mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 16:39:42 +02:00
Merge remote-tracking branch 'origin/master' into pr251-review-fixes
# Conflicts: # CLAUDE.md
This commit is contained in:
@@ -0,0 +1,125 @@
|
||||
/**
|
||||
* @fileoverview Approvals Inbox routes.
|
||||
*
|
||||
* The cross-session queue of prompts waiting on a human (see
|
||||
* web/approval-inbox.ts, docs/approvals-inbox-plan.md):
|
||||
* - `GET /api/approvals`: pending items, ownership-scoped in multi-user mode
|
||||
* - `POST /api/approvals/:id/answer`: answer in place by sending the
|
||||
* corresponding keystrokes to the session (digit / Esc / idle-prompt text)
|
||||
* - `POST /api/approvals/:id/dismiss`: drop the item without keystrokes
|
||||
*
|
||||
* Normal authed API surface (NOT the localhost hook-secret bypass). Answering
|
||||
* is take-then-write: the item is removed BEFORE keystrokes go out so a
|
||||
* double-tap (or the service worker retrying a push action) cannot
|
||||
* double-send; a failed write restores the item.
|
||||
*/
|
||||
|
||||
import { FastifyInstance } from 'fastify';
|
||||
import { ApiErrorCode, createErrorResponse } from '../../types.js';
|
||||
import { ApprovalAnswerSchema } from '../schemas.js';
|
||||
import { parseBody, getAuthUser, canAccessOwned, findSessionOrFail } from '../route-helpers.js';
|
||||
import { approvalInbox, type ApprovalItem } from '../approval-inbox.js';
|
||||
import { hooksAvailableForMode } from '../session-wait-registry.js';
|
||||
import type { SessionPort } from '../ports/index.js';
|
||||
|
||||
/**
|
||||
* Keystrokes for an answer, or an error string. Menu answers are a single digit
|
||||
* or Esc (dialogs react to the keypress itself, so no Enter is ever sent for
|
||||
* them). Free text is allowed only for idle prompts (there IS no dialog; the
|
||||
* text lands in the composer and `\r` submits it, per the CLAUDE.md input
|
||||
* discipline). `option` digits must match a PARSED option so a blind digit can
|
||||
* never be routed at a dialog we could not read.
|
||||
*/
|
||||
function keystrokesFor(
|
||||
item: ApprovalItem,
|
||||
answer: { action: 'approve' | 'deny' | 'option' | 'text'; option?: number; text?: string }
|
||||
): { keys: string } | { error: string } {
|
||||
switch (answer.action) {
|
||||
case 'approve':
|
||||
if (item.kind === 'idle') return { error: 'Idle prompts take a text answer, not approve/deny' };
|
||||
return { keys: '1' };
|
||||
case 'deny':
|
||||
if (item.kind === 'idle') return { error: 'Idle prompts take a text answer, not approve/deny' };
|
||||
return { keys: '\x1b' };
|
||||
case 'option': {
|
||||
if (item.kind === 'idle') return { error: 'Idle prompts take a text answer, not an option digit' };
|
||||
if (answer.option === undefined) return { error: 'action "option" requires the option field' };
|
||||
if (!item.options?.some((o) => o.n === answer.option)) {
|
||||
return { error: `Option ${answer.option} is not among the parsed dialog options` };
|
||||
}
|
||||
return { keys: String(answer.option) };
|
||||
}
|
||||
case 'text': {
|
||||
if (item.kind !== 'idle') return { error: 'Text answers are only valid for idle prompts' };
|
||||
const text = (answer.text ?? '').replace(/[\r\n]+/g, ' ').trim();
|
||||
if (!text) return { error: 'action "text" requires non-empty text' };
|
||||
return { keys: `${text}\r` };
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
export function registerApprovalRoutes(app: FastifyInstance, ctx: SessionPort): void {
|
||||
// List pending approvals. Items whose session is gone resolve lazily; items
|
||||
// whose session the caller cannot access are filtered (never 403-leaked),
|
||||
// matching the session-list scoping policy.
|
||||
app.get('/api/approvals', async (req) => {
|
||||
const user = getAuthUser(req);
|
||||
const approvals = approvalInbox.listPending().filter((item) => {
|
||||
const session = ctx.sessions.get(item.sessionId);
|
||||
if (!session) {
|
||||
approvalInbox.resolveForSession(item.sessionId, 'session_ended');
|
||||
return false;
|
||||
}
|
||||
return canAccessOwned(user, session.owner);
|
||||
});
|
||||
return { success: true, data: { approvals } };
|
||||
});
|
||||
|
||||
app.post<{ Params: { id: string } }>('/api/approvals/:id/answer', async (req) => {
|
||||
const answer = parseBody(ApprovalAnswerSchema, req.body);
|
||||
const item = approvalInbox.getById(req.params.id);
|
||||
if (!item) {
|
||||
// Covers unknown, already-answered, superseded and expired ids alike.
|
||||
return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Approval not found or no longer pending');
|
||||
}
|
||||
// Throws 404 (not 403) for sessions the caller does not own, same
|
||||
// no-existence-leak rule as every other session route.
|
||||
const session = findSessionOrFail(ctx, item.sessionId, req);
|
||||
if (!hooksAvailableForMode(session.mode)) {
|
||||
return createErrorResponse(ApiErrorCode.CONFLICT, 'Session mode cannot have pending approvals');
|
||||
}
|
||||
|
||||
// Re-capture the pane before aiming keystrokes at it: if the dialog was
|
||||
// answered in the terminal moments ago, the digit would land in whatever
|
||||
// now has focus. Conclusive only for items whose frame parsed options.
|
||||
if (!approvalInbox.verifyStillAnswerable(item.id)) {
|
||||
return createErrorResponse(ApiErrorCode.CONFLICT, 'The dialog is no longer on screen');
|
||||
}
|
||||
|
||||
const resolved = keystrokesFor(item, answer);
|
||||
if ('error' in resolved) {
|
||||
return createErrorResponse(ApiErrorCode.INVALID_INPUT, resolved.error);
|
||||
}
|
||||
|
||||
const taken = approvalInbox.take(item.id);
|
||||
if (!taken) {
|
||||
return createErrorResponse(ApiErrorCode.CONFLICT, 'Approval was resolved by another actor');
|
||||
}
|
||||
const written = await session.writeViaMux(resolved.keys);
|
||||
if (!written) {
|
||||
approvalInbox.restore(taken);
|
||||
return createErrorResponse(ApiErrorCode.OPERATION_FAILED, 'Session is not accepting input');
|
||||
}
|
||||
return { success: true, data: { id: item.id, sessionId: item.sessionId, action: answer.action } };
|
||||
});
|
||||
|
||||
app.post<{ Params: { id: string } }>('/api/approvals/:id/dismiss', async (req) => {
|
||||
const item = approvalInbox.getById(req.params.id);
|
||||
if (!item) {
|
||||
return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Approval not found or no longer pending');
|
||||
}
|
||||
findSessionOrFail(ctx, item.sessionId, req);
|
||||
approvalInbox.dismiss(item.id);
|
||||
return { success: true, data: { id: item.id } };
|
||||
});
|
||||
}
|
||||
@@ -315,11 +315,25 @@ function findMatchingPickerRoot(roots: FilesystemBrowseRoot[], candidate: string
|
||||
.sort((a, b) => b.path.length - a.path.length)[0];
|
||||
}
|
||||
|
||||
/**
|
||||
* Whether a path has a dot-prefixed segment anywhere below its browse root.
|
||||
*
|
||||
* Checked against the REALPATH, so a plainly-named symlink pointing into a
|
||||
* hidden tree is caught too. Callers skip it when the request opts into hidden
|
||||
* entries (`showHidden`), which is why the sensitive-path blocklist and the
|
||||
* blocked-tree checks must stand on their own: with the toggle on, this is no
|
||||
* longer the thing keeping `~/.config/gh/hosts.yml` out of reach.
|
||||
*/
|
||||
function containsHiddenPickerSegment(root: string, candidate: string): boolean {
|
||||
const rel = relative(root, candidate);
|
||||
return rel !== '' && rel.split(sep).some((segment) => segment.startsWith('.'));
|
||||
}
|
||||
|
||||
/** Parses the picker's opt-in `showHidden` query flag (absent means off). */
|
||||
function wantsHiddenPickerEntries(showHidden?: string): boolean {
|
||||
return showHidden === 'true';
|
||||
}
|
||||
|
||||
function getFilesystemPreviewKind(fileName: string): FilesystemPreviewKind | undefined {
|
||||
const extension = extname(fileName).slice(1).toLowerCase();
|
||||
if (FILESYSTEM_IMAGE_PREVIEW_EXTENSIONS.has(extension)) return 'image';
|
||||
@@ -431,7 +445,8 @@ async function resolveFilesystemPickerPath(
|
||||
ctx: SessionPort & ConfigPort,
|
||||
req: FastifyRequest,
|
||||
requestedPath: string | undefined,
|
||||
sessionId?: string
|
||||
sessionId?: string,
|
||||
showHidden = false
|
||||
): Promise<ResolvedFilesystemPickerPath> {
|
||||
const roots = await resolveFilesystemPickerRoots(ctx, req, sessionId);
|
||||
if (roots.length === 0) {
|
||||
@@ -453,7 +468,7 @@ async function resolveFilesystemPickerPath(
|
||||
if (!matchingRoot) {
|
||||
throwFilesystemPickerError(403, ApiErrorCode.INVALID_INPUT, 'Path is outside the allowed browse roots');
|
||||
}
|
||||
if (containsHiddenPickerSegment(matchingRoot.path, resolvedPath)) {
|
||||
if (!showHidden && containsHiddenPickerSegment(matchingRoot.path, resolvedPath)) {
|
||||
throwFilesystemPickerError(403, ApiErrorCode.INVALID_INPUT, 'Hidden paths are not available in the file picker');
|
||||
}
|
||||
|
||||
@@ -662,12 +677,14 @@ function inheritedHeaders(reply: {
|
||||
export function registerFileRoutes(app: FastifyInstance, ctx: SessionPort & EventPort & ConfigPort): void {
|
||||
// Lazy filesystem listing for the Link Existing and mobile input path pickers.
|
||||
app.get('/api/filesystem/browse', async (req, reply): Promise<ApiResponse<FilesystemBrowseData>> => {
|
||||
const { path: requestedPath, sessionId } = parseBody(FilesystemBrowseQuerySchema, req.query);
|
||||
const { path: requestedPath, sessionId, showHidden } = parseBody(FilesystemBrowseQuerySchema, req.query);
|
||||
const includeHidden = wantsHiddenPickerEntries(showHidden);
|
||||
const { candidatePath, resolvedPath, roots, matchingRoot, blockedTrees } = await resolveFilesystemPickerPath(
|
||||
ctx,
|
||||
req,
|
||||
requestedPath,
|
||||
sessionId
|
||||
sessionId,
|
||||
includeHidden
|
||||
);
|
||||
|
||||
if (isBlockedPickerPath(resolvedPath, blockedTrees, true)) {
|
||||
@@ -703,7 +720,7 @@ export function registerFileRoutes(app: FastifyInstance, ctx: SessionPort & Even
|
||||
const entries: FilesystemBrowseEntry[] = [];
|
||||
let truncated = false;
|
||||
for (const entry of dirEntries) {
|
||||
if (entry.name.startsWith('.')) continue;
|
||||
if (!includeHidden && entry.name.startsWith('.')) continue;
|
||||
if (entries.length >= FILESYSTEM_PICKER_ENTRY_LIMIT) {
|
||||
truncated = true;
|
||||
break;
|
||||
@@ -718,7 +735,8 @@ export function registerFileRoutes(app: FastifyInstance, ctx: SessionPort & Even
|
||||
}
|
||||
|
||||
const targetRoot = findMatchingPickerRoot(roots, targetPath);
|
||||
if (!targetRoot || containsHiddenPickerSegment(targetRoot.path, targetPath)) continue;
|
||||
if (!targetRoot) continue;
|
||||
if (!includeHidden && containsHiddenPickerSegment(targetRoot.path, targetPath)) continue;
|
||||
|
||||
let type: FilesystemBrowseEntry['type'];
|
||||
let size: number | undefined;
|
||||
@@ -783,12 +801,13 @@ export function registerFileRoutes(app: FastifyInstance, ctx: SessionPort & Even
|
||||
|
||||
// Inline preview for files selected through the root-confined filesystem picker.
|
||||
app.get('/api/filesystem/preview', { compress: false }, async (req, reply): Promise<void> => {
|
||||
const { path: requestedPath, sessionId } = parseBody(FilesystemPreviewQuerySchema, req.query);
|
||||
const { path: requestedPath, sessionId, showHidden } = parseBody(FilesystemPreviewQuerySchema, req.query);
|
||||
const { candidatePath, resolvedPath, blockedTrees } = await resolveFilesystemPickerPath(
|
||||
ctx,
|
||||
req,
|
||||
requestedPath,
|
||||
sessionId
|
||||
sessionId,
|
||||
wantsHiddenPickerEntries(showHidden)
|
||||
);
|
||||
if (isBlockedPickerPath(resolvedPath, blockedTrees)) {
|
||||
throwFilesystemPickerError(403, ApiErrorCode.INVALID_INPUT, 'Access to this file is blocked');
|
||||
|
||||
@@ -2,6 +2,9 @@
|
||||
* @fileoverview Hook event route.
|
||||
* Receives Claude Code hook events and broadcasts to SSE clients.
|
||||
* This endpoint bypasses auth (Claude Code hooks curl from localhost).
|
||||
* Prompt events (permission_prompt / elicitation_dialog / idle_prompt) also
|
||||
* open Approvals Inbox items; stop and the elicitation-closed events clear
|
||||
* them (see web/approval-inbox.ts and docs/approvals-inbox-plan.md).
|
||||
*/
|
||||
|
||||
import { FastifyInstance } from 'fastify';
|
||||
@@ -11,8 +14,19 @@ import { sanitizeHookData, parseBody } from '../route-helpers.js';
|
||||
import { persistDockerCaseClaudeSessionId } from '../../docker-hosts.js';
|
||||
import { getDataDir } from '../../config/instance.js';
|
||||
import { sessionWaits, hooksAvailableForMode } from '../session-wait-registry.js';
|
||||
import { approvalInbox, type ApprovalKind } from '../approval-inbox.js';
|
||||
import type { SessionPort, EventPort, RespawnPort, ConfigPort, InfraPort } from '../ports/index.js';
|
||||
|
||||
/** Hook events that open an Approvals Inbox item. */
|
||||
const APPROVAL_KIND_BY_EVENT: Record<string, ApprovalKind> = {
|
||||
permission_prompt: 'permission',
|
||||
elicitation_dialog: 'question',
|
||||
idle_prompt: 'idle',
|
||||
};
|
||||
|
||||
/** Hook events that close a session's pending item without an inbox answer. */
|
||||
const APPROVAL_RESOLVING_EVENTS = new Set(['stop', 'elicitation_complete', 'elicitation_response']);
|
||||
|
||||
export function registerHookEventRoutes(
|
||||
app: FastifyInstance,
|
||||
ctx: SessionPort & EventPort & RespawnPort & ConfigPort & InfraPort
|
||||
@@ -88,12 +102,60 @@ export function registerHookEventRoutes(
|
||||
|
||||
// Sanitize forwarded data: only include known safe fields, limit size
|
||||
const safeData = sanitizeHookData(data);
|
||||
ctx.broadcast(`hook:${event}`, { sessionId, timestamp: Date.now(), ...safeData });
|
||||
|
||||
// Send push notifications for hook events
|
||||
const session = ctx.sessions.get(sessionId);
|
||||
const sessionName = session?.name ?? sessionId.slice(0, 8);
|
||||
ctx.sendPushNotifications(`hook:${event}`, { sessionId, sessionName, ...safeData });
|
||||
|
||||
// Approvals Inbox: prompt events open an item, dialog-closed/stop events
|
||||
// clear it. Mode-gated like the wait signals above (hook events carry no
|
||||
// identity beyond the shared per-instance secret, so a prompt claimed for a
|
||||
// session that can never show one must not create an answerable item).
|
||||
let approvalId: string | undefined;
|
||||
const approvalKind = APPROVAL_KIND_BY_EVENT[event];
|
||||
if (session && hooksAvailableForMode(session.mode)) {
|
||||
if (approvalKind) {
|
||||
const toolInput =
|
||||
safeData.tool_input && typeof safeData.tool_input === 'object'
|
||||
? (safeData.tool_input as Record<string, unknown>)
|
||||
: undefined;
|
||||
const toolSummary = toolInput
|
||||
? [toolInput.command, toolInput.file_path, toolInput.description].find((v) => typeof v === 'string')
|
||||
: undefined;
|
||||
const item = approvalInbox.notePrompt({
|
||||
sessionId,
|
||||
sessionName,
|
||||
kind: approvalKind,
|
||||
toolName: typeof safeData.tool_name === 'string' ? safeData.tool_name : undefined,
|
||||
toolSummary: typeof toolSummary === 'string' ? toolSummary : undefined,
|
||||
message: typeof safeData.message === 'string' ? safeData.message : undefined,
|
||||
cwd: typeof safeData.cwd === 'string' ? safeData.cwd : undefined,
|
||||
// Visible tmux frame first (it IS the dialog); raw byte-buffer tail as
|
||||
// the fallback for direct-PTY sessions and the no-op test mux.
|
||||
capture: () => {
|
||||
const muxName = session.muxName;
|
||||
const frame = muxName ? (ctx.mux.capturePaneBuffer?.(muxName) ?? null) : null;
|
||||
return frame ?? session.terminalBuffer.slice(-8192) ?? null;
|
||||
},
|
||||
});
|
||||
approvalId = item.id;
|
||||
} else if (APPROVAL_RESOLVING_EVENTS.has(event)) {
|
||||
approvalInbox.resolveForSession(sessionId, 'resolved_in_terminal');
|
||||
}
|
||||
}
|
||||
|
||||
ctx.broadcast(`hook:${event}`, {
|
||||
sessionId,
|
||||
timestamp: Date.now(),
|
||||
...safeData,
|
||||
...(approvalId && { approvalId }),
|
||||
});
|
||||
|
||||
// Send push notifications for hook events
|
||||
ctx.sendPushNotifications(`hook:${event}`, {
|
||||
sessionId,
|
||||
sessionName,
|
||||
...safeData,
|
||||
...(approvalId && { approvalId }),
|
||||
});
|
||||
|
||||
// Track in run summary
|
||||
const summaryTracker = ctx.runSummaryTrackers.get(sessionId);
|
||||
|
||||
@@ -10,6 +10,8 @@ export { registerScheduledRoutes } from './scheduled-routes.js';
|
||||
export { registerCronRoutes } from './cron-routes.js';
|
||||
export { registerSystemRoutes } from './system-routes.js';
|
||||
export { registerHookEventRoutes } from './hook-event-routes.js';
|
||||
export { registerApprovalRoutes } from './approval-routes.js';
|
||||
export { registerReadMyMindRoutes } from './readmymind-routes.js';
|
||||
export { registerStatusTelemetryRoutes } from './status-telemetry-routes.js';
|
||||
export { registerCaseRoutes } from './case-routes.js';
|
||||
export { registerSessionRoutes } from './session-routes.js';
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
/**
|
||||
* @fileoverview Read My Mind intent routes.
|
||||
*
|
||||
* Per-case intent profiles feeding the Read My Mind predictor
|
||||
* (docs/readmymind-plan.md):
|
||||
* - `GET /api/sessions/:id/intent`: the profile for the session's case
|
||||
* - `PUT /api/sessions/:id/intent`: replace the goals text
|
||||
* - `DELETE /api/sessions/:id/intent`: forget the case's profile
|
||||
*
|
||||
* The profile is keyed by owner + workingDir, so multi-user scoping is
|
||||
* structural; session ownership is still enforced via `findSessionOrFail`
|
||||
* (with `req`, so a foreign session id 404s) to keep the session-routes
|
||||
* no-existence-leak policy.
|
||||
*
|
||||
* Deliberately session-scoped rather than a raw `/api/intents/:key` surface:
|
||||
* the session resolves owner + workingDir server-side, so a caller can never
|
||||
* address another case's profile by guessing keys.
|
||||
*
|
||||
* Registrations use the bare `app.<method>('path', ...)` + `req.params as`
|
||||
* shape (session-routes style): these endpoints are documented in the agent
|
||||
* skill, and the endpoints.md drift test's scanner does not see registrations
|
||||
* with a generic between the method and the path.
|
||||
*/
|
||||
|
||||
import { FastifyInstance } from 'fastify';
|
||||
import { IntentGoalsSchema } from '../schemas.js';
|
||||
import { parseBody, findSessionOrFail } from '../route-helpers.js';
|
||||
import { intentStore } from '../../intent-store.js';
|
||||
import type { SessionPort } from '../ports/index.js';
|
||||
|
||||
export function registerReadMyMindRoutes(app: FastifyInstance, ctx: SessionPort): void {
|
||||
app.get('/api/sessions/:id/intent', async (req) => {
|
||||
const { id } = req.params as { id: string };
|
||||
const session = findSessionOrFail(ctx, id, req);
|
||||
return { success: true, data: { intent: intentStore.getProfile(session.owner, session.workingDir) } };
|
||||
});
|
||||
|
||||
app.put('/api/sessions/:id/intent', async (req) => {
|
||||
const { id } = req.params as { id: string };
|
||||
const body = parseBody(IntentGoalsSchema, req.body);
|
||||
const session = findSessionOrFail(ctx, id, req);
|
||||
return { success: true, data: { intent: intentStore.setGoals(session.owner, session.workingDir, body.goals) } };
|
||||
});
|
||||
|
||||
app.delete('/api/sessions/:id/intent', async (req) => {
|
||||
const { id } = req.params as { id: string };
|
||||
const session = findSessionOrFail(ctx, id, req);
|
||||
return { success: true, data: { deleted: intentStore.deleteProfile(session.owner, session.workingDir) } };
|
||||
});
|
||||
}
|
||||
Reference in New Issue
Block a user