Skip to content

feat: v2.8.3 – Antigravity multi-account launcher, terminal links in Chrome - #1

Merged
Pikaswelt merged 5 commits into
mainfrom
feat/antigravity-accounts
Oct 5, 2026
Merged

Pikaswelt merged 5 commits into
mainfrom
feat/antigravity-accounts

Conversation

@Pikaswelt

Copy link
Copy Markdown
Owner

What changed

Antigravity multi-account launcher

  • New settings section Antigravity Accounts (src/components/AgyAccounts.tsx): add, rename and remove up to 6 accounts. Each row shows the signed-in e-mail (read from the agy log in that profile) and has buttons to start only that account or log it out.
  • New Home button "Antigravity starten (n)": opens one terminal workspace with one agy tab per account. The terminal grid now holds up to 6 panes (3×2 for 5–6).
  • TerminalTab.agyAccountId is passed through shell:create. The main process then runs that PTY with:
    • USERPROFILE/HOME set to userData/agy-accounts/<id>
    • the SSH_CONNECTION/SSH_CLIENT/SSH_TTY variables, so agy stores its token in a file below HOME
    • GIT_CONFIG_GLOBAL/NPM_CONFIG_USERCONFIG pointing back to the real config files
  • New IPC: agy-accounts:status and agy-accounts:remove-profile. Logout kills that account's PTYs, waits for them to exit, then deletes the profile folder.

Terminal links open in Chrome

  • xterm linkHandler (OSC 8 links, which is how agy prints its login URL) and the main window's setWindowOpenHandler now send http(s) URLs to Chrome via shell:open-in-chrome, falling back to the default browser. Before, they opened as an extra Electron window.

Version bumped to 2.8.3.

Why

agy keeps its OAuth token in one fixed Windows credential entry (gemini:antigravity). Only one account can be signed in at a time, so switching accounts after hitting a rate limit means logging out and in again. When agy sees an SSH session, it logs "Using file-based token storage because SSH session detected" and stores the token as a file below HOME. That gives each account its own persistent login without touching the user's main agy login.

Notes for reviewers

  • Security
    • Account IDs are validated (/^[a-z0-9][a-z0-9-]{0,63}$/i) and the resolved path must stay inside the accounts root. Tested: .., ../../x, a/b, C: and '' are all rejected.
    • The accounts root gets an icacls ACL that grants the current user only.
    • New profiles copy only agy settings.json and GEMINI.md, never login data.
    • Account tabs never go through the external SSH server option.
  • Side effect: inside account terminals, tools see the account folder as home. Git and npm config are redirected back to the real files; other tools that read their config from home will not find it there.
  • This branch also contains the earlier unpushed main commit 6c30262 (ssh2 dependency safeguard).

Testing

  • tsc --noEmit and node --check electron/main.cjs pass.
  • E2E against an isolated dev instance (separate --user-data-dir), driven over CDP:
    • 5 accounts gave 5 panes in a 3×2 grid. Each pane showed the agy login prompt and logged file-based token storage, with no fallback to the main login.
    • Logout works while that account's terminal is running.
    • The settings section renders correctly.
  • Checked by capturing agy's raw PTY output that the login URL is emitted as an OSC 8 link.
  • The packaged build (2.8.2 / 2.8.3) was smoke-tested and installed locally.
  • Not tested: a full Google login (needs a real account) and the actual Chrome launch from a link click.

🤖 Generated with Claude Code

Pikaswelt and others added 5 commits September 30, 2026 19:47
…in Chrome

Home gets an "Antigravity starten" button that opens one agy terminal per
account saved in Settings (up to 6, grid up to 3x2). Each account runs with
its own home folder; SSH env markers make agy keep its OAuth token in a file
there instead of the shared Windows credential entry, so logins stay
separate and persistent.

Terminal links (e.g. the agy Google login) and window.open popups now open
in Chrome (default browser as fallback) instead of an app window.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Removing an account no longer drops the entry when deleting its profile
folder failed, so the stored token cannot be orphaned. A failed Chrome
spawn now falls back to the default browser instead of raising an
unhandled 'error' event in the main process.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
codeforge opens a menu: 1 starts agy with the main login, 2 starts one of
the saved accounts, 3 adds an account, 4 deletes one. Each account runs
with its own HOME under ~/.codeforge/agy-accounts, like the desktop app,
and agy always starts with --dangerously-skip-permissions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Menu: 1 pick an account, 2 settings (add, rename, log out, delete),
3 all accounts in a tiled grid, 4 running sessions. Every start runs in a
tmux session, so agy keeps running when the SSH connection drops and only
ends when it is closed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Pikaswelt
Pikaswelt merged commit 175c5f2 into main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant