fix(core): press CUA keypress combinations as a single chord (#2266) - #2298
Merged
Conversation
## why
CUA `keypress` actions describe a single key **chord** (modifiers held
down while the main key is pressed), but
`V3CuaAgentHandler.executeAction` pressed each key in the array
**separately**. `page.keyPress(modifier)` presses and *releases* the
modifier, so by the time the main key was pressed the modifier was
already up.
The concrete failure: a `["Control", "A"]` keypress sends `Control` on
its own (a no-op) and then `A` through the plain typing path — so
instead of select-all, the agent **types a literal `a` into the focused
field**. Any select-all / copy / paste / cut / shortcut pattern silently
fails *and* corrupts input. Because the agent-replay cache recorded the
broken per-key sequence, replays reproduced the bug too.
This is provider-dependent, based on the shape each client emits:
| Provider | emits for a combo | old behavior | status |
| --- | --- | --- | --- |
| OpenAI | `keys: ["CTRL", "A"]` | `Ctrl` then literal `a` | ❌ broken |
| Google (`key_combination`) | `.split("+")` → `["Control", "A"]` |
`Ctrl` then literal `a` | ❌ broken |
| Microsoft (`fara-7b`) | `keys: string[]` (per-key) | `Ctrl` then
literal `a` | ❌ broken |
| Anthropic | `keys: ["ctrl+s"]` (single `+`-joined string) | chorded
correctly | ✅ unaffected |
Anthropic only worked by accident — it pre-joins with `+`, which
`page.keyPress` already chords internally.
## what changed
`packages/core/lib/v3/handlers/v3CuaAgentHandler.ts` — in the `keypress`
case, map each key and **join into one `+`-delimited combination**, then
call `page.keyPress` once. `page.keyPress` already holds modifiers down
for the final key and already special-cases the literal `+` key, so
single keys, already-combined strings, and `Ctrl++`-style inputs all
stay correct. `mapKeyToPlaywright` is idempotent (`CTRL`/`Control` →
`Control`), so Google's pre-mapped arrays and Anthropic's combined
string are unchanged. The recorded replay step is now a single `press
Control+A` instead of the broken `press Control, press A`.
## test plan
New `packages/core/tests/unit/cua-keypress-chord.test.ts` (5 cases, all
passing):
- `["Control", "A"]` → single `keyPress("Control+A")`
- alias normalization: `["CTRL", "A"]` → `keyPress("Control+A")`
- single key `["Enter"]` → `keyPress("Enter")` (unchanged)
- already-combined `["ctrl+s"]` → `keyPress("ctrl+s")` (Anthropic shape,
unchanged)
- empty `[]` → no `keyPress` call
Existing CUA suites (`anthropic-cua-triple-click`, `openai-cua-client`,
`microsoft-cua-client`, `anthropic-cua-adaptive-thinking`) — 25 tests
still green.
---
Related: this is exactly the class of provider-specific CUA regression
that #2188 proposes catching with a deterministic bench task.
<!-- This is an auto-generated description by cubic. -->
---
## Summary by cubic
Fixes CUA keypress combos by pressing them as one chord, not as separate
keys. Shortcuts like Ctrl+A now work across OpenAI, Google
`key_combination`, and Microsoft clients instead of typing letters.
- **Bug Fixes**
- Map keys and join with "+" before one `page.keyPress` call; supports
arrays, already-joined strings, and the literal "+" key.
- Added unit tests for combos, alias normalization, single key,
already-combined, and empty input.
<sup>Written for commit 4f921ee.
Summary will update on new commits.</sup>
<a
href="https://cubic.dev/pr/browserbase/stagehand/pull/2266?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>
<!-- End of auto-generated description by cubic. -->
🦋 Changeset detectedLatest commit: c966475 The changes in this PR will be included in the next version bump. This PR includes changesets to release 3 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Contributor
There was a problem hiding this comment.
No issues found across 3 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Architecture diagram
sequenceDiagram
participant CUA as CUA Client
participant Handler as V3CuaAgentHandler
participant Replay as Agent Replay Cache
participant Playwright as Playwright page
Note over CUA,Playwright: Keypress Action Flow
CUA->>Handler: executeAction({ type: "keypress", keys })
alt keys is array (OpenAI, Google, Microsoft)
alt keys.length > 0
Handler->>Handler: map each key via mapKeyToPlaywright()
Handler->>Handler: join() mapped keys with "+"
Note over Handler: e.g., ["Control","A"] → "Control+A"
Handler->>Playwright: page.keyPress("Control+A")
Playwright-->>Handler: done
opt recording enabled
Handler->>Replay: recordCuaActStep("press Control+A")
end
else keys.length === 0
Note over Handler: No-op, skip keyPress
end
else keys is single string (Anthropic)
Handler->>Handler: wrap in array → ["ctrl+s"]
Handler->>Handler: map via mapKeyToPlaywright() → ["ctrl+s"]
Handler->>Handler: join() → "ctrl+s"
Handler->>Playwright: page.keyPress("ctrl+s")
Playwright-->>Handler: done
opt recording enabled
Handler->>Replay: recordCuaActStep("press ctrl+s")
end
end
Handler-->>CUA: { success: true }
tkattkat
approved these changes
Jul 1, 2026
This was referenced Jul 1, 2026
Merged
seanmcguire12
pushed a commit
that referenced
this pull request
Jul 13, 2026
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @browserbasehq/stagehand@3.7.0 ### Minor Changes - [#2283](#2283) [`871ca7e`](871ca7e) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - add `context.setDomainPolicy({ allowedDomains: ["allowed.domain"] })` which allows users to define a set of domains that are accessible to stagehand - [#2274](#2274) [`f31980f`](f31980f) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - add `context.setDomainPolicy({blockedDomains: ["some.domain"]})` which allows users to define a list of domains that will be blocked by stagehand ### Patch Changes - [#2305](#2305) [`cd1daad`](cd1daad) Thanks [@shrey150](https://github.com/shrey150)! - Remove the noisy AI SDK "system message in messages" warning logged on every hybrid/DOM `agent.execute()` call. - [#2328](#2328) [`d287ff4`](d287ff4) Thanks [@miguelg719](https://github.com/miguelg719)! - Allow modelName "auto" in the constructor and per-primitive model overrides when running through the Stagehand API - [#2294](#2294) [`3938590`](3938590) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - automatically close popups that violate user defined domain policy - [#2298](#2298) [`892701a`](892701a) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - Fix CUA `keypress` actions to press key combinations as a single chord. - [#2345](#2345) [`21826c7`](21826c7) Thanks [@monadoid](https://github.com/monadoid)! - Repair malformed UTF-16 snapshot text before it reaches model prompts. - [#2306](#2306) [`8dcef1b`](8dcef1b) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - Use the screenshot provider's declared media type when sending CUA image payloads. The `setScreenshotProvider` callback now returns `ScreenshotProviderResult` (`{ base64, mediaType }`) instead of a bare base64 string. - [#2273](#2273) [`93a23d3`](93a23d3) Thanks [@miguelg719](https://github.com/miguelg719)! - Add support for the new `google/gemini-3.5-flash` computer-use tools model - [#2278](#2278) [`022d68f`](022d68f) Thanks [@shrey150](https://github.com/shrey150)! - Fix `TypeError: Converting circular structure to JSON` when creating an agent with MCP `integrations` that include a `Client` instance (e.g. a local/stdio server from `connectToMCPServer`). The agent-creation log serialized the raw `integrations` array, and a live MCP `Client` is circular. It now logs a safe descriptor (URL strings kept, client instances summarized) so `agent({ integrations: [client] })` works. - [#2288](#2288) [`bb5ffa6`](bb5ffa6) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - clean up cdp session event handlers on target detach ## @browserbasehq/stagehand-evals@2.0.4 ### Patch Changes - Updated dependencies \[[`cd1daad`](cd1daad), [`d287ff4`](d287ff4), [`3938590`](3938590), [`892701a`](892701a), [`21826c7`](21826c7), [`8dcef1b`](8dcef1b), [`93a23d3`](93a23d3), [`871ca7e`](871ca7e), [`022d68f`](022d68f), [`bb5ffa6`](bb5ffa6), [`f31980f`](f31980f)]: - @browserbasehq/stagehand@3.7.0 ## @browserbasehq/stagehand-server-v3@3.7.2 ### Patch Changes - Updated dependencies \[[`cd1daad`](cd1daad), [`d287ff4`](d287ff4), [`3938590`](3938590), [`892701a`](892701a), [`21826c7`](21826c7), [`8dcef1b`](8dcef1b), [`93a23d3`](93a23d3), [`871ca7e`](871ca7e), [`022d68f`](022d68f), [`bb5ffa6`](bb5ffa6), [`f31980f`](f31980f)]: - @browserbasehq/stagehand@3.7.0 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
felipeofdev-ai
pushed a commit
to felipeofdev-ai/stagehand
that referenced
this pull request
Aug 4, 2026
…base#2266) (browserbase#2298) thanks @yawbtng for the contribution here!! ## why CUA `keypress` actions describe a single key **chord** (modifiers held down while the main key is pressed), but `V3CuaAgentHandler.executeAction` pressed each key in the array **separately**. `page.keyPress(modifier)` presses and *releases* the modifier, so by the time the main key was pressed the modifier was already up. The concrete failure: a `["Control", "A"]` keypress sends `Control` on its own (a no-op) and then `A` through the plain typing path — so instead of select-all, the agent **types a literal `a` into the focused field**. Any select-all / copy / paste / cut / shortcut pattern silently fails *and* corrupts input. Because the agent-replay cache recorded the broken per-key sequence, replays reproduced the bug too. This is provider-dependent, based on the shape each client emits: | Provider | emits for a combo | old behavior | status | | --- | --- | --- | --- | | OpenAI | `keys: ["CTRL", "A"]` | `Ctrl` then literal `a` | ❌ broken | | Google (`key_combination`) | `.split("+")` → `["Control", "A"]` | `Ctrl` then literal `a` | ❌ broken | | Microsoft (`fara-7b`) | `keys: string[]` (per-key) | `Ctrl` then literal `a` | ❌ broken | | Anthropic | `keys: ["ctrl+s"]` (single `+`-joined string) | chorded correctly | ✅ unaffected | Anthropic only worked by accident — it pre-joins with `+`, which `page.keyPress` already chords internally. ## what changed `packages/core/lib/v3/handlers/v3CuaAgentHandler.ts` — in the `keypress` case, map each key and **join into one `+`-delimited combination**, then call `page.keyPress` once. `page.keyPress` already holds modifiers down for the final key and already special-cases the literal `+` key, so single keys, already-combined strings, and `Ctrl++`-style inputs all stay correct. `mapKeyToPlaywright` is idempotent (`CTRL`/`Control` → `Control`), so Google's pre-mapped arrays and Anthropic's combined string are unchanged. The recorded replay step is now a single `press Control+A` instead of the broken `press Control, press A`. ## test plan New `packages/core/tests/unit/cua-keypress-chord.test.ts` (5 cases, all passing): - `["Control", "A"]` → single `keyPress("Control+A")` - alias normalization: `["CTRL", "A"]` → `keyPress("Control+A")` - single key `["Enter"]` → `keyPress("Enter")` (unchanged) - already-combined `["ctrl+s"]` → `keyPress("ctrl+s")` (Anthropic shape, unchanged) - empty `[]` → no `keyPress` call Existing CUA suites (`anthropic-cua-triple-click`, `openai-cua-client`, `microsoft-cua-client`, `anthropic-cua-adaptive-thinking`) — 25 tests still green. --- Related: this is exactly the class of provider-specific CUA regression that browserbase#2188 proposes catching with a deterministic bench task. <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Fixes CUA keypress combos by pressing them as one chord. Shortcuts like Ctrl+A now work across OpenAI, Google `key_combination`, and Microsoft clients instead of typing letters. - **Bug Fixes** - Map keys, join with "+", and call `page.keyPress` once; supports arrays, already-joined strings, and the literal "+" key. - Normalize aliases (`CTRL` → `Control`) and record a single `press Control+A` step for replays. - Added unit tests for combos, alias normalization, single key, already-combined, and empty input. <sup>Written for commit c966475. Summary will update on new commits.</sup> <a href="https://cubic.dev/pr/browserbase/stagehand/pull/2298?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> ---------
felipeofdev-ai
pushed a commit
to felipeofdev-ai/stagehand
that referenced
this pull request
Aug 4, 2026
This PR was opened by the [Changesets release](https://github.com/changesets/action) GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated. # Releases ## @browserbasehq/stagehand@3.7.0 ### Minor Changes - [browserbase#2283](browserbase#2283) [`871ca7e`](browserbase@871ca7e) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - add `context.setDomainPolicy({ allowedDomains: ["allowed.domain"] })` which allows users to define a set of domains that are accessible to stagehand - [browserbase#2274](browserbase#2274) [`f31980f`](browserbase@f31980f) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - add `context.setDomainPolicy({blockedDomains: ["some.domain"]})` which allows users to define a list of domains that will be blocked by stagehand ### Patch Changes - [browserbase#2305](browserbase#2305) [`cd1daad`](browserbase@cd1daad) Thanks [@shrey150](https://github.com/shrey150)! - Remove the noisy AI SDK "system message in messages" warning logged on every hybrid/DOM `agent.execute()` call. - [browserbase#2328](browserbase#2328) [`d287ff4`](browserbase@d287ff4) Thanks [@miguelg719](https://github.com/miguelg719)! - Allow modelName "auto" in the constructor and per-primitive model overrides when running through the Stagehand API - [browserbase#2294](browserbase#2294) [`3938590`](browserbase@3938590) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - automatically close popups that violate user defined domain policy - [browserbase#2298](browserbase#2298) [`892701a`](browserbase@892701a) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - Fix CUA `keypress` actions to press key combinations as a single chord. - [browserbase#2345](browserbase#2345) [`21826c7`](browserbase@21826c7) Thanks [@monadoid](https://github.com/monadoid)! - Repair malformed UTF-16 snapshot text before it reaches model prompts. - [browserbase#2306](browserbase#2306) [`8dcef1b`](browserbase@8dcef1b) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - Use the screenshot provider's declared media type when sending CUA image payloads. The `setScreenshotProvider` callback now returns `ScreenshotProviderResult` (`{ base64, mediaType }`) instead of a bare base64 string. - [browserbase#2273](browserbase#2273) [`93a23d3`](browserbase@93a23d3) Thanks [@miguelg719](https://github.com/miguelg719)! - Add support for the new `google/gemini-3.5-flash` computer-use tools model - [browserbase#2278](browserbase#2278) [`022d68f`](browserbase@022d68f) Thanks [@shrey150](https://github.com/shrey150)! - Fix `TypeError: Converting circular structure to JSON` when creating an agent with MCP `integrations` that include a `Client` instance (e.g. a local/stdio server from `connectToMCPServer`). The agent-creation log serialized the raw `integrations` array, and a live MCP `Client` is circular. It now logs a safe descriptor (URL strings kept, client instances summarized) so `agent({ integrations: [client] })` works. - [browserbase#2288](browserbase#2288) [`bb5ffa6`](browserbase@bb5ffa6) Thanks [@seanmcguire12](https://github.com/seanmcguire12)! - clean up cdp session event handlers on target detach ## @browserbasehq/stagehand-evals@2.0.4 ### Patch Changes - Updated dependencies \[[`cd1daad`](browserbase@cd1daad), [`d287ff4`](browserbase@d287ff4), [`3938590`](browserbase@3938590), [`892701a`](browserbase@892701a), [`21826c7`](browserbase@21826c7), [`8dcef1b`](browserbase@8dcef1b), [`93a23d3`](browserbase@93a23d3), [`871ca7e`](browserbase@871ca7e), [`022d68f`](browserbase@022d68f), [`bb5ffa6`](browserbase@bb5ffa6), [`f31980f`](browserbase@f31980f)]: - @browserbasehq/stagehand@3.7.0 ## @browserbasehq/stagehand-server-v3@3.7.2 ### Patch Changes - Updated dependencies \[[`cd1daad`](browserbase@cd1daad), [`d287ff4`](browserbase@d287ff4), [`3938590`](browserbase@3938590), [`892701a`](browserbase@892701a), [`21826c7`](browserbase@21826c7), [`8dcef1b`](browserbase@8dcef1b), [`93a23d3`](browserbase@93a23d3), [`871ca7e`](browserbase@871ca7e), [`022d68f`](browserbase@022d68f), [`bb5ffa6`](browserbase@bb5ffa6), [`f31980f`](browserbase@f31980f)]: - @browserbasehq/stagehand@3.7.0
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
thanks @yawbtng for the contribution here!!
why
CUA
keypressactions describe a single key chord (modifiers held down while the main key is pressed), butV3CuaAgentHandler.executeActionpressed each key in the array separately.page.keyPress(modifier)presses and releases the modifier, so by the time the main key was pressed the modifier was already up.The concrete failure: a
["Control", "A"]keypress sendsControlon its own (a no-op) and thenAthrough the plain typing path — so instead of select-all, the agent types a literalainto the focused field. Any select-all / copy / paste / cut / shortcut pattern silently fails and corrupts input. Because the agent-replay cache recorded the broken per-key sequence, replays reproduced the bug too.This is provider-dependent, based on the shape each client emits:
| Provider | emits for a combo | old behavior | status | | --- | --- | --- | --- |
| OpenAI |
keys: ["CTRL", "A"]|Ctrlthen literala| ❌ broken | | Google (key_combination) |.split("+")→["Control", "A"]|Ctrlthen literala| ❌ broken || Microsoft (
fara-7b) |keys: string[](per-key) |Ctrlthen literala| ❌ broken || Anthropic |
keys: ["ctrl+s"](single+-joined string) | chorded correctly | ✅ unaffected |Anthropic only worked by accident — it pre-joins with
+, whichpage.keyPressalready chords internally.what changed
packages/core/lib/v3/handlers/v3CuaAgentHandler.ts— in thekeypresscase, map each key and join into one+-delimited combination, then callpage.keyPressonce.page.keyPressalready holds modifiers down for the final key and already special-cases the literal+key, so single keys, already-combined strings, andCtrl++-style inputs all stay correct.mapKeyToPlaywrightis idempotent (CTRL/Control→Control), so Google's pre-mapped arrays and Anthropic's combined string are unchanged. The recorded replay step is now a singlepress Control+Ainstead of the brokenpress Control, press A.test plan
New
packages/core/tests/unit/cua-keypress-chord.test.ts(5 cases, all passing):["Control", "A"]→ singlekeyPress("Control+A")["CTRL", "A"]→keyPress("Control+A")["Enter"]→keyPress("Enter")(unchanged)["ctrl+s"]→keyPress("ctrl+s")(Anthropic shape, unchanged)[]→ nokeyPresscallExisting CUA suites (
anthropic-cua-triple-click,openai-cua-client,microsoft-cua-client,anthropic-cua-adaptive-thinking) — 25 tests still green.Related: this is exactly the class of provider-specific CUA regression that #2188 proposes catching with a deterministic bench task.
Summary by cubic
Fixes CUA keypress combos by pressing them as one chord. Shortcuts like Ctrl+A now work across OpenAI, Google
key_combination, and Microsoft clients instead of typing letters.page.keyPressonce; supports arrays, already-joined strings, and the literal "+" key.CTRL→Control) and record a singlepress Control+Astep for replays.Written for commit c966475. Summary will update on new commits.