* Add implementation plan doc
* feat(hooks): reintroduce runtime hooks feature toggle
* fix: thread effective hooks toggle through hook execution
* test: cover hooks feature toggle visibility and settings wiring
* Remove implementation plan doc
* Move Hooks toggle to Advanced section in Feature Settings
* Fixes as per PR feedback
* Clarifying hooksEnabled
* Make hooksEnabled true by default
* Further fixes as per Greptile feedback
* Further fixes as per Greptile feedback
* Fix failing tests
Fixes#9269 - Thinking blocks missing in Bedrock Opus 4.6
Changes:
- Add explicit handling for 'thinking' and 'redacted_thinking' content types
in formatMessagesForConverseAPI() so they are silently skipped instead of
triggering 'Unsupported content type: thinking' warnings
- Capture signature from additionalModelResponseFields thinking responses
- Add signature_delta handling in contentBlockDelta for streaming
- Add redacted_thinking block handling in contentBlockStart for streaming
- Extend ContentBlockStart/Delta interfaces with signature and data fields
- Add 'redacted_thinking' and 'document' to SupportedContentType union
- Add tests for thinking/redacted_thinking block filtering in message conversion
* feat(cli): add --hooks-dir flag for runtime hook injection
Adds a --hooks-dir <path> CLI flag that allows passing an additional
hooks directory at spawn time. This enables orchestration tools (like
Kanbanana) to inject per-session lifecycle hooks without mutating
the user's global or workspace hooks directories.
The runtime hooks directory is included alongside existing global
(~/Documents/Cline/Hooks/) and workspace (.clinerules/hooks/)
directories during hook discovery. All hooks from all directories
are merged and run in parallel, so runtime hooks are purely additive.
* fix(cli): initialize runtime hooks before interactive startup
Add --no-verify to the initial checkpoint commit in
CheckpointGitOperations.ts. This was already used for subsequent
commits in CheckpointTracker.ts but was missing from the initial
empty commit, causing Cline to fail to initialize when users have
global pre-commit hooks (e.g., conventional commits enforcement).
Fixes#9672
* feat: add telemetry for AI output accepted/rejected across tool handlers
Add line-level diff stats and file operation tracking to telemetry
events when users accept or reject tool outputs. Introduces a shared
`computeLineDiffStats` utility and `captureAiOutputAccepted`/
`captureAiOutputRejected` methods on the telemetry service, wired
into ApplyPatch, WriteToFile, ExecuteCommand, InsertContent, and
SearchAndReplace handlers.
* feat(telemetry): add source tracking for agent vs human edits
Add telemetry differentiation between agent-generated changes and
human modifications to capture more granular edit metrics:
- Add 'source' field to captureAiOutputAccepted telemetry events
- Track human edits by computing diff stats between agent's proposed
content and final saved content
- Apply source tracking to ApplyPatchHandler and WriteToFileToolHandler
- Enable separate analytics for agent vs human contributions
This allows measuring how often and to what extent users modify
AI-generated code, providing insights into AI output quality and
user trust patterns.
* refactor(telemetry): centralize ai output attribution across file edit handlers
- add shared `AiOutputTelemetry` utility for accepted/rejected events
- refactor `WriteToFileToolHandler` and `ApplyPatchHandler` to use shared helpers
- preserve existing telemetry behavior (`source: "agent" | "human"`) while reducing duplication
- keep line diff/file-op attribution semantics unchanged
* fix(telemetry): use pre-save content for human edit line diff stats
The source:"human" telemetry was diffing agent content against
finalContent (post-save), which includes auto-formatting changes
from the editor. This inflated linesChanged/linesDeleted counts
when the formatter modified lines alongside the user's actual edits.
Use diff.applyPatch() to reconstruct the user's pre-save content
from the existing userEdits patch, excluding formatter noise from
the line diff stats.
* fixing syntax error
* refactor(telemetry): make next-hunk bounds check explicit
* remove comment
Co-authored-by: Tomás Barreiro <52393857+BarreiroT@users.noreply.github.com>
---------
Co-authored-by: Tomás Barreiro <52393857+BarreiroT@users.noreply.github.com>
Add author_association check so only MEMBER, OWNER, and COLLABORATOR
users can trigger the JetBrains test workflow via issue comments.
Previously any GitHub user could trigger it, allowing unauthorized
use of the GitHub App token and Actions minutes.
Fixes GHSA-5fq9-fh5x-w83r (SEC-29)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add provider/model context to all hook payloads
* Fixes as per Greptile feedback
* Further fixes as per Greptile feedback
* Further fixes as per Greptile feedback
* further fixes as per Greptile feedback
* Fix flapping hooks tests on Windows
* fix: stop infinite getLatestMcpServers RPC loop when opening MCP servers panel
The ServersToggleModal useEffect had setMcpServers in its dependency array,
but the context provided an unstable inline wrapper around the useState setter,
creating a new function reference on every render. This caused the effect to
re-fire on every context re-render while the modal was visible, producing 14+
RPC calls in ~15ms.
- Remove setMcpServers from useEffect deps in ServersToggleModal (the effect
should only fire when visibility changes)
- Replace inline arrow wrappers in ExtensionStateContext with direct references
to the stable useState setters (setMcpServers, setRequestyModels,
setHuggingFaceModels, setMcpMarketplaceCatalog)
* address review feedback: add setMcpServers back to deps, use property shorthand
- Add setMcpServers back to useEffect deps in ServersToggleModal now that the
context passes the stable useState setter directly (per Copilot review)
- Remove eslint-disable comment since it's no longer needed
- Use property shorthand for setGroqModels and setBasetenModels in context value
* initial doc changes
* rm general api endpoint
* Add API documentation section with endpoint reference pages
- Add new API docs: overview, getting-started, authentication, models,
chat-completions, errors, and SDK examples
- Update api/reference.mdx with expanded endpoint documentation
- Update enterprise-solutions/api-reference.mdx with improvements
- Update docs.json with new API section navigation entries
---------
Co-authored-by: Juan Pablo <juan@cline.bot>
Co-authored-by: Tony Loehr <turingxo@gmail.com>
* fix: prevent Chinese filename escaping in diff view
Use Uri.parse() instead of Uri.from() for the diff view URI to prevent
non-ASCII characters (e.g. Chinese) in filenames from being
percent-encoded. This is consistent with how other diff URIs are created
in openMultiFileDiff.ts and VscodeCommentReviewController.ts.
Uri.from() encodes the path component, turning Chinese characters into
percent-encoded sequences like %E7%A0%94..., which causes the diff view
to display escaped filenames and fail to open properly.
* fix: encode URI-reserved delimiters in filename before Uri.parse
Encode %, #, and ? in the filename before passing to Uri.parse() to
prevent them from being interpreted as URI delimiters. This handles
edge cases where filenames contain these characters (valid on macOS/Linux)
while preserving non-ASCII characters like Chinese.
* feat(hooks): add Windows hook execution via PowerShell
* chore(changeset): add release note for Windows hooks
* Get hooks working on Windows
Remove changeset file (we no longer use changeset files)
feat(hooks): support Windows PowerShell hook resolution and management
feat(hooks): complete windows powershell hook support and tests
Detect linux-style hooks only on macOS and linux and detect PowerShell-style hooks only on Windows
Fixes for failing unit tests on Windows in CI
Fix failing unit tests on Windows in CI
Fix unit tests for hooks on Windows
Be clear about .ps1 file extension for hooks in PowerShell vs. bash/binary for linux-style hooks
Remove separate test suite step
Reapply hooks-specific test suite
Fix failing hooks tests
* Harden Windows hook PowerShell runtime and test coverage
* test: centralize hook test env and platform overrides
---------
Co-authored-by: Saoud Rizwan <7799382+saoudrizwan@users.noreply.github.com>
When OCA token refresh fails with 400 invalid_grant or 401, legacy secrets
ocaAccessToken and ocaTokenSet (from older Cline versions) were left in VS
Code's secret storage. clearAuth() only cleared ocaApiKey and ocaRefreshToken,
causing every subsequent re-auth attempt to fail in a loop requiring manual
SQLite deletion to recover.
Fix:
- Add ocaAccessToken and ocaTokenSet to SecretKeys in state-keys.ts
- Update OcaAuthProvider.clearAuth() to clear all 4 OCA secrets
Fixes#9567
* fix: resolve 'Could not find the file context' error in Explain Changes
Both handleCommentReply() in explainChangesShared.ts and the onCommentStart
callback in explainChanges.ts were using a strict absolutePath-only match
when looking up files in changedFiles. If the VS Code comment controller
returns a path in a different format (relative vs absolute, different
separators on Windows), the lookup would silently fail and show
'Error: Could not find the file context'.
Add relativePath as a fallback in both lookup sites, making them
consistent with the already-correct logic in streamAIExplanationComments.
Fixes#9382
* Refactor to use parseInt instead of Number.parseInt
* Adding 1m
* fix: wire cline model proto fields for api config
* fix: wire cline picker to shared recommended model logic
* fix: address Cline model picker parity and startup model-info sync
* remove OpenRouter preset model ID support
* rename Cline endpoint feature flag
* Fixing stuff
* Fixing stuff
* Fixing stuff
* refactor: gate cline models endpoint behind feature flag
- Update refreshClineModels to use the EXTENSION_CLINE_MODELS_ENDPOINT feature flag instead of a hardcoded boolean, allowing controlled rollouts of the endpoint source.
- Remove recommended/free models fallback logic, featured model cards, and the initialTab property from OpenRouterModelPicker to simplify the UI component.
* fix: use JSON_SCHEMA for yaml.load to prevent unsafe deserialization
Add { schema: yaml.JSON_SCHEMA } to both yaml.load() calls to reject
custom YAML tags (e.g. !!js/function) that could enable code execution
from untrusted .clinerules or skills files.
Add security tests verifying custom tags are rejected.
* add changeset
The CLI's applyProviderConfig() was reading model info from a disk
cache (controller.readOpenRouterModels) instead of fetching from
the provider API. In headless/Docker environments (e.g., terminal-bench)
the cache doesn't exist, so model info was never set. Both handlers
then fell back to openRouterDefaultModelInfo with maxTokens: 8192,
causing write_to_file truncation on large outputs.
Changes:
- Replace controller.readOpenRouterModels() (disk cache) with
refreshOpenRouterModels() (fetches from API, with cache fallback)
- Add vercel-ai-gateway to the model info fetch path using
refreshVercelAiGatewayModels()
Relates to #7998
Co-authored-by: Cursor <cursoragent@cursor.com>
The "Generate Commit Message" feature was using all changes instead of
only staged changes. Now prioritizes staged changes via getGitDiffStagedFirst(),
falling back to all changes only when nothing is staged.
Closes#5749
Co-authored-by: Raushan Singh <raushrak@Raushans-MacBook-Air.local>
* fix: update stale maxTokens values for Claude 3.7+ models
Every Claude model from 3.7 Sonnet onward had maxTokens set to 8192
in the static model definitions. These values were correct for Claude
3.5 and earlier, but Anthropic has significantly increased output
limits for newer models:
- Claude Opus 4.6: 128K (was 8192, 15.6x too low)
- Claude 3.7 Sonnet: 128K (was 8192, 15.6x too low)
- Claude Sonnet 4.6/4.5/4, Haiku 4.5, Opus 4.5: 64K (was 8192)
- Claude Opus 4, Opus 4.1: 32K (was 8192)
These static definitions are the source of truth for Anthropic direct,
Bedrock, Vertex, and SAP AI Core providers. With the old values, any
write_to_file call exceeding 8192 output tokens would be silently
truncated, producing a missing 'content' parameter error.
Values verified against Anthropic docs, AWS Bedrock docs, Google
Vertex AI docs, and the Vercel AI Gateway API.
Relates to #7998
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: update openRouterDefaultModelInfo.maxTokens to 64K
This fallback ModelInfo (representing claude-sonnet-4.5) is used
when dynamic model info isn't available — notably by the Cline and
Vercel providers in the CLI when the model cache is empty (e.g.,
fresh Docker containers in terminal-bench).
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
The OpenRouter stream transform had a 30-line switch statement that
hardcoded max_tokens=8192 for every Claude model. This was written when
8192 was the actual max output for Claude, but modern Claude models
support much higher limits (e.g. 128K for Sonnet 4.6, 64K for others).
OpenRouter's API already reports the correct max_completion_tokens per
model, and model.info.maxTokens reflects this (128000 for Sonnet 4.6).
The hardcoded switch was silently overriding the dynamic value.
This caused write_to_file failures on OpenRouter (and the Cline
provider, which shares this code path) whenever the tool call content
exceeded 8192 output tokens. The response was truncated
(finish_reason: "length"), producing incomplete JSON that lost the
content parameter.
Runtime evidence:
- Before: max_tokens=8192 sent, completion_tokens=8192 (ceiling),
finish_reason="length", write_to_file content missing
- After: max_tokens=128000 sent, completion_tokens=9824 (needed more
than 8192), finish_reason="tool_calls", write_to_file succeeded
Fixes#7998
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat: add MiniMax M2.5 model to MiniMax provider
- Add MiniMax-M2.5 to minimaxModels with 192K context, 128K max tokens,
prompt caching, and reasoning/thinking support
- Update minimaxDefaultModelId to MiniMax-M2.5
- Add minimax/minimax-m2.5 to OpenRouter prompt caching switch
Closes#9391
* fix: add temperature: 1 to MiniMax M2.5 for reasoning support
* docs: update MiniMax provider docs with M2.5 model
* feat: wire up thinking/reasoning support for MiniMax M2.5
- Pass thinkingBudgetTokens from factory to MinimaxHandler
- Use thinking param in API call when reasoning is enabled
- Disable temperature and forced tool_choice when thinking is on
- Add ThinkingBudgetSlider to MiniMaxProvider UI for M2.5
* Add MiniMax-M2.5-highspeed
* Add thinking for highspeed
* Refactor thinking logic
---------
Co-authored-by: BarreiroT <tomasmbarreiroi@gmail.com>
Co-authored-by: Tomás Barreiro <52393857+BarreiroT@users.noreply.github.com>
- Update model ID and name from gpt-5.2-codex to gpt-5.3-codex
- Change tag from "HOT" to "NEW" for the updated model
- Add What's New banner entry promoting Codex 5.3 availability
This commit ensures that internal placeholder tools, specifically `focus_chain`, are filtered out from the final list of native tools exposed to the LLM.
- Added a test case in `PromptRegistry.test.ts` to verify `focus_chain` is excluded from native tools output.
- Updated snapshot files for various models (OpenAI GPT-5, Vertex Gemini 3, etc.) to reflect the removal of the `focus_chain` tool definition.