Skip to content

[Feat] Add Critique visual review to frontend tasks - #3373

Draft
roomote-roomote[bot] wants to merge 6 commits into
developfrom
feature/critique-visual-review-0gee270d0rsh5
Draft

roomote-roomote[bot] wants to merge 6 commits into
developfrom
feature/critique-visual-review-0gee270d0rsh5

Conversation

@roomote-roomote

@roomote-roomote roomote-roomote Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

​Created by Roomote. Follow up by mentioning @roomote-roomote, in the web UI, or in Slack.

Related issue

No linked issue. This is internal Roomote product work requested through a Roomote task.

Why this PR exists

  • A maintainer explicitly invited this PR in the linked issue or discussion
  • I am a maintainer / this is internal Roomote work

Critique needs access to the exact authenticated UI state a coding task has already prepared, without asking an external service to reload the page or introducing a second browser runtime. The external credential must also remain outside task sandboxes because each review is billable.

What changed

  • adds an opt-in critique_visual_review task tool for viewport screenshots and sanitized rendered-DOM snapshots from the active task-scoped agent-browser session
  • accepts only bounded capture/review/comparison intent from task code; the API uses a short-lived purpose-specific sandbox-control token to invoke a worker-owned capture procedure and keeps capture bytes in worker memory
  • revalidates worker captures on the control plane, re-encodes PNGs, sanitizes the connected DOM tree, excludes task-supplied review context, and constructs the external multipart without accepting task-supplied pixels or DOM
  • enforces the two-call paid review/comparison limit with a dedicated Redis quota that fails closed when Redis is unavailable
  • bounds task-controlled JSON intent to 64 KB before parsing, including chunked requests without Content-Length
  • preserves partial advisory findings and ships a packaged skill that limits autonomous repair to one fix/comparison pass
  • documents CRITIQUE_BASE_URL and CRITIQUE_API_TOKEN across supported deployment templates

How it was tested

  • focused worker tests cover capture, DOM correctness/sanitization, multipart construction, and task-facing review/comparison behavior
  • focused API tests cover trusted sandbox-control capture routing, rejection of task-supplied image/DOM/context, fail-closed quota behavior, two-call enforcement, and declared/streamed oversized intent rejection
  • the full worker run-task.test.ts suite passes all 83 tests
  • pnpm lint:fast, pnpm check-types:fast, pnpm knip, focused suites, commit hooks, and pre-push gates pass
  • current-head GitHub Test, Roomote code review, Lint, Type Check, Knip, docs, build, upgrade, backup, and security checks pass
  • visual proof timed out under the shared five-minute budget; no artifacts were retained and no retry was attempted

Checklist

  • The PR title follows the repo convention
  • This PR is scoped to one feature
  • pnpm lint and pnpm check-types pass locally
  • I added tests or included a clear manual validation note above
  • I removed secrets, tokens, private keys, and customer data from code, logs, and screenshots
  • If this change should appear in the changelog, I ran pnpm changeset

@roomote-community

roomote-community Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

No code issues found. See task

  • The Critique proxy accepts arbitrary multipart task data, bypassing capture sanitization (apps/api/src/handlers/critique/index.ts:76).
  • The Critique submission capability remains recoverable by arbitrary task code (apps/worker/src/commands/setup/setup-mcps.ts:365).
  • The proxy accepts fabricated task-originated image and DOM data as a Critique capture (apps/api/src/handlers/critique/index.ts:480).
  • The paid Critique-call cap fails open while Redis is unavailable (apps/api/src/route-policies.ts:373).
  • Task-controlled review context is forwarded to Critique without a trusted capture source (apps/api/src/handlers/critique/index.ts:632).
  • The Critique JSON endpoint parses unbounded task-controlled request bodies before enforcing its size cap (apps/api/src/handlers/critique/index.ts:553).

Reviewed 33fe41b

Comment thread apps/api/src/handlers/critique/index.ts Outdated
Comment thread apps/worker/src/commands/setup/setup-mcps.ts Outdated
Comment thread apps/api/src/handlers/critique/index.ts Outdated
Comment thread apps/api/src/route-policies.ts Outdated
Comment thread apps/api/src/handlers/critique/index.ts Outdated
Comment thread apps/api/src/handlers/critique/index.ts Outdated
@roomote-roomote
roomote-roomote Bot marked this pull request as ready for review October 2, 2026 12:08
@roomote-roomote
roomote-roomote Bot marked this pull request as draft October 2, 2026 12:11

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant