mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-05 23:19:43 +02:00
Each item is from the pre-merge review of the PR it names, applied on master rather than by pushing to a contributor branch. #400 (response viewer, shenlvkang-collab) - The brief view opened at `scrollTop = 0`, right when it was a single card holding the last row. Now that it renders the whole turn, the top is the turn's first narration line and the answer can be screens below it, while loadFullContext already scrolls to the bottom of the same turn. A multi-row turn now opens at its newest text; a single card still opens at the top. #401 (loopback links as web tabs, shenlvkang-collab) - Drop `*.localhost` from the auto-route set. Every other member is an address literal that can only mean this box; a `*.localhost` DNS name is not one, and a resolver with a search domain retries `evil.localhost` as `evil.localhost.<search domain>`. The link source is agent-written terminal output, so that set is the whole confinement on a tap that makes Codeman fetch a URL server-side and persist it. The page-side test stays broader (`isOnBoxHostname`), where a false positive only declines to proxy. - A link to the origin root navigated nothing: the path was flattened to '', which openWebview reads as "no deep link", leaving an open frame where it was. - `this.webviews` being set does not mean it is loaded. initWebviews() assigns a truthy empty map and only then awaits the list, so a tap during page load found nothing to reuse and POSTed a duplicate record. Join the in-flight refresh instead. - One dashboard per dev server rather than per host spelling, which is what the method's own comment already promised. - Toast on the auto-create: it writes webviews.json, broadcasts over SSE and adds a Run-dropdown row on every signed-in device, with a new tab as its only previous signal. #362 (remote omp continuation, timkjr) - Accept the allowlisted `mode === 'omp'` arm as-is; a blanket registry render would hand deepseek a locally-resolved --profile and bypass claude's own overlay. A registry-declared switch is the follow-up if a third mode needs it. - Revert the whole-file Prettier reformat of docs/remote-sessions.md (docs/ is hand-formatted and outside `npm run format`), keeping only the two new sections. - Correct three stale passages: architecture-invariants' `exec claude --dangerously-skip-permissions`, the `exec <cli>` paragraph (claude and omp now have their own arms, and the claude pane's PID is the login shell), and omp-integration's `-c 'omp'`. RemoteCommandMode gains deepseek and omp. - Add the missing `_maybeCaptureOmpSessionId` remote-guard test; the sibling guard in `_pinOmpRespawnId` had one and this path runs earlier, on the first idle turn. #388 (keyCode 229 recovery, aakhter) - Gate notifyCanonicalData on shouldSuppressTerminalQueryResponse and isTerminalFocusOrMouseReport. onData also carries the DA/DSR/CPR/OSC replies xterm answers during Ink redraws and its SGR mouse and focus reports; any of those landing between the keydown and the candidate's resolution was read as "xterm spoke for this keystroke", standing the recovery down and leaving the character dropped, worst on a busy agent pane. Reached through window.CodemanTerminalInput: the predicates live in a module IIFE that closes long before this call site, so bare references would throw into the surrounding try/catch and stop the notify from ever running. Every fix has a test that fails without it (verified by reverting each). Full gate green on the combined tree: 358 files, 6849 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -170,4 +170,47 @@ describe('OMP: fresh session vs. reattach must not share resumeSessionId resolut
|
||||
expect(state.ompConfig?.continueSession).toBe(true);
|
||||
expect(session.claudeSessionId).toBe(session.id);
|
||||
});
|
||||
|
||||
it('_maybeCaptureOmpSessionId() is subject to the same remote guard, so a first idle turn cannot alias a remote session onto a local conversation', () => {
|
||||
// The sibling guard in _pinOmpRespawnId has the test above; this one runs on
|
||||
// the FIRST turn going idle, before any respawn, and reads the same local
|
||||
// ~/.omp tree. Without the `this._remote` early return it would claim this
|
||||
// unrelated local conversation's uuid as the remote session's identity, and
|
||||
// every later respawn would then inherit the wrong pin.
|
||||
seedOmpSessionFile('wrong-local-conversation-id');
|
||||
|
||||
const remote: SessionRemote = {
|
||||
hostId: 'remote-box',
|
||||
label: 'remote-box',
|
||||
host: 'remote-box',
|
||||
username: 'someone',
|
||||
remotePath: workingDir,
|
||||
owned: true,
|
||||
};
|
||||
|
||||
const muxSession: MuxSession = {
|
||||
sessionId: 'placeholder',
|
||||
muxName: 'codeman-deadbeef',
|
||||
pid: 1,
|
||||
createdAt: Date.now(),
|
||||
workingDir,
|
||||
mode: 'omp',
|
||||
attached: false,
|
||||
};
|
||||
|
||||
const session = new Session({
|
||||
workingDir,
|
||||
mode: 'omp',
|
||||
mux: new TmuxManager(),
|
||||
useMux: true,
|
||||
muxSession,
|
||||
remote,
|
||||
});
|
||||
sessions.push(session);
|
||||
|
||||
(session as unknown as { _maybeCaptureOmpSessionId(): void })._maybeCaptureOmpSessionId();
|
||||
|
||||
expect(session.claudeSessionId).toBe(session.id);
|
||||
expect(session.toState().ompConfig?.resumeSessionId).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
@@ -145,6 +145,47 @@ describe('response viewer brief view (last answered turn)', () => {
|
||||
expect(viewer.classList.contains('visible')).toBe(true);
|
||||
});
|
||||
|
||||
it('opens a multi-row turn at its NEWEST text, and a single card at the top', async () => {
|
||||
// `body.scrollTop = 0` was right when the brief view was one card holding
|
||||
// the last row. With the whole turn rendered, the top of the scroller is
|
||||
// the turn's FIRST narration line and the answer the eye button exists to
|
||||
// show can be several screens below it; loadFullContext already scrolls to
|
||||
// the bottom for the same turn, so the two views disagreed.
|
||||
// jsdom does no layout, so scrollHeight is stubbed and the write recorded.
|
||||
const spyScroll = (body: HTMLElement) => {
|
||||
const writes: number[] = [];
|
||||
Object.defineProperty(body, 'scrollHeight', { configurable: true, get: () => 4200 });
|
||||
Object.defineProperty(body, 'scrollTop', {
|
||||
configurable: true,
|
||||
get: () => writes[writes.length - 1] ?? 0,
|
||||
set: (v: number) => void writes.push(v),
|
||||
});
|
||||
return writes;
|
||||
};
|
||||
|
||||
const many = mountViewer();
|
||||
const manyWrites = spyScroll(many.body);
|
||||
await makeApp({
|
||||
text: 'Done.',
|
||||
timestamp: 't',
|
||||
messages: [
|
||||
{ role: 'assistant', text: 'Looking at the file.', turn: 2 },
|
||||
{ role: 'assistant', text: 'Done.', turn: 2 },
|
||||
],
|
||||
}).app.toggleResponseViewer();
|
||||
expect(manyWrites.at(-1)).toBe(4200);
|
||||
|
||||
document.body.innerHTML = '';
|
||||
const one = mountViewer();
|
||||
const oneWrites = spyScroll(one.body);
|
||||
await makeApp({
|
||||
text: 'Done.',
|
||||
timestamp: 't',
|
||||
messages: [{ role: 'assistant', text: 'Done.', turn: 2 }],
|
||||
}).app.toggleResponseViewer();
|
||||
expect(oneWrites.at(-1)).toBe(0);
|
||||
});
|
||||
|
||||
it('falls back to text when the server sends no messages, keeping one badged card', async () => {
|
||||
const { body } = mountViewer();
|
||||
const { app } = makeApp({ text: 'Only the last row.', timestamp: 't' });
|
||||
|
||||
@@ -89,6 +89,27 @@ function harness({ screenReader = false } = {}) {
|
||||
};
|
||||
}
|
||||
|
||||
/** terminal-ui.js's exported predicates, loaded the same way as in test/mobile-shell-keyboard.test.ts. */
|
||||
function loadTerminalInput() {
|
||||
const source = readFileSync(new URL('../src/web/public/terminal-ui.js', import.meta.url), 'utf8');
|
||||
const win: Record<string, any> = {
|
||||
addEventListener() {},
|
||||
matchMedia: () => ({ matches: false, addEventListener() {} }),
|
||||
};
|
||||
const sandbox: Record<string, any> = {
|
||||
window: win,
|
||||
globalThis: win,
|
||||
document: { addEventListener() {} },
|
||||
CodemanApp: class {},
|
||||
};
|
||||
win.CodemanApp = sandbox.CodemanApp;
|
||||
vm.runInNewContext(source, sandbox, { filename: 'terminal-ui.js' });
|
||||
return win.CodemanTerminalInput as {
|
||||
shouldSuppressTerminalQueryResponse(data: string): boolean;
|
||||
isTerminalFocusOrMouseReport(data: string): boolean;
|
||||
};
|
||||
}
|
||||
|
||||
describe('orphaned terminal input recovery', () => {
|
||||
it('forwards the committed text when xterm stayed silent', () => {
|
||||
const h = harness();
|
||||
@@ -276,3 +297,60 @@ describe('orphaned terminal input recovery', () => {
|
||||
expect(h.emitted).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('terminal-ui wiring: what counts as "xterm spoke for this keystroke"', () => {
|
||||
const terminalSource = readFileSync(new URL('../src/web/public/terminal-ui.js', import.meta.url), 'utf8');
|
||||
|
||||
it('gates notifyCanonicalData on the two predicates this file already owns', () => {
|
||||
// onData does NOT only carry keystrokes: xterm answers DA/DSR/CPR/OSC
|
||||
// queries through it during Ink redraws, and emits SGR mouse and focus
|
||||
// reports on its own initiative. Counting one of those as canonical data
|
||||
// for the pending keystroke stands the recovery down and leaves the
|
||||
// character dropped, worst on a busy agent pane, which is the case this
|
||||
// exists for. Same gate, same two predicates, as the one-shot Ctrl
|
||||
// modifier uses for the same question (test/mobile-shell-keyboard.test.ts).
|
||||
const notify = terminalSource.indexOf('_keyCode229Recovery?.notifyCanonicalData?.()');
|
||||
expect(notify).toBeGreaterThan(0);
|
||||
|
||||
const gate = terminalSource.lastIndexOf(
|
||||
'!input?.shouldSuppressTerminalQueryResponse(data) && !input?.isTerminalFocusOrMouseReport(data)',
|
||||
notify
|
||||
);
|
||||
expect(gate).toBeGreaterThan(0);
|
||||
expect(gate).toBeLessThan(notify);
|
||||
|
||||
// ⚠️ The predicates live inside the module IIFE that ends long before this
|
||||
// call site, so they are reachable ONLY through the global. Bare references
|
||||
// would throw a ReferenceError straight into the surrounding try/catch,
|
||||
// which swallows it, and notifyCanonicalData would then NEVER run: the
|
||||
// recovery would re-emit a character xterm already delivered.
|
||||
expect(terminalSource.slice(gate - 120, notify)).toContain('window.CodemanTerminalInput');
|
||||
});
|
||||
|
||||
it('stands down for a real keystroke, but not for a mouse report or a query reply', () => {
|
||||
// The gate as terminal-ui.js writes it. The wiring test above pins the real
|
||||
// source; this proves the behaviour it buys.
|
||||
const input = loadTerminalInput();
|
||||
const onData = (h: ReturnType<typeof harness>, data: string) => {
|
||||
if (!input.shouldSuppressTerminalQueryResponse(data) && !input.isTerminalFocusOrMouseReport(data)) {
|
||||
h.controller.notifyCanonicalData();
|
||||
}
|
||||
};
|
||||
|
||||
for (const noise of ['\x1b[<0;10;5M', '\x1b[I', '\x1b[?1;2c']) {
|
||||
const h = harness();
|
||||
h.keydown();
|
||||
h.input('x');
|
||||
onData(h, noise);
|
||||
h.flushTimers();
|
||||
expect(h.emitted, `${JSON.stringify(noise)} must not stand the recovery down`).toEqual(['x']);
|
||||
}
|
||||
|
||||
const typed = harness();
|
||||
typed.keydown();
|
||||
typed.input('x');
|
||||
onData(typed, 'x');
|
||||
typed.flushTimers();
|
||||
expect(typed.emitted, 'xterm really did deliver this one').toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -95,6 +95,8 @@ function boot(pageUrl = 'http://192.168.1.135:8095/') {
|
||||
|
||||
interface WebviewLinks {
|
||||
isLoopbackHostname(host: string): boolean;
|
||||
isOnBoxHostname(host: string): boolean;
|
||||
webTabOriginKey(url: URL): string;
|
||||
linkNeedsWebTabProxy(url: string, pageHostname: string): boolean;
|
||||
}
|
||||
|
||||
@@ -108,16 +110,7 @@ describe('loopback link decision', () => {
|
||||
const links = win.CodemanWebviewLinks;
|
||||
|
||||
it('recognises every loopback spelling and nothing else', () => {
|
||||
for (const host of [
|
||||
'localhost',
|
||||
'LOCALHOST',
|
||||
'app.localhost',
|
||||
'127.0.0.1',
|
||||
'127.1.2.3',
|
||||
'0.0.0.0',
|
||||
'[::1]',
|
||||
'::1',
|
||||
]) {
|
||||
for (const host of ['localhost', 'LOCALHOST', '127.0.0.1', '127.1.2.3', '0.0.0.0', '[::1]', '::1']) {
|
||||
expect(links.isLoopbackHostname(host), host).toBe(true);
|
||||
}
|
||||
for (const host of [
|
||||
@@ -133,6 +126,31 @@ describe('loopback link decision', () => {
|
||||
}
|
||||
});
|
||||
|
||||
it('keeps *.localhost OUT of the auto-route set, because it is a DNS name an attacker can steer', () => {
|
||||
// Every other member of the set is an address literal that can only mean
|
||||
// this box. `evil.localhost` is not: on a resolver that does not synthesise
|
||||
// *.localhost locally and has a search domain configured, it NXDOMAINs as
|
||||
// absolute and is retried as `evil.localhost.<search domain>`. The link
|
||||
// source is agent-written terminal output, so this set is the whole
|
||||
// confinement on a tap that makes Codeman fetch a URL and persist it.
|
||||
expect(links.isLoopbackHostname('app.localhost')).toBe(false);
|
||||
expect(links.isLoopbackHostname('evil.localhost')).toBe(false);
|
||||
expect(links.linkNeedsWebTabProxy('http://evil.localhost/', '192.168.1.135')).toBe(false);
|
||||
|
||||
// The PAGE-side test stays broader: a false positive there only ever
|
||||
// DECLINES to proxy, leaving the caller's own direct open untouched.
|
||||
expect(links.isOnBoxHostname('app.localhost')).toBe(true);
|
||||
expect(links.linkNeedsWebTabProxy('http://localhost:5173/', 'app.localhost')).toBe(false);
|
||||
});
|
||||
|
||||
it('keys a dashboard per dev server, not per host spelling', () => {
|
||||
const key = (u: string) => links.webTabOriginKey(new URL(u));
|
||||
expect(key('http://localhost:5173/')).toBe(key('http://127.0.0.1:5173/'));
|
||||
expect(key('http://localhost:5173/')).not.toBe(key('http://localhost:5174/'));
|
||||
expect(key('http://localhost:5173/')).not.toBe(key('https://localhost:5173/'));
|
||||
expect(key('http://box.ts.net:3000/')).toBe('http://box.ts.net:3000');
|
||||
});
|
||||
|
||||
it('proxies a loopback http(s) link only when the page is not on that box', () => {
|
||||
expect(links.linkNeedsWebTabProxy('http://localhost:5173/', '192.168.1.135')).toBe(true);
|
||||
expect(links.linkNeedsWebTabProxy('https://127.0.0.1:8443/x?y=1', 'box.ts.net')).toBe(true);
|
||||
@@ -171,6 +189,54 @@ describe('openLinkThroughWebTabIfLoopback', () => {
|
||||
expect(win.document.querySelectorAll('.webview-frame').length).toBe(1);
|
||||
});
|
||||
|
||||
it('navigates an already-mounted frame back to the origin ROOT, which used to do nothing', async () => {
|
||||
// openUrlInWebTab used to flatten '/' to '', and openWebview reads an empty
|
||||
// path as "no deep link", so it mounted with navigate:false and an open
|
||||
// frame stayed on whatever page it was showing. Deep links navigated; a tap
|
||||
// on the bare origin silently did not.
|
||||
const { win, app } = boot();
|
||||
await app.openUrlInWebTab('http://localhost:5173/deep/page?a=1');
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/deep/page?a=1');
|
||||
|
||||
await app.openUrlInWebTab('http://localhost:5173/');
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/');
|
||||
expect(win.document.querySelectorAll('.webview-frame').length).toBe(1);
|
||||
});
|
||||
|
||||
it('reuses one dashboard across host spellings of the same dev server', async () => {
|
||||
const { win, app, calls } = boot();
|
||||
// The saved dashboard is http://localhost:5173/; a 127.0.0.1 link to the
|
||||
// same port is the same server and must not mint a second tab.
|
||||
await app.openUrlInWebTab('http://127.0.0.1:5173/status');
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/status');
|
||||
expect(calls.find((c) => c.method === 'POST' && c.path === '/api/webviews')).toBeUndefined();
|
||||
expect(win.document.querySelectorAll('.webview-frame').length).toBe(1);
|
||||
});
|
||||
|
||||
it('waits for an in-flight webview load instead of POSTing a duplicate record', async () => {
|
||||
// initWebviews() assigns a truthy EMPTY map synchronously and only then
|
||||
// awaits GET /api/webviews, so "is this.webviews set" answered "is it
|
||||
// loaded" wrongly: a tap inside that round trip found nothing to reuse and
|
||||
// saved a second dashboard for an origin that already existed server-side.
|
||||
const { win, app, calls } = boot();
|
||||
const loaded = app.webviews;
|
||||
app.webviews = new Map();
|
||||
let release: () => void = () => {};
|
||||
const gate = new Promise<void>((resolve) => {
|
||||
release = resolve;
|
||||
});
|
||||
(app as unknown as { _webviewsRefresh: Promise<void> })._webviewsRefresh = gate.then(() => {
|
||||
app.webviews = loaded;
|
||||
});
|
||||
|
||||
const tap = app.openUrlInWebTab('http://localhost:5173/late');
|
||||
release();
|
||||
await tap;
|
||||
|
||||
expect(calls.find((c) => c.method === 'POST' && c.path === '/api/webviews')).toBeUndefined();
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/late');
|
||||
});
|
||||
|
||||
it('saves an unknown origin under its host:port, then opens it', async () => {
|
||||
const { win, app, calls } = boot();
|
||||
expect(app.openLinkThroughWebTabIfLoopback('http://127.0.0.1:3000/')).toBe(true);
|
||||
|
||||
Reference in New Issue
Block a user