Files
hermes-agent/plugins/browser/browserbase/provider.py
Teknium a9838c2100 fix(multiplex): tool and memory-provider env reads stay inside the routed profile
Under gateway.multiplex_profiles, os.environ holds the DEFAULT profile's .env; a
secondary profile's values exist only in the per-turn secret scope. Every reader
below still read os.environ/os.getenv at call time, so a secondary profile's turn
silently used the default profile's value.

Credentials (F6): FIRECRAWL_API_KEY (read_file hosted OCR), OPENVIKING_API_KEY,
mem0-OSS OPENAI_API_KEY, MODAL_TOKEN_ID/SECRET and BROWSER_USE_API_KEY presence
gates, and the xAI video plugin's os.getenv("XAI_API_KEY") fallback AFTER the
scoped resolver had already missed — the exact fallback-after-miss shape
gateway/AGENTS.md forbids. Deleted, not re-scoped: the resolver is the scope.

Identity / tenant (F7): MEM0_USER_ID/AGENT_ID/HOST/MODE, SUPERMEMORY_CONTAINER_TAG,
RETAINDB_PROJECT, OPENVIKING_ACCOUNT/USER/AGENT (and the whole layered() env
read), HINDSIGHT_BANK_ID/MODE/retain shaping, HERMES_HONCHO_HOST. A raw read
put a secondary profile's memories into the default profile's account/bank/
project/tenant and recalled them back into the default's turns. Each now uses
get_secret with the provider's own per-profile default on a miss.

Endpoints (F8): OPENAI_BASE_URL (aux custom runtime + direct-alias expansion),
XAI_BASE_URL/HERMES_XAI_BASE_URL (aux OAuth), NOUS_INFERENCE_BASE_URL (#65941,
both the aux builder and hermes_cli.auth_nous._nous_inference_env_override),
GATEWAY_PROXY_URL (same UnscopedSecretError-only fallback shape as
GATEWAY_PROXY_KEY three lines below), FIRECRAWL_API_URL, BROWSERBASE_BASE_URL,
SUPERMEMORY/RETAINDB/HONCHO/HINDSIGHT URLs. The keys beside them were already
scoped, so a secondary's key was sent to the default profile's proxy or host.

Targets / display (F11): WEIXIN_HOME_CHANNEL (message posted into the default's
chat), HERMES_LANGUAGE, and agent/i18n's process-wide lru_cache of
display.language — now keyed by HERMES_HOME.

Outbound webhooks: hooks.outbound[].secret_env resolved from os.environ while
the gateway registers each profile's targets inside that profile's scope, so a
secondary's deliveries were signed with the default's secret or left unsigned.

Agent-cache eviction: _spawn_release_thread started a bare threading.Thread, so
commit_memory_session -> provider on_session_end ran with an EMPTY context. The
thread now runs copy_context() and, for the unscoped housekeeping sweep, enters
the owning profile's _profile_runtime_scope resolved from the session key
(agent:<profile>:...). The pressure batch does the same per key.

session_search (#82903): agent/inline_tool_executors.py::_session_search
forwarded every schema argument except `profile`, so a gateway agent could
never select a named profile's store. Forwarded; the ownership-scoping design
in #87779/#87847 is a separate design call and is not attempted here.

Live repro (/tmp/mux_audit/fix-tool-memory-reads/repro.py): 28 FAIL on
origin/main -> 0 FAIL with this change; 10 new invariant tests red on base.

Fixes #82903
Fixes #65941
Fixes #99121
Addresses #87779
Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com>
Co-authored-by: Michael Versluis (Berry) <michael@wve.nl>
2026-09-11 15:26:46 -07:00

141 lines
6.2 KiB
Python

"""Browserbase cloud browser provider: direct ``BROWSERBASE_API_KEY`` + ``BROWSERBASE_PROJECT_ID``
only (the Nous subscription routes through Browser Use). Config ``browser.cloud_provider:
"browserbase"``; knobs ``BROWSERBASE_BASE_URL``, ``BROWSERBASE_PROXIES`` (true),
``BROWSERBASE_ADVANCED_STEALTH`` (false), ``BROWSERBASE_KEEP_ALIVE`` (true),
``BROWSERBASE_SESSION_TIMEOUT`` (seconds, max 21600)."""
from __future__ import annotations
import logging
import os
from typing import Any, Dict, Optional
from agent.secret_scope import get_secret
from plugins.browser._common import CloudBrowserProvider
logger = logging.getLogger(__name__)
# 402 fallbacks, in retry order: (session_config key, warning logged when dropped).
_PAID_FEATURE_FALLBACKS = (
("keepAlive", "keepAlive may require paid plan (402), retrying without it. "
"Sessions may timeout during long operations."),
("proxies", "Proxies unavailable (402), retrying without proxies. "
"Bot detection may be less effective."))
class BrowserbaseBrowserProvider(CloudBrowserProvider):
"""Browserbase (https://browserbase.com) cloud browser backend."""
provider_id = "browserbase"
label = "Browserbase"
release_method = "post"
release_path = "/v1/sessions/{session_id}"
missing_credentials_error = (
"Browserbase requires BROWSERBASE_API_KEY and BROWSERBASE_PROJECT_ID "
"environment variables.")
close_fail_fmt = "Failed to close session %s: HTTP %s - %s"
setup_tag = "Cloud browser with stealth and proxies"
setup_env_vars = [
{"key": "BROWSERBASE_API_KEY", "prompt": "Browserbase API key", "url": "https://browserbase.com"},
{"key": "BROWSERBASE_PROJECT_ID", "prompt": "Browserbase project ID"},
]
def _get_config_or_none(self) -> Optional[Dict[str, Any]]:
api_key = get_secret("BROWSERBASE_API_KEY")
project_id = get_secret("BROWSERBASE_PROJECT_ID")
if not (api_key and project_id):
return None
return {
"api_key": api_key,
"project_id": project_id,
# Per-profile like the key: the scoped key must not be sent to the default profile's endpoint.
"base_url": (get_secret("BROWSERBASE_BASE_URL", "") or "https://api.browserbase.com").rstrip("/"),
}
def _headers(self, config: Dict[str, Any]) -> Dict[str, str]:
return {"Content-Type": "application/json", "X-BB-API-Key": config["api_key"]}
def _release_headers(self, config: Dict[str, Any]) -> Dict[str, str]:
return {"X-BB-API-Key": config["api_key"], "Content-Type": "application/json"}
def _release_body(self, config: Dict[str, Any]) -> Dict[str, object]:
return {"projectId": config["project_id"], "status": "REQUEST_RELEASE"}
def create_session(self, task_id: str) -> Dict[str, object]:
config = self._get_config()
enable_proxies = os.environ.get("BROWSERBASE_PROXIES", "true").lower() != "false"
enable_advanced_stealth = os.environ.get("BROWSERBASE_ADVANCED_STEALTH", "false").lower() == "true"
enable_keep_alive = os.environ.get("BROWSERBASE_KEEP_ALIVE", "true").lower() != "false"
custom_timeout_ms = os.environ.get("BROWSERBASE_SESSION_TIMEOUT")
session_config: Dict[str, object] = {"projectId": config["project_id"]}
if enable_keep_alive:
session_config["keepAlive"] = True
if custom_timeout_ms:
try:
timeout_val = int(custom_timeout_ms)
if timeout_val > 0:
session_config["timeout"] = timeout_val
except ValueError:
logger.warning("Invalid BROWSERBASE_SESSION_TIMEOUT value: %s", custom_timeout_ms)
if enable_proxies:
session_config["proxies"] = True
if enable_advanced_stealth:
session_config["browserSettings"] = {"advancedStealth": True}
url = f"{config['base_url']}/v1/sessions"
headers = self._headers(config)
response = self._post_create(url, headers, session_config)
# 402 — paid features unavailable: drop keepAlive, then proxies, and retry.
dropped = set()
for key, warning in _PAID_FEATURE_FALLBACKS:
if response.status_code == 402 and key in session_config:
dropped.add(key)
logger.warning(warning)
session_config.pop(key)
response = self._post_create(url, headers, session_config)
self._check_created(response)
session_data = response.json()
session_name = self._session_name(task_id)
features_enabled = {
"basic_stealth": True,
"proxies": enable_proxies and "proxies" not in dropped,
"advanced_stealth": enable_advanced_stealth,
"keep_alive": enable_keep_alive and "keepAlive" not in dropped,
"custom_timeout": bool(custom_timeout_ms) and "timeout" in session_config,
}
feature_str = ", ".join(k for k, v in features_enabled.items() if v)
logger.info("Created Browserbase session %s with features: %s", session_name, feature_str)
return {
"session_name": session_name,
"bb_session_id": session_data["id"],
"cdp_url": session_data["connectUrl"],
"features": features_enabled,
}
# ---- BEGIN PLUGIN-COMPAT (revert-scheduled; see COMPAT_MANIFEST.md) ----
# Names external plugins imported from this module before the Sep 2026 decomposition.
# Internal code MUST NOT use these (scripts/check_compat_pointers.py fails CI if it does).
# The whole block is removed by reverting the commit that added it.
import requests # noqa: F401,E402
import uuid # noqa: F401,E402
_PLUGIN_COMPAT_LAZY = {
'BrowserProvider': ('agent.browser_provider', 'BrowserProvider'),
}
def __getattr__(name): # PEP 562 — lazy so no import cycles
target = _PLUGIN_COMPAT_LAZY.get(name)
if target is None:
raise AttributeError(f"module {__name__!r} has no attribute {name!r}")
import importlib
from hermes_cli.plugin_compat import warn_once
warn_once(__name__, name, *target)
return getattr(importlib.import_module(target[0]), target[1])
# ---- END PLUGIN-COMPAT ----