| Dimension | Shared | Only in A | Only in B | Overlap |
|---|---|---|---|---|
| Sections | 0 | 19 | 7 | 0% |
| Commands | 0 | 3 | 0 | 0% |
| Section tags | 1 | 4 | 2 | 14% |
What each file covers
Sections
0 shared · 19 only in A · 7 only in B- − Debug Harness
- − Quick start
- − Build extension first if needed (protos + esbuild):
- − Launch (skip-build if already built). Run with node, NOT bun — Playwright's
- − Electron launch times out under bun:
- − In another terminal:
- − Data Isolation
- − Browser Capture & OAuth
- − OAuth API
- − OAuth testing flow
- − Navigating Views — Use Commands, Not Clicks
- − Key commands
- − Typical Session
- − 1. Launch
- − 2. Open sidebar + dismiss overlays (ALWAYS do this first)
- − 3. Navigate to view
- − 4. Check captured OAuth URLs if testing auth
- − 5. Verify
- − Caveats
- + Networking & Proxy Support
- + Guidelines
- + 1. Using `fetch`
- + 2. Using `axios`
- + 3. Third-Party Clients (OpenAI, Ollama, etc.)
- + 4. Tests
- + Verification
Commands
0 shared · 3 only in A · 0 only in B- − bun run protos && IS_DEV=true bun esbuild.mjs
- − node src/dev/debug-harness/server.ts --skip-build --auto-launch
- − bun run dev:mcp-oauth-test-server
Section tags
1 shared · 4 only in A · 2 only in B- − build
- − test
- − security
- − api
- + code-style
- + dependencies
- testing-strategy
Line diff
cline/cline · .clinerules/debug-harness.md
@@ −1 @@
1# Debug Harness
2
3HTTP-controlled debugger for the VSCode extension at `src/dev/debug-harness/server.ts`.
4
5## Quick start
6
7```bash
8# Build extension first if needed (protos + esbuild):
9bun run protos && IS_DEV=true bun esbuild.mjs
10
11# Launch (skip-build if already built). Run with node, NOT bun — Playwright's
12# Electron launch times out under bun:
13node src/dev/debug-harness/server.ts --skip-build --auto-launch
14
15# In another terminal:
16curl localhost:19229/api -d '{"method":"status"}'
17```
18
19## Data Isolation
20
21The debugee runs with `CLINE_DIR=~/.cline2` by default, separate from your real `~/.cline`.
22This prevents the debugee's logout from logging out the debugger, and vice versa.
23Override with `--cline-dir /tmp/test-dir`. Check with `status()` → `clineDir`.
24
25## Browser Capture & OAuth
26
27The debugee runs with `CLINE_CAPTURE_BROWSER=1`, which intercepts `openExternal()` in
28`src/utils/env.ts`. URLs are captured instead of opening a real browser:
29
30- Logged to `$CLINE_DIR/data/debug-captured-urls.jsonl`
31- POSTed in real-time to `/captured-url` on the harness server
32- Queryable via `oauth.captured_urls`
33
34### OAuth API
35
36- **`oauth.captured_urls`** `{clear?}` — URLs the debugee tried to open
37- **`oauth.read_stored_token`** — Check auth token presence in secrets.json
38- **`oauth.simulate_callback`** `{path, code?, state?, provider?, token?}` — Build vscode:// callback URI
39- **`oauth.read_captured_urls_file`** — Read on-disk JSONL of captured URLs
40
41### OAuth testing flow
42
43For **Cline OAuth** (SDK local callback): The SDK starts a local HTTP server, the auth URL
44is captured. To complete: open the captured URL in a real browser (it redirects back to the
45SDK's callback server), OR extract the callback port and `curl http://127.0.0.1:PORT/callback?code=...`.
46
47For **MCP/Provider OAuth** (vscode:// URI): The redirect goes to a vscode:// URI.
48`oauth.simulate_callback` only *builds* the URI — it does not deliver it, and the ESM
49extension host can't `require()` the handler. To actually deliver the callback, call the
50debug-only hook via `ext.evaluate` (with `awaitPromise: true`):
51`globalThis.__clineHandleUri("vscode://saoudrizwan.claude-dev/...?code=...&state=...")`.
52It runs the same `SharedUriHandler.handleUri` as VSCode's real URI handler and exists only
53when `CLINE_CAPTURE_BROWSER` is set (the harness always sets it; never ships in prod).
54For end-to-end MCP OAuth, get a real `code` from the local MCP OAuth test server
55(`bun run dev:mcp-oauth-test-server`).
56
57## Navigating Views — Use Commands, Not Clicks
58
59Don't try to find/click small sidebar icons. Use VSCode commands via command palette.
60Registered in `src/registry.ts`:
61
62| Command | View |
63|---------|------|
64| `cline.accountButtonClicked` | Account / sign-in |
65| `cline.historyButtonClicked` | Task history |
66| `cline.settingsButtonClicked` | Settings |
67| `cline.mcpButtonClicked` | MCP servers |
68| `cline.plusButtonClicked` | New task (chat) |
69| `cline.worktreesButtonClicked` | Worktrees |
70
71```bash
72curl localhost:19229/api -d '{"method":"ui.command_palette","params":{"command":"cline.accountButtonClicked"}}'
73```
74
75## Key commands
76
77All via `POST localhost:19229/api` with `{"method":"...", "params":{...}}`:
78
79- **`launch`** / **`shutdown`** — lifecycle
80- **`ui.screenshot`** — screenshot to `/tmp/cline-debug/`; returns `{path}` — **use `read_file` on the path to examine, do NOT `open` the file** (Preview.app covers the VSCode window)
81- **`ui.open_sidebar`** — open the Cline sidebar
82- **`ext.set_breakpoint`** `{file, line, condition?}` — breakpoint by source file (sourcemap-resolved)
83- **`ext.evaluate`** `{expression, callFrameId?}` — eval in extension host
84- **`ext.resume`** / **`ext.step_over`** / **`ext.step_into`** — stepping
85- **`ext.call_stack`** — inspect when paused
86- **`web.evaluate`** `{expression}` — eval in webview
87- **`web.post_message`** `{message}` — send postMessage to extension host via exposed vsCodeApi
88- **`wait_for_pause`** `{timeout?}` — block until breakpoint hit
89- **`ui.locator`** `{role?, testId?, text?, frame?}` — Playwright locator (auto-retries on stale sidebar frame)
90- **`ui.react_input`** `{text, selector?, clear?, submit?}` — set React textarea value via `execCommand('insertText')`; works reliably across multiple tasks
91- **`ui.send_message`** `{text, images?, files?, responseType?}` — send chat message bypassing the textarea entirely (via gRPC postMessage)
92- **`ui.command_palette`** `{command}` — run VSCode command
93
94## Typical Session
95
96```bash
97# 1. Launch
98curl localhost:19229/api -d '{"method":"launch","params":{"skipBuild":true}}'
99
100# 2. Open sidebar + dismiss overlays (ALWAYS do this first)
101curl localhost:19229/api -d '{"method":"ui.open_sidebar"}'
102curl localhost:19229/api -d '{"method":"web.evaluate","params":{"expression":"document.querySelectorAll(\".sr-only\").forEach(el => el.parentElement?.click())"}}'
103
104# 3. Navigate to view
105curl localhost:19229/api -d '{"method":"ui.command_palette","params":{"command":"cline.accountButtonClicked"}}'
106
107# 4. Check captured OAuth URLs if testing auth
108curl localhost:19229/api -d '{"method":"oauth.captured_urls"}'
109
110# 5. Verify
111curl localhost:19229/api -d '{"method":"ui.screenshot"}'
112```
113
114## Caveats
115
116- **⚠️ Dismiss promotional overlays FIRST**: On fresh launches, full-screen promo overlays block the sidebar. **Dismiss immediately after `ui.open_sidebar`**, before any other interaction or screenshot. May need to run twice:
117 ```bash
118 curl localhost:19229/api -d '{"method": "ui.open_sidebar"}'
119 curl localhost:19229/api -d '{"method": "web.evaluate", "params": {"expression": "document.querySelectorAll(\".sr-only\").forEach(el => el.parentElement?.click())"}}'
120 ```
121- **Screenshots — don't open the file**: `ui.screenshot` and `ui.sidebar_screenshot` save PNGs to `/tmp/cline-debug/` and return the `{path}`. Use `read_file` on that path to examine screenshots. Running `open <path>` launches Preview.app on macOS which covers the VSCode window.
122- **Scripts count = 0 after launch**: CDP connects after extension host starts, so scripts parsed during startup aren't tracked. Breakpoints still work via sourcemap resolution.
123- **Port 9230**: Extension host inspector. If another VSCode instance uses this port, the harness will fail to connect. Kill other debug instances first.
124- **macOS only** for now (Playwright Electron launch behavior).
125- **Webview CDP**: `connect_webview` may fail depending on Electron version. `web.evaluate` still works via Playwright's `frame.evaluate()` fallback.
126- **Sourcemap paths**: esbuild outputs relative paths like `../src/extension.ts` in the sourcemap. The resolver handles this, but if a file isn't found, use `ext.source_files` to see exact paths.
127- **OAuth with fake codes**: Browser capture intercepts the URL but doesn't provide a valid auth code. For real OAuth testing, open the captured URL in a browser. For unit testing, mock the token exchange.
128
129See `src/dev/debug-harness/README.md` for full API reference.
130
cline/cline · .clinerules/network.md
@@ +1 @@
1# Networking & Proxy Support
2
3To ensure Cline works correctly in all environments (VSCode, JetBrains, CLI) and with various network configurations (especially corporate proxies), strictly follow these guidelines for all network activity.
4
5In extension code, do NOT use the global `fetch` or a default `axios` instance. (Note, `shared/net.ts` is exempt from these rules because it sets up the fetch wrappers.) In Webview code, you SHOULD use global `fetch`.
6
7Global `fetch` and default `axios` do not automatically pick up proxy configurations in all environments (specifically JetBrains and CLI). You MUST use the provided utilities in `@/shared/net` which handle proxy agent configuration. In the webview, the browser/embedder handles proxies.
8
9## Guidelines
10
11### 1. Using `fetch`
12
13Instead of `fetch(...)`, import the proxy-aware wrapper:
14
15```typescript
16import { fetch } from '@/shared/net'
17
18// Usage is identical to global fetch
19const response = await fetch('https://api.example.com/data')
20```
21
22### 2. Using `axios`
23
24When using `axios`, you must apply the settings from `getAxiosSettings()`:
25
26```typescript
27import axios from 'axios'
28import { getAxiosSettings } from '@/shared/net'
29
30const response = await axios.get('https://api.example.com/data', {
31 headers: { 'Authorization': '...' },
32 ...getAxiosSettings() // <--- CRITICAL: Injects the proxy agent if needed
33})
34```
35
36### 3. Third-Party Clients (OpenAI, Ollama, etc.)
37
38Most API client libraries allow you to customize the `fetch` implementation. You **MUST** pass the proxy-aware `fetch` to these clients.
39
40**Example (OpenAI):**
41```typescript
42import OpenAI from "openai"
43import { fetch } from "@/shared/net"
44
45this.client = new OpenAI({
46 apiKey: '...',
47 fetch, // <--- CRITICAL: Pass our fetch wrapper
48})
49```
50
51### 4. Tests
52
53Use `mockFetchForTesting` to mock the underlying fetch implementation.
54
55**Example (callback):**
56
57```
58import { mockFetchForTesting } from "@/shared/net"
59
60...
61 let mockFetch = ...
62 mockFetchForTesting(mockFetch, () => {
63 // This calls mockFetch
64 fetch('https://foo.example').then(...)
65 })
66 // Original fetch is restored immediately when the call returns.
67```
68
69**Example (Promise):**
70
71```
72import { mockFetchForTesting } from "@/shared/net"
73
74...
75 let mockFetch = ...
76 await mockFetchForTesting(mockFetch, async () => {
77 await ...
78 // This calls mockFetch
79 await fetch('https://foo.example')
80 ...
81 })
82 // Original fetch is restored when the Promise from the callback settles
83```
84
85## Verification
86
87If you are adding a new network call or integration:
881. Check `@/shared/net.ts` is imported.
892. Ensure `fetch` or `getAxiosSettings` is being used.
903. Verify that third-party clients are configured to use the custom fetch.
91
@@ −1 +1 @@
1−# Debug Harness
1+# Networking & Proxy Support
22
3−HTTP-controlled debugger for the VSCode extension at `src/dev/debug-harness/server.ts`.
3+To ensure Cline works correctly in all environments (VSCode, JetBrains, CLI) and with various network configurations (especially corporate proxies), strictly follow these guidelines for all network activity.
44
5−## Quick start
5+In extension code, do NOT use the global `fetch` or a default `axios` instance. (Note, `shared/net.ts` is exempt from these rules because it sets up the fetch wrappers.) In Webview code, you SHOULD use global `fetch`.
66
7−```bash
8−# Build extension first if needed (protos + esbuild):
9−bun run protos && IS_DEV=true bun esbuild.mjs
7+Global `fetch` and default `axios` do not automatically pick up proxy configurations in all environments (specifically JetBrains and CLI). You MUST use the provided utilities in `@/shared/net` which handle proxy agent configuration. In the webview, the browser/embedder handles proxies.
108
11−# Launch (skip-build if already built). Run with node, NOT bun — Playwright's
12−# Electron launch times out under bun:
13−node src/dev/debug-harness/server.ts --skip-build --auto-launch
9+## Guidelines
1410
15−# In another terminal:
16−curl localhost:19229/api -d '{"method":"status"}'
17−```
11+### 1. Using `fetch`
1812
19−## Data Isolation
13+Instead of `fetch(...)`, import the proxy-aware wrapper:
2014
21−The debugee runs with `CLINE_DIR=~/.cline2` by default, separate from your real `~/.cline`.
22−This prevents the debugee's logout from logging out the debugger, and vice versa.
23−Override with `--cline-dir /tmp/test-dir`. Check with `status()` → `clineDir`.
15+```typescript
16+import { fetch } from '@/shared/net'
2417
25−## Browser Capture & OAuth
18+// Usage is identical to global fetch
19+const response = await fetch('https://api.example.com/data')
20+```
2621
27−The debugee runs with `CLINE_CAPTURE_BROWSER=1`, which intercepts `openExternal()` in
28−`src/utils/env.ts`. URLs are captured instead of opening a real browser:
22+### 2. Using `axios`
2923
30−- Logged to `$CLINE_DIR/data/debug-captured-urls.jsonl`
31−- POSTed in real-time to `/captured-url` on the harness server
32−- Queryable via `oauth.captured_urls`
24+When using `axios`, you must apply the settings from `getAxiosSettings()`:
3325
34−### OAuth API
26+```typescript
27+import axios from 'axios'
28+import { getAxiosSettings } from '@/shared/net'
3529
36−- **`oauth.captured_urls`** `{clear?}` — URLs the debugee tried to open
37−- **`oauth.read_stored_token`** — Check auth token presence in secrets.json
38−- **`oauth.simulate_callback`** `{path, code?, state?, provider?, token?}` — Build vscode:// callback URI
39−- **`oauth.read_captured_urls_file`** — Read on-disk JSONL of captured URLs
30+const response = await axios.get('https://api.example.com/data', {
31+ headers: { 'Authorization': '...' },
32+ ...getAxiosSettings() // <--- CRITICAL: Injects the proxy agent if needed
33+})
34+```
4035
41−### OAuth testing flow
36+### 3. Third-Party Clients (OpenAI, Ollama, etc.)
4237
43−For **Cline OAuth** (SDK local callback): The SDK starts a local HTTP server, the auth URL
44−is captured. To complete: open the captured URL in a real browser (it redirects back to the
45−SDK's callback server), OR extract the callback port and `curl http://127.0.0.1:PORT/callback?code=...`.
38+Most API client libraries allow you to customize the `fetch` implementation. You **MUST** pass the proxy-aware `fetch` to these clients.
4639
47−For **MCP/Provider OAuth** (vscode:// URI): The redirect goes to a vscode:// URI.
48−`oauth.simulate_callback` only *builds* the URI — it does not deliver it, and the ESM
49−extension host can't `require()` the handler. To actually deliver the callback, call the
50−debug-only hook via `ext.evaluate` (with `awaitPromise: true`):
51−`globalThis.__clineHandleUri("vscode://saoudrizwan.claude-dev/...?code=...&state=...")`.
52−It runs the same `SharedUriHandler.handleUri` as VSCode's real URI handler and exists only
53−when `CLINE_CAPTURE_BROWSER` is set (the harness always sets it; never ships in prod).
54−For end-to-end MCP OAuth, get a real `code` from the local MCP OAuth test server
55−(`bun run dev:mcp-oauth-test-server`).
40+**Example (OpenAI):**
41+```typescript
42+import OpenAI from "openai"
43+import { fetch } from "@/shared/net"
5644
57−## Navigating Views — Use Commands, Not Clicks
58−
59−Don't try to find/click small sidebar icons. Use VSCode commands via command palette.
60−Registered in `src/registry.ts`:
61−
62−| Command | View |
63−|---------|------|
64−| `cline.accountButtonClicked` | Account / sign-in |
65−| `cline.historyButtonClicked` | Task history |
66−| `cline.settingsButtonClicked` | Settings |
67−| `cline.mcpButtonClicked` | MCP servers |
68−| `cline.plusButtonClicked` | New task (chat) |
69−| `cline.worktreesButtonClicked` | Worktrees |
70−
71−```bash
72−curl localhost:19229/api -d '{"method":"ui.command_palette","params":{"command":"cline.accountButtonClicked"}}'
45+this.client = new OpenAI({
46+ apiKey: '...',
47+ fetch, // <--- CRITICAL: Pass our fetch wrapper
48+})
7349 ```
7450
75−## Key commands
51+### 4. Tests
7652
77−All via `POST localhost:19229/api` with `{"method":"...", "params":{...}}`:
53+Use `mockFetchForTesting` to mock the underlying fetch implementation.
7854
79−- **`launch`** / **`shutdown`** — lifecycle
80−- **`ui.screenshot`** — screenshot to `/tmp/cline-debug/`; returns `{path}` — **use `read_file` on the path to examine, do NOT `open` the file** (Preview.app covers the VSCode window)
81−- **`ui.open_sidebar`** — open the Cline sidebar
82−- **`ext.set_breakpoint`** `{file, line, condition?}` — breakpoint by source file (sourcemap-resolved)
83−- **`ext.evaluate`** `{expression, callFrameId?}` — eval in extension host
84−- **`ext.resume`** / **`ext.step_over`** / **`ext.step_into`** — stepping
85−- **`ext.call_stack`** — inspect when paused
86−- **`web.evaluate`** `{expression}` — eval in webview
87−- **`web.post_message`** `{message}` — send postMessage to extension host via exposed vsCodeApi
88−- **`wait_for_pause`** `{timeout?}` — block until breakpoint hit
89−- **`ui.locator`** `{role?, testId?, text?, frame?}` — Playwright locator (auto-retries on stale sidebar frame)
90−- **`ui.react_input`** `{text, selector?, clear?, submit?}` — set React textarea value via `execCommand('insertText')`; works reliably across multiple tasks
91−- **`ui.send_message`** `{text, images?, files?, responseType?}` — send chat message bypassing the textarea entirely (via gRPC postMessage)
92−- **`ui.command_palette`** `{command}` — run VSCode command
55+**Example (callback):**
9356
94−## Typical Session
57+```
58+import { mockFetchForTesting } from "@/shared/net"
9559
96−```bash
97−# 1. Launch
98−curl localhost:19229/api -d '{"method":"launch","params":{"skipBuild":true}}'
60+...
61+ let mockFetch = ...
62+ mockFetchForTesting(mockFetch, () => {
63+ // This calls mockFetch
64+ fetch('https://foo.example').then(...)
65+ })
66+ // Original fetch is restored immediately when the call returns.
67+```
9968
100−# 2. Open sidebar + dismiss overlays (ALWAYS do this first)
101−curl localhost:19229/api -d '{"method":"ui.open_sidebar"}'
102−curl localhost:19229/api -d '{"method":"web.evaluate","params":{"expression":"document.querySelectorAll(\".sr-only\").forEach(el => el.parentElement?.click())"}}'
69+**Example (Promise):**
10370
104−# 3. Navigate to view
105−curl localhost:19229/api -d '{"method":"ui.command_palette","params":{"command":"cline.accountButtonClicked"}}'
71+```
72+import { mockFetchForTesting } from "@/shared/net"
10673
107−# 4. Check captured OAuth URLs if testing auth
108−curl localhost:19229/api -d '{"method":"oauth.captured_urls"}'
109−
110−# 5. Verify
111−curl localhost:19229/api -d '{"method":"ui.screenshot"}'
74+...
75+ let mockFetch = ...
76+ await mockFetchForTesting(mockFetch, async () => {
77+ await ...
78+ // This calls mockFetch
79+ await fetch('https://foo.example')
80+ ...
81+ })
82+ // Original fetch is restored when the Promise from the callback settles
11283 ```
11384
114−## Caveats
85+## Verification
11586
116−- **⚠️ Dismiss promotional overlays FIRST**: On fresh launches, full-screen promo overlays block the sidebar. **Dismiss immediately after `ui.open_sidebar`**, before any other interaction or screenshot. May need to run twice:
117− ```bash
118− curl localhost:19229/api -d '{"method": "ui.open_sidebar"}'
119− curl localhost:19229/api -d '{"method": "web.evaluate", "params": {"expression": "document.querySelectorAll(\".sr-only\").forEach(el => el.parentElement?.click())"}}'
120− ```
121−- **Screenshots — don't open the file**: `ui.screenshot` and `ui.sidebar_screenshot` save PNGs to `/tmp/cline-debug/` and return the `{path}`. Use `read_file` on that path to examine screenshots. Running `open <path>` launches Preview.app on macOS which covers the VSCode window.
122−- **Scripts count = 0 after launch**: CDP connects after extension host starts, so scripts parsed during startup aren't tracked. Breakpoints still work via sourcemap resolution.
123−- **Port 9230**: Extension host inspector. If another VSCode instance uses this port, the harness will fail to connect. Kill other debug instances first.
124−- **macOS only** for now (Playwright Electron launch behavior).
125−- **Webview CDP**: `connect_webview` may fail depending on Electron version. `web.evaluate` still works via Playwright's `frame.evaluate()` fallback.
126−- **Sourcemap paths**: esbuild outputs relative paths like `../src/extension.ts` in the sourcemap. The resolver handles this, but if a file isn't found, use `ext.source_files` to see exact paths.
127−- **OAuth with fake codes**: Browser capture intercepts the URL but doesn't provide a valid auth code. For real OAuth testing, open the captured URL in a browser. For unit testing, mock the token exchange.
128−
129−See `src/dev/debug-harness/README.md` for full API reference.
87+If you are adding a new network call or integration:
88+1. Check `@/shared/net.ts` is imported.
89+2. Ensure `fetch` or `getAxiosSettings` is being used.
90+3. Verify that third-party clients are configured to use the custom fetch.
13091
