Skip to content

feat: add browser routing cache#99

Open
rgarcia wants to merge 14 commits intonextfrom
raf/browser-scoped-client
Open

feat: add browser routing cache#99
rgarcia wants to merge 14 commits intonextfrom
raf/browser-scoped-client

Conversation

@rgarcia
Copy link
Copy Markdown
Contributor

@rgarcia rgarcia commented Apr 13, 2026

Summary

  • remove the public browserRouting client constructor config and move rollout control to KERNEL_BROWSER_ROUTING_SUBRESOURCES
  • default direct-to-VM request interception to curl when the env var is unset, and treat an explicit empty string as disabling browser subresource routing
  • keep BrowserRouteCache public for debugging while making the routing fetch wrapper fully internal to the client constructor and withOptions()
  • keep browsers.fetch() cache-backed so raw HTTP continues to go directly to the browser VM’s /curl/raw path with no control-plane fallback

Rollout behavior

  • env var unset: route only curl subresources directly to the browser VM
  • env var set to "": disable browser subresource routing entirely
  • env var set to a comma-separated list: route exactly those subresources directly to the browser VM
  • browsers.fetch() still always goes direct to the browser VM because it resolves through the shared browser route cache and /curl/raw

Test plan

  • ./node_modules/.bin/jest tests/lib/browser-routing.test.ts
  • ./node_modules/.bin/eslint src/client.ts src/lib/browser-routing.ts src/index.ts tests/lib/browser-routing.test.ts examples/browser-routing.ts
  • ./node_modules/.bin/tsc -p tsconfig.json --noEmit
  • KERNEL_API_KEY=... KERNEL_BASE_URL=https://api.onkernel.com ./node_modules/.bin/ts-node examples/browser-routing.ts

Note

Medium Risk
Wraps the client’s fetch to transparently reroute some /browsers/{session}/{subresource} calls directly to the browser VM based on cached route data, which could affect request routing/headers and break integrations if misconfigured.

Overview
Adds a shared BrowserRouteCache that is auto-populated by sniffing JSON API responses for browser session_id/base_url and a JWT (from jwt or cdp_ws_url). The Kernel client now wraps its underlying fetch to intercept allowlisted /browsers/{sessionId}/{subresource} requests and send them directly to the browser VM base_url, stripping authorization and injecting jwt as a query param.

Rollout is controlled by KERNEL_BROWSER_ROUTING_SUBRESOURCES (unset defaults to routing curl; empty string disables routing; comma-list routes those subresources). Adds browsers.fetch() implemented via new browserFetch() to always issue raw HTTP through the VM’s /curl/raw endpoint using the cache, expands HTTPMethod to include head/options, exports the new types, and includes an example and Jest coverage for routing/cache/withOptions() behavior.

Reviewed by Cursor Bugbot for commit 9b24280. Bugbot is set up for automated code reviews on this repo. Configure here.

@firetiger-agent
Copy link
Copy Markdown

Firetiger deploy monitoring skipped

This PR didn't match the auto-monitor filter configured on your GitHub connection:

Any PR that changes the kernel API. Monitor changes to API endpoints (packages/api/cmd/api/) and Temporal workflows (packages/api/lib/temporal) in the kernel repo

Reason: PR modifies client library code (browser session client) rather than API endpoints or Temporal workflows in packages/api/

To monitor this PR anyway, reply with @firetiger monitor this.

Comment thread src/lib/kernel-browser-session.ts Outdated
Comment thread src/lib/kernel-browser-session.ts Outdated
Comment thread src/lib/browser-transport.ts Outdated
rgarcia added 4 commits April 21, 2026 13:09
Bind browser subresource calls to a browser session's base_url and expose raw HTTP through fetch so metro-routed access feels like normal JavaScript networking.

Made-with: Cursor
Fail fast when browser-scoped clients do not have a session base_url, route subresource calls through the browser session base directly, and clean up browser-vm wording.

Made-with: Cursor
Fail fast when browser-scoped clients are missing a browser session base_url, route subresource calls through the session base consistently, and keep lint output clean.

Made-with: Cursor
Replace the handwritten Node browser-scoped façade with deterministic generated bindings from the browser resource graph, and enforce regeneration during lint and build.

Made-with: Cursor
@rgarcia rgarcia force-pushed the raf/browser-scoped-client branch from c5731cb to e730af8 Compare April 21, 2026 17:09
Comment thread examples/browser-scoped.ts Outdated
Route direct-to-VM browser requests through the shared client cache so the SDK no longer needs the generated browser session wrapper layer.

Made-with: Cursor
Comment thread src/lib/browser-routing.ts
Comment thread src/client.ts Outdated
Trim the node browser routing changes down to the cache/interceptor shape from PR #100 and remove the leftover browser-scoped example and priming surface.

Made-with: Cursor
@rgarcia rgarcia changed the title feat: add browser-scoped session client feat: add browser routing cache Apr 22, 2026
Comment thread src/lib/browser-routing.ts
rgarcia added 3 commits April 22, 2026 12:57
Shorten the browserRouting allowlist field to subresources so the direct-to-VM configuration reads more cleanly without changing behavior.

Made-with: Cursor
Keep the node browser-routing example showing both direct subresource routing and the cache-backed /curl/raw path.

Made-with: Cursor
Bring back the cache-backed browser fetch helper so raw HTTP stays on the SDK's language-native surface instead of falling through to manual /curl/raw requests.

Made-with: Cursor
Comment thread src/lib/browser-routing.ts
Comment thread src/lib/browser-transport.ts Outdated
rgarcia added 3 commits April 22, 2026 13:19
Remove the unnecessary generated resource and dependency diffs from the node branch and keep BrowserRouteCache.set() as a direct assignment without trimming user input.

Made-with: Cursor
Tighten the browser routing files to the repo's formatter expectations so the node CI lint job passes cleanly again.

Made-with: Cursor
Split browser.fetch into its own helper, remove unused browser transport code, and simplify withOptions cache sharing so the routing layer stays easier to reason about.

Made-with: Cursor
Comment thread src/lib/browser-fetch.ts Outdated
Comment thread src/lib/browser-fetch.ts
Remove the public browser routing constructor knobs and read direct-to-VM subresource rollout from KERNEL_BROWSER_ROUTING_SUBRESOURCES instead, defaulting to curl while leaving browser.fetch cache-backed.
Comment thread src/lib/browser-routing.ts
Keep the routing wrapper from stripping runtime-specific fetch init options when requests fall through or route directly to the VM, and share the browser fetch helpers so routed methods stay type-safe and covered by regression tests.

Made-with: Cursor
Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue. You can view the agent here.

Reviewed by Cursor Bugbot for commit 9b24280. Configure here.

const response = await routeRequest(innerFetch, { input, init, request }, apiOrigin, allowed, cache);
await sniffAndPopulateCache(response, cache);
return response;
};
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Every JSON response cloned and parsed unnecessarily

Medium Severity

sniffAndPopulateCache is await-ed on every single fetch response — including non-browser endpoints like deployments, invocations, credentials, etc. For every JSON response, the body is cloned and fully parsed before the response is returned to the caller. This blocks the caller until the entire response body has been received and parsed as JSON, adding latency proportional to response size on every API call. Only responses to browser-related paths (matching the /browsers/ pattern) can ever contain cacheable route data, so the work is wasted for all other endpoints.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 9b24280. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants