Skip to content

feat(web): pull request links follow the "Open links in" setting - #16585

Open
SnaetWarre wants to merge 3 commits into
pingdotgg:mainfrom
SnaetWarre:feat/pr-links-follow-open-links-in
Open

SnaetWarre wants to merge 3 commits into
pingdotgg:mainfrom
SnaetWarre:feat/pr-links-follow-open-links-in

Conversation

@SnaetWarre

@SnaetWarre SnaetWarre commented Oct 6, 2026 •

Copy link
Copy Markdown

Problem

Clicking a recognized pull request link always opens it in T3 Code's pull request panel, even when Settings → Integrations → Open links in is set to Your default browser. People who review in GitHub have to Cmd/Ctrl-click every pull request link. On web the setting can't be changed at all, because it sits in the desktop-only browser settings group.

Change

Pull request links now follow Open links in. Cmd/Ctrl-click opens the other destination, so both stay one gesture away:

Open links in Plain click Cmd/Ctrl-click
T3 Code (new default) Pull request panel Default browser
Your default browser Default browser Pull request panel
  • shouldOpenPullRequestExternally takes the preference. useOpenChangeRequestLink and useOpenPrLink subscribe to it, so every pull request entry point follows it: chat links, #123 references in pull request descriptions, the sidebar badge, View PR, the branch toolbar, and the thread's pull request list.
  • #123 references decide panel or browser before looking up the pull request. Browser-bound clicks keep the link's own navigation, so a slow lookup can't outlive the click's permission to open a tab. Panel-bound clicks carry Cmd/Ctrl through the lookup. Before, a modified click always followed the raw /issues/123 link.
  • A plain click headed for the browser goes through openExternal instead of the anchor's default. Rows in the thread pull request list have no target, so the anchor's default would have replaced the T3 tab on web.
  • The setting moves above the desktop-only browser group and is enabled on web, because the pull request panel exists there too. Its description now says Cmd/Ctrl swaps destinations only for pull request links in the chat: terminal links have no pull request recognition. Mobile doesn't read this setting.
  • Default changes from "Your default browser" to "T3 Code", so pull request links keep opening in the panel for anyone who never changed the setting. The trade-off: ordinary chat and terminal links now open in the in-app browser by default wherever one exists. That's the desktop app, and web when the server provides a browser. Elsewhere they still go to the default browser.

Scope and approval

Part of #11403: the pull request half. File links (editor vs. file viewer) are left out, because they need a new setting plus decisions for the file browser and remote environments.

This does not have explicit maintainer approval. In the triage comment, Julius asked whether the pull request part warrants revisiting #8335 and said to keep today's destinations as the defaults. #8335 was declined for adding a separate pull request preference. This PR reuses the existing Open links in setting instead, as suggested on the issue. It keeps the pull request panel as the default. The one default that does change is ordinary links where an in-app browser exists (above), which needs a maintainer call. Happy to rework it, or close it, if you want a different direction.

Verification

Automated, run locally:

  • vp test run on the pull request link, browser link target, settings, ChatMarkdown, chat, pull request, preview, and desktop settings suites: 2325 tests passed. New cases cover all four preference × modifier combinations.
  • apps/web and packages/contracts typecheck pass. Lint on the changed files is clean apart from existing warnings in ChatMarkdown.tsx.

Manual, in the web client against a dev server with real project data and a thread linking #16523 and #7765. To tell "handled in-app" from "handed to the browser", I watched whether the click reached the window listener, whether window.open was called, and what the panel showed:

  • T3 Code: plain click on a chat pull request link opened the panel. Ctrl-click was passed to the browser. Ctrl-click on a #9939 reference called window.open with the link.
  • Your default browser: plain click on a chat link was passed to the browser. Ctrl-click opened the panel. Ctrl-click on a #9939 reference in fix(desktop): build AppImage with the static runtime toolset (fixes libfuse2 launch failure) #7765's description opened refactor: remove duplicate runtime logic and test scaffolding #9939 in the panel. Plain click on a row in the thread pull request list, and on the sidebar badge, called window.open with the link, and T3 stayed on the thread. Ctrl-click on the row opened the panel.
  • The setting is selectable on web, persists across reloads, and renders above the dimmed "Only available in the desktop app" group.
  • After the second review's fixes, I re-checked the settings layout in the browser. I did not re-click the reference-link paths, so the native browser-bound reference behaviour rests on unit tests and code reading.

Not checked: the desktop app. The paths are shared, but nobody has clicked through Electron's external-open path or the new in-app default for ordinary links.

Screenshots of the setting before (disabled on web, old description), the #9939 reference opening in the panel, and the thread pull request list follow in a comment. gh can't attach images to a PR without write access to this repository. An updated "after" screenshot of the moved setting is still to come.

Model: Claude Opus 5.5. Harness: Claude Code in T3 Code.

Recognized pull request links always opened in the pull request panel,
whatever "Open links in" said. They now take that setting as their
plain-click destination, and Cmd/Ctrl-click opens the other one.

The setting defaults to T3 Code, so pull request links keep opening in
the panel unless the user picks their default browser. The setting is
no longer desktop-only, because the panel exists on every client.

Part of pingdotgg#11403.
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Oct 6, 2026
SnaetWarre and others added 2 commits October 6, 2026 23:06
…etting

- pingdotgg#123 reference links decide panel or browser before the pull request
  lookup. Browser-bound clicks keep the anchor's own navigation, so a
  slow lookup can no longer outlive the click's permission to open a tab.
- "Open links in" sits above the desktop-only browser group, so web no
  longer shows it dimmed under "Only available in the desktop app".
- The description says Cmd/Ctrl swaps destinations for pull request links
  in the chat only; terminal links have no pull request recognition.
- Schema comments describe the "app" default and that mobile ignores it.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e06661e0-024a-451c-987f-e40b95f01274
📥 Commits

Reviewing files that changed from the base of the PR and between f21d6da and 0f58d72.

📒 Files selected for processing (8)
  • apps/web/src/browser/browserLinkTarget.ts
  • apps/web/src/components/ChatMarkdown.tsx
  • apps/web/src/components/pullRequest/PullRequestLinkPreview.tsx
  • apps/web/src/components/settings/IntegrationsSettings.tsx
  • apps/web/src/components/settings/SettingsPanels.logic.test.ts
  • apps/web/src/lib/openPullRequestLink.test.ts
  • apps/web/src/lib/openPullRequestLink.ts
  • packages/contracts/src/settings.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The browser link target now defaults to the in-app option. Pull-request link handling uses the preference and click modifiers to select a destination. The setting is rendered outside the desktop-only group, and preview callbacks forward click modifiers.

Changes

Browser link routing

Layer / File(s) Summary
Browser link target setting
packages/contracts/src/settings.ts, apps/web/src/components/settings/IntegrationsSettings.tsx, apps/web/src/components/settings/SettingsPanels.logic.test.ts, apps/web/src/browser/browserLinkTarget.ts
The default target changes to "app". The setting is rendered outside the desktop-only group, and its description and related test data are updated.
Pull-request destination selection
apps/web/src/lib/openPullRequestLink.ts, apps/web/src/lib/openPullRequestLink.test.ts
The destination helper and pull-request link hooks use the browser link preference. Tests cover unmodified, Cmd, and Ctrl clicks for both preference values.
Preview click modifier forwarding
apps/web/src/components/pullRequest/PullRequestLinkPreview.tsx, apps/web/src/components/ChatMarkdown.tsx
The preview retains native navigation for specified clicks and forwards Meta and Ctrl state to pull-request and fallback callbacks. ChatMarkdown passes the modifiers to the link handlers.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  actor User
  participant PullRequestLinkPreview
  participant ChatMarkdown
  participant openChangeRequestLink
  participant openDeferredMarkdownLink
  User->>PullRequestLinkPreview: Click link with modifier state
  PullRequestLinkPreview->>ChatMarkdown: Pass URL and modifiers to pull-request callback
  ChatMarkdown->>openChangeRequestLink: Forward URL and modifiers
  opt Pull-request callback does not handle the link
    PullRequestLinkPreview->>ChatMarkdown: Pass URL and modifiers to fallback callback
    ChatMarkdown->>openDeferredMarkdownLink: Forward URL and modifiers as event
  end
Loading

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 0f58d

The reviewed link-routing behavior has no established merge-blocking issue. Merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0f58d

Pull-request routing retains repository and capability checks, and no introduced security bypass was established. The broader default change can also send ordinary links to a connected environment’s browser; its network and profile exposure remains only partially assessed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — For clients inheriting the new default, ordinary attacker-influenced HTTP(S) Markdown links can reach the connected environment’s preview browser after a user click. The affected authority includes the selected browser profile and environment network location, not merely the pull-request panel; the inspected evidence does not establish an exploit or cross-environment compromise.

Trust Boundaries and Controls

  • observed — Ordinary-link preview selection requires HTTP(S) and preview availability. The preview-open RPC is assigned orchestration-operate scope. Server browser launch enables Chromium sandboxing unless explicitly disabled by an operator, and distinguishes isolated/incognito contexts from persistent profile contexts. These controls are counterevidence to an automatic grant of unrestricted host authority.

Resilience and Maintainability Implications

  • observed — The inspected click transition decides native external navigation synchronously and revalidates resolved URLs before panel opening. Lookup interruption returns without navigation, while resolving-state cleanup remains unconditional.

Hardening Proposals

  • proposed — Consider making the environment-hosted destination explicit when ordinary links inherit the app default, or separating the pull-request-panel default from ordinary-link browsing. This would reduce implicit changes of network and profile context; it is a design proposal, not an observed security finding.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the main change: pull request links follow the “Open links in” setting.
Description check ✅ Passed The description covers the problem, change, scope, and verification in detail. It reports test and typecheck results, identifies unverified desktop behavior, and notes that explicit maintainer approva…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant