Skip to content

fix(mcp): keep upload modal, skip short secrets and bad headers - #42713

Merged
Devin Rousso (dcrousso) merged 4 commits into
microsoft:mainfrom
SebTardif:fix-mcp-upload-route-secrets
Sep 17, 2026
Merged

Devin Rousso (dcrousso) merged 4 commits into
microsoft:mainfrom
SebTardif:fix-mcp-upload-route-secrets

Conversation

@SebTardif

Copy link
Copy Markdown
Contributor

Summary

  • Skip MCP secret redaction for values shorter than 4 characters.
  • Ignore browser_route header lines that have no name.
  • Clear the file-chooser modal only after setFiles succeeds.

Problem

Short secrets such as e ran through replaceAll and rewrote the whole tool response. Header strings without : became a header named "". browser_file_upload cleared modal state before setFiles, so a failed upload could not be retried.

Change

  • redactSecrets ignores empty and length-less-than-4 values (empty was already skipped).
  • Route header parsing skips entries whose : is missing or first.
  • clearModalState runs after setFiles completes.

Validation

  • tests/mcp/secrets.spec.ts: short secret e does not inject <secret> markers into hello.
  • tests/mcp/route.spec.ts: NotAHeader is ignored; X-Custom-Header still applies.
  • tests/mcp/files.spec.ts: missing path keeps the chooser; a second upload succeeds.

Do not redact secret values shorter than 4 characters. Ignore route
header lines that have no name. Clear the file chooser only after
setFiles succeeds so a failed upload can be retried.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@github-actions

This comment has been minimized.

waitForCompletion returns immediately when a fileChooser modal is
already listed, so wrapping setFiles in it skipped the upload. Call
setFiles first, keep the chooser on failure, then settle.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
Comment thread packages/playwright-core/src/tools/backend/route.ts Outdated
Return an argument error for values that are not Name: Value.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
redactSecrets(text: string): string {
for (const [secretName, secretValue] of Object.entries(this.config.secrets ?? {})) {
if (!secretValue)
if (!secretValue || secretValue.length < 4)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please avoid configuring guessable values such as abc as secrets rather than silently disabling redaction for short values (see microsoft/playwright-mcp#1106 (comment))

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Rousso (@dcrousso)

please avoid configuring guessable values such as abc as secrets rather than silently disabling redaction for short values

Removed the length < 4 skip. Empty values are still ignored. The short-secret test is gone. 36971b002

}
}
tab.clearModalState(modalState);
await tab.waitForCompletion(async () => {});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

starting the completion wait after setFiles() misses requests triggered by the upload on WebKit, so the tool can return before those requests finish

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Rousso (@dcrousso)

starting the completion wait after setFiles() misses requests triggered by the upload on WebKit

setFiles is back inside waitForCompletion. The file chooser is cleared first so the wait actually runs. 36971b002

if (paths)
if (paths) {
try {
await modalState.fileChooser.setFiles(paths);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

awaiting setFiles() outside waitForCompletion() makes uploads whose change handler opens a dialog time out instead of returning the dialog for handling

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Rousso (@dcrousso)

awaiting setFiles() outside waitForCompletion() makes uploads whose change handler opens a dialog time out instead of returning the dialog for handling

Same change: setFiles runs inside waitForCompletion after the chooser is cleared, so a dialog from the change handler is returned. If setFiles throws, the chooser is restored. 36971b002

@github-actions

This comment has been minimized.

Clear the file chooser first so waitForCompletion can run, then
setFiles inside it so WebKit upload requests and change-handler
dialogs are observed. Restore the chooser if setFiles fails.

Redact all non-empty secret values. Do not skip short ones.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

2 failed
❌ [firefox] › mcp/annotate.spec.ts:269 › should start dashboard and annotate when no dashboard is running @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-session.spec.ts:54 › idle timeout shuts the session down @mcp-windows-latest-firefox

8614 passed, 1446 skipped


Merge workflow run.

@dcrousso Devin Rousso (dcrousso) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks for the fix!

@dcrousso
Devin Rousso (dcrousso) merged commit 464318b into microsoft:main Sep 17, 2026
17 of 18 checks passed
@pavelfeldman

Copy link
Copy Markdown
Member

Please file those issues next time!

Copilot AI added a commit to microsoft/playwright-mcp that referenced this pull request Sep 18, 2026
## What's New

### New Tools

- **`browser_emulate_media`** — Emulate color scheme, reduced motion, forced colors, contrast, and screen/print media. Pass `null` to clear an override ([#42668](microsoft/playwright#42668)).

### Other Changes

- **Tool removal:** `browser_webmcp_list` and `browser_webmcp_call` are now skill-only and no longer exposed as MCP tools ([#42671](microsoft/playwright#42671)).

## Bug Fixes

- Failed `browser_file_upload` calls preserve the file chooser, allowing another upload attempt without reopening it ([#42713](microsoft/playwright#42713)).
- Corrected the Playwright import in the published configuration types ([#1762](#1762)).

Co-authored-by: pavelfeldman <883973+pavelfeldman@users.noreply.github.com>
Copilot AI added a commit to microsoft/playwright-mcp that referenced this pull request Sep 18, 2026
## What's New

### New Tools

- **`browser_emulate_media`** — Emulate color scheme, reduced motion, forced colors, contrast, and screen/print media. Pass `null` to clear an override ([#42668](microsoft/playwright#42668)).

### Other Changes

- **Tool removal:** `browser_webmcp_list` and `browser_webmcp_call` are now skill-only and no longer exposed as MCP tools ([#42671](microsoft/playwright#42671)).

## Bug Fixes

- Failed `browser_file_upload` calls preserve the file chooser, allowing another upload attempt without reopening it ([#42713](microsoft/playwright#42713)).
- Corrected the Playwright import in the published configuration types ([#1762](#1762)).

Co-authored-by: pavelfeldman <883973+pavelfeldman@users.noreply.github.com>
Pavel Feldman (pavelfeldman) added a commit to microsoft/playwright-cli that referenced this pull request Sep 18, 2026
## ✨ Highlights

- **🎬 Smooth 60 fps, styleable videos** — `video-start --fps=60` records
smooth 60 fps videos instead of the default 25, and `video-start
--cursor` renders an animated mouse cursor that travels to each action
point and stays visible between actions. `video-show-actions` takes
`--point-style`, `--highlight-style` and `--title-style` CSS
declarations; the action point marker and the target highlight are now
only shown when styled.
([microsoft/playwright#42752](microsoft/playwright#42752),
[microsoft/playwright#42758](microsoft/playwright#42758))
- **🧰 WebMCP tools show up in the snapshot** — the tools a page
registers are listed at the top of the page snapshot with their
descriptions and input schemas, so `webmcp-call` can be used without
running `webmcp-list` first. Set `webmcp: false` in the config file (env
`PLAYWRIGHT_MCP_WEBMCP=false`) to stop collecting page-registered tools.
([microsoft/playwright#42671](microsoft/playwright#42671))
- **🌗 Switch between light and dark color scheme**
([microsoft/playwright#42243](microsoft/playwright#42243))
— an agent working on a dark theme had no way to see it mid-session. New
`set-color-scheme`, `set-reduced-motion`, `set-forced-colors`,
`set-contrast` and `set-media` commands emulate media features on the
fly, and the matching `clear-*` commands reset them.
([microsoft/playwright#42668](microsoft/playwright#42668))
- **📁 Absolute paths in results**
([microsoft/playwright#42497](microsoft/playwright#42497))
— links to snapshots, screenshots, console logs and downloads are
relative to the working directory, which a consumer without one cannot
resolve. Set `filePaths: "absolute"` in the config file (env
`PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead.
([microsoft/playwright#42673](microsoft/playwright#42673))

## 🐛 Fixes

- `fix(chromium): bypass service workers on the storage state page` —
`state-save` no longer runs the site's own scripts, or fails when they
redirect, for origins with an active service worker
([microsoft/playwright#42656](microsoft/playwright#42656)).
([#42664](microsoft/playwright#42664),
[#42741](microsoft/playwright#42741))
- `fix(mcp): keep upload modal, skip short secrets and bad headers` — a
failed `upload` keeps the file chooser open so it can be retried,
secrets shorter than 4 characters no longer rewrite the whole output
with `<secret>` markers, and `route` ignores header lines that have no
name. ([#42713](microsoft/playwright#42713))

## 📦 Upgrading

```bash
npm install -g @playwright/cli@0.1.21
```
Pavel Feldman (pavelfeldman) added a commit to microsoft/playwright-mcp that referenced this pull request Sep 18, 2026
## ✨ Highlights

- **🧰 WebMCP tools become real MCP tools** — the tools a page registers
through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API
now show up right in the tool list as `webmcp_<tool>`, with the page's
own input schema and annotations, so an agent can call them directly and
let the page do the work instead of driving its UI. The list follows the
current tab, and clients get a `tools/list_changed` notification when it
changes. This replaces `browser_webmcp_list` / `browser_webmcp_call`
from v0.0.81, which are no longer exposed over MCP. Tool names,
descriptions, schemas and results come from the page, so treat them as
untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env
`PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see
[WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how
to enable it.
([microsoft/playwright#42671](microsoft/playwright#42671))
- **🌗 Switch between light and dark color scheme**
([microsoft/playwright#42243](microsoft/playwright#42243))
— an agent working on a dark theme had no way to see it mid-session. The
new **`browser_emulate_media`** tool emulates media features on the fly:
`colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the
`media` type (screen / print). Omitted parameters are left unchanged,
`null` clears an override.
([microsoft/playwright#42668](microsoft/playwright#42668))
- **📁 Absolute paths in results**
([microsoft/playwright#42497](microsoft/playwright#42497))
— links to snapshots, screenshots, console logs and downloads are
relative to the workspace root, which a client without one cannot
resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`,
env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead.
([microsoft/playwright#42673](microsoft/playwright#42673))

## 🐛 Fixes

- `fix(mcp): keep upload modal and reject bad headers` — a failed
`browser_file_upload` (e.g. a missing file) reports the error and keeps
the file chooser open so it can be retried, and `browser_route` (opt-in
via `--caps=network`) returns an error for a header that is not in the
`Name: Value` form instead of setting a header named `""`.
([microsoft/playwright#42713](microsoft/playwright#42713))
- `fix(chromium): bypass service workers on the storage state page` —
`browser_storage_state` (opt-in via `--caps=storage`) no longer runs the
site's own scripts, or fails when they redirect, for origins with an
active service worker
([microsoft/playwright#42656](microsoft/playwright#42656)).
([microsoft/playwright#42664](microsoft/playwright#42664),
[microsoft/playwright#42741](microsoft/playwright#42741))

## 📦 Upgrading

Configs that use `@playwright/mcp@latest` pick this release up on the
next client restart. To pin it:

```bash
npx @playwright/mcp@0.0.82
```
renovate Bot added a commit to soodoh/dotfiles that referenced this pull request Sep 19, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[@types/node](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node)
([source](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node))
| [`^26.6.1` →
`^26.6.2`](https://renovatebot.com/diffs/npm/@types%2fnode/26.6.1/26.6.2)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@types%2fnode/26.6.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@types%2fnode/26.6.1/26.6.2?slim=true)
|
| [npm:@playwright/mcp](https://playwright.dev)
([source](https://redirect.github.com/microsoft/playwright-mcp)) |
`0.0.81` → `0.0.82` |
![age](https://developer.mend.io/api/mc/badges/age/npm/@playwright%2fmcp/0.0.82?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@playwright%2fmcp/0.0.81/0.0.82?slim=true)
|

---

### Release Notes

<details>
<summary>microsoft/playwright-mcp (npm:@&#8203;playwright/mcp)</summary>

###
[`v0.0.82`](https://redirect.github.com/microsoft/playwright-mcp/releases/tag/v0.0.82)

[Compare
Source](https://redirect.github.com/microsoft/playwright-mcp/compare/v0.0.81...v0.0.82)

#### ✨ Highlights

- **🎬 Smooth 60 fps, styleable videos** — `browser_start_video` (opt-in
via `--caps=devtools`) takes `fps`, so `fps: 60` records smooth 60 fps
videos instead of the default 25, and `cursor: true` renders an animated
mouse cursor that travels to each action point and stays visible between
actions. `browser_video_show_actions` takes a `style` with `point`,
`highlight` and `title` CSS declarations; the action point marker and
the target highlight are now only shown when styled.
([microsoft/playwright#42752](https://redirect.github.com/microsoft/playwright/pull/42752),
[microsoft/playwright#42758](https://redirect.github.com/microsoft/playwright/pull/42758))
- **🧰 WebMCP tools become real MCP tools** — the tools a page registers
through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API
now show up right in the tool list as `webmcp_<tool>`, with the page's
own input schema and annotations, so an agent can call them directly and
let the page do the work instead of driving its UI. The list follows the
current tab, and clients get a `tools/list_changed` notification when it
changes. This replaces `browser_webmcp_list` / `browser_webmcp_call`
from v0.0.81, which are no longer exposed over MCP. Tool names,
descriptions, schemas and results come from the page, so treat them as
untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env
`PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see
[WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how
to enable it.
([microsoft/playwright#42671](https://redirect.github.com/microsoft/playwright/pull/42671))
- **🌗 Switch between light and dark color scheme**
([microsoft/playwright#42243](https://redirect.github.com/microsoft/playwright/issues/42243))
— an agent working on a dark theme had no way to see it mid-session. The
new **`browser_emulate_media`** tool emulates media features on the fly:
`colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the
`media` type (screen / print). Omitted parameters are left unchanged,
`null` clears an override.
([microsoft/playwright#42668](https://redirect.github.com/microsoft/playwright/pull/42668))
- **📁 Absolute paths in results**
([microsoft/playwright#42497](https://redirect.github.com/microsoft/playwright/issues/42497))
— links to snapshots, screenshots, console logs and downloads are
relative to the workspace root, which a client without one cannot
resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`,
env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead.
([microsoft/playwright#42673](https://redirect.github.com/microsoft/playwright/pull/42673))

#### 🐛 Fixes

- `fix(mcp): keep upload modal and reject bad headers` — a failed
`browser_file_upload` (e.g. a missing file) reports the error and keeps
the file chooser open so it can be retried, and `browser_route` (opt-in
via `--caps=network`) returns an error for a header that is not in the
`Name: Value` form instead of setting a header named `""`.
([microsoft/playwright#42713](https://redirect.github.com/microsoft/playwright/pull/42713))
- `fix(chromium): bypass service workers on the storage state page` —
`browser_storage_state` (opt-in via `--caps=storage`) no longer runs the
site's own scripts, or fails when they redirect, for origins with an
active service worker
([microsoft/playwright#42656](https://redirect.github.com/microsoft/playwright/issues/42656)).
([microsoft/playwright#42664](https://redirect.github.com/microsoft/playwright/pull/42664),
[microsoft/playwright#42741](https://redirect.github.com/microsoft/playwright/pull/42741))

#### 📦 Upgrading

Configs that use `@playwright/mcp@latest` pick this release up on the
next client restart. To pin it:

```bash
npx @playwright/mcp@0.0.82
```

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/soodoh/dotfiles).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Paul Sorensen (paulnsorensen) added a commit to paulnsorensen/dotfiles that referenced this pull request Sep 19, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Adoption](https://docs.renovatebot.com/merge-confidence/) |
[Passing](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|---|---|
| [@playwright/mcp](https://playwright.dev)
([source](https://redirect.github.com/microsoft/playwright-mcp)) |
`0.0.81` → `0.0.82` |
![age](https://developer.mend.io/api/mc/badges/age/npm/@playwright%2fmcp/0.0.82?slim=true)
|
![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@playwright%2fmcp/0.0.82?slim=true)
|
![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@playwright%2fmcp/0.0.81/0.0.82?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@playwright%2fmcp/0.0.81/0.0.82?slim=true)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the warning logs for
more information.

---

### Release Notes

<details>
<summary>microsoft/playwright-mcp (@&#8203;playwright/mcp)</summary>

###
[`v0.0.82`](https://redirect.github.com/microsoft/playwright-mcp/releases/tag/v0.0.82)

[Compare
Source](https://redirect.github.com/microsoft/playwright-mcp/compare/v0.0.81...v0.0.82)

#### ✨ Highlights

- **🎬 Smooth 60 fps, styleable videos** — `browser_start_video` (opt-in
via `--caps=devtools`) takes `fps`, so `fps: 60` records smooth 60 fps
videos instead of the default 25, and `cursor: true` renders an animated
mouse cursor that travels to each action point and stays visible between
actions. `browser_video_show_actions` takes a `style` with `point`,
`highlight` and `title` CSS declarations; the action point marker and
the target highlight are now only shown when styled.
([microsoft/playwright#42752](https://redirect.github.com/microsoft/playwright/pull/42752),
[microsoft/playwright#42758](https://redirect.github.com/microsoft/playwright/pull/42758))
- **🧰 WebMCP tools become real MCP tools** — the tools a page registers
through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API
now show up right in the tool list as `webmcp_<tool>`, with the page's
own input schema and annotations, so an agent can call them directly and
let the page do the work instead of driving its UI. The list follows the
current tab, and clients get a `tools/list_changed` notification when it
changes. This replaces `browser_webmcp_list` / `browser_webmcp_call`
from v0.0.81, which are no longer exposed over MCP. Tool names,
descriptions, schemas and results come from the page, so treat them as
untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env
`PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see
[WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how
to enable it.
([microsoft/playwright#42671](https://redirect.github.com/microsoft/playwright/pull/42671))
- **🌗 Switch between light and dark color scheme**
([microsoft/playwright#42243](https://redirect.github.com/microsoft/playwright/issues/42243))
— an agent working on a dark theme had no way to see it mid-session. The
new **`browser_emulate_media`** tool emulates media features on the fly:
`colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the
`media` type (screen / print). Omitted parameters are left unchanged,
`null` clears an override.
([microsoft/playwright#42668](https://redirect.github.com/microsoft/playwright/pull/42668))
- **📁 Absolute paths in results**
([microsoft/playwright#42497](https://redirect.github.com/microsoft/playwright/issues/42497))
— links to snapshots, screenshots, console logs and downloads are
relative to the workspace root, which a client without one cannot
resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`,
env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead.
([microsoft/playwright#42673](https://redirect.github.com/microsoft/playwright/pull/42673))

#### 🐛 Fixes

- `fix(mcp): keep upload modal and reject bad headers` — a failed
`browser_file_upload` (e.g. a missing file) reports the error and keeps
the file chooser open so it can be retried, and `browser_route` (opt-in
via `--caps=network`) returns an error for a header that is not in the
`Name: Value` form instead of setting a header named `""`.
([microsoft/playwright#42713](https://redirect.github.com/microsoft/playwright/pull/42713))
- `fix(chromium): bypass service workers on the storage state page` —
`browser_storage_state` (opt-in via `--caps=storage`) no longer runs the
site's own scripts, or fails when they redirect, for origins with an
active service worker
([microsoft/playwright#42656](https://redirect.github.com/microsoft/playwright/issues/42656)).
([microsoft/playwright#42664](https://redirect.github.com/microsoft/playwright/pull/42664),
[microsoft/playwright#42741](https://redirect.github.com/microsoft/playwright/pull/42741))

#### 📦 Upgrading

Configs that use `@playwright/mcp@latest` pick this release up on the
next client restart. To pin it:

```bash
npx @playwright/mcp@0.0.82
```

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/paulnsorensen/dotfiles).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Chores**
  - Updated the Playwright MCP package to version 0.0.82.
  - Synchronized the package version used by the Codex profile test.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: dep-harvest-bot <paulnsorensen@gmail.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
renovate Bot added a commit to izumin5210/dotfiles that referenced this pull request Sep 22, 2026
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@playwright/mcp](https://playwright.dev)
([source](https://redirect.github.com/microsoft/playwright-mcp)) |
[`0.0.81` →
`0.0.82`](https://renovatebot.com/diffs/npm/@playwright%2fmcp/0.0.81/0.0.82)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@playwright%2fmcp/0.0.82?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@playwright%2fmcp/0.0.81/0.0.82?slim=true)
|

---

### Release Notes

<details>
<summary>microsoft/playwright-mcp (@&#8203;playwright/mcp)</summary>

###
[`v0.0.82`](https://redirect.github.com/microsoft/playwright-mcp/releases/tag/v0.0.82)

[Compare
Source](https://redirect.github.com/microsoft/playwright-mcp/compare/v0.0.81...v0.0.82)

#### ✨ Highlights

- **🎬 Smooth 60 fps, styleable videos** — `browser_start_video` (opt-in
via `--caps=devtools`) takes `fps`, so `fps: 60` records smooth 60 fps
videos instead of the default 25, and `cursor: true` renders an animated
mouse cursor that travels to each action point and stays visible between
actions. `browser_video_show_actions` takes a `style` with `point`,
`highlight` and `title` CSS declarations; the action point marker and
the target highlight are now only shown when styled.
([microsoft/playwright#42752](https://redirect.github.com/microsoft/playwright/pull/42752),
[microsoft/playwright#42758](https://redirect.github.com/microsoft/playwright/pull/42758))
- **🧰 WebMCP tools become real MCP tools** — the tools a page registers
through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API
now show up right in the tool list as `webmcp_<tool>`, with the page's
own input schema and annotations, so an agent can call them directly and
let the page do the work instead of driving its UI. The list follows the
current tab, and clients get a `tools/list_changed` notification when it
changes. This replaces `browser_webmcp_list` / `browser_webmcp_call`
from v0.0.81, which are no longer exposed over MCP. Tool names,
descriptions, schemas and results come from the page, so treat them as
untrusted input. Pass `--no-webmcp` (config `webmcp: false`, env
`PLAYWRIGHT_MCP_WEBMCP=false`) to opt out. WebMCP is experimental, see
[WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how
to enable it.
([microsoft/playwright#42671](https://redirect.github.com/microsoft/playwright/pull/42671))
- **🌗 Switch between light and dark color scheme**
([microsoft/playwright#42243](https://redirect.github.com/microsoft/playwright/issues/42243))
— an agent working on a dark theme had no way to see it mid-session. The
new **`browser_emulate_media`** tool emulates media features on the fly:
`colorScheme`, `reducedMotion`, `forcedColors`, `contrast` and the
`media` type (screen / print). Omitted parameters are left unchanged,
`null` clears an override.
([microsoft/playwright#42668](https://redirect.github.com/microsoft/playwright/pull/42668))
- **📁 Absolute paths in results**
([microsoft/playwright#42497](https://redirect.github.com/microsoft/playwright/issues/42497))
— links to snapshots, screenshots, console logs and downloads are
relative to the workspace root, which a client without one cannot
resolve. Pass `--file-paths=absolute` (config `filePaths: "absolute"`,
env `PLAYWRIGHT_MCP_FILE_PATHS=absolute`) to get absolute paths instead.
([microsoft/playwright#42673](https://redirect.github.com/microsoft/playwright/pull/42673))

#### 🐛 Fixes

- `fix(mcp): keep upload modal and reject bad headers` — a failed
`browser_file_upload` (e.g. a missing file) reports the error and keeps
the file chooser open so it can be retried, and `browser_route` (opt-in
via `--caps=network`) returns an error for a header that is not in the
`Name: Value` form instead of setting a header named `""`.
([microsoft/playwright#42713](https://redirect.github.com/microsoft/playwright/pull/42713))
- `fix(chromium): bypass service workers on the storage state page` —
`browser_storage_state` (opt-in via `--caps=storage`) no longer runs the
site's own scripts, or fails when they redirect, for origins with an
active service worker
([microsoft/playwright#42656](https://redirect.github.com/microsoft/playwright/issues/42656)).
([microsoft/playwright#42664](https://redirect.github.com/microsoft/playwright/pull/42664),
[microsoft/playwright#42741](https://redirect.github.com/microsoft/playwright/pull/42741))

#### 📦 Upgrading

Configs that use `@playwright/mcp@latest` pick this release up on the
next client restart. To pin it:

```bash
npx @playwright/mcp@0.0.82
```

</details>

---

### Configuration

📅 **Schedule**: (in timezone Asia/Tokyo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/izumin5210/dotfiles).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants