Skip to content

Browser toolbox C: credentialed acting over web_host - #26

Draft
josephschorr wants to merge 2 commits into
pr/browser-bfrom
pr/browser-c
Draft

josephschorr wants to merge 2 commits into
pr/browser-bfrom
pr/browser-c

Conversation

@josephschorr

Copy link
Copy Markdown
Member

Gates the browser acting tools on a session-only web_host slot (External on the live page host), adds the no-secret credential filler with an in-memory hold (blanking filled fields from observation until navigation), request_human_step/login_human_step for in-page human actions, and persistence/re-injection of credentialed browser state across reap and wake.

This is part of the stacked browser toolbox series (A→E), to be reviewed and merged bottom-up. Stacked on B.

Draft: the integration + e2e execution legs (envtest + SpiceDB) are pending — the local box is under sustained load. Full build, go vet -tags=integration/e2e, manifest-drift, and all changed packages under -race are green. The gate will run and this will be marked ready before merge.

@vercel

vercel Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
openagentprimitives Ready Ready Preview Oct 11, 2026 4:02am UTC

Request Review

…thout leaking them

Adds the web_host session-only slot, the browser acting tools gated External on the live page host, query_logins and the toolbox prompt fragment, and the no-secret credential filler with an in-memory hold — blanking filled fields from observation (by node liveness) until real navigation.
… reap/wake

Adds request_human_step and the login_human_step category (the code carried as free text, typed into the page by the runner and guarded from renderers), SpiceDB-escaped web_host ids, the unattended-grant no-identity backstop, and persistence/re-injection of credentialed browser state across reap and wake.

This branch was successfully deployed

1 active deployment
Preview — 6ff159d6 Deployed Oct 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant