee18 0.1.1 2026-02-23 12:40:25 +00:00
Ivan Pereira 29723c50e3 Upgrade npm to latest before publish for OIDC support 2026-02-23 12:36:34 +00:00
Ivan Pereira 6737807356 Switch to OIDC trusted publishing, drop NPM_TOKEN 2026-02-23 12:35:44 +00:00
Ivan Pereira 10c2b1cf6b Add npm publish GitHub Actions workflow 2026-02-23 12:32:53 +00:00
Ivan Pereira f375b9bf9c Remove ToS link from disclaimer 2026-02-23 12:22:52 +00:00
Ivan Pereira 66f4fee0a7 Remove architecture doc 2026-02-23 11:16:50 +00:00
Ivan Pereira 45dcfe21d9 Remove project structure from README 2026-02-23 11:16:22 +00:00
Ivan Pereira 3f7fda1e2c Add disclaimer to README 2026-02-23 11:15:18 +00:00
Ivan Pereira 560ff5df75 Rewrite README for GitHub 2026-02-23 11:06:24 +00:00
Ivan Pereira 043c83a722 Add npm publish metadata and MIT license 2026-02-23 11:06:22 +00:00
Ivan Pereira 4a49cbf930 Replace real captured JWE token with fake fixture
The REAL_JWE_TOKEN constant in otp-flow.test.ts contained an actual
token captured from a live Perplexity auth response. Replace with a
structurally valid but non-functional placeholder.
2026-02-23 10:51:40 +00:00
Ivan Pereira a01f0681a0 Document design decisions; update plan to reflect dropped jwt.ts 2026-02-23 10:49:49 +00:00
Ivan Pereira 431a814e9a Add asPositiveInteger helper, use for limit display 2026-02-23 10:49:46 +00:00
Ivan Pereira 56ef5533a3 Standardize ellipsis to … in snippet truncation 2026-02-23 10:49:43 +00:00
Ivan Pereira 909145de94 Remove closure cancel flags from login command
canceledAtEmailPrompt and canceledAtOtpPrompt were closure booleans
set inside prompt callbacks to detect user cancellation after the
fact. Fragile if authenticate ever retries prompts or changes order.

In the command context both prompt functions are always provided, so
AuthError(NO_TOKEN) unambiguously means the user declined to enter
required input. Check the error code directly instead.
2026-02-23 10:49:39 +00:00
Ivan Pereira 63eb22316a Replace brittle error text detection with isError flag
renderPerplexityResult was pattern-matching content text prefixes
to decide whether to render in error style. This was tightly coupled
to exact message strings in index.ts — a wording change would
silently break the error styling.

Set isError: true in details on every error return path in execute,
and check details.isError in the renderer instead.
2026-02-23 10:49:33 +00:00
Ivan Pereira 2c5b558271 Extract shared Perplexity API constants to src/constants.ts
PERPLEXITY_USER_AGENT and PERPLEXITY_API_VERSION were duplicated
in auth/login.ts and search/client.ts. Centralise both so updates
only need to happen in one place.
2026-02-23 10:49:23 +00:00