Merge branch 'master' into pr180

This commit is contained in:
Codeman maintainer
2026-08-04 23:37:59 +02:00
77 changed files with 7995 additions and 541 deletions
+123
View File
@@ -0,0 +1,123 @@
import { describe, expect, it } from 'vitest';
import { CreateSessionSchema, QuickStartSchema } from '../src/web/schemas.js';
import { buildSpawnCommand } from '../src/tmux-manager.js';
import { defaultDockerCommandForMode } from '../src/docker-hosts.js';
import { defaultRemoteCommandForMode } from '../src/remote-hosts.js';
import { isExternalCliMode, isAltScreenStripMode } from '../src/session.js';
describe('Antigravity mode schemas', () => {
it('accepts Antigravity session creation config', () => {
const parsed = CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'antigravity',
antigravityConfig: {
model: 'gemini-3-pro',
dangerouslySkipPermissions: true,
},
});
expect(parsed.mode).toBe('antigravity');
expect(parsed.antigravityConfig).toEqual({
model: 'gemini-3-pro',
dangerouslySkipPermissions: true,
});
});
it('accepts Antigravity quick-start config', () => {
const parsed = QuickStartSchema.parse({
caseName: 'antigravity-case',
mode: 'antigravity',
antigravityConfig: {
resumeConversationId: 'conv-1234abcd',
},
});
expect(parsed.mode).toBe('antigravity');
expect(parsed.antigravityConfig?.resumeConversationId).toBe('conv-1234abcd');
});
it('rejects unsafe Antigravity model strings', () => {
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'antigravity',
antigravityConfig: { model: 'agy; rm -rf /' },
})
).toThrow();
});
it('allows ANTIGRAVITY_* env overrides and still rejects unknown prefixes', () => {
const parsed = CreateSessionSchema.parse({
workingDir: '/tmp',
mode: 'antigravity',
envOverrides: { ANTIGRAVITY_LOG_LEVEL: 'debug' },
});
expect(parsed.envOverrides).toEqual({ ANTIGRAVITY_LOG_LEVEL: 'debug' });
expect(() =>
CreateSessionSchema.parse({
workingDir: '/tmp',
envOverrides: { RANDOM_PREFIX_KEY: 'x' },
})
).toThrow();
});
});
describe('Antigravity spawn command', () => {
it('builds a bare agy command when no config is sent (safe default, no bypass)', () => {
const cmd = buildSpawnCommand({ mode: 'antigravity', sessionId: 'abc12345' });
expect(cmd).toBe('agy');
});
it('adds --dangerously-skip-permissions only when explicitly requested', () => {
const cmd = buildSpawnCommand({
mode: 'antigravity',
sessionId: 'abc12345',
antigravityConfig: { dangerouslySkipPermissions: true, model: 'gemini-3-pro' },
});
expect(cmd).toBe('agy --dangerously-skip-permissions --model gemini-3-pro');
});
it('passes --conversation for resume and drops unsafe ids', () => {
expect(
buildSpawnCommand({
mode: 'antigravity',
sessionId: 'abc12345',
antigravityConfig: { resumeConversationId: 'conv-99' },
})
).toBe('agy --conversation conv-99');
expect(
buildSpawnCommand({
mode: 'antigravity',
sessionId: 'abc12345',
antigravityConfig: { resumeConversationId: 'x; rm -rf /' },
})
).toBe('agy');
});
it('drops unsafe model strings from the spawn command', () => {
expect(
buildSpawnCommand({
mode: 'antigravity',
sessionId: 'abc12345',
antigravityConfig: { model: 'a`b' },
})
).toBe('agy');
});
});
describe('Antigravity mode gates', () => {
it('is an external CLI mode (readiness/ralph/respawn gating)', () => {
expect(isExternalCliMode('antigravity')).toBe(true);
});
it('is NOT an alt-screen strip mode (unverified Go TUI, like opencode)', () => {
expect(isAltScreenStripMode('antigravity')).toBe(false);
});
it('has docker/remote default commands', () => {
expect(defaultDockerCommandForMode('antigravity')).toBe('exec agy');
expect(defaultRemoteCommandForMode('antigravity')).toBe('exec agy');
});
});
+51 -10
View File
@@ -1,10 +1,10 @@
/**
* COD-91 — `refreshStaleHookSecret` self-heal.
* COD-91 — `refreshStaleCodemanHooks` self-heal.
*
* Making the hook-event secret unconditionally required (PR #127) would silently 401 the
* hook curls baked into cases created before the secret header existed (COD-54). Those
* curls live in `.claude/settings.local.json` and `writeHooksConfig` only runs at case
* CREATION, so existing cases never refresh. `refreshStaleHookSecret` regenerates the
* CREATION, so existing cases never refresh. `refreshStaleCodemanHooks` regenerates the
* hooks block on session spawn — but ONLY when the case already holds Codeman's own
* pre-secret hook curls, never clobbering a user's customizations.
*
@@ -15,7 +15,7 @@ import { describe, it, expect, beforeEach, afterEach } from 'vitest';
import { mkdtempSync, mkdirSync, writeFileSync, readFileSync, existsSync, rmSync } from 'node:fs';
import { join } from 'node:path';
import { tmpdir } from 'node:os';
import { refreshStaleHookSecret } from '../src/hooks-config.js';
import { refreshStaleCodemanHooks } from '../src/hooks-config.js';
const SECRET_HEADER = 'X-Codeman-Hook-Secret';
@@ -41,7 +41,7 @@ function staleCodemanHooks() {
};
}
describe('refreshStaleHookSecret', () => {
describe('refreshStaleCodemanHooks', () => {
let dir: string;
let settingsPath: string;
@@ -60,7 +60,7 @@ describe('refreshStaleHookSecret', () => {
settingsPath,
JSON.stringify({ env: { CLAUDE_CODE_FOO: '1' }, model: 'opus', hooks: staleCodemanHooks() }, null, 2)
);
await refreshStaleHookSecret(dir);
await refreshStaleCodemanHooks(dir);
const after = JSON.parse(readFileSync(settingsPath, 'utf-8'));
expect(JSON.stringify(after.hooks)).toContain(SECRET_HEADER);
@@ -73,11 +73,11 @@ describe('refreshStaleHookSecret', () => {
it('leaves a hooks block that already carries the secret unchanged', async () => {
// Seed with a current block by healing a stale one first, then re-heal: second pass must no-op.
writeFileSync(settingsPath, JSON.stringify({ hooks: staleCodemanHooks() }, null, 2));
await refreshStaleHookSecret(dir);
await refreshStaleCodemanHooks(dir);
const healed = readFileSync(settingsPath, 'utf-8');
expect(healed).toContain(SECRET_HEADER);
await refreshStaleHookSecret(dir);
await refreshStaleCodemanHooks(dir);
expect(readFileSync(settingsPath, 'utf-8')).toBe(healed); // byte-identical: no rewrite
});
@@ -88,19 +88,60 @@ describe('refreshStaleHookSecret', () => {
2
);
writeFileSync(settingsPath, foreign);
await refreshStaleHookSecret(dir);
await refreshStaleCodemanHooks(dir);
expect(readFileSync(settingsPath, 'utf-8')).toBe(foreign);
});
it('preserves user handlers and events in a mixed stale configuration', async () => {
const hooks = staleCodemanHooks();
hooks.Stop[0].hooks.push({
type: 'command',
command: './notify-user.sh',
timeout: 10,
});
const customPostToolUse = {
matcher: 'Write',
hooks: [{ type: 'command', command: './format.sh' }],
};
const customEvent = [
{
hooks: [{ type: 'command', command: './audit.sh' }],
},
];
writeFileSync(
settingsPath,
JSON.stringify(
{
hooks: {
...hooks,
PostToolUse: [customPostToolUse],
CustomEvent: customEvent,
},
},
null,
2
)
);
await refreshStaleCodemanHooks(dir);
const after = JSON.parse(readFileSync(settingsPath, 'utf-8'));
expect(JSON.stringify(after.hooks)).toContain(SECRET_HEADER);
expect(JSON.stringify(after.hooks)).toContain('CODEMAN_BACKGROUND_REWAKE_V');
expect(JSON.stringify(after.hooks.Stop)).toContain('./notify-user.sh');
expect(after.hooks.PostToolUse).toEqual(expect.arrayContaining([customPostToolUse]));
expect(after.hooks.CustomEvent).toEqual(customEvent);
});
it('is a no-op when settings.local.json is absent (does not create one)', async () => {
await refreshStaleHookSecret(dir);
await refreshStaleCodemanHooks(dir);
expect(existsSync(settingsPath)).toBe(false);
});
it('leaves a malformed settings file untouched', async () => {
const garbage = '{ not valid json';
writeFileSync(settingsPath, garbage);
await refreshStaleHookSecret(dir);
await refreshStaleCodemanHooks(dir);
expect(readFileSync(settingsPath, 'utf-8')).toBe(garbage);
});
});
+180 -6
View File
@@ -9,7 +9,13 @@ import { describe, it, expect, beforeAll, beforeEach, afterAll, afterEach } from
import { existsSync, readFileSync, writeFileSync, mkdirSync, rmSync } from 'node:fs';
import { join } from 'node:path';
import { tmpdir } from 'node:os';
import { generateHooksConfig, writeHooksConfig } from '../src/hooks-config.js';
import { spawn } from 'node:child_process';
import {
generateBackgroundWakeScript,
generateHooksConfig,
refreshStaleCodemanHooks,
writeHooksConfig,
} from '../src/hooks-config.js';
describe('generateHooksConfig', () => {
it('should return an object with hooks key', () => {
@@ -29,6 +35,30 @@ describe('generateHooksConfig', () => {
expect(config.hooks.Stop).toHaveLength(1);
});
it('should configure a self-contained Bash background-task rewake hook', () => {
const config = generateHooksConfig();
const postToolHooks = config.hooks.PostToolUse as Array<{
matcher: string;
hooks: Array<{
type: string;
command: string;
args: string[];
asyncRewake: boolean;
timeout: number;
}>;
}>;
expect(postToolHooks).toHaveLength(1);
expect(postToolHooks[0].matcher).toBe('Bash');
expect(postToolHooks[0].hooks[0]).toMatchObject({
type: 'command',
command: 'node',
asyncRewake: true,
});
expect(postToolHooks[0].hooks[0].args).toEqual(['-e', generateBackgroundWakeScript()]);
expect(postToolHooks[0].hooks[0].timeout).toBeGreaterThanOrEqual(3600);
});
it('should configure idle_prompt matcher', () => {
const config = generateHooksConfig();
const notifHooks = config.hooks.Notification as Array<{ matcher?: string }>;
@@ -65,10 +95,10 @@ describe('generateHooksConfig', () => {
expect(notifHooks[0].hooks[0].command).toContain('|| true');
});
it('should set timeout to 10000ms', () => {
it('should set timeout to 10 seconds (hook timeout fields are seconds)', () => {
const config = generateHooksConfig();
const notifHooks = config.hooks.Notification as Array<{ hooks: Array<{ timeout: number }> }>;
expect(notifHooks[0].hooks[0].timeout).toBe(10000);
expect(notifHooks[0].hooks[0].timeout).toBe(10);
});
it('should include correct event names in curl payloads', () => {
@@ -157,7 +187,75 @@ describe('writeHooksConfig', () => {
expect(parsed.hooks).toBeDefined();
});
it('should overwrite existing hooks key', async () => {
it('should upgrade Codeman-owned hooks that predate background rewake', async () => {
const claudeDir = join(testDir, '.claude');
const settingsPath = join(claudeDir, 'settings.local.json');
mkdirSync(claudeDir, { recursive: true });
const oldHooks = generateHooksConfig().hooks;
delete oldHooks.PostToolUse;
writeFileSync(settingsPath, JSON.stringify({ hooks: oldHooks }, null, 2));
await refreshStaleCodemanHooks(testDir);
const parsed = JSON.parse(readFileSync(settingsPath, 'utf-8'));
expect(parsed.hooks.PostToolUse).toHaveLength(1);
expect(JSON.stringify(parsed.hooks.PostToolUse)).toContain('CODEMAN_BACKGROUND_REWAKE_V');
});
it('should replace an older rewake script version without duplicating it', async () => {
const claudeDir = join(testDir, '.claude');
const settingsPath = join(claudeDir, 'settings.local.json');
mkdirSync(claudeDir, { recursive: true });
// Simulate a case healed by the previous release: current curls (secret present)
// plus a V1 rewake handler. The version bump must swap the handler in place.
const hooks = generateHooksConfig().hooks;
hooks.PostToolUse = [
{
matcher: 'Bash',
hooks: [
{
type: 'command',
command: 'node',
args: ['-e', 'const CODEMAN_BACKGROUND_REWAKE_V1 = true; process.exit(0);'],
asyncRewake: true,
timeout: 21600,
},
],
},
];
writeFileSync(settingsPath, JSON.stringify({ hooks }, null, 2));
await refreshStaleCodemanHooks(testDir);
const parsed = JSON.parse(readFileSync(settingsPath, 'utf-8'));
const serialized = JSON.stringify(parsed.hooks.PostToolUse);
expect(parsed.hooks.PostToolUse).toHaveLength(1);
expect(parsed.hooks.PostToolUse[0].hooks).toHaveLength(1);
expect(serialized).toContain('CODEMAN_BACKGROUND_REWAKE_V2');
expect(serialized).not.toContain('CODEMAN_BACKGROUND_REWAKE_V1');
});
it('should not add rewake hooks to a user-owned hook configuration', async () => {
const claudeDir = join(testDir, '.claude');
const settingsPath = join(claudeDir, 'settings.local.json');
mkdirSync(claudeDir, { recursive: true });
const userHooks = {
PostToolUse: [
{
matcher: 'Write',
hooks: [{ type: 'command', command: './format.sh' }],
},
],
};
writeFileSync(settingsPath, JSON.stringify({ hooks: userHooks }, null, 2));
await refreshStaleCodemanHooks(testDir);
const parsed = JSON.parse(readFileSync(settingsPath, 'utf-8'));
expect(parsed.hooks).toEqual(userHooks);
});
it('should preserve user hook events while installing Codeman hooks', async () => {
const claudeDir = join(testDir, '.claude');
mkdirSync(claudeDir, { recursive: true });
writeFileSync(join(claudeDir, 'settings.local.json'), JSON.stringify({ hooks: { oldHook: [] } }, null, 2));
@@ -165,7 +263,7 @@ describe('writeHooksConfig', () => {
await writeHooksConfig(testDir);
const parsed = JSON.parse(readFileSync(join(claudeDir, 'settings.local.json'), 'utf-8'));
expect(parsed.hooks.oldHook).toBeUndefined();
expect(parsed.hooks.oldHook).toEqual([]);
expect(parsed.hooks.Notification).toBeDefined();
});
@@ -187,6 +285,82 @@ describe('writeHooksConfig', () => {
});
});
describe('background task rewake helper', () => {
const testDir = join(tmpdir(), 'codeman-background-rewake-test-' + Date.now());
beforeEach(() => {
mkdirSync(testDir, { recursive: true });
});
afterEach(() => {
rmSync(testDir, { recursive: true, force: true });
});
function runHelper(input: Record<string, unknown>): Promise<{ code: number | null; stderr: string }> {
return new Promise((resolve, reject) => {
const child = spawn(process.execPath, ['-e', generateBackgroundWakeScript()], {
stdio: ['pipe', 'ignore', 'pipe'],
});
let stderr = '';
const timeout = setTimeout(() => {
child.kill();
reject(new Error('background rewake helper timed out'));
}, 5000);
child.stderr.setEncoding('utf8');
child.stderr.on('data', (chunk) => {
stderr += chunk;
});
child.on('error', reject);
child.on('close', (code) => {
clearTimeout(timeout);
resolve({ code, stderr });
});
child.stdin.end(JSON.stringify(input));
});
}
it('exits without waiting for an ordinary Bash result', async () => {
const result = await runHelper({
transcript_path: join(testDir, 'transcript.jsonl'),
tool_response: { stdout: 'ordinary command completed' },
});
expect(result.code).toBe(0);
expect(result.stderr).toBe('');
});
it('exits 2 when the matching background command completes', async () => {
const transcriptPath = join(testDir, 'transcript.jsonl');
writeFileSync(transcriptPath, '');
const resultPromise = runHelper({
transcript_path: transcriptPath,
tool_response: {
stdout: 'Command running in background with ID: bg-test-1. Output is being written to: /tmp/bg-test-1.output.',
},
});
await new Promise((resolve) => setTimeout(resolve, 100));
writeFileSync(
transcriptPath,
JSON.stringify({
type: 'queue-operation',
operation: 'enqueue',
content:
'<task-notification>\n<task-id>bg-test-1</task-id>\n<status>completed</status>\n' +
'<output-file>/tmp/bg-test-1.output</output-file>\n</task-notification>',
}) + '\n'
);
const result = await resultPromise;
expect(result.code).toBe(2);
expect(result.stderr).toContain('bg-test-1');
expect(result.stderr).toContain('completed');
expect(result.stderr).toContain('/tmp/bg-test-1.output');
});
});
// ========== Hook Event API Integration Tests ==========
// Port 3130 reserved for hooks integration tests
@@ -700,7 +874,7 @@ describe('Hook Config Generation - Extended', () => {
expect(hook.matcher).toBeDefined();
expect(hook.hooks).toHaveLength(1);
expect(hook.hooks[0].type).toBe('command');
expect(hook.hooks[0].timeout).toBe(10000);
expect(hook.hooks[0].timeout).toBe(10);
expect(hook.hooks[0].command).toBeTruthy();
}
});
+113
View File
@@ -245,6 +245,119 @@ describe('Inline rename input', () => {
expect(result.threw).toBe(false);
});
it('Render guard: _renderSessionTabsImmediate() does not destroy an open rename input', async () => {
await resetState();
// The debounced tab render is scheduled by renderSessionTabs() but EXECUTED by
// _renderSessionTabsImmediate(). A render queued just before the rename opened
// still fires ~100ms later and lands in the executor directly, so the guard has
// to live there too, otherwise the incremental branch rewrites .tab-name's
// innerHTML and the user's half-typed description is lost.
//
// The tab MUST live inside the real #sessionTabs container and be the only
// session in app.sessions: the renderer walks that container, so a synthetic
// node parked on <body> would make this test pass with the guard removed.
const result = await page.evaluate(() => {
const app = (
window as unknown as {
app: {
sessions: Map<string, { id: string; name: string; status: string }>;
sessionOrder: string[];
startInlineRename: (id: string) => void;
_renderSessionTabsImmediate: () => void;
_activeRename: unknown;
};
}
).app;
const id = 'render-race';
app.sessions.set(id, { id, name: 'w9-case', status: 'idle' });
app.sessionOrder = [id];
const container = document.getElementById('sessionTabs') as HTMLElement;
const tab = document.createElement('div');
tab.setAttribute('data-test-tab', '1');
tab.className = 'session-tab';
tab.dataset.id = id;
tab.innerHTML =
'<span class="tab-status idle"></span><span class="tab-info"><span class="tab-name-row">' +
`<span class="tab-name" data-session-id="${id}">w9-case</span>` +
'</span></span>';
container.appendChild(tab);
app.startInlineRename(id);
const input = document.querySelector('input.tab-rename-input') as HTMLInputElement | null;
if (!input) return { opened: false };
input.value = 'half-typed';
// Exactly what a debounce timer queued before the rename would do.
app._renderSessionTabsImmediate();
const after = document.querySelector('input.tab-rename-input') as HTMLInputElement | null;
return {
opened: true,
stillInDom: !!after && document.body.contains(after),
value: after?.value ?? null,
renameStillActive: !!app._activeRename,
};
});
expect(result.opened).toBe(true);
expect(result.stillInDom).toBe(true);
expect(result.value).toBe('half-typed');
expect(result.renameStillActive).toBe(true);
});
it('Modal: closeSessionOptions() commits the Session Name field before clearing the id', async () => {
await resetState();
// Every autosave handler in the session-options modal bails on a null
// editingSessionId, and hiding the modal blurs the focused input. If the id is
// cleared first, the blur-driven save is dropped and the typed name vanishes,
// which is what Escape and backdrop-click used to do.
const result = await page.evaluate(async () => {
const app = (
window as unknown as {
app: {
editingSessionId: string | null;
sessions: Map<string, { id: string; name: string }>;
closeSessionOptions: () => void;
};
}
).app;
app.sessions.set('modal-id', { id: 'modal-id', name: 'w9-case' });
app.editingSessionId = 'modal-id';
const nameInput = document.getElementById('modalSessionName') as HTMLInputElement;
const modal = document.getElementById('sessionOptionsModal') as HTMLElement;
modal.classList.add('active');
// The Session Name field lives on the modal's Context tab, which is hidden
// until selected: a hidden input cannot take focus.
document.getElementById('context-tab')?.classList.remove('hidden');
nameInput.value = 'mydesc';
nameInput.focus();
const wasFocused = document.activeElement === nameInput;
let putBody: string | null = null;
const origFetch = window.fetch;
window.fetch = (async (input: RequestInfo | URL, init?: RequestInit) => {
if (String(input).includes('/api/sessions/modal-id/name')) putBody = String(init?.body ?? '');
return new Response('{"success":true}', { status: 200 });
}) as typeof window.fetch;
app.closeSessionOptions();
await new Promise((r) => setTimeout(r, 30));
window.fetch = origFetch;
modal.classList.remove('active');
return { wasFocused, putBody, editingAfter: app.editingSessionId };
});
expect(result.wasFocused).toBe(true);
// Prefixed session: the suffix the user typed is appended to the w9-case prefix.
expect(result.putBody).toContain('w9-case: mydesc');
expect(result.editingAfter).toBe(null);
});
it('Re-entry: starting rename while one is active aborts the previous one', async () => {
await resetState();
expect(await startRename('first-id', 'First')).toBe(true);
+274
View File
@@ -0,0 +1,274 @@
// Port: none (pure model + static markup assertions — no browser, no server).
//
// The phone home screen (src/web/public/mobile-overview.js) replaces the welcome
// overlay under 430px. Its grouping logic is the part that can silently go wrong:
// a session blocked on a permission prompt landing in "idle" is exactly the bug
// this surface exists to prevent. buildMobileOverviewModel() is pure for that
// reason, so it can be exercised here against plain objects.
import { readFileSync } from 'node:fs';
import { resolve } from 'node:path';
import vm from 'node:vm';
import { describe, expect, it } from 'vitest';
const PUBLIC = resolve(import.meta.dirname, '../src/web/public');
function loadOverviewApp(overrides: Record<string, any> = {}) {
const CodemanApp = function CodemanApp(this: any) {};
const context = vm.createContext({
CodemanApp,
console,
window: {},
document: { getElementById: () => null },
MobileDetection: { getDeviceType: () => 'mobile' },
});
vm.runInContext(readFileSync(resolve(PUBLIC, 'mobile-overview.js'), 'utf8'), context, {
filename: 'mobile-overview.js',
});
const app = new (CodemanApp as any)();
app.getSessionName = (session: any) => session.name || session.workingDir?.split('/').pop() || session.id.slice(0, 8);
app._shortenHomePath = (p: string) => (p || '').replace(/^\/home\/[^/]+\//, '~/');
app.loadAppSettingsFromStorage = () => ({});
Object.assign(app, overrides);
return app;
}
const CASES = [
{ name: 'claudeman', path: '/home/arkon/default/claudeman', location: 'local' },
{ name: 'beta', path: '/home/arkon/codeman-cases/beta', location: 'local' },
{ name: 'boxed', path: '/srv/boxed', location: 'docker' },
];
function session(over: Record<string, any>) {
return { id: 'x', status: 'idle', mode: 'claude', workingDir: '/home/arkon/default/claudeman', ...over };
}
describe('mobile overview model', () => {
it('routes a session with a pending permission prompt into NEEDS YOU, not idle', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
sessions: [session({ id: 'a', status: 'idle' })],
cases: CASES,
pendingHooks: new Map([['a', new Set(['permission_prompt'])]]),
});
expect(model.needsYou.map((r: any) => r.id)).toEqual(['a']);
expect(model.current).toHaveLength(0);
expect(model.needsYou[0].state).toBe('needs');
expect(model.needsYou[0].pill).toBe('needs you');
});
it('ranks an action hook above an idle hook above a stale busy status', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
// An idle_prompt hook on a session the server still calls 'busy': the hook
// is the newer signal, so it must win.
sessions: [
session({ id: 'busy-with-idle-hook', status: 'busy' }),
session({ id: 'elicit', status: 'busy' }),
session({ id: 'plain-busy', status: 'busy' }),
],
cases: CASES,
pendingHooks: new Map([
['busy-with-idle-hook', new Set(['idle_prompt'])],
['elicit', new Set(['elicitation_dialog'])],
]),
});
expect(model.needsYou.map((r: any) => r.id)).toEqual(['elicit', 'busy-with-idle-hook']);
expect(model.current.map((r: any) => r.id)).toEqual(['plain-busy']);
});
it('buckets busy / idle / stopped / error and labels each pill', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
sessions: [
session({ id: 'w', status: 'busy' }),
session({ id: 'i', status: 'idle' }),
session({ id: 'd', status: 'stopped' }),
session({ id: 'e', status: 'error' }),
],
cases: CASES,
});
// Everything that is not blocked on you shares one "current" section,
// most demanding first.
expect(model.current.map((r: any) => [r.id, r.pill])).toEqual([
['w', 'working'],
['i', 'idle'],
['d', 'done'],
]);
expect(model.needsYou.map((r: any) => r.pill)).toEqual(['error']);
expect(model.sessionCount).toBe(4);
});
it('keeps the user tab order as the tiebreak inside a section', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
sessions: [session({ id: 'first' }), session({ id: 'second' }), session({ id: 'third' })],
cases: CASES,
sessionOrder: ['third', 'first', 'second'],
});
expect(model.current.map((r: any) => r.id)).toEqual(['third', 'first', 'second']);
});
it('matches a session started in a subdirectory to its case (longest prefix)', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
sessions: [
session({ id: 'sub', workingDir: '/home/arkon/default/claudeman/src/web' }),
session({ id: 'outside', workingDir: '/tmp/scratch' }),
],
cases: [...CASES, { name: 'claudeman-web', path: '/home/arkon/default/claudeman/src/web' }],
});
const rows = Object.fromEntries(model.current.map((r: any) => [r.id, r.caseName]));
expect(rows.sub).toBe('claudeman-web');
expect(rows.outside).toBe('');
});
it('lists past conversations newest first and never repeats a live session', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
sessions: [session({ id: 'live-1' })],
cases: CASES,
history: [
// Same id as the running session: the unified list includes live rows,
// and showing one in both sections would be a duplicate.
{ sessionId: 'live-1', workingDir: '/home/arkon/default/claudeman', lastActivityAt: 500 },
{
sessionId: 'old-a',
workingDir: '/home/arkon/codeman-cases/beta',
firstPrompt: 'fix the mobile header',
claudeSessionId: 'claude-uuid-a',
lastActivityAt: 100,
},
{
sessionId: 'old-b',
workingDir: '/home/arkon/default/claudeman',
name: 'w4-claudeman',
lastActivityAt: 400,
},
],
});
expect(model.past.map((r: any) => r.id)).toEqual(['old-b', 'old-a']);
expect(model.past[1]).toMatchObject({
title: 'fix the mobile header',
caseName: 'beta',
claudeSessionId: 'claude-uuid-a',
workingDir: '/home/arkon/codeman-cases/beta',
});
// A row with no prompt falls back to its name, so it is never a bare UUID.
expect(model.past[0].title).toBe('w4-claudeman');
});
it('does not title a past row with the transcript reader placeholder', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({
sessions: [],
cases: CASES,
history: [
{ sessionId: 'blank', workingDir: '/home/arkon/default/claudeman', firstPrompt: '(no content)' },
{ sessionId: 'spaces', workingDir: '/home/arkon/codeman-cases/beta', firstPrompt: ' ' },
],
});
expect(model.past.map((r: any) => r.title)).toEqual(['claudeman', 'beta']);
});
it('accepts the live Map as-is and survives an empty state', () => {
const app = loadOverviewApp();
const fromMap = app.buildMobileOverviewModel({
sessions: new Map([['a', session({ id: 'a' })]]),
cases: CASES,
});
expect(fromMap.current.map((r: any) => r.id)).toEqual(['a']);
const empty = app.buildMobileOverviewModel({});
expect(empty).toMatchObject({ needsYou: [], current: [], past: [], sessionCount: 0 });
});
it('no longer builds a spaces section', () => {
const app = loadOverviewApp();
const model = app.buildMobileOverviewModel({ sessions: [session({ id: 'a' })], cases: CASES });
expect(model.spaces).toBeUndefined();
});
});
describe('mobile overview gate', () => {
it('is phone-width only, off in solo windows, and off when explicitly disabled', () => {
expect(loadOverviewApp().shouldUseMobileOverview()).toBe(true);
expect(loadOverviewApp({ isSoloWindow: true }).shouldUseMobileOverview()).toBe(false);
expect(
loadOverviewApp({
loadAppSettingsFromStorage: () => ({ mobileOverviewEnabled: false }),
}).shouldUseMobileOverview()
).toBe(false);
// An unset value must read as ON: phones that already have saved settings
// from before this feature existed have no key for it.
expect(loadOverviewApp({ loadAppSettingsFromStorage: () => ({ skin: 'og' }) }).shouldUseMobileOverview()).toBe(
true
);
});
});
describe('mobile overview wiring', () => {
const html = readFileSync(resolve(PUBLIC, 'index.html'), 'utf8');
const mobileCss = readFileSync(resolve(PUBLIC, 'mobile.css'), 'utf8');
const moduleSrc = readFileSync(resolve(PUBLIC, 'mobile-overview.js'), 'utf8');
it('speaks the same status language as the session tabs', () => {
// A session that is fine reads green on the tabs; anything else here would
// mean two meanings for one color on the same screen.
expect(mobileCss).toMatch(/\.mobile-overview-dot--idle\s*\{\s*background:\s*var\(--green\)/);
expect(mobileCss).toMatch(/\.mobile-overview-dot--working\s*\{[^}]*var\(--green\)[^}]*animation:\s*pulse/);
// Waiting-for-input blinks yellow, asked-a-question blinks red, same as
// tab-alert-idle / tab-alert-action.
expect(mobileCss).toMatch(/\.mobile-overview-row--waiting\s*\{[^}]*animation:\s*mobile-overview-blink-yellow/);
expect(mobileCss).toMatch(/\.mobile-overview-row--needs\s*\{[^}]*animation:\s*mobile-overview-blink-red/);
expect(mobileCss).toContain('@keyframes mobile-overview-blink-red');
expect(mobileCss).toContain('@keyframes mobile-overview-blink-yellow');
// The alert must survive reduced-motion as a held color, not vanish.
expect(mobileCss).toMatch(/prefers-reduced-motion[^}]*\}[\s\S]*?\.mobile-overview-row--needs/);
});
it('reuses the toolbar Run button classes instead of its own palette', () => {
// The per-backend gradient lives in styles.css keyed on
// `.btn-toolbar.btn-run.mode-<backend>` (and light skins override exactly
// those); carrying the same classes keeps both Run buttons identical.
expect(moduleSrc).toContain('btn-toolbar btn-run mode-');
expect(moduleSrc).toContain('btn-toolbar btn-run-gear mode-');
// The two button rules (not the dropdown below them) must set no color at
// all, or they would win over the mode gradient.
const buttonRules = mobileCss.match(/\.mobile-overview-run(-caret)?\s*\{[^}]*\}/g) || [];
expect(buttonRules.length).toBe(2);
for (const rule of buttonRules) {
expect(rule).not.toMatch(/\b(background|color)\s*:/);
}
});
it('ships the container hidden and loads the module', () => {
expect(html).toMatch(/<div class="mobile-overview" id="mobileOverview" hidden><\/div>/);
expect(html).toContain('<script defer src="mobile-overview.js"></script>');
});
it('never gives .mobile-overview a bare display rule', () => {
// Desktop does not load mobile.css at all, so the [hidden] attribute is the
// only thing keeping the overview off desktop. A bare
// `.mobile-overview { display: … }` rule would beat the UA [hidden] rule.
const bareDisplay = /\.mobile-overview\s*\{[^}]*display\s*:/;
expect(bareDisplay.test(mobileCss)).toBe(false);
expect(mobileCss).toContain('.mobile-overview.visible {');
});
it('styles the overview from skin tokens rather than hardcoded colors', () => {
// Skins re-point the :root tokens, so a hex literal here is a rule that
// silently stays dark on the four light skins.
const rules = mobileCss.match(/\.mobile-overview[^{}]*\{[^}]*\}/g) || [];
expect(rules.length).toBeGreaterThan(10);
const hardcoded = rules.flatMap((rule) => rule.match(/:\s*#[0-9a-f]{3,8}\b/gi) || []);
expect(hardcoded).toEqual([]);
});
});
+215
View File
@@ -0,0 +1,215 @@
/**
* Regression tests for the node-pty spawn-helper repair (issues #6, #204).
*
* node-pty@1.1.0 publishes `prebuilds/darwin-<arch>/spawn-helper` with mode 0644,
* so on macOS every PTY spawn dies with `posix_spawnp failed.`. These tests pin
* the two things the old fix got wrong: it looked ONLY in `build/Release` (which
* does not exist on macOS, where the prebuilt binary is used), and it never
* checked whether the repair actually worked.
*/
import { describe, it, expect, beforeEach, afterEach } from 'vitest';
import { chmodSync, mkdirSync, mkdtempSync, rmSync, statSync, writeFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import {
isSpawnHelperFailure,
listSpawnHelpers,
repairSpawnHelperPermissions,
spawnPtyWithHelperRepair,
resetSpawnHelperRepairState,
SPAWN_HELPER_FIX_HINT,
} from '../src/utils/node-pty-repair.js';
/** Builds a fake node-pty tree; each entry is a directory that gets a spawn-helper. */
function makeFakePtyDir(helpers: Array<{ dir: string; mode: number }>): string {
const root = mkdtempSync(join(tmpdir(), 'codeman-node-pty-'));
for (const { dir, mode } of helpers) {
const full = join(root, dir);
mkdirSync(full, { recursive: true });
const helper = join(full, 'spawn-helper');
writeFileSync(helper, '#!/bin/sh\nexit 0\n');
chmodSync(helper, mode);
}
return root;
}
function modeOf(path: string): number {
return statSync(path).mode & 0o777;
}
describe('node-pty spawn-helper repair', () => {
const created: string[] = [];
beforeEach(() => resetSpawnHelperRepairState());
afterEach(() => {
for (const dir of created.splice(0)) rmSync(dir, { recursive: true, force: true });
});
function fixture(helpers: Array<{ dir: string; mode: number }>): string {
const root = makeFakePtyDir(helpers);
created.push(root);
return root;
}
describe('isSpawnHelperFailure', () => {
it('matches the native error node-pty throws on macOS', () => {
expect(isSpawnHelperFailure(new Error('posix_spawnp failed.'))).toBe(true);
});
it('matches errors that name the helper directly', () => {
expect(isSpawnHelperFailure(new Error('ENOENT: no such file, spawn-helper'))).toBe(true);
});
it('ignores unrelated spawn failures', () => {
expect(isSpawnHelperFailure(new Error('cwd does not exist'))).toBe(false);
expect(isSpawnHelperFailure(undefined)).toBe(false);
});
});
describe('listSpawnHelpers', () => {
it('finds the prebuilt helper, which is the ONLY one that exists on macOS', () => {
// A stock macOS install has no build/ directory at all: node-pty ships a
// darwin prebuild, so node-gyp never runs.
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
expect(listSpawnHelpers(root)).toEqual([join(root, 'prebuilds', 'darwin-arm64', 'spawn-helper')]);
});
it('finds helpers across build/Release, build/Debug and every prebuilds arch', () => {
const root = fixture([
{ dir: 'build/Release', mode: 0o755 },
{ dir: 'build/Debug', mode: 0o644 },
{ dir: 'prebuilds/darwin-arm64', mode: 0o644 },
{ dir: 'prebuilds/darwin-x64', mode: 0o644 },
]);
expect(listSpawnHelpers(root).sort()).toEqual(
[
join(root, 'build', 'Release', 'spawn-helper'),
join(root, 'build', 'Debug', 'spawn-helper'),
join(root, 'prebuilds', 'darwin-arm64', 'spawn-helper'),
join(root, 'prebuilds', 'darwin-x64', 'spawn-helper'),
].sort()
);
});
it('returns nothing for a Linux install, which has no spawn-helper at all', () => {
const root = fixture([]);
mkdirSync(join(root, 'build', 'Release'), { recursive: true });
writeFileSync(join(root, 'build', 'Release', 'pty.node'), 'stub');
expect(listSpawnHelpers(root)).toEqual([]);
});
});
describe('repairSpawnHelperPermissions', () => {
it('adds the execute bit to the 0644 prebuilt helper', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
const helper = join(root, 'prebuilds', 'darwin-arm64', 'spawn-helper');
const repaired = repairSpawnHelperPermissions(root);
expect(repaired).toEqual([helper]);
expect(modeOf(helper) & 0o111).toBe(0o111);
});
it('is a no-op on an already-executable helper', () => {
const root = fixture([{ dir: 'build/Release', mode: 0o755 }]);
expect(repairSpawnHelperPermissions(root)).toEqual([]);
expect(modeOf(join(root, 'build', 'Release', 'spawn-helper'))).toBe(0o755);
});
it('repairs every copy, not just the first one found', () => {
const root = fixture([
{ dir: 'prebuilds/darwin-arm64', mode: 0o644 },
{ dir: 'prebuilds/darwin-x64', mode: 0o644 },
]);
expect(repairSpawnHelperPermissions(root)).toHaveLength(2);
for (const arch of ['darwin-arm64', 'darwin-x64']) {
expect(modeOf(join(root, 'prebuilds', arch, 'spawn-helper')) & 0o111).toBe(0o111);
}
});
it('preserves the non-execute permission bits it was given', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o640 }]);
const helper = join(root, 'prebuilds', 'darwin-arm64', 'spawn-helper');
repairSpawnHelperPermissions(root);
expect(modeOf(helper)).toBe(0o755 | 0o640);
});
it('returns nothing when node-pty has no helper to repair', () => {
expect(repairSpawnHelperPermissions(fixture([]))).toEqual([]);
});
});
describe('spawnPtyWithHelperRepair', () => {
it('passes the spawn result straight through when nothing is wrong', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o755 }]);
expect(spawnPtyWithHelperRepair(() => 'pty', root)).toBe('pty');
});
it('repairs and retries once after a posix_spawnp failure', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
const helper = join(root, 'prebuilds', 'darwin-arm64', 'spawn-helper');
let attempts = 0;
const result = spawnPtyWithHelperRepair(() => {
attempts++;
// Mirror the real failure: node-pty only throws while the helper is 0644.
if ((modeOf(helper) & 0o111) !== 0o111) throw new Error('posix_spawnp failed.');
return 'pty';
}, root);
expect(result).toBe('pty');
expect(attempts).toBe(2);
expect(modeOf(helper) & 0o111).toBe(0o111);
});
it('rethrows unrelated errors untouched, without chmodding anything', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
const helper = join(root, 'prebuilds', 'darwin-arm64', 'spawn-helper');
expect(() =>
spawnPtyWithHelperRepair(() => {
throw new Error('cwd does not exist');
}, root)
).toThrow('cwd does not exist');
expect(modeOf(helper)).toBe(0o644);
});
it('surfaces the manual fix command when the retry still fails', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
expect(() =>
spawnPtyWithHelperRepair(() => {
throw new Error('posix_spawnp failed.');
}, root)
).toThrow(SPAWN_HELPER_FIX_HINT);
});
it('surfaces the fix command when there is no helper to repair', () => {
const root = fixture([]);
expect(() =>
spawnPtyWithHelperRepair(() => {
throw new Error('posix_spawnp failed.');
}, root)
).toThrow(SPAWN_HELPER_FIX_HINT);
});
it('does not chmod-storm: only the first failure triggers a repair attempt', () => {
const root = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
const boom = () => {
throw new Error('posix_spawnp failed.');
};
expect(() => spawnPtyWithHelperRepair(boom, root)).toThrow(SPAWN_HELPER_FIX_HINT);
// Second call: repair already attempted, so it fails fast with the hint and
// never re-walks the tree.
const untouched = fixture([{ dir: 'prebuilds/darwin-arm64', mode: 0o644 }]);
expect(() => spawnPtyWithHelperRepair(boom, untouched)).toThrow(SPAWN_HELPER_FIX_HINT);
expect(modeOf(join(untouched, 'prebuilds', 'darwin-arm64', 'spawn-helper'))).toBe(0o644);
});
});
});
+150
View File
@@ -0,0 +1,150 @@
import { readFileSync } from 'node:fs';
import { JSDOM } from 'jsdom';
import { afterEach, describe, expect, it } from 'vitest';
const SOURCE = readFileSync(new URL('../src/web/public/notification-manager.js', import.meta.url), 'utf8');
type EventPreference = {
enabled: boolean;
browser: boolean;
audio: boolean;
push: boolean;
};
type NotificationPreferences = {
enabled: boolean;
eventTypes: Record<string, EventPreference>;
_version: number;
};
type Manager = {
preferences: NotificationPreferences;
notifications: unknown[];
getStorageKey: () => string;
normalizePreferences: (preferences: Record<string, unknown>) => NotificationPreferences;
notify: (notification: Record<string, unknown>) => void;
};
const openWindows: JSDOM[] = [];
function loadManager(
saved?: Record<string, unknown>,
device: { deviceType?: string; handheld?: boolean } = {}
): { dom: JSDOM; manager: Manager } {
const dom = new JSDOM(
'<!doctype html><body><span id="notifBadge"></span><div id="notifList"></div><div id="notifEmpty"></div></body>',
{
url: 'http://localhost/',
runScripts: 'outside-only',
}
);
openWindows.push(dom);
const win = dom.window as unknown as Window &
typeof globalThis & {
MobileDetection: {
getDeviceType: () => string;
isHandheldDevice?: () => boolean;
};
STUCK_THRESHOLD_DEFAULT_MS: number;
GROUPING_TIMEOUT_MS: number;
NOTIFICATION_LIST_CAP: number;
};
win.MobileDetection = {
getDeviceType: () => device.deviceType ?? 'desktop',
...(typeof device.handheld === 'boolean' ? { isHandheldDevice: () => device.handheld === true } : {}),
};
win.STUCK_THRESHOLD_DEFAULT_MS = 600_000;
win.GROUPING_TIMEOUT_MS = 5_000;
win.NOTIFICATION_LIST_CAP = 100;
win.requestAnimationFrame = ((callback: FrameRequestCallback) => {
callback(0);
return 1;
}) as typeof requestAnimationFrame;
if (saved) {
win.localStorage.setItem('codeman-notification-prefs', JSON.stringify(saved));
}
win.eval(`
${SOURCE}
window.__testNotificationManager = NotificationManager;
`);
const NotificationManager = (
win as unknown as {
__testNotificationManager: new (app: { sessions: Map<unknown, unknown> }) => Manager;
}
).__testNotificationManager;
const manager = new NotificationManager({ sessions: new Map() }) as Manager;
return { dom, manager };
}
afterEach(() => {
for (const dom of openWindows.splice(0)) dom.window.close();
});
describe('notification noise defaults', () => {
it('keeps response-complete and team lifecycle drawer entries opt-in', () => {
const { manager } = loadManager();
expect(manager.preferences.eventTypes.stop.enabled).toBe(false);
for (const category of ['hook-stop', 'hook-teammate-idle', 'hook-task-completed']) {
manager.notify({
urgency: 'info',
category,
sessionId: 'session-1',
sessionName: 'session',
title: category,
message: category,
});
}
expect(manager.notifications).toHaveLength(0);
});
it('migrates the old drawer-only Stop default but preserves explicit delivery', () => {
const quietV4 = {
enabled: true,
eventTypes: {
stop: { enabled: true, browser: false, audio: false, push: false },
},
_version: 4,
};
const { manager: quietManager } = loadManager(quietV4);
expect(quietManager.preferences.eventTypes.stop.enabled).toBe(false);
expect(quietManager.preferences._version).toBe(5);
const browserV4 = {
enabled: true,
eventTypes: {
stop: { enabled: true, browser: true, audio: false, push: false },
},
_version: 4,
};
const { manager: browserManager } = loadManager(browserV4);
expect(browserManager.preferences.eventTypes.stop.enabled).toBe(true);
});
it('normalizes server-hydrated v4 preferences through the same quiet migration', () => {
const { manager } = loadManager();
manager.preferences = manager.normalizePreferences({
enabled: true,
eventTypes: {
stop: { enabled: true, browser: false, audio: false, push: false },
},
_version: 4,
});
expect(manager.preferences.eventTypes.stop.enabled).toBe(false);
expect(manager.preferences._version).toBe(5);
});
it('keeps mobile notification defaults and storage on an unfolded handheld', () => {
const { manager } = loadManager(undefined, {
deviceType: 'desktop',
handheld: true,
});
expect(manager.preferences.enabled).toBe(false);
expect(manager.getStorageKey()).toBe('codeman-notification-prefs-mobile');
});
});
+24 -7
View File
@@ -1,11 +1,28 @@
import { describe, it, expect, beforeAll, afterAll, beforeEach, afterEach } from 'vitest';
import { WebServer } from '../src/web/server.js';
import { existsSync, rmSync, mkdirSync } from 'node:fs';
import type { WebServer } from '../src/web/server.js';
import { existsSync, rmSync, mkdirSync, mkdtempSync } from 'node:fs';
import { join } from 'node:path';
import { homedir } from 'node:os';
import { tmpdir } from 'node:os';
const TEST_PORT = 3099;
const CASES_DIR = join(homedir(), 'codeman-cases');
const ORIGINAL_HOME = process.env.HOME;
const TEST_HOME = mkdtempSync(join(tmpdir(), 'codeman-quick-start-'));
const CASES_DIR = join(TEST_HOME, 'codeman-cases');
let webServerModule: Promise<typeof import('../src/web/server.js')> | undefined;
process.env.HOME = TEST_HOME;
async function createTestServer(port: number): Promise<WebServer> {
webServerModule ??= import('../src/web/server.js');
const { WebServer: TestWebServer } = await webServerModule;
return new TestWebServer(port, false, true);
}
afterAll(() => {
if (ORIGINAL_HOME === undefined) delete process.env.HOME;
else process.env.HOME = ORIGINAL_HOME;
rmSync(TEST_HOME, { recursive: true, force: true });
});
describe('Quick Start API', () => {
let server: WebServer;
@@ -13,7 +30,7 @@ describe('Quick Start API', () => {
const createdCases: string[] = [];
beforeAll(async () => {
server = new WebServer(TEST_PORT, false, true);
server = await createTestServer(TEST_PORT);
await server.start();
baseUrl = `http://localhost:${TEST_PORT}`;
});
@@ -147,7 +164,7 @@ describe('Session Management', () => {
let baseUrl: string;
beforeAll(async () => {
server = new WebServer(TEST_PORT + 1, false, true);
server = await createTestServer(TEST_PORT + 1);
await server.start();
baseUrl = `http://localhost:${TEST_PORT + 1}`;
});
@@ -206,7 +223,7 @@ describe('Case Management', () => {
const createdCases: string[] = [];
beforeAll(async () => {
server = new WebServer(TEST_PORT + 2, false, true);
server = await createTestServer(TEST_PORT + 2);
await server.start();
baseUrl = `http://localhost:${TEST_PORT + 2}`;
});
@@ -0,0 +1,146 @@
/**
* @fileoverview PUT /api/settings must not reset service state on a PARTIAL body.
*
* The three service toggles (subagent watcher, workflow-run watcher, image
* watcher) used to read the RAW REQUEST BODY with `??` defaults, so any key the
* caller omitted was treated as "apply the default". A body of just
* `{statusLineTelemetry:true}` therefore STARTED the subagent watcher (`?? true`)
* and STOPPED the workflow + image watchers (`?? false`), silently undoing the
* persisted config. Nothing triggered it in practice only because every shipped
* client sends a full settings payload rebuilt from the DOM.
*
* They now resolve from `merged` (existing settings.json + incoming), so a PUT
* reconciles services to the effective stored state. These tests pin that:
* omitted keys preserve state, explicit keys still take effect.
*
* Uses app.inject() — no real HTTP ports needed. Port: N/A.
*/
import { describe, it, expect, beforeEach, afterEach, vi } from 'vitest';
import { createRouteTestHarness, type RouteTestHarness } from './_route-test-utils.js';
import { registerSystemRoutes } from '../../src/web/routes/system-routes.js';
// vi.mock factories are hoisted above module-level consts, so the stubs and the
// persisted-settings fixture have to be built inside vi.hoisted().
const { EXISTING_SETTINGS, subagentWatcher, imageWatcher, workflowRunWatcher } = vi.hoisted(() => {
/** Watcher stub whose isRunning() reflects its persisted state. */
const makeWatcher = (running: boolean) => {
let isOn = running;
return {
isRunning: vi.fn(() => isOn),
start: vi.fn(() => {
isOn = true;
}),
stop: vi.fn(() => {
isOn = false;
}),
getStats: vi.fn(() => ({})),
watchSession: vi.fn(),
getRecentRunSummaries: vi.fn(() => []),
// The stubs are module singletons (vi.mock needs them hoisted), so a
// start()/stop() in one test would otherwise carry into the next and make
// its "not called" assertion pass vacuously — isRunning() already matches
// the expected end state, so toggleService short-circuits.
__resetRunning: () => {
isOn = running;
},
};
};
return {
// Persisted settings.json for these tests: two watchers ON, subagent tracking OFF.
EXISTING_SETTINGS: { subagentTrackingEnabled: false, imageWatcherEnabled: true, showUltracodeAgents: true },
subagentWatcher: makeWatcher(false),
imageWatcher: makeWatcher(true),
workflowRunWatcher: makeWatcher(true),
};
});
vi.mock('node:fs/promises', () => ({
default: {
readFile: vi.fn(async () => JSON.stringify(EXISTING_SETTINGS)),
writeFile: vi.fn(async () => undefined),
},
}));
vi.mock('node:fs', async (importOriginal) => {
const actual = await importOriginal<typeof import('node:fs')>();
return { ...actual, existsSync: vi.fn(() => true), mkdirSync: vi.fn(), readdirSync: vi.fn(() => []) };
});
vi.mock('../../src/subagent-watcher.js', () => ({ subagentWatcher }));
vi.mock('../../src/image-watcher.js', () => ({ imageWatcher }));
vi.mock('../../src/workflow-run-watcher.js', () => ({ workflowRunWatcher }));
describe('PUT /api/settings — partial body must not reset service toggles', () => {
let harness: RouteTestHarness;
beforeEach(async () => {
harness = await createRouteTestHarness(registerSystemRoutes);
for (const w of [subagentWatcher, imageWatcher, workflowRunWatcher]) {
w.start.mockClear();
w.stop.mockClear();
w.__resetRunning(); // running state, not just call records — see makeWatcher
}
});
afterEach(async () => {
await harness.app.close();
});
it('leaves all three watchers alone when the body omits their keys', async () => {
const res = await harness.app.inject({
method: 'PUT',
url: '/api/settings',
// Action-only body: the exact shape that used to flip all three watchers.
payload: { statusLineTelemetry: true },
});
expect(res.statusCode).toBe(200);
// Persisted OFF and omitted — must NOT be started by the `?? true` default.
expect(subagentWatcher.start).not.toHaveBeenCalled();
// Persisted ON and omitted — must NOT be stopped by the `?? false` defaults.
expect(imageWatcher.stop).not.toHaveBeenCalled();
expect(workflowRunWatcher.stop).not.toHaveBeenCalled();
});
it('still starts a watcher when the body explicitly enables it', async () => {
const res = await harness.app.inject({
method: 'PUT',
url: '/api/settings',
payload: { subagentTrackingEnabled: true },
});
expect(res.statusCode).toBe(200);
expect(subagentWatcher.start).toHaveBeenCalledTimes(1);
// Unrelated watchers stay untouched.
expect(imageWatcher.stop).not.toHaveBeenCalled();
expect(workflowRunWatcher.stop).not.toHaveBeenCalled();
});
it('still stops a watcher when the body explicitly disables it', async () => {
const res = await harness.app.inject({
method: 'PUT',
url: '/api/settings',
payload: { imageWatcherEnabled: false },
});
expect(res.statusCode).toBe(200);
expect(imageWatcher.stop).toHaveBeenCalledTimes(1);
expect(subagentWatcher.start).not.toHaveBeenCalled();
expect(workflowRunWatcher.stop).not.toHaveBeenCalled();
});
it('keeps the workflow watcher running when only one of its two keys is sent', async () => {
// Either showUltracodeAgents OR ultracodeFloatingWindows keeps it alive, and
// the OR must be evaluated over merged state, not over this partial body.
const res = await harness.app.inject({
method: 'PUT',
url: '/api/settings',
payload: { ultracodeFloatingWindows: false },
});
expect(res.statusCode).toBe(200);
// showUltracodeAgents is still true in settings.json, so it stays up.
expect(workflowRunWatcher.stop).not.toHaveBeenCalled();
});
});
+34
View File
@@ -81,12 +81,18 @@ vi.mock('../../src/utils/gemini-cli-resolver.js', () => ({
resolveGeminiDir: vi.fn(() => null),
}));
vi.mock('../../src/utils/antigravity-cli-resolver.js', () => ({
isAntigravityAvailable: vi.fn(() => false),
resolveAntigravityDir: vi.fn(() => null),
}));
import fs from 'node:fs/promises';
import { existsSync, readdirSync } from 'node:fs';
import { subagentWatcher } from '../../src/subagent-watcher.js';
import { getLifecycleLog } from '../../src/session-lifecycle-log.js';
import { isOpenCodeAvailable, resolveOpenCodeDir } from '../../src/utils/opencode-cli-resolver.js';
import { isGeminiAvailable, resolveGeminiDir } from '../../src/utils/gemini-cli-resolver.js';
import { isAntigravityAvailable, resolveAntigravityDir } from '../../src/utils/antigravity-cli-resolver.js';
const mockedReadFile = vi.mocked(fs.readFile);
const mockedWriteFile = vi.mocked(fs.writeFile);
@@ -98,6 +104,8 @@ const mockedIsOpenCodeAvailable = vi.mocked(isOpenCodeAvailable);
const mockedResolveOpenCodeDir = vi.mocked(resolveOpenCodeDir);
const mockedIsGeminiAvailable = vi.mocked(isGeminiAvailable);
const mockedResolveGeminiDir = vi.mocked(resolveGeminiDir);
const mockedIsAntigravityAvailable = vi.mocked(isAntigravityAvailable);
const mockedResolveAntigravityDir = vi.mocked(resolveAntigravityDir);
describe('system-routes', () => {
let harness: RouteTestHarness;
@@ -805,6 +813,32 @@ describe('system-routes', () => {
});
});
// ========== GET /api/antigravity/status ==========
describe('GET /api/antigravity/status', () => {
it('returns unavailable when agy is not installed', async () => {
mockedIsAntigravityAvailable.mockReturnValue(false);
mockedResolveAntigravityDir.mockReturnValue(null);
const res = await harness.app.inject({ method: 'GET', url: '/api/antigravity/status' });
expect(res.statusCode).toBe(200);
const body = JSON.parse(res.body);
expect(body.available).toBe(false);
expect(body.path).toBeNull();
});
it('returns available with path when agy is installed', async () => {
mockedIsAntigravityAvailable.mockReturnValue(true);
mockedResolveAntigravityDir.mockReturnValue('/home/user/.local/bin');
const res = await harness.app.inject({ method: 'GET', url: '/api/antigravity/status' });
expect(res.statusCode).toBe(200);
const body = JSON.parse(res.body);
expect(body.available).toBe(true);
expect(body.path).toBe('/home/user/.local/bin');
});
});
// ========== GET /api/execution/model-config ==========
describe('GET /api/execution/model-config', () => {
+63
View File
@@ -71,6 +71,16 @@ describe('run mode UI', () => {
expect(app.runMode).toBe('gemini');
expect(runBtnLabel.textContent).toBe('Run GM');
});
it('accepts Antigravity mode from server sync and updates the run button label', async () => {
const { app, storage, runBtnLabel } = loadRunModeHarness();
storage.set('codeman_runMode', 'claude');
await app.loadAppSettingsFromServer(Promise.resolve({ runMode: 'antigravity' }));
expect(app.runMode).toBe('antigravity');
expect(runBtnLabel.textContent).toBe('Run AG');
});
});
describe('Run launch synchronization', () => {
@@ -587,3 +597,56 @@ describe('Gemini quick start', () => {
expect(selected).toEqual(['sess-gm']);
});
});
describe('Antigravity quick start', () => {
// Same envelope-unwrap regression guard as the Gemini block above, for runAntigravity().
it('drives runAntigravity() through the {success,data} envelope and selects the new session', async () => {
const elements: Record<string, any> = {
quickStartCase: { value: 'ag-case' },
};
const requests: Array<{ url: string; body?: any }> = [];
const CodemanApp = function CodemanApp(this: any) {};
const context = vm.createContext({
CodemanApp,
localStorage: { getItem: () => null, setItem: () => {} },
document: { getElementById: (id: string) => elements[id] ?? null },
fetch: async (url: string, init?: { body?: string }) => {
requests.push({ url, body: init?.body ? JSON.parse(init.body) : undefined });
if (url === '/api/antigravity/status')
return { json: async () => ({ success: true, data: { available: true } }) };
if (url === '/api/quick-start')
return { json: async () => ({ success: true, data: { sessionId: 'sess-ag' } }) };
if (url === '/api/sessions/sess-ag')
return { json: async () => ({ success: true, data: { id: 'sess-ag', name: 'w1-ag-case' } }) };
throw new Error(`unexpected fetch: ${url}`);
},
console,
});
const sessionUi = readFileSync(resolve(import.meta.dirname, '../src/web/public/session-ui.js'), 'utf8');
vm.runInContext(sessionUi, context, { filename: 'session-ui.js' });
const app = new (CodemanApp as any)();
app.terminal = { clear: () => {}, writeln: () => {}, focus: () => {} };
app.loadAppSettingsFromStorage = () => ({});
app.getCaseSettings = () => ({});
app.buildEnvOverrides = () => ({});
app.sessions = new Map();
app._onSessionCreated = (session: any) => app.sessions.set(session.id, session);
app._renderSessionTabsImmediate = vi.fn();
const selected: string[] = [];
app.selectSession = async (id: string) => {
selected.push(id);
};
await app.runAntigravity();
expect(requests.find((req) => req.url === '/api/quick-start')?.body).toMatchObject({
caseName: 'ag-case',
mode: 'antigravity',
antigravityConfig: { dangerouslySkipPermissions: true },
});
expect(selected).toEqual(['sess-ag']);
});
});
+55 -5
View File
@@ -1,16 +1,36 @@
/**
* @fileoverview Global test setup for Codeman tests
*
* SAFETY: TmuxManager has built-in test mode detection
* (via process.env.VITEST) that makes ALL shell commands no-ops.
* This means tests CANNOT kill, create, or interact with real tmux
* sessions regardless of what the test code does.
* SAFETY: The suite gets a temporary HOME and explicitly enables runtime test
* mode before application modules load. Tests therefore cannot touch the real
* Codeman state/cases tree or launch external tmux-backed agent sessions.
*
* This setup file strips shell-level auth configuration that can leak from a
* running Codeman instance, then handles mock/timer cleanup between tests.
*/
import { afterEach, vi } from 'vitest';
import { mkdtempSync, rmSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { afterAll, afterEach, vi } from 'vitest';
const originalHome = process.env.HOME;
const originalUserProfile = process.env.USERPROFILE;
const originalVitest = process.env.VITEST;
const originalPlaywrightBrowsersPath = process.env.PLAYWRIGHT_BROWSERS_PATH;
const testHome = mkdtempSync(join(tmpdir(), 'codeman-vitest-'));
if (originalPlaywrightBrowsersPath === undefined && originalHome) {
process.env.PLAYWRIGHT_BROWSERS_PATH =
process.platform === 'darwin'
? join(originalHome, 'Library', 'Caches', 'ms-playwright')
: process.platform === 'win32'
? join(process.env.LOCALAPPDATA || join(originalHome, 'AppData', 'Local'), 'ms-playwright')
: join(originalHome, '.cache', 'ms-playwright');
}
process.env.HOME = testHome;
process.env.USERPROFILE = testHome;
process.env.VITEST = 'true';
delete process.env.CODEMAN_PASSWORD;
delete process.env.CODEMAN_USERNAME;
@@ -23,3 +43,33 @@ afterEach(() => {
vi.clearAllMocks();
vi.useRealTimers();
});
afterAll(async () => {
// Let in-flight console-log rpc forwards drain before the worker environment
// tears down. On loaded CI runners the channel otherwise closes while the last
// "onUserConsoleLog" call is still pending, and that single unhandled
// EnvironmentTeardownError fails the run after every test has passed
// (observed twice on the PR #175/#176 merge commit; never locally).
await new Promise((resolve) => setTimeout(resolve, 50));
if (originalHome === undefined) delete process.env.HOME;
else process.env.HOME = originalHome;
if (originalUserProfile === undefined) delete process.env.USERPROFILE;
else process.env.USERPROFILE = originalUserProfile;
if (originalVitest === undefined) delete process.env.VITEST;
else process.env.VITEST = originalVitest;
if (originalPlaywrightBrowsersPath === undefined) delete process.env.PLAYWRIGHT_BROWSERS_PATH;
else process.env.PLAYWRIGHT_BROWSERS_PATH = originalPlaywrightBrowsersPath;
rmSync(testHome, { recursive: true, force: true });
});
// afterAll never fires for a fully-skipped test file (no tests execute), which
// would leak the temp home created above. The exit hook is the backstop; rmSync
// with force is a no-op when afterAll already removed it.
process.on('exit', () => {
rmSync(testHome, { recursive: true, force: true });
});
+102
View File
@@ -0,0 +1,102 @@
/**
* Regression tests for issue #208 — "Plain shell PTY exits with code 1 after
* successful tmux creation in Docker".
*
* The shell-mode pane command used to be the literal string `$SHELL`. It ends up
* inside the `bash -c "…"` argument of the respawn-pane line, which execSync runs
* through `/bin/sh -c`, so it was expanded by the SERVER process's shell against
* the SERVER process's env. Containers (and system-level systemd units) do not set
* SHELL, so it expanded to nothing and the pane command ended in a dangling `&&`:
*
* bash: -c: line 1: syntax error: unexpected end of file
*
* These tests pin the resolver's guarantees and assert that a shell launch command
* survives the outer `sh -c` layer with an unset SHELL.
*/
import { describe, it, expect, beforeEach, afterEach } from 'vitest';
import { execFileSync } from 'node:child_process';
import { buildSpawnCommand } from '../src/tmux-manager.js';
import { resolveLocalShell } from '../src/utils/shell-resolver.js';
describe('resolveLocalShell', () => {
const originalShell = process.env.SHELL;
afterEach(() => {
if (originalShell === undefined) delete process.env.SHELL;
else process.env.SHELL = originalShell;
});
it('returns an absolute executable path when SHELL is unset (container case)', () => {
delete process.env.SHELL;
const shell = resolveLocalShell();
expect(shell).not.toBe('');
expect(shell.startsWith('/')).toBe(true);
// Proves the resolved path is really launchable, not just a plausible string.
expect(execFileSync(shell, ['-c', 'echo ok'], { encoding: 'utf8' }).trim()).toBe('ok');
});
it('returns an absolute executable path when SHELL is empty or whitespace', () => {
for (const value of ['', ' ']) {
process.env.SHELL = value;
const shell = resolveLocalShell();
expect(shell.startsWith('/')).toBe(true);
expect(execFileSync(shell, ['-c', 'echo ok'], { encoding: 'utf8' }).trim()).toBe('ok');
}
});
it('honors a valid $SHELL', () => {
process.env.SHELL = '/bin/sh';
expect(resolveLocalShell()).toBe('/bin/sh');
});
it('ignores a $SHELL that does not exist', () => {
process.env.SHELL = '/nonexistent/shell-that-is-not-here';
const shell = resolveLocalShell();
expect(shell).not.toBe('/nonexistent/shell-that-is-not-here');
expect(shell.startsWith('/')).toBe(true);
});
it('ignores a relative $SHELL (never emits a bare word into the launch command)', () => {
process.env.SHELL = 'bash';
expect(resolveLocalShell().startsWith('/')).toBe(true);
});
it('ignores nologin-style stubs that would exit instantly', () => {
process.env.SHELL = '/usr/sbin/nologin';
expect(resolveLocalShell()).not.toContain('nologin');
process.env.SHELL = '/bin/false';
expect(resolveLocalShell()).not.toBe('/bin/false');
});
});
describe('shell-mode spawn command (issue #208)', () => {
const originalShell = process.env.SHELL;
beforeEach(() => {
delete process.env.SHELL;
});
afterEach(() => {
if (originalShell === undefined) delete process.env.SHELL;
else process.env.SHELL = originalShell;
});
it('never emits an unexpanded $SHELL into the pane command', () => {
const cmd = buildSpawnCommand({ mode: 'shell', sessionId: 'abc123de-0000-0000-0000-000000000000' });
expect(cmd).not.toContain('$SHELL');
expect(cmd.trim()).not.toBe('');
});
it('produces a launch command that parses after the outer sh -c expansion layer', () => {
const cmd = buildSpawnCommand({ mode: 'shell', sessionId: 'abc123de-0000-0000-0000-000000000000' });
// Mirrors tmux-manager: `… bash -c ${JSON.stringify(launchCmd)}` handed to `sh -c`.
const launchCmd = `cd ${JSON.stringify('/tmp')} && export CODEMAN_MUX=1 && ${cmd}`;
const outer = `bash -n -c ${JSON.stringify(launchCmd)}`;
// `bash -n` parses without executing: exits 0 on the fix, 2 with the dangling `&&`.
const result = execFileSync('/bin/sh', ['-c', `${outer}; echo "rc=$?"`], { encoding: 'utf8' });
expect(result).toContain('rc=0');
expect(result).not.toContain('unexpected end of file');
});
});
+68 -31
View File
@@ -88,14 +88,16 @@ describe('TranscriptWatcher', () => {
watcher.start(testFile);
// Add user entry
const userEntry = { type: 'user', timestamp: new Date().toISOString(), message: { role: 'user', content: 'test' } };
const userEntry = {
type: 'user',
timestamp: new Date().toISOString(),
message: { role: 'user', content: 'test' },
};
appendFileSync(testFile, JSON.stringify(userEntry) + '\n');
// Wait for processing
await new Promise(resolve => setTimeout(resolve, 100));
const state = watcher.getState();
expect(state.entryCount).toBeGreaterThanOrEqual(1);
await vi.waitFor(() => {
expect(watcher.getState().entryCount).toBeGreaterThanOrEqual(1);
});
});
it('should emit transcript:complete on result entry', async () => {
@@ -109,10 +111,9 @@ describe('TranscriptWatcher', () => {
const resultEntry = { type: 'result', timestamp: new Date().toISOString() };
appendFileSync(testFile, JSON.stringify(resultEntry) + '\n');
// Wait for processing
await new Promise(resolve => setTimeout(resolve, 200));
expect(completeHandler).toHaveBeenCalled();
await vi.waitFor(() => {
expect(completeHandler).toHaveBeenCalled();
});
const state = watcher.getState();
expect(state.isComplete).toBe(true);
});
@@ -130,22 +131,62 @@ describe('TranscriptWatcher', () => {
timestamp: new Date().toISOString(),
message: {
role: 'assistant',
content: [
{ type: 'tool_use', name: 'Read', input: { file_path: '/test.txt' } }
]
}
content: [{ type: 'tool_use', name: 'Read', input: { file_path: '/test.txt' } }],
},
};
appendFileSync(testFile, JSON.stringify(assistantEntry) + '\n');
// Wait for processing
await new Promise(resolve => setTimeout(resolve, 200));
expect(toolStartHandler).toHaveBeenCalledWith('Read');
await vi.waitFor(() => {
expect(toolStartHandler).toHaveBeenCalledWith('Read');
});
const state = watcher.getState();
expect(state.toolExecuting).toBe(true);
expect(state.currentTool).toBe('Read');
});
it('should complete a tool when Claude writes tool_result in a user entry', async () => {
writeFileSync(testFile, '');
watcher.start(testFile);
const toolEndHandler = vi.fn();
watcher.on('transcript:tool_end', toolEndHandler);
appendFileSync(
testFile,
JSON.stringify({
type: 'assistant',
timestamp: new Date().toISOString(),
message: {
role: 'assistant',
content: [{ type: 'tool_use', name: 'Bash', input: { command: 'printf done' } }],
},
}) + '\n'
);
await vi.waitFor(() => {
expect(watcher.getState().toolExecuting).toBe(true);
});
appendFileSync(
testFile,
JSON.stringify({
type: 'user',
timestamp: new Date().toISOString(),
message: {
role: 'user',
content: [{ type: 'tool_result', tool_use_id: 'toolu_1', content: 'done', is_error: false }],
},
}) + '\n'
);
await vi.waitFor(() => {
expect(toolEndHandler).toHaveBeenCalledWith('Bash', false);
});
expect(watcher.getState()).toMatchObject({
toolExecuting: false,
currentTool: null,
});
});
it('should detect plan mode from AskUserQuestion tool', async () => {
writeFileSync(testFile, '');
watcher.start(testFile);
@@ -159,17 +200,14 @@ describe('TranscriptWatcher', () => {
timestamp: new Date().toISOString(),
message: {
role: 'assistant',
content: [
{ type: 'tool_use', name: 'AskUserQuestion', input: { question: 'test?' } }
]
}
content: [{ type: 'tool_use', name: 'AskUserQuestion', input: { question: 'test?' } }],
},
};
appendFileSync(testFile, JSON.stringify(assistantEntry) + '\n');
// Wait for processing
await new Promise(resolve => setTimeout(resolve, 200));
expect(planModeHandler).toHaveBeenCalled();
await vi.waitFor(() => {
expect(planModeHandler).toHaveBeenCalled();
});
const state = watcher.getState();
expect(state.planModeDetected).toBe(true);
});
@@ -182,15 +220,14 @@ describe('TranscriptWatcher', () => {
const resultEntry = {
type: 'result',
timestamp: new Date().toISOString(),
error: { type: 'api_error', message: 'Rate limited' }
error: { type: 'api_error', message: 'Rate limited' },
};
appendFileSync(testFile, JSON.stringify(resultEntry) + '\n');
// Wait for processing
await new Promise(resolve => setTimeout(resolve, 200));
await vi.waitFor(() => {
expect(watcher.getState().hasError).toBe(true);
});
const state = watcher.getState();
expect(state.hasError).toBe(true);
expect(state.errorMessage).toContain('Rate limited');
});
});
+61 -3
View File
@@ -42,9 +42,16 @@ beforeEach(async () => {
// Stand-ins for the real surfaces, so a reachable route means auth let it through.
app.all('/webview/:cap/*', async () => ({ proxied: true }));
app.all('/api/sessions', async () => ({ sensitive: true }));
// Parametric on purpose: the exemption's fence has to resolve a CONCRETE url
// against it, which is precisely what `hasRoute()` cannot do.
app.all('/api/sessions/:id', async () => ({ sensitive: true }));
app.all('/q/:token', async () => ({ qr: true }));
app.get('/', async () => 'app shell');
app.get('/static/app.js', async () => 'asset');
app.get('/webviewfoo/bar', async () => 'lookalike');
// Stand-in for @fastify/static mounted at '/', which is what actually serves
// /static/app.js in production. It matches EVERY path, so the fence must treat a
// root catch-all as "no real route" or the Referer form could never apply at all.
app.get('/*', async () => 'static asset');
await app.ready();
});
@@ -109,6 +116,21 @@ describe('the exemption applies to a live capability', () => {
});
expect(res.statusCode).toBe(200);
});
it("covers the dashboard's OWN /api namespace, which no Codeman route claims", async () => {
// A dashboard serving `<img src="/api/hero?slug=x">` from page script is the
// case this exists for: the URL is root-absolute, so it lands on Codeman, and
// nothing here matches a real route. Refusing it by `/api` prefix (as this once
// did) left dashboard images permanently broken with no way to rescue them.
for (const url of ['/api/hero?slug=x', '/api/slide?owner=o&n=01', '/api/preview']) {
const res = await app.inject({
method: 'GET',
url,
headers: { referer: `http://localhost/webview/${capability}/panel` },
});
expect(res.statusCode, url).toBe(200);
}
});
});
describe('the exemption does NOT widen anywhere else', () => {
@@ -132,8 +154,8 @@ describe('the exemption does NOT widen anywhere else', () => {
expect((await app.inject({ method: 'GET', url: '/webviewfoo/bar' })).statusCode).toBe(401);
});
it('NEVER exempts the Codeman API, even with a valid capability in the Referer', async () => {
// This is the hole the Referer form would open if it were not path-fenced.
it('NEVER exempts a real Codeman API route, even with a valid capability in the Referer', async () => {
// This is the hole the Referer form would open if it were not fenced.
const res = await app.inject({
method: 'GET',
url: '/api/sessions',
@@ -142,6 +164,42 @@ describe('the exemption does NOT widen anywhere else', () => {
expect(res.statusCode).toBe(401);
});
it('NEVER exempts a PARAMETRIC API route matched by a concrete url', async () => {
// The fence has to route `/api/sessions/abc` onto `/api/sessions/:id`. A literal
// pattern check (`hasRoute`) reports no match here and would hand out an
// exemption on a live, session-scoped API route.
for (const url of ['/api/sessions/abc', '/api/sessions/abc?x=1']) {
const res = await app.inject({
method: 'GET',
url,
headers: { referer: `http://localhost/webview/${capability}/panel` },
});
expect(res.statusCode, url).toBe(401);
}
});
it('still refuses the websocket namespace outright', async () => {
// `/q/` is deliberately absent here: QR login is PUBLIC by its own bypass
// (an unauthenticated device is the entire point), so it can never demonstrate
// anything about this exemption. The `/q/` guard alongside it is belt-and-braces.
const res = await app.inject({
method: 'GET',
url: '/ws/anything',
headers: { referer: `http://localhost/webview/${capability}/panel` },
});
expect(res.statusCode).toBe(401);
});
it('does not exempt an unrouted /api path without a live capability in the Referer', async () => {
expect((await app.inject({ method: 'GET', url: '/api/hero?slug=x' })).statusCode).toBe(401);
const stale = await app.inject({
method: 'GET',
url: '/api/hero?slug=x',
headers: { referer: `http://localhost/webview/${'Z'.repeat(32)}/panel` },
});
expect(stale.statusCode).toBe(401);
});
it('does not let the Referer form carry a WRITE', async () => {
const res = await app.inject({
method: 'POST',
+157
View File
@@ -0,0 +1,157 @@
/**
* @fileoverview Frontend test for the "Web / URL" rows in the Run dropdown
* (webview-tabs.js).
*
* A saved URL used to render as a single open-button, so the ONLY way to remove one
* was to open it as a tab and go through the tab's gear, which is a dead end for a
* URL you no longer want open. These pin the per-row edit/delete affordance and the
* delete path behind it, because a UI affordance is exactly the kind of thing a
* later render refactor drops silently.
*
* Builds a JSDOM window in-test under the default node env, same shape as
* test/admin-ui.test.ts. Do NOT declare a per-file jsdom environment: it
* externalizes node:fs under vite and the readFileSync calls below stop working.
* ⚠ Do not name that directive in a comment either, vitest matches the string
* anywhere in the file.
*/
import { describe, it, expect, vi } from 'vitest';
import { readFileSync } from 'node:fs';
import { JSDOM } from 'jsdom';
const CONSTANTS = readFileSync(new URL('../src/web/public/constants.js', import.meta.url), 'utf-8');
const WEBVIEW_TABS = readFileSync(new URL('../src/web/public/webview-tabs.js', import.meta.url), 'utf-8');
interface AppLike {
webviews: Map<string, { id: string; name: string; url: string; icon?: string }>;
webviewOrder: string[];
activeWebviewId: string | null;
renderWebviewMenuItems(): void;
renderSessionTabs(): void;
deleteWebviewById(id: string): Promise<void>;
_confirmAndDeleteWebview(id: string): Promise<boolean>;
_removeWebviewTab(id: string): void;
_apiDelete(path: string): Promise<{ ok: boolean } | null>;
showToast?: (msg: string, kind: string) => void;
showWebviewModal(id?: string): void;
}
function boot(deleteOk = true) {
const dom = new JSDOM(
`<!doctype html><body>
<div class="run-mode-menu active" id="runModeMenu">
<div class="run-mode-webviews" id="runModeWebviews"></div>
</div>
<div id="sessionTabs"></div>
<div id="webviewLayer"></div>
</body>`,
{ url: 'http://localhost/', runScripts: 'outside-only' }
);
const win = dom.window as unknown as Window &
typeof globalThis & { app: AppLike; CodemanApp: new () => AppLike; confirm: () => boolean };
// webview-tabs.js is a prototype mixin, so it needs the class it extends plus the
// escapeHtml global from constants.js. Everything else it touches is stubbed.
// One eval, not three: lexical declarations in a global eval do not survive into
// the next one, and the class must be a window property for the same reason.
(win as unknown as { eval: (s: string) => void }).eval(
['window.CodemanApp = class CodemanApp {};', CONSTANTS, WEBVIEW_TABS].join('\n')
);
const deleted: string[] = [];
const app = new win.CodemanApp();
app.webviews = new Map([
['id-a', { id: 'id-a', name: 'Bio Dashboard', url: 'https://box.ts.net:4000', icon: '📈' }],
['id-b', { id: 'id-b', name: 'Grafana', url: 'http://127.0.0.1:3000/d/x' }],
]);
app.webviewOrder = [];
app.activeWebviewId = null;
app.renderSessionTabs = () => {};
app._apiDelete = async (path: string) => {
deleted.push(path);
return deleteOk ? { ok: true } : { ok: false };
};
win.app = app;
win.confirm = () => true;
app.renderWebviewMenuItems();
return { dom, win, app, deleted };
}
const rows = (win: Window) => win.document.querySelectorAll('#runModeWebviews .run-mode-row--web');
describe('Run dropdown Web/URL rows', () => {
it('gives every saved URL an open, edit and delete control', () => {
const { win } = boot();
expect(rows(win)).toHaveLength(2);
expect(win.document.querySelectorAll('#runModeWebviews .run-mode-option--web')).toHaveLength(2);
expect(win.document.querySelectorAll('#runModeWebviews .run-mode-webview-edit')).toHaveLength(2);
expect(win.document.querySelectorAll('#runModeWebviews .run-mode-webview-delete')).toHaveLength(2);
});
it('escapes the name and url rather than interpolating them raw', () => {
const { win, app } = boot();
const name = '<img src=x onerror=alert(1)>';
const url = 'https://h/"onmouseover="x';
app.webviews.set('id-x', { id: 'id-x', name, url });
app.renderWebviewMenuItems();
// Assert on the DOM, not on innerHTML: attribute serialization does not
// re-escape `<`, so a string check reads as a breakout when there is none.
expect(win.document.querySelectorAll('#runModeWebviews img')).toHaveLength(0);
const row = rows(win)[2];
expect(row.querySelector('.run-mode-option--web')!.textContent).toContain(name);
expect(row.querySelector('.run-mode-option--web')!.getAttribute('title')).toBe(url);
expect(row.querySelector('.run-mode-webview-delete')!.getAttribute('aria-label')).toBe(`Delete ${name}`);
});
it('stops the delete click from also opening the dashboard', () => {
const { win, app } = boot();
let opened = 0;
(app as unknown as { openWebviewFromMenu: () => void }).openWebviewFromMenu = () => {
opened++;
};
const del = win.document.querySelector<HTMLElement>('#runModeWebviews .run-mode-webview-delete')!;
expect(del.getAttribute('onclick')).toContain('event.stopPropagation()');
del.click();
expect(opened).toBe(0);
});
it('deletes server-side and drops the row, leaving the menu open', async () => {
const { win, app, deleted } = boot();
app._removeWebviewTab = () => {};
await app.deleteWebviewById('id-a');
expect(deleted).toEqual(['/api/webviews/id-a']);
expect(app.webviews.has('id-a')).toBe(false);
expect(rows(win)).toHaveLength(1);
// Deleting one of several URLs should leave you looking at the rest of the list.
expect(win.document.getElementById('runModeMenu')!.classList.contains('active')).toBe(true);
});
it('does nothing when the confirm is declined', async () => {
const { win, app, deleted } = boot();
win.confirm = () => false;
await app.deleteWebviewById('id-a');
expect(deleted).toEqual([]);
expect(app.webviews.has('id-a')).toBe(true);
expect(rows(win)).toHaveLength(2);
});
it('keeps the row and warns when the server refuses the delete', async () => {
const { win, app } = boot(false);
const toast = vi.fn();
app.showToast = toast;
app._removeWebviewTab = () => {};
await app.deleteWebviewById('id-a');
expect(toast).toHaveBeenCalledWith('Could not delete URL', 'error');
expect(app.webviews.has('id-a')).toBe(true);
expect(rows(win)).toHaveLength(2);
});
it('still renders the empty state when nothing is saved', () => {
const { win, app } = boot();
app.webviews.clear();
app.renderWebviewMenuItems();
expect(rows(win)).toHaveLength(0);
expect(win.document.querySelector('.run-mode-empty')).toBeTruthy();
});
});
+162
View File
@@ -6,6 +6,7 @@
*/
import { describe, it, expect } from 'vitest';
import { JSDOM } from 'jsdom';
import {
buildDownstreamResponseHeaders,
buildProxyCorsHeaders,
@@ -474,6 +475,167 @@ describe('runtimeUrlShim', () => {
});
});
/**
* The DOM half of the shim, run in a real jsdom document rather than the fake
* window above, because these patches ARE DOM behavior: what matters is the URL the
* browser would end up requesting after `innerHTML = ...`, not whether some
* function got wrapped.
*
* The bug being pinned: a dashboard rendering `<img src="/api/hero?slug=x">` from
* page script escapes `<base>` (which never applies to root-absolute URLs) and
* escapes `rewriteHtml()` (which only sees the initial document), so every image
* 404s on Codeman's own root while the dashboard's fetch-driven data loads fine.
*
* Node environment on purpose, like test/markdown-sanitizer.test.ts: a per-file
* jsdom environment directive would externalize node builtins under vite. The
* directive is deliberately not written out here, even in prose: vitest scans
* comments for it, and naming it flipped this whole file to the jsdom
* environment while this comment claimed the opposite.
*/
describe('runtimeUrlShim DOM sinks', () => {
const body = runtimeUrlShim(PREFIX)
.replace(/^<script>/, '')
.replace(/<\/script>$/, '');
function newDom() {
const dom = new JSDOM('<!doctype html><html><head></head><body><div id="box"></div></body></html>', {
url: `https://codeman.local${PREFIX}page`,
runScripts: 'outside-only',
});
dom.window.eval(body);
return dom;
}
/** src of the first <img> in #box, as the attribute the browser would fetch. */
function imgSrc(dom: JSDOM): string | null {
return dom.window.document.querySelector('#box img')!.getAttribute('src');
}
it('rewrites a root-absolute img src injected via innerHTML', () => {
const dom = newDom();
dom.window.document.getElementById('box')!.innerHTML =
'<img class="thumb" loading="lazy" src="/api/hero?slug=x" alt="">';
expect(imgSrc(dom)).toBe(`${PREFIX}api/hero?slug=x`);
});
it('rewrites single-quoted markup and insertAdjacentHTML too', () => {
const dom = newDom();
dom.window.document.getElementById('box')!.insertAdjacentHTML('beforeend', "<img src='/api/logo'>");
expect(imgSrc(dom)).toBe(`${PREFIX}api/logo`);
});
it('rewrites the img.src property setter', () => {
const dom = newDom();
const img = new dom.window.Image();
img.src = '/api/slide?owner=o&n=01';
expect(img.getAttribute('src')).toBe(`${PREFIX}api/slide?owner=o&n=01`);
});
it('rewrites setAttribute and media src/poster', () => {
const dom = newDom();
const video = dom.window.document.createElement('video');
video.setAttribute('src', '/api/video?owner=o');
video.poster = '/thumb.png';
expect(video.getAttribute('src')).toBe(`${PREFIX}api/video?owner=o`);
expect(video.getAttribute('poster')).toBe(`${PREFIX}thumb.png`);
});
it('rewrites every candidate in a srcset, leaving cross-origin ones alone', () => {
const dom = newDom();
const img = dom.window.document.createElement('img');
img.setAttribute('srcset', '/a.png 1x, /b.png 2x, https://cdn.example/c.png 3x');
expect(img.getAttribute('srcset')).toBe(`${PREFIX}a.png 1x, ${PREFIX}b.png 2x, https://cdn.example/c.png 3x`);
});
it('leaves relative, cross-origin, hash, data: and already-proxied URLs untouched', () => {
const dom = newDom();
const box = dom.window.document.getElementById('box')!;
box.innerHTML = [
'<img id="rel" src="api/rel.png">',
'<img id="cross" src="https://cdn.example/z.png">',
'<img id="data" src="data:image/gif;base64,AAAA">',
`<img id="done" src="${PREFIX}api/hero">`,
'<a id="hash" href="#top">t</a>',
].join('');
const at = (id: string, attr: string) => dom.window.document.getElementById(id)!.getAttribute(attr);
expect(at('rel', 'src')).toBe('api/rel.png');
expect(at('cross', 'src')).toBe('https://cdn.example/z.png');
expect(at('data', 'src')).toBe('data:image/gif;base64,AAAA');
expect(at('done', 'src')).toBe(`${PREFIX}api/hero`);
expect(at('hash', 'href')).toBe('#top');
});
it('catches a node built through an UNPATCHED sink via the MutationObserver net', async () => {
const dom = newDom();
const { document } = dom.window;
// createContextualFragment parses markup without going through innerHTML or
// setAttribute, so only the observer can fix this one.
const frag = document.createRange().createContextualFragment('<img id="net" src="/api/net.png">');
expect(frag.querySelector('img')!.getAttribute('src')).toBe('/api/net.png');
document.getElementById('box')!.appendChild(frag);
await new Promise((resolve) => setTimeout(resolve, 10));
expect(document.getElementById('net')!.getAttribute('src')).toBe(`${PREFIX}api/net.png`);
});
it('does not double-prefix when a page re-injects its own markup', () => {
const dom = newDom();
const box = dom.window.document.getElementById('box')!;
box.innerHTML = '<img src="/api/hero">';
const roundTrip = box.innerHTML;
box.innerHTML = roundTrip;
expect(imgSrc(dom)).toBe(`${PREFIX}api/hero`);
});
it('leaves an empty src empty, the "no image for this row" case', () => {
const dom = newDom();
dom.window.document.getElementById('box')!.innerHTML = '<img class="thumb" src="" alt="">';
expect(imgSrc(dom)).toBe('');
});
/**
* CSS is the sink no relay can rescue: a <style> element has no URL of its own,
* so an opaque-origin document sends an EMPTY Referer with the image request it
* triggers, and the 404 fallback has nothing to key on. Verified in Chromium.
*/
it('rewrites root-absolute url() inside a <style> injected as markup', () => {
const dom = newDom();
dom.window.document.getElementById('box')!.innerHTML = '<style>#hero{background-image:url(/api/hero.png)}</style>';
expect(dom.window.document.querySelector('#box style')!.textContent).toBe(
`#hero{background-image:url(${PREFIX}api/hero.png)}`
);
});
it('rewrites url() in a <style> built with textContent, via the observer', async () => {
const dom = newDom();
const { document } = dom.window;
const style = document.createElement('style');
style.textContent = "#late{background-image:url('/api/late.png')}";
document.head.appendChild(style);
await new Promise((resolve) => setTimeout(resolve, 10));
expect(style.textContent).toBe(`#late{background-image:url('${PREFIX}api/late.png')}`);
});
it('leaves relative, cross-origin and data: url() alone', () => {
const dom = newDom();
const css = [
'a{background:url(img/rel.png)}',
'b{background:url(https://cdn.example/z.png)}',
'c{background:url(data:image/gif;base64,AAAA)}',
`d{background:url(${PREFIX}api/done.png)}`,
].join('');
dom.window.document.getElementById('box')!.innerHTML = `<style>${css}</style>`;
expect(dom.window.document.querySelector('#box style')!.textContent).toBe(css);
});
it('is idempotent when a value passes through two layers', () => {
const dom = newDom();
const img = dom.window.document.createElement('img');
img.src = '/api/hero';
img.setAttribute('src', img.getAttribute('src')!);
expect(img.getAttribute('src')).toBe(`${PREFIX}api/hero`);
});
});
describe('misc helpers', () => {
it('identifies HTML content types, parameters included', () => {
expect(isHtmlContentType('text/html; charset=utf-8')).toBe(true);