mirror of
https://github.com/only-cli/oc.git
synced 2026-09-15 10:40:56 +02:00
Version 0.5.1 in package.json, the lockfile, the plugin manifest, the marketplace entry, and the npx pins inside the skill. CHANGELOG covers the fingerprint fallback (#40), the footer no longer offering planned commands (#44), and find in every footer (#46). The README install note and llms.txt now describe the full transport chain: Chrome, then Firefox, then native fetch.
5.1 KiB
5.1 KiB
Changelog
Notable changes per release. Releases before 0.4.0 are listed at github.com/only-cli/oc/releases.
0.5.1
Added
find <query>in everyactions:footer, afterdo <n>and beforeread <n>, the order the skill's "going further, cheapest first" list already gives. One command lands on the block that matters, wherereadneeds the right number first andnextpages toward it. The entry costs 3 or 4 tokens per render. (#46)
Fixed
oc openno longer dies withImpersonating chrome150 is not supportedon machines where impers loads a system copy of libcurl-impersonate older than v2.1.0, which predates the fingerprint thechromealias resolves to. A refused fingerprint now downgrades the same way a blocked response already did: chrome falls back to firefox, and when both identities are refused the plain fetch transport still gets the page. Any other impers failure propagates unchanged, and installs where impers works keep the newest chrome fingerprint. (#40)- The
actions:footer no longer offersfill <n> <text>andsubmiton pages with an input. Both are still planned, and following the footer's own suggestion always failed. A test now keeps every footer free of commands that are not available yet. (#44)
0.5.0
Added
- Language documentation shortcuts:
py,mdn,node,ruby,go,rust,java,php,cpp, andts, plus adotnetverb onlearnfor the .NET API browser.searchonpy,node, andrubyranks the docs' own search index locally and onmdnasks the site's API; the sites that only render docs search client-side go through DuckDuckGo with a baked-insite:filter instead. (#25) - Authenticated sessions:
oc loginseeds cookies for a session and every fetch in that session sends them;oc logoutforgets a session early, cookies and saved page both. Cookies live in a per-session jar underOC_HOME, separate from page state, pinned to the exact host they were seeded for, and marked secure by default so they travel over https only (--allow-httpat login opts a plain-http site in). A session lasts an hour unless--expiressays otherwise.--cookie -reads the header from stdin, the form to prefer since an argv secret is visible inpsand kept in shell history. (#4)
Fixed
- Response bodies are bounded at every transport, 25MB decoded, checked
against
Content-Lengthbefore the bytes arrive and counted as they land, so a hostile URL is no longer an unbounded allocation and a decompression bomb stops at the cap. (#27) - Titles, headings, and input names are cut at the render boundary like every
other block, so one hostile page-written scalar can no longer print
unbounded output whatever the budget said. The distilled page keeps the
full values and
--jsonstays the machine-stable view. (#28) - A short page is judged unreadable by evidence, not by length alone: nothing extracted is empty whatever the page weighed, and a short render only fails when the markup behind it was far too big to have carried only that. A status endpoint or a one-line answer now exits 0; script-only shells and consent walls still exit 2. (#29)
0.4.0
Added
- Site shortcuts are dispatched, not just documented.
oc <site> <verb> [args]resolves to a URL and then takes the same pathoc opendoes, so it costs the same and reads the same. A site is named by short name, bare name, or domain (oc hn,oc ycombinator,oc news.ycombinator.com), the last argument absorbs every word after it so a query needs no quoting, andoc siteslists every site with its verbs. Shortcuts come fromclis/*.json, so adding a site is a JSON file and no code. (#19) - Wikipedia shortcuts:
oc wiki article <title>,oc wiki search <query>, andoc wiki lang <code> <title>for the other language editions. Articles are read throughaction=render, which serves the article body without the site chrome, navigation, and edit controls that surround/wiki/<Title>. (#22) - Outbound fetches honor
HTTP_PROXY,HTTPS_PROXY, andNO_PROXY, including the lowercase forms, so oc works in a sandbox whose only route out is a proxy. HTTP and HTTPS proxies are supported and proxy credentials in the URL are sent asProxy-Authorization. (#17) - The MIT
LICENSEfile that the badge andpackage.jsonwere already claiming. (#18)
Changed
- A page that distills to no readable text now fails loud instead of printing an
empty render and exiting 0. It writes one line to stderr and exits 2, which is
distinct from the exit 1 every other failure uses, so a caller can tell "this
page is empty" from "oc could not read this page" and fall back to a browser
only when that is worth doing.
--jsoncarries the same verdict as anemptyfield. (#20) - The SSRF guard runs before a proxy is chosen, so a proxied request cannot be used to reach an address the direct path would have refused. (#17)
Fixed
- GitHub and Reddit shortcut URL templates corrected so their verbs reach the pages they name. (#19)