Skip to content

fix(mistral): Browser-access failures, and added recovery controls - #143

Closed
sgogriff wants to merge 8 commits into
onllm-dev:mainfrom
sgogriff:mistral
Closed

sgogriff wants to merge 8 commits into
onllm-dev:mainfrom
sgogriff:mistral

Conversation

@sgogriff

Copy link
Copy Markdown
Contributor

Follow-up to #138. Browser-access failures could leave Mistral showing stale usage until a long backoff elapsed, even after access was granted. This PR fixes this and adds UI controls for users.

Changes

  • Distinguish browser permissions, credential-store failures, missing sessions, and rejected sessions with sanitized diagnostics.
  • Add explicit retry support, retaining source/account selection, coalescing requests, and respecting cooldowns and server rate limits.
  • Add compact recovery controls to the dashboard and menubar. The native macOS menubar can open the existing browser-access picker and retry after verified access.
  • Use content-based recovery asset URLs so updated controls appear after same-version redeploys.
  • Cover cancellation, stale feedback, duplicate refresh prevention, manager lifecycle, and native callback completion after host destruction.

Validation

  • Full ./app.sh --test race suite passed before and after merging current upstream main.
  • go vet ./... and production ./app.sh --build passed on the merged code.
  • Native checks passed with:
    GOFLAGS='-tags=menubar,desktop,production,granttest -run=TestBrowserGrant|TestMistral|TestAgentManager|TestMenubar' ./app.sh --test
  • Native Go callback statement coverage: 100%; shared grant flow: 93.8%.

Track included API and Vibe Code allowances alongside separate
pay-as-you-go spend.

Support automatic browser-session import and manual cookies,
with browser-folder access through the macOS menu bar.

Add dashboard and menu bar reporting, configurable PAYG visibility,
source-partitioned history, retention, and stale-data indicators.

Handle partial endpoint failures without interrupting working
allowance polling, and apply SQLite pragmas to pooled connections.

Include regression tests and setup documentation.
Codecov flagged 0% coverage on readMistralSafariScopes, the hand-rolled
Cookies.binarycookies parser, and on the Mistral tracker's Process/onReset
path. Adds a synthetic binary-cookie fixture builder to exercise the parser's
bounds checks (truncated/malformed input must fail closed with
ErrMistralAuth) plus tracker, MistralCycleOverview, and CookieNames tests.
watchBrowserAccess listed Chrome/Edge/Firefox data folders every 2 minutes
and could show "Grant Browser Access..." for every tray user, regardless of
whether Mistral was enabled. Adds an explicit mistral_enabled flag to the
menubar snapshot (a provider card only appears there after its first
successful poll, so checking for a mistral card would hide the grant item
exactly when it's needed) and gates the probe on it.
@prakersh

prakersh commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Thanks @sgogriff, this is merged to main via fast-forward (your three commits kept as authored: 3d9de6a, b89b1e6, df7419d), so closing the PR here.

The retry state machine, the sanitized diagnostics and the native bridge origin checks were solid. We added four small commits on top:

  • e4b4293: matching the tray paths under ONWATCH_BASE_PATH made them public to anyone behind a same-host reverse proxy (the proxy connects from 127.0.0.1). Reverted that match and forwarded requests are no longer treated as loopback. The tray does not use the base path, so nothing functional is lost.
  • e626015: a 429 or 5xx without Retry-After now waits at least 2 minutes, so Retry can no longer reset the backoff.
  • f966e2b: the quick view survives a missing recovery script, the popover stops replaying old grant results on every open, and a rejected grant answers instead of leaving the page waiting.
  • 3b73f5d: MistralConnection is now api.ProviderConnection so RetryableRunner is not tied to one provider.

Appreciate the thorough tests, they made the follow-ups easy.

@prakersh prakersh closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants