fix(mcp): keep upload modal, skip short secrets and bad headers - #42713
Devin Rousso (dcrousso) merged 4 commits into
Conversation
Do not redact secret values shorter than 4 characters. Ignore route header lines that have no name. Clear the file chooser only after setFiles succeeds so a failed upload can be retried. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
This comment has been minimized.
This comment has been minimized.
waitForCompletion returns immediately when a fileChooser modal is already listed, so wrapping setFiles in it skipped the upload. Call setFiles first, keep the chooser on failure, then settle. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
Return an argument error for values that are not Name: Value. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
| redactSecrets(text: string): string { | ||
| for (const [secretName, secretValue] of Object.entries(this.config.secrets ?? {})) { | ||
| if (!secretValue) | ||
| if (!secretValue || secretValue.length < 4) |
There was a problem hiding this comment.
please avoid configuring guessable values such as abc as secrets rather than silently disabling redaction for short values (see microsoft/playwright-mcp#1106 (comment))
There was a problem hiding this comment.
please avoid configuring guessable values such as
abcas secrets rather than silently disabling redaction for short values
Removed the length < 4 skip. Empty values are still ignored. The short-secret test is gone. 36971b002
| } | ||
| } | ||
| tab.clearModalState(modalState); | ||
| await tab.waitForCompletion(async () => {}); |
There was a problem hiding this comment.
starting the completion wait after setFiles() misses requests triggered by the upload on WebKit, so the tool can return before those requests finish
There was a problem hiding this comment.
starting the completion wait after
setFiles()misses requests triggered by the upload on WebKit
setFiles is back inside waitForCompletion. The file chooser is cleared first so the wait actually runs. 36971b002
| if (paths) | ||
| if (paths) { | ||
| try { | ||
| await modalState.fileChooser.setFiles(paths); |
There was a problem hiding this comment.
awaiting setFiles() outside waitForCompletion() makes uploads whose change handler opens a dialog time out instead of returning the dialog for handling
There was a problem hiding this comment.
awaiting
setFiles()outsidewaitForCompletion()makes uploads whosechangehandler opens a dialog time out instead of returning the dialog for handling
Same change: setFiles runs inside waitForCompletion after the chooser is cleared, so a dialog from the change handler is returned. If setFiles throws, the chooser is restored. 36971b002
This comment has been minimized.
This comment has been minimized.
Clear the file chooser first so waitForCompletion can run, then setFiles inside it so WebKit upload requests and change-handler dialogs are observed. Restore the chooser if setFiles fails. Redact all non-empty secret values. Do not skip short ones. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
Test results for "MCP"2 failed 8614 passed, 1446 skipped Merge workflow run. |
Devin Rousso (dcrousso)
left a comment
There was a problem hiding this comment.
thanks for the fix!
464318b
into
microsoft:main
|
Please file those issues next time! |
## What's New ### New Tools - **`browser_emulate_media`** — Emulate color scheme, reduced motion, forced colors, contrast, and screen/print media. Pass `null` to clear an override ([#42668](microsoft/playwright#42668)). ### Other Changes - **Tool removal:** `browser_webmcp_list` and `browser_webmcp_call` are now skill-only and no longer exposed as MCP tools ([#42671](microsoft/playwright#42671)). ## Bug Fixes - Failed `browser_file_upload` calls preserve the file chooser, allowing another upload attempt without reopening it ([#42713](microsoft/playwright#42713)). - Corrected the Playwright import in the published configuration types ([#1762](#1762)). Co-authored-by: pavelfeldman <883973+pavelfeldman@users.noreply.github.com>
## What's New ### New Tools - **`browser_emulate_media`** — Emulate color scheme, reduced motion, forced colors, contrast, and screen/print media. Pass `null` to clear an override ([#42668](microsoft/playwright#42668)). ### Other Changes - **Tool removal:** `browser_webmcp_list` and `browser_webmcp_call` are now skill-only and no longer exposed as MCP tools ([#42671](microsoft/playwright#42671)). ## Bug Fixes - Failed `browser_file_upload` calls preserve the file chooser, allowing another upload attempt without reopening it ([#42713](microsoft/playwright#42713)). - Corrected the Playwright import in the published configuration types ([#1762](#1762)). Co-authored-by: pavelfeldman <883973+pavelfeldman@users.noreply.github.com>
## ✨ Highlights - **🎬 Smooth 60 fps, styleable videos** — `video-start --fps=60` records smooth 60 fps videos instead of the default 25, and `video-start --cursor` renders an animated mouse cursor that travels to each action point and stays visible between actions. `video-show-actions` takes `--point-style`, `--highlight-style` and `--title-style` CSS declarations; the action point marker and the target highlight are now only shown when styled. ([microsoft/playwright#42752](microsoft/playwright#42752), [microsoft/playwright#42758](microsoft/playwright#42758)) - **🧰 WebMCP tools show up in the snapshot** — the tools a page registers are listed at the top of the page snapshot with their descriptions and input schemas, so `webmcp-call` can be used without running `webmcp-list` first. Set `webmcp: false` in the config file (env `PLAYWRIGHT_MCP_WEBMCP=false`) to stop collecting page-registered tools. ([microsoft/playwright#42671](microsoft/playwright#42671)) - **🌗 Switch between light and dark color scheme** ([microsoft/playwright#42243](microsoft/playwright#42243)) — an agent working on a dark theme had no way to see it mid-session. New `set-color-scheme`, `set-reduced-motion`, `set-forced-colors`, `set-contrast` and `set-media` commands emulate media features on the fly, and the matching `clear-*` commands reset them. ([microsoft/playwright#42668](microsoft/playwright#42668)) - **📁 Absolute paths in results** ([microsoft/playwright#42497](microsoft/playwright#42497)) — links to snapshots, screenshots, console logs and downloads are relative to the working directory, which a consumer without one cannot resolve. Set `filePaths: "absolute"` in the config file (env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead. ([microsoft/playwright#42673](microsoft/playwright#42673)) ## 🐛 Fixes - `fix(chromium): bypass service workers on the storage state page` — `state-save` no longer runs the site's own scripts, or fails when they redirect, for origins with an active service worker ([microsoft/playwright#42656](microsoft/playwright#42656)). ([#42664](microsoft/playwright#42664), [#42741](microsoft/playwright#42741)) - `fix(mcp): keep upload modal, skip short secrets and bad headers` — a failed `upload` keeps the file chooser open so it can be retried, secrets shorter than 4 characters no longer rewrite the whole output with `<secret>` markers, and `route` ignores header lines that have no name. ([#42713](microsoft/playwright#42713)) ## 📦 Upgrading ```bash npm install -g @playwright/cli@0.1.21 ```
## ✨ Highlights - **🧰 WebMCP tools become real MCP tools** — the tools a page registers through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API now show up right in the tool list as `webmcp_<tool>`, with the page's own input schema and annotations, so an agent can call them directly and let the page do the work instead of driving its UI. The list follows the current tab, and clients get a `tools/list_changed` notification when it changes. This replaces `browser_webmcp_list` / `browser_webmcp_call` from v0.0.81, which are no longer exposed over MCP. Tool names, descriptions, schemas and results come from the page, so treat them as untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env `PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see [WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how to enable it. ([microsoft/playwright#42671](microsoft/playwright#42671)) - **🌗 Switch between light and dark color scheme** ([microsoft/playwright#42243](microsoft/playwright#42243)) — an agent working on a dark theme had no way to see it mid-session. The new **`browser_emulate_media`** tool emulates media features on the fly: `colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the `media` type (screen / print). Omitted parameters are left unchanged, `null` clears an override. ([microsoft/playwright#42668](microsoft/playwright#42668)) - **📁 Absolute paths in results** ([microsoft/playwright#42497](microsoft/playwright#42497)) — links to snapshots, screenshots, console logs and downloads are relative to the workspace root, which a client without one cannot resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`, env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead. ([microsoft/playwright#42673](microsoft/playwright#42673)) ## 🐛 Fixes - `fix(mcp): keep upload modal and reject bad headers` — a failed `browser_file_upload` (e.g. a missing file) reports the error and keeps the file chooser open so it can be retried, and `browser_route` (opt-in via `--caps=network`) returns an error for a header that is not in the `Name: Value` form instead of setting a header named `""`. ([microsoft/playwright#42713](microsoft/playwright#42713)) - `fix(chromium): bypass service workers on the storage state page` — `browser_storage_state` (opt-in via `--caps=storage`) no longer runs the site's own scripts, or fails when they redirect, for origins with an active service worker ([microsoft/playwright#42656](microsoft/playwright#42656)). ([microsoft/playwright#42664](microsoft/playwright#42664), [microsoft/playwright#42741](microsoft/playwright#42741)) ## 📦 Upgrading Configs that use `@playwright/mcp@latest` pick this release up on the next client restart. To pin it: ```bash npx @playwright/mcp@0.0.82 ```
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@types/node](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node) ([source](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)) | [`^26.6.1` → `^26.6.2`](https://renovatebot.com/diffs/npm/@types%2fnode/26.6.1/26.6.2) |  |  | | [npm:@playwright/mcp](https://playwright.dev) ([source](https://redirect.github.com/microsoft/playwright-mcp)) | `0.0.81` → `0.0.82` |  |  | --- ### Release Notes <details> <summary>microsoft/playwright-mcp (npm:@​playwright/mcp)</summary> ### [`v0.0.82`](https://redirect.github.com/microsoft/playwright-mcp/releases/tag/v0.0.82) [Compare Source](https://redirect.github.com/microsoft/playwright-mcp/compare/v0.0.81...v0.0.82) #### ✨ Highlights - **🎬 Smooth 60 fps, styleable videos** — `browser_start_video` (opt-in via `--caps=devtools`) takes `fps`, so `fps: 60` records smooth 60 fps videos instead of the default 25, and `cursor: true` renders an animated mouse cursor that travels to each action point and stays visible between actions. `browser_video_show_actions` takes a `style` with `point`, `highlight` and `title` CSS declarations; the action point marker and the target highlight are now only shown when styled. ([microsoft/playwright#42752](https://redirect.github.com/microsoft/playwright/pull/42752), [microsoft/playwright#42758](https://redirect.github.com/microsoft/playwright/pull/42758)) - **🧰 WebMCP tools become real MCP tools** — the tools a page registers through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API now show up right in the tool list as `webmcp_<tool>`, with the page's own input schema and annotations, so an agent can call them directly and let the page do the work instead of driving its UI. The list follows the current tab, and clients get a `tools/list_changed` notification when it changes. This replaces `browser_webmcp_list` / `browser_webmcp_call` from v0.0.81, which are no longer exposed over MCP. Tool names, descriptions, schemas and results come from the page, so treat them as untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env `PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see [WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how to enable it. ([microsoft/playwright#42671](https://redirect.github.com/microsoft/playwright/pull/42671)) - **🌗 Switch between light and dark color scheme** ([microsoft/playwright#42243](https://redirect.github.com/microsoft/playwright/issues/42243)) — an agent working on a dark theme had no way to see it mid-session. The new **`browser_emulate_media`** tool emulates media features on the fly: `colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the `media` type (screen / print). Omitted parameters are left unchanged, `null` clears an override. ([microsoft/playwright#42668](https://redirect.github.com/microsoft/playwright/pull/42668)) - **📁 Absolute paths in results** ([microsoft/playwright#42497](https://redirect.github.com/microsoft/playwright/issues/42497)) — links to snapshots, screenshots, console logs and downloads are relative to the workspace root, which a client without one cannot resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`, env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead. ([microsoft/playwright#42673](https://redirect.github.com/microsoft/playwright/pull/42673)) #### 🐛 Fixes - `fix(mcp): keep upload modal and reject bad headers` — a failed `browser_file_upload` (e.g. a missing file) reports the error and keeps the file chooser open so it can be retried, and `browser_route` (opt-in via `--caps=network`) returns an error for a header that is not in the `Name: Value` form instead of setting a header named `""`. ([microsoft/playwright#42713](https://redirect.github.com/microsoft/playwright/pull/42713)) - `fix(chromium): bypass service workers on the storage state page` — `browser_storage_state` (opt-in via `--caps=storage`) no longer runs the site's own scripts, or fails when they redirect, for origins with an active service worker ([microsoft/playwright#42656](https://redirect.github.com/microsoft/playwright/issues/42656)). ([microsoft/playwright#42664](https://redirect.github.com/microsoft/playwright/pull/42664), [microsoft/playwright#42741](https://redirect.github.com/microsoft/playwright/pull/42741)) #### 📦 Upgrading Configs that use `@playwright/mcp@latest` pick this release up on the next client restart. To pin it: ```bash npx @playwright/mcp@0.0.82 ``` </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/soodoh/dotfiles). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@playwright/mcp](https://playwright.dev) ([source](https://redirect.github.com/microsoft/playwright-mcp)) | `0.0.81` → `0.0.82` |  |  |  |  | --- > [!WARNING] > Some dependencies could not be looked up. Check the warning logs for more information. --- ### Release Notes <details> <summary>microsoft/playwright-mcp (@​playwright/mcp)</summary> ### [`v0.0.82`](https://redirect.github.com/microsoft/playwright-mcp/releases/tag/v0.0.82) [Compare Source](https://redirect.github.com/microsoft/playwright-mcp/compare/v0.0.81...v0.0.82) #### ✨ Highlights - **🎬 Smooth 60 fps, styleable videos** — `browser_start_video` (opt-in via `--caps=devtools`) takes `fps`, so `fps: 60` records smooth 60 fps videos instead of the default 25, and `cursor: true` renders an animated mouse cursor that travels to each action point and stays visible between actions. `browser_video_show_actions` takes a `style` with `point`, `highlight` and `title` CSS declarations; the action point marker and the target highlight are now only shown when styled. ([microsoft/playwright#42752](https://redirect.github.com/microsoft/playwright/pull/42752), [microsoft/playwright#42758](https://redirect.github.com/microsoft/playwright/pull/42758)) - **🧰 WebMCP tools become real MCP tools** — the tools a page registers through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API now show up right in the tool list as `webmcp_<tool>`, with the page's own input schema and annotations, so an agent can call them directly and let the page do the work instead of driving its UI. The list follows the current tab, and clients get a `tools/list_changed` notification when it changes. This replaces `browser_webmcp_list` / `browser_webmcp_call` from v0.0.81, which are no longer exposed over MCP. Tool names, descriptions, schemas and results come from the page, so treat them as untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env `PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see [WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how to enable it. ([microsoft/playwright#42671](https://redirect.github.com/microsoft/playwright/pull/42671)) - **🌗 Switch between light and dark color scheme** ([microsoft/playwright#42243](https://redirect.github.com/microsoft/playwright/issues/42243)) — an agent working on a dark theme had no way to see it mid-session. The new **`browser_emulate_media`** tool emulates media features on the fly: `colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the `media` type (screen / print). Omitted parameters are left unchanged, `null` clears an override. ([microsoft/playwright#42668](https://redirect.github.com/microsoft/playwright/pull/42668)) - **📁 Absolute paths in results** ([microsoft/playwright#42497](https://redirect.github.com/microsoft/playwright/issues/42497)) — links to snapshots, screenshots, console logs and downloads are relative to the workspace root, which a client without one cannot resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`, env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead. ([microsoft/playwright#42673](https://redirect.github.com/microsoft/playwright/pull/42673)) #### 🐛 Fixes - `fix(mcp): keep upload modal and reject bad headers` — a failed `browser_file_upload` (e.g. a missing file) reports the error and keeps the file chooser open so it can be retried, and `browser_route` (opt-in via `--caps=network`) returns an error for a header that is not in the `Name: Value` form instead of setting a header named `""`. ([microsoft/playwright#42713](https://redirect.github.com/microsoft/playwright/pull/42713)) - `fix(chromium): bypass service workers on the storage state page` — `browser_storage_state` (opt-in via `--caps=storage`) no longer runs the site's own scripts, or fails when they redirect, for origins with an active service worker ([microsoft/playwright#42656](https://redirect.github.com/microsoft/playwright/issues/42656)). ([microsoft/playwright#42664](https://redirect.github.com/microsoft/playwright/pull/42664), [microsoft/playwright#42741](https://redirect.github.com/microsoft/playwright/pull/42741)) #### 📦 Upgrading Configs that use `@playwright/mcp@latest` pick this release up on the next client restart. To pin it: ```bash npx @playwright/mcp@0.0.82 ``` </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/paulnsorensen/dotfiles). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Chores** - Updated the Playwright MCP package to version 0.0.82. - Synchronized the package version used by the Codex profile test. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: dep-harvest-bot <paulnsorensen@gmail.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@playwright/mcp](https://playwright.dev) ([source](https://redirect.github.com/microsoft/playwright-mcp)) | [`0.0.81` → `0.0.82`](https://renovatebot.com/diffs/npm/@playwright%2fmcp/0.0.81/0.0.82) |  |  | --- ### Release Notes <details> <summary>microsoft/playwright-mcp (@​playwright/mcp)</summary> ### [`v0.0.82`](https://redirect.github.com/microsoft/playwright-mcp/releases/tag/v0.0.82) [Compare Source](https://redirect.github.com/microsoft/playwright-mcp/compare/v0.0.81...v0.0.82) #### ✨ Highlights - **🎬 Smooth 60 fps, styleable videos** — `browser_start_video` (opt-in via `--caps=devtools`) takes `fps`, so `fps: 60` records smooth 60 fps videos instead of the default 25, and `cursor: true` renders an animated mouse cursor that travels to each action point and stays visible between actions. `browser_video_show_actions` takes a `style` with `point`, `highlight` and `title` CSS declarations; the action point marker and the target highlight are now only shown when styled. ([microsoft/playwright#42752](https://redirect.github.com/microsoft/playwright/pull/42752), [microsoft/playwright#42758](https://redirect.github.com/microsoft/playwright/pull/42758)) - **🧰 WebMCP tools become real MCP tools** — the tools a page registers through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API now show up right in the tool list as `webmcp_<tool>`, with the page's own input schema and annotations, so an agent can call them directly and let the page do the work instead of driving its UI. The list follows the current tab, and clients get a `tools/list_changed` notification when it changes. This replaces `browser_webmcp_list` / `browser_webmcp_call` from v0.0.81, which are no longer exposed over MCP. Tool names, descriptions, schemas and results come from the page, so treat them as untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env `PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see [WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how to enable it. ([microsoft/playwright#42671](https://redirect.github.com/microsoft/playwright/pull/42671)) - **🌗 Switch between light and dark color scheme** ([microsoft/playwright#42243](https://redirect.github.com/microsoft/playwright/issues/42243)) — an agent working on a dark theme had no way to see it mid-session. The new **`browser_emulate_media`** tool emulates media features on the fly: `colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the `media` type (screen / print). Omitted parameters are left unchanged, `null` clears an override. ([microsoft/playwright#42668](https://redirect.github.com/microsoft/playwright/pull/42668)) - **📁 Absolute paths in results** ([microsoft/playwright#42497](https://redirect.github.com/microsoft/playwright/issues/42497)) — links to snapshots, screenshots, console logs and downloads are relative to the workspace root, which a client without one cannot resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`, env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead. ([microsoft/playwright#42673](https://redirect.github.com/microsoft/playwright/pull/42673)) #### 🐛 Fixes - `fix(mcp): keep upload modal and reject bad headers` — a failed `browser_file_upload` (e.g. a missing file) reports the error and keeps the file chooser open so it can be retried, and `browser_route` (opt-in via `--caps=network`) returns an error for a header that is not in the `Name: Value` form instead of setting a header named `""`. ([microsoft/playwright#42713](https://redirect.github.com/microsoft/playwright/pull/42713)) - `fix(chromium): bypass service workers on the storage state page` — `browser_storage_state` (opt-in via `--caps=storage`) no longer runs the site's own scripts, or fails when they redirect, for origins with an active service worker ([microsoft/playwright#42656](https://redirect.github.com/microsoft/playwright/issues/42656)). ([microsoft/playwright#42664](https://redirect.github.com/microsoft/playwright/pull/42664), [microsoft/playwright#42741](https://redirect.github.com/microsoft/playwright/pull/42741)) #### 📦 Upgrading Configs that use `@playwright/mcp@latest` pick this release up on the next client restart. To pin it: ```bash npx @playwright/mcp@0.0.82 ``` </details> --- ### Configuration 📅 **Schedule**: (in timezone Asia/Tokyo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/izumin5210/dotfiles). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Summary
browser_routeheader lines that have no name.setFilessucceeds.Problem
Short secrets such as
eran throughreplaceAlland rewrote the whole tool response. Header strings without:became a header named"".browser_file_uploadcleared modal state beforesetFiles, so a failed upload could not be retried.Change
redactSecretsignores empty and length-less-than-4 values (empty was already skipped).:is missing or first.clearModalStateruns aftersetFilescompletes.Validation
tests/mcp/secrets.spec.ts: short secretedoes not inject<secret>markers intohello.tests/mcp/route.spec.ts:NotAHeaderis ignored;X-Custom-Headerstill applies.tests/mcp/files.spec.ts: missing path keeps the chooser; a second upload succeeds.