mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 07:59:42 +02:00
Each item is from the pre-merge review of the PR it names, applied on master rather than by pushing to a contributor branch. #400 (response viewer, shenlvkang-collab) - The brief view opened at `scrollTop = 0`, right when it was a single card holding the last row. Now that it renders the whole turn, the top is the turn's first narration line and the answer can be screens below it, while loadFullContext already scrolls to the bottom of the same turn. A multi-row turn now opens at its newest text; a single card still opens at the top. #401 (loopback links as web tabs, shenlvkang-collab) - Drop `*.localhost` from the auto-route set. Every other member is an address literal that can only mean this box; a `*.localhost` DNS name is not one, and a resolver with a search domain retries `evil.localhost` as `evil.localhost.<search domain>`. The link source is agent-written terminal output, so that set is the whole confinement on a tap that makes Codeman fetch a URL server-side and persist it. The page-side test stays broader (`isOnBoxHostname`), where a false positive only declines to proxy. - A link to the origin root navigated nothing: the path was flattened to '', which openWebview reads as "no deep link", leaving an open frame where it was. - `this.webviews` being set does not mean it is loaded. initWebviews() assigns a truthy empty map and only then awaits the list, so a tap during page load found nothing to reuse and POSTed a duplicate record. Join the in-flight refresh instead. - One dashboard per dev server rather than per host spelling, which is what the method's own comment already promised. - Toast on the auto-create: it writes webviews.json, broadcasts over SSE and adds a Run-dropdown row on every signed-in device, with a new tab as its only previous signal. #362 (remote omp continuation, timkjr) - Accept the allowlisted `mode === 'omp'` arm as-is; a blanket registry render would hand deepseek a locally-resolved --profile and bypass claude's own overlay. A registry-declared switch is the follow-up if a third mode needs it. - Revert the whole-file Prettier reformat of docs/remote-sessions.md (docs/ is hand-formatted and outside `npm run format`), keeping only the two new sections. - Correct three stale passages: architecture-invariants' `exec claude --dangerously-skip-permissions`, the `exec <cli>` paragraph (claude and omp now have their own arms, and the claude pane's PID is the login shell), and omp-integration's `-c 'omp'`. RemoteCommandMode gains deepseek and omp. - Add the missing `_maybeCaptureOmpSessionId` remote-guard test; the sibling guard in `_pinOmpRespawnId` had one and this path runs earlier, on the first idle turn. #388 (keyCode 229 recovery, aakhter) - Gate notifyCanonicalData on shouldSuppressTerminalQueryResponse and isTerminalFocusOrMouseReport. onData also carries the DA/DSR/CPR/OSC replies xterm answers during Ink redraws and its SGR mouse and focus reports; any of those landing between the keydown and the candidate's resolution was read as "xterm spoke for this keystroke", standing the recovery down and leaving the character dropped, worst on a busy agent pane. Reached through window.CodemanTerminalInput: the predicates live in a module IIFE that closes long before this call site, so bare references would throw into the surrounding try/catch and stop the notify from ever running. Every fix has a test that fails without it (verified by reverting each). Full gate green on the combined tree: 358 files, 6849 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -95,6 +95,8 @@ function boot(pageUrl = 'http://192.168.1.135:8095/') {
|
||||
|
||||
interface WebviewLinks {
|
||||
isLoopbackHostname(host: string): boolean;
|
||||
isOnBoxHostname(host: string): boolean;
|
||||
webTabOriginKey(url: URL): string;
|
||||
linkNeedsWebTabProxy(url: string, pageHostname: string): boolean;
|
||||
}
|
||||
|
||||
@@ -108,16 +110,7 @@ describe('loopback link decision', () => {
|
||||
const links = win.CodemanWebviewLinks;
|
||||
|
||||
it('recognises every loopback spelling and nothing else', () => {
|
||||
for (const host of [
|
||||
'localhost',
|
||||
'LOCALHOST',
|
||||
'app.localhost',
|
||||
'127.0.0.1',
|
||||
'127.1.2.3',
|
||||
'0.0.0.0',
|
||||
'[::1]',
|
||||
'::1',
|
||||
]) {
|
||||
for (const host of ['localhost', 'LOCALHOST', '127.0.0.1', '127.1.2.3', '0.0.0.0', '[::1]', '::1']) {
|
||||
expect(links.isLoopbackHostname(host), host).toBe(true);
|
||||
}
|
||||
for (const host of [
|
||||
@@ -133,6 +126,31 @@ describe('loopback link decision', () => {
|
||||
}
|
||||
});
|
||||
|
||||
it('keeps *.localhost OUT of the auto-route set, because it is a DNS name an attacker can steer', () => {
|
||||
// Every other member of the set is an address literal that can only mean
|
||||
// this box. `evil.localhost` is not: on a resolver that does not synthesise
|
||||
// *.localhost locally and has a search domain configured, it NXDOMAINs as
|
||||
// absolute and is retried as `evil.localhost.<search domain>`. The link
|
||||
// source is agent-written terminal output, so this set is the whole
|
||||
// confinement on a tap that makes Codeman fetch a URL and persist it.
|
||||
expect(links.isLoopbackHostname('app.localhost')).toBe(false);
|
||||
expect(links.isLoopbackHostname('evil.localhost')).toBe(false);
|
||||
expect(links.linkNeedsWebTabProxy('http://evil.localhost/', '192.168.1.135')).toBe(false);
|
||||
|
||||
// The PAGE-side test stays broader: a false positive there only ever
|
||||
// DECLINES to proxy, leaving the caller's own direct open untouched.
|
||||
expect(links.isOnBoxHostname('app.localhost')).toBe(true);
|
||||
expect(links.linkNeedsWebTabProxy('http://localhost:5173/', 'app.localhost')).toBe(false);
|
||||
});
|
||||
|
||||
it('keys a dashboard per dev server, not per host spelling', () => {
|
||||
const key = (u: string) => links.webTabOriginKey(new URL(u));
|
||||
expect(key('http://localhost:5173/')).toBe(key('http://127.0.0.1:5173/'));
|
||||
expect(key('http://localhost:5173/')).not.toBe(key('http://localhost:5174/'));
|
||||
expect(key('http://localhost:5173/')).not.toBe(key('https://localhost:5173/'));
|
||||
expect(key('http://box.ts.net:3000/')).toBe('http://box.ts.net:3000');
|
||||
});
|
||||
|
||||
it('proxies a loopback http(s) link only when the page is not on that box', () => {
|
||||
expect(links.linkNeedsWebTabProxy('http://localhost:5173/', '192.168.1.135')).toBe(true);
|
||||
expect(links.linkNeedsWebTabProxy('https://127.0.0.1:8443/x?y=1', 'box.ts.net')).toBe(true);
|
||||
@@ -171,6 +189,54 @@ describe('openLinkThroughWebTabIfLoopback', () => {
|
||||
expect(win.document.querySelectorAll('.webview-frame').length).toBe(1);
|
||||
});
|
||||
|
||||
it('navigates an already-mounted frame back to the origin ROOT, which used to do nothing', async () => {
|
||||
// openUrlInWebTab used to flatten '/' to '', and openWebview reads an empty
|
||||
// path as "no deep link", so it mounted with navigate:false and an open
|
||||
// frame stayed on whatever page it was showing. Deep links navigated; a tap
|
||||
// on the bare origin silently did not.
|
||||
const { win, app } = boot();
|
||||
await app.openUrlInWebTab('http://localhost:5173/deep/page?a=1');
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/deep/page?a=1');
|
||||
|
||||
await app.openUrlInWebTab('http://localhost:5173/');
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/');
|
||||
expect(win.document.querySelectorAll('.webview-frame').length).toBe(1);
|
||||
});
|
||||
|
||||
it('reuses one dashboard across host spellings of the same dev server', async () => {
|
||||
const { win, app, calls } = boot();
|
||||
// The saved dashboard is http://localhost:5173/; a 127.0.0.1 link to the
|
||||
// same port is the same server and must not mint a second tab.
|
||||
await app.openUrlInWebTab('http://127.0.0.1:5173/status');
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/status');
|
||||
expect(calls.find((c) => c.method === 'POST' && c.path === '/api/webviews')).toBeUndefined();
|
||||
expect(win.document.querySelectorAll('.webview-frame').length).toBe(1);
|
||||
});
|
||||
|
||||
it('waits for an in-flight webview load instead of POSTing a duplicate record', async () => {
|
||||
// initWebviews() assigns a truthy EMPTY map synchronously and only then
|
||||
// awaits GET /api/webviews, so "is this.webviews set" answered "is it
|
||||
// loaded" wrongly: a tap inside that round trip found nothing to reuse and
|
||||
// saved a second dashboard for an origin that already existed server-side.
|
||||
const { win, app, calls } = boot();
|
||||
const loaded = app.webviews;
|
||||
app.webviews = new Map();
|
||||
let release: () => void = () => {};
|
||||
const gate = new Promise<void>((resolve) => {
|
||||
release = resolve;
|
||||
});
|
||||
(app as unknown as { _webviewsRefresh: Promise<void> })._webviewsRefresh = gate.then(() => {
|
||||
app.webviews = loaded;
|
||||
});
|
||||
|
||||
const tap = app.openUrlInWebTab('http://localhost:5173/late');
|
||||
release();
|
||||
await tap;
|
||||
|
||||
expect(calls.find((c) => c.method === 'POST' && c.path === '/api/webviews')).toBeUndefined();
|
||||
expect(frameSrc(win, 'dev')).toBe('/webview/cap-dev/late');
|
||||
});
|
||||
|
||||
it('saves an unknown origin under its host:port, then opens it', async () => {
|
||||
const { win, app, calls } = boot();
|
||||
expect(app.openLinkThroughWebTabIfLoopback('http://127.0.0.1:3000/')).toBe(true);
|
||||
|
||||
Reference in New Issue
Block a user