Skip to content

fix: native click input and Windows Skill diagnostics (1.2.4) - #34

Merged
254808127 merged 2 commits into
mainfrom
fix/native-click-input
Sep 21, 2026
Merged

254808127 merged 2 commits into
mainfrom
fix/native-click-input

Conversation

@254808127

Copy link
Copy Markdown
Collaborator

Summary

  • Replace HTMLElement.click() with native CDP mouse move/press/release input. The old implementation can report success while window.open() receives no user activation and is blocked.
  • Keep the original DOM object, scroll and hit-test it, then recheck the same object/point after hover. Reject hidden, disabled, inert, covered, moved or replaced targets before pressing; preserve input errors and release remote objects.
  • Keep explicit page routing and the existing success/error JSON contracts. No JavaScript-click fallback, automatic retries, inferred navigation, implicit tab switching, or user-gesture grant to arbitrary eval.
  • Include the independently validated Windows Skill guidance: run the installed executable's doctor directly; use the harness's existing Bash tool when PowerShell omits stdout/stderr; require the actual readiness JSON. Keep normal execution policy and sandbox permissions.
  • Synchronize Cargo, lockfile and both bootstrap defaults to 1.2.4. This PR does not publish a release or upgrade installations.

Commits

  1. Native click implementation, regression tests, CI browser coverage, documentation and 1.2.4 version metadata.
  2. Windows Skill diagnostic entry point and missing-output guidance.

Verification before PR

  • New popup regression fails on the old implementation: isTrusted=false, user activation false, popup not opened. It passes with native input on full Chrome 151.0.7922.108.
  • cargo test --all-targets --locked: 60 passed; the 3 opt-in browser tests were run separately.
  • Same full suite with invalid inherited proxy settings and --offline: 60 passed.
  • Real-browser suite: 3/3 passed on full Chrome and 3/3 passed on the previously used headless-shell 145.0.7632.6. Assertions check trusted events/user activation, not just popup count.
  • Release build and cargo test --release --locked --test page_targets_browser -- --ignored --nocapture: 3/3 passed. Includes 23 actionability scenarios, same-tab navigation, unchanged arbitrary-eval semantics, popup discovery, explicit reconnects and closed-target no-fallback behavior.
  • cargo fmt --all -- --check, cargo clippy --all-targets --locked -- -D warnings, and git diff --check: passed.
  • Four-file release version gate: 1.2.4. Release-version tests 19 passed; published bootstrap-selection tests 19 passed.
  • Combined 1.2.4/Skill local verification: 74 checks passed, including 10 real shell commands under Windows PowerShell's Restricted process policy and existing Git Bash, against a loopback-only mock API. Valid credentials/API, API failure, missing credentials, and task-local JSON capture all preserve actual readiness. The Skill structure validator passed.
  • The same two Skill guidance files had previously passed a bounded real WorkBuddy 5.5.3.0 / CLI 1.2.3 read-only diagnostic. No new WorkBuddy business run was performed for this PR; local combination checks are not an agent end-to-end pass.
  • Self-review completed before submission; no outstanding findings identified within this change's scope.

Boundaries

  • Selector scope remains main-document CSS; no iframe/shadow-root traversal is added.
  • A successful click means native input was dispatched, not that site logic completed the task. The final check and press cannot atomically lock a changing page.
  • WorkBuddy's internal PowerShell output handling is not modified; the Skill uses existing supported tools and does not lower execution policy or install another shell.
  • Full Chrome coverage is now explicitly invoked by CI, since headless-shell alone can allow untrusted popups. Remote CI and Linux/macOS builds still need to complete after this PR opens.
  • No production sessions, user credentials, historical evaluation results or deployed test-machine versions are changed.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T08:46:48.510578Z 9fee204 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@254808127
254808127 merged commit 8b88003 into main Sep 21, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant