mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
review fixes: never install workspace hooks for a remote attach or a cwd-fallback create
A claude-mode attachRemoteSession create overwrites workingDir with the user@host:session pseudo-path, which is a RELATIVE path locally — the old refresh-only call no-op'd on it, but ensureCodemanHooks mkdirs, so it created a junk local directory. And with workingDir omitted the cwd fallback reaches the hooks write unvalidated; under installer-created services cwd is $HOME, so hooks materialized in ~/.claude/settings.local.json. Both guarded at the applyWorkspaceHooks call site; regression tests prove the remote attach leaves no junk dir and the no-workingDir create leaves the server cwd untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -793,8 +793,12 @@ export function registerSessionRoutes(
|
||||
}
|
||||
|
||||
// Hooks for the workspace this session runs in (install vs refresh-only is the
|
||||
// `workspaceHooksEnabled` setting; see applyWorkspaceHooks).
|
||||
if ((body.mode ?? 'claude') === 'claude') {
|
||||
// `workspaceHooksEnabled` setting; see applyWorkspaceHooks). Never for a remote
|
||||
// attach (workingDir is a user@host:session pseudo-path — mkdir would create it
|
||||
// as a junk local dir), and only when the caller named a workingDir: the
|
||||
// process-cwd fallback is $HOME under installer-created services, and hooks
|
||||
// materializing in ~/.claude/settings.local.json was never asked for.
|
||||
if (!remote && body.workingDir && (body.mode ?? 'claude') === 'claude') {
|
||||
await applyWorkspaceHooks(ctx, workingDir);
|
||||
// Agent skill (docs/agent-control-plan.md §2): ADD-ONLY on create, same shared-
|
||||
// .claude rationale as the statusLine above: a create must never remove the
|
||||
|
||||
Reference in New Issue
Block a user