Skip to content

feat(paseo-shared-browser): add independent workspace tabs and control prompts - #280

Draft
RyanEwen wants to merge 30 commits into
omercnet:mainfrom
RyanEwen:codex/independent-shared-browser-tabs
Draft

RyanEwen wants to merge 30 commits into
omercnet:mainfrom
RyanEwen:codex/independent-shared-browser-tabs

Conversation

@RyanEwen

@RyanEwen RyanEwen commented Oct 6, 2026 •

Copy link
Copy Markdown

Maintainer readiness: HOLD, not merge-ready

Exact current head: 60632299f04827c733b79b2fff9f542e7d5c3fc7.
Independent Astra verdict: HOLD / duplicate with blockers at this exact SHA. No source changes or competing implementation were pushed here.

All six first-parent tab/control commits are already ancestors of current #274 (a3924e05). Keep #280 explicitly accounted for, but do not merge it separately on the assumption that it is a new independent implementation. Canonical repairs are being integrated into #274; the final merge plan must account for this overlap.

Current gates

  • Current-head CI completed failure: all three shared-browser OS jobs fail at the compiler step. Local reproduction identifies the undeclared @getpaseo/server dependency. Other affected plugin jobs passed.
  • Typecheck fails with seven errors against the declared SDK, including unpublished encoded-video members.
  • The complete browser smoke fails at close/reopen. Do not infer its root cause or claim a pass from raw CLI probes.
  • Astra reproduced an expired-but-unpruned viewer-token bypass in tab creation and tab metadata access. This also affects the canonical current feat(paseo-shared-browser): add tab-scoped input and opt-in video #274 and is assigned there.
  • Astra also reproduced stale-document text publication and origin-based mouse cleanup at this old head. Partial-failure capture invalidation passes; absence of later fix commits alone is not treated as proof of every historical bug.
  • Local full unit suite: 67 files / 590 tests passed. Astra independently ran 133 tests across 12 complete modules and both video smoke cases. These do not override the blockers above.

Live inspection and screenshots

Passwordless, host-local test daemon: http://127.0.0.1:39280/ . Synthetic fixture: http://127.0.0.1:39281/ . Fresh isolated home, relay disabled, loopback listeners only, no user sessions or credentials. Main independently verified an unauthenticated plugin RPC and the intended archived source running. These URLs are not public; remote use requires the operator's existing secure local forwarding.

The attached captures are real UI pixels from this exact held head: new-tab selection, independent viewer selection, and observer control confirmations. Linux web emulation only: wide 1440 x 900 CSS pixels at scale 1.25, compact 390 x 844 at scale 2. They are not physical-phone or native Windows/macOS qualification, and do not imply merge readiness.

Daemon version: 0.11.1. Home: /var/tmp/shared-browser-wrapup-6a2FjM/daemons/pr-280/home. It and the synthetic fixture remain available as detached processes that survive broker shutdown. Stop the dedicated daemon with paseo daemon stop --home /var/tmp/shared-browser-wrapup-6a2FjM/daemons/pr-280/home; managed names are sb-wrapup-pr280-daemon-d and sb-wrapup-pr280-fixture-d in the owning worker's context.

No merge or PR closure has been performed. Original contributor description and historical validation follow; the current-head qualification above takes precedence.

Summary

  • Keep one Chromium process and profile per workspace while allowing up to eight independent tabs. Each viewer and agent can select a tab without switching anyone else's page. Tabs share cookies and site logins, with separate page control, viewport, and video.
  • Show per-tab viewers and control in the tab strip. Closing a tab removes it for everyone viewing that tab; closing the browser ends all tabs until a person reopens it.
  • Let an observer choose a browser action, confirm taking control, and continue that action once control is granted. Tab and browser close still have separate confirmations.
  • Accept the tested Paseo 0.11.0 beta.3 and beta.4 plugin hosts.

Review context

This branch builds on #274 and #275, which are still open. It also includes the close and reopen work from ryan/dev. The diff against main includes those earlier changes until the upstream PRs merge. Please keep this PR in draft until its dependencies are resolved and the resulting diff is reviewed.

Validation

  • 590 unit tests passed, including tab isolation, viewer authorization, concurrent attachment, and agent control.
  • Real Chromium browser and native video smoke suites passed with isolated homes.
  • Mounted panel checks passed for ordinary takeover, taking control from another controller, and cancelling a stale queued action.
  • Biome check and current SDK typecheck passed. The merged source is running in the WSL Paseo instance used for manual testing.

AI disclosure: this PR and the related code were written with the assistance of AI.

New tabs now become selected immediately in the creating panel. Older cached or in-flight tab lists cannot switch selection back to the previous tab. Selection remains local to each viewer.

Validation for this follow-up: mounted desktop and compact panel checks pass, including a delayed pre-creation list; the same regression fixture fails before the fix. Seven tab/control-identity regressions, TypeScript against the current companion-app SDK and Biome pass.

AI disclosure: this comment and the related code were written with the assistance of AI.

PR 280 HELD exact SHA 60632299f04827c733b79b2fff9f542e7d5c3fc7 Linux web observer control confirmation

PR 280 HELD exact SHA 60632299f04827c733b79b2fff9f542e7d5c3fc7 Linux web second viewer selects beta

PR 280 HELD exact SHA 60632299f04827c733b79b2fff9f542e7d5c3fc7 Linux compact web alpha selected independently from beta viewers

PR 280 HELD exact SHA 60632299f04827c733b79b2fff9f542e7d5c3fc7 Linux compact web takeover confirmation

…contracts

Add encoded packet limits, independent density and encoder targets, and versioned display preferences. Keep additions compatible with existing image clients and separate continuous human admission from strict agent frame targeting.

Validate the contract and settings regressions and the complete TypeScript build.
Capture the exact workspace tab through a private immutable extension and isolate encoder cohorts. Bound encoded buffers, retire idle media, and recover source failures without changing geometry or resetting healthy peer encoders.

Cover packet backlog, byte conversion, failure isolation, cleanup, codec allocation and source timestamps with native helper regressions.
… control

Fence media and input across native attachment, document, bridge and viewport transitions. Admit continuous human geometry while retaining strict agent receipts, reserve control and heartbeat capacity, and reconcile navigation without blocking steady video reads.

Add redacted operation diagnostics, demand-driven JPEG capture, bounded recovery and transition regressions. Register shared contract tests in the standard unit gate. TypeScript and all 475 checkpoint tests pass.
Decode bounded native packets into a retained canvas, keep input continuous during paints, and hand off to qualified image fallback without flashing stale frames. Add independent encoder and capture-density controls.

Fence delayed mutations across viewer and controller replacement and split panel styles, chrome, native keyboard and presence into focused modules. Include decoder, mounted settlement and real native capture-to-canvas regressions.
…servation

Do not invalidate a pending acquisition when media first observes the same viewer as controller. Competing ownership and viewer replacement still revoke delayed replies. Reproduce the race in the full React panel and verify the returned token reaches the next navigation.
…n input

Bind in-flight agent work to the original ticket and native page. Validate agent requests with the shared schemas and preserve the original failure while attempting paired cleanup once.
Add direct keyboard, pointer and touch controls, display presets and favorites, toolbar menus, sharp captures, native desktop hover, and stable frame buffering. Preserve page state during mode changes and reduce redundant frame transfers. Include regression tests and fork reconciliation notes.
Format the embedded extension program and document frame units, peer ownership, codec recovery and teardown contracts without changing its capture protocol.
… review

Apply pinned formatting, type the viewport fixture, align the smoke with default capture quality, and document isolated validation and the supported SDK.
…d SDK

Require Paseo 0.11 with the tested beta allowance. Ship design and research references, document isolated validation and quality trade-offs, and add real SDK compilation and Linux video decoding to CI.
Resolve CSS auto cursors over selectable glyphs and editable surfaces while preserving explicit cursor styles and existing control authority. Cover native text, padding, vertical text and shadow content with isolated Chromium checks.
Use recognizable height labels, add 1440-wide desktop choices, and project favorites in picker order without rewriting saved IDs. Include shared contract tests in the normal regression command.
Use each icon control accessibility label as its native web hover title, including contextual mode labels. Keep native accessibility and shared toolbar behavior intact.
@RyanEwen RyanEwen changed the title feat(shared-browser): independent workspace tabs and control prompts feat(paseo-shared-browser): add independent workspace tabs and control prompts Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant