← Commit history
BRIDGE_VERSION+1−1
@@ -1 +1 @@-1.9.135\ No newline at end of file+1.9.136\ No newline at end of file
adom-bridge-fusion-manifest.json+4−4
@@ -1,10 +1,10 @@ {   "manifest_version": 1,   "name": "fusion360",-  "version": "1.9.135",-  "url": "https://wiki.adom.inc/download/adom/fusion-bridge/1.9.153/adom-bridge-fusion-v1.9.135.zip",-  "sha256": "22f164cc4593c72331096e45edf1975ca6d97c1a0143508f424d03f0725deb10",-  "size": 470036,+  "version": "1.9.136",+  "url": "https://wiki.adom.inc/download/adom/fusion-bridge/1.9.154/adom-bridge-fusion-v1.9.136.zip",+  "sha256": "462b7242bc02676b808a3356eab28231e5ebe6f91d165a680bafc529d5a9c13d",+  "size": 470777,   "verbPrefixes": [     "fusion_"   ],
aps.py+23
@@ -864,6 +864,29 @@ def handle_signin(args: dict) -> dict:                        "openedVia": res.pop("openedVia", None),                        "openedBrowser": res.pop("openedBrowser", None),                        "needsExtensionOpen": res.pop("needsExtensionOpen", False)}+        # SURFACE OPTIONS + TRADEOFFS (found live 2026-08-22; full matrix in the+        # fusion-auth-surfaces dev skill). The AI reads this hint, not the skill, so it+        # rides in the output. A browser you did not foreground does NOT paint, so a+        # background SCREENSHOT is stale - read the DOM (CDP eval), never diagnose from a+        # bg screenshot alone.+        res["data"]["_surfaceOptions"] = {+            "nb": "BEST if installed: nbrowser_eval (CDP) fills/clicks in the user's REAL "+                  "browser - their real Google/MS logins, Autodesk accepts it, no focus "+                  "steal, DOM is live so no stale-screenshot problem. Cost: the nbe install "+                  "is a heavy ask.",+            "pup": "No install, fully background. BUT (1) pup's profile only has accounts "+                   "YOU signed into it - it will NOT have an arbitrary account the user "+                   "'has'; (2) Autodesk gates pup at the PASSWORD page ('browser not "+                   "supported', survives a clean UA - it fingerprints the CDP launch), so "+                   "prefer the email-first PASSWORDLESS email-OTP path (fetch the code via "+                   "adom-google) and avoid the password page; (3) screenshots are stale "+                   "unless pup_configure {highFps:on}.",+            "foreground": "desktop_click on the real browser - real logins, vendor-accepted, "+                          "but STEALS FOCUS (rude). Last resort for one gated step; narrate it.",+            "_pathFacts": "Not every email has an Autodesk account ([email protected] did NOT - "+                          "email-first said 'couldn't find an account'); such users MUST use "+                          "SSO or Create Account. 'Continue with Google' only lists accounts "+                          "signed into THE BROWSER PROFILE you are driving."}     return res  
bridge.json+1−1
@@ -2,7 +2,7 @@   "manifest_version": 1,   "name": "fusion360",   "displayName": "Autodesk Fusion 360",-  "version": "1.9.135",+  "version": "1.9.136",   "description": "Drive Autodesk Fusion 360 from the cloud: launch Fusion, electronics board layout, design rules, exports (STEP/IGES/STL/3MF/USDZ/OBJ/DXF/DWG/Gerbers/BOM/CPL), fast APS server-indexed cloud search plus browse/recent/file-info/versions, cloud file download/upload and folder creation, and in-app parametric modeling (fusion_run_modeling_script). Never-charge: APS calls are capped to the free tier.",   "homepage": "https://wiki.adom.inc/adom/fusion-bridge",   "author": "Adom Inc.",
dev-skills/fusion-auth-surfaces/SKILL.mdadded+80
@@ -0,0 +1,80 @@+---+name: fusion-auth-surfaces+description: DEVELOPER-only. USE WHEN driving ANY browser-based sign-in for the Fusion bridge (Autodesk/APS OAuth), or when a screenshot of a browser came back stale/blank, or when deciding whether to drive nb (the extension) vs pup vs the user's foreground browser. The hard-won tradeoff matrix - why Chrome does not render in the background, why pup screenshots need highFps, why Autodesk gates pup as non-native, and which surface to reach for. Trigger words - aps signin surface, which browser, nb vs pup, background screenshot blank, chrome not rendering background, pup captcha, autodesk browser not supported, highFps, fusion auth automation, drive sign in, stale screenshot.+user-invocable: false+---++# Driving a browser sign-in for the Fusion bridge: the surface tradeoffs++Autodesk/APS sign-in is a browser OAuth flow. There are three surfaces to drive it, and **each+has a disqualifying weakness for some case**. There is no single right answer; pick per situation+and tell the user's AI why. All three learned live during the 2026-08-22 auth-test matrix.++## The one-paragraph mental model++A browser you did not foreground **does not paint** (Chrome/Edge throttle background rendering),+so a background *screenshot* is STALE - it shows an old frame while the page has moved on. This+bit us repeatedly: a "Sending code" spinner captured three times after the form had advanced, a+blank pink page after the sign-in card had rendered. **The screenshot lies; the DOM does not.**+So the axis that matters is: can I read/drive this surface WITHOUT a screenshot and WITHOUT+stealing focus? CDP `eval`/`click` (pup and nb both) is isTrusted, needs no focus, and reads live+DOM - that is the reliable channel. Reserve screenshots for a final human-facing proof, and even+then force a paint first (see below).++## The matrix++| | **nb** (extension / nbrowser_*) | **pup** (Puppeteer bridge) | **foreground real browser** (desktop_click) |+|---|---|---|---|+| Background screenshot | ❌ stale (Chrome won't paint bg) - drive via `nbrowser_eval` (CDP) instead | ⚠️ stale by default; `pup_configure {highFps:on}` forces continuous paint so bg shots are true | ✅ foreground paints, but that's the whole problem |+| Reads/clicks in background | ✅ CDP eval/click, isTrusted, no focus steal | ✅ CDP eval/click, isTrusted, no focus steal | ❌ SendInput needs focus = steals it (RUDE) |+| Has the user's REAL logins | ✅ their real Chrome/Edge profiles - every Google/MS account they use | ❌ isolated durable profile - ONLY accounts you sign into pup itself | ✅ their real profiles |+| Autodesk (and other vendors) accept it | ✅ real browser, no gate | ❌ detects automation → "This browser is not currently supported" gate on the CREDENTIAL page (survives a clean UA + webdriver:false - it fingerprints the CDP launch) | ✅ real browser |+| Install / setup ask | ❌ HEAVY - user must install the browser extension (nbe) | ✅ none - pup manages Chrome for Testing / installed Chrome | ✅ none |++## How to choose++1. **The account's Google session is already warm in the user's real browser, and nb is+   installed** → drive **nb over CDP** (`nbrowser_eval` to fill/click). Best of everything: real+   logins, vendor-accepted, no focus steal, no stale-screenshot problem because you read the DOM.+   This is the target experience. Its only cost is the nbe install, which is a heavy ask.+2. **nb is NOT installed** (the common release case) → **pup**, and know its two limits:+   - pup's profile only has accounts YOU signed into it. To use a specific account you either+     sign that account into pup once, or use a path that needs no prior session.+   - Autodesk gates pup at the **password** step. AVOID that page: prefer Autodesk's **email-first+     → passwordless email-OTP** path (fetch the OTP via `adom-google --account <acct>`), which for+     many accounts skips the password page entirely. If the account has an Autodesk *password*,+     pup will hit the gate - fall back to (1) or (3).+   - Turn on `highFps` only if you must screenshot; otherwise just read the DOM.+3. **Neither works and the user is present** → drive the **foreground real browser** for the one+   gated step, having done everything else in the background, and NARRATE it (you are about to+   steal focus for a few seconds - say why). Last resort; John's standing rule is never be rude+   without cause.++## Facts that change the path (found live 2026-08-22)++- **Not every email has an Autodesk account.** `[email protected]` returned "We couldn't find an+  account with this email" on the email-first page - it exists as a Google account but never as an+  Autodesk identity. Such a user MUST use SSO ("Continue with Google/Apple/Microsoft") or Create+  Account; the email+OTP path dead-ends. Detect this from the page text and branch, don't retry.+- **SSO needs the session where you're driving.** "Continue with Google" only lists accounts+  signed into THAT browser profile. In pup's isolated profile that's only what you put there; in+  nb it's the user's real accounts. This is the single biggest reason pup can't reach an arbitrary+  account the user "has".+- **The passwordless path is genuinely good** when the account supports it: Google SSO →+  consent → Autodesk "Linkable email OTP" → code to the account's inbox → `adom-google` fetches+  it automatically → signed in, zero passwords typed by the AI.++## When you DO screenshot a browser, force a paint first++If a human needs to see the page: nudge focus with a neutral click (`desktop_click` on a dead+area of the window, or `pup` with `highFps`) THEN capture. A raw background `desktop_screenshot_window`+of Chrome returns the last-painted frame, which is often minutes stale. Never diagnose a browser+flow from a background screenshot alone - read the DOM (`pup_evaluate` / `nbrowser_eval`) and use+the screenshot only as corroboration.++## Cross-refs++- `fusion-aps-signin` (user skill) - the happy-path recipe.+- `fusion-autodesk-signin` - the first-run Fusion login (same OAuth handoff, protocol-launch traps).+- pup-bridge#71 - the open ask for pup to defeat Autodesk's automation detection; if that lands,+  option (2) becomes as good as (1) with no install.
package.json+1−1
@@ -1,6 +1,6 @@ {   "slug": "fusion-bridge",-  "version": "1.9.153",+  "version": "1.9.154",   "type": "app",   "description": "This package installs the bridge's SKILLS into your container so your AI knows how to drive it; Adom Bridge loads the bridge runtime itself from the release zip.",   "dependencies": {
page.json+10−7
@@ -1,6 +1,6 @@ {   "slug": "fusion-bridge",-  "version": "1.9.153",+  "version": "1.9.154",   "type": "app",   "description": "This package installs the bridge's SKILLS into your container so your AI knows how to drive it; Adom Bridge loads the bridge runtime itself from the release zip.",   "dependencies": {@@ -11,6 +11,10 @@     "uninstall": "./uninstall.sh"   },   "tags": [+    "ab",+    "bridge",+    "fusion",+    "desktop-app",     "fusion360",     "autodesk",     "cad",@@ -70,7 +74,10 @@     "build a basic parts library",     "add a 3d model to a component",     "make a fusion 360 library with 3d",-    "set up the fusion bridge"+    "set up the fusion bridge",+    "fusion dashboard",+    "fusion status page",+    "open the fusion launch page"   ],   "discovery_pitch": "Use the Adom Bridge Fusion 360 bridge when the user wants to DRIVE Autodesk Fusion 360 from the cloud: open/search their team's Fusion cloud designs, lay out a PCB or do electronics, export STEP/IGES/STL/Gerbers/BOM, or build a component library with real rendering 3D. It runs Fusion on the user's own machine via Adom Bridge. NOT for web/browser/login/form-filling (that's the native-browser extension) and NOT for KiCad (that's the kicad bridge).",   "brief": "Drive Autodesk Fusion 360 from the cloud via Adom Bridge: component libraries, IPC package generation, board layout, exports (STEP/Gerbers/BOM/CPL), fast APS cloud search, and parametric modeling.",@@ -99,9 +106,5 @@       "label": "Part volume",       "prompt": "How much material does each printed part in this assembly use?"     }-  ],-  "author": {-    "name": "John Lauer",-    "email": "[email protected]"-  }+  ] }\ No newline at end of file
tools/release-files.txt+1
@@ -56,3 +56,4 @@ start.bat uninstall.sh handlers/taskbar_overlay.py resources/adom-overlay-32.png+dev-skills/fusion-auth-surfaces/SKILL.md