COD-39 attachment history drawer

Stacks on COD-38: accumulates a per-session attachment history and exposes it
through a slide-in drawer with an unread badge, so attachments stay reachable
after their cards are dismissed.

Backend:
- session-attachment-history: history state — dedupe by source path / relative
  path, newest-first, 100-item cap, and externalPath sanitization (the absolute
  host path is server-private and never leaves toState()).
- session.ts: _attachmentHistory + getter (sanitized) / upsert / restore /
  getAttachmentHistoryForPersist; restored from saved state in the constructor.
- file-routes: GET /attachments (list — resolves each entry to live metadata +
  routes; external entries are re-registered) and GET /attachments/:id
  (metadata poll). The by-id route guards via the registry's TOCTOU-safe
  resolveServableAttachmentPath.
- server.ts: detected/registered attachments upsert into history and persist;
  the private (externalPath-bearing) history rides on disk under
  __attachmentHistory, separate from the sanitized public copy, and is restored
  on mux-session recovery.
- types/session.ts: SessionAttachmentHistoryItem + SessionState.attachmentHistory.

Frontend:
- panels-ui: the drawer (lazy-built), unread badge, list render with per-item
  preview/download/open/"Card" (reshow) actions, and live refresh of the open
  drawer on new detections.
- app.js: history state + per-session badge/cleanup wiring.
- index.html / styles.css / mobile.css: header button + badge and the drawer.

Verified: tsc / eslint / prettier / frontend-syntax / public-assets clean; new
history-module unit tests pass; full test:ci green (2866 passed); badge, drawer
open/render/reshow/close verified in-browser.
This commit is contained in:
Aamer Akhter
2026-06-14 09:05:17 +02:00
committed by Claude (Codeman maintainer)
parent 5eacb1cf03
commit 577b6d7384
11 changed files with 1025 additions and 6 deletions
+116
View File
@@ -0,0 +1,116 @@
import { describe, expect, it } from 'vitest';
import { Session } from '../src/session.js';
import type { SessionAttachmentHistoryItem } from '../src/types/session.js';
import {
ATTACHMENT_HISTORY_LIMIT,
buildDetectedAttachmentHistoryItem,
buildExternalAttachmentHistoryItem,
upsertAttachmentHistory,
} from '../src/session-attachment-history.js';
describe('session attachment history', () => {
it('dedupes explicit external attachments by source path and moves latest to top', () => {
const first = buildExternalAttachmentHistoryItem({
sessionId: 's1',
externalPath: '/mnt/c/docs/brief.docx',
fileName: 'brief.docx',
extension: 'docx',
size: 100,
mtimeMs: 1,
timestamp: 10,
});
const second = { ...first, size: 200, mtimeMs: 2, timestamp: 20 };
const result = upsertAttachmentHistory(upsertAttachmentHistory([], first), second);
expect(result).toHaveLength(1);
expect(result[0]).toMatchObject({
size: 200,
mtimeMs: 2,
timestamp: 20,
externalPath: '/mnt/c/docs/brief.docx',
});
});
it('dedupes detected workspace attachments by relative path', () => {
const first = buildDetectedAttachmentHistoryItem({
sessionId: 's1',
filePath: 'report.pdf',
relativePath: 'out/report.pdf',
fileName: 'report.pdf',
extension: 'pdf',
attachmentType: 'pdf',
size: 100,
timestamp: 10,
});
const second = { ...first, size: 150, timestamp: 20 };
const result = upsertAttachmentHistory(upsertAttachmentHistory([], first), second);
expect(result).toHaveLength(1);
expect(result[0]).toMatchObject({ relativePath: 'out/report.pdf', size: 150, timestamp: 20 });
});
it('caps history to newest 100 items', () => {
let history: SessionAttachmentHistoryItem[] = [];
for (let i = 0; i < ATTACHMENT_HISTORY_LIMIT + 5; i++) {
history = upsertAttachmentHistory(
history,
buildDetectedAttachmentHistoryItem({
sessionId: 's1',
filePath: `${i}.png`,
relativePath: `out/${i}.png`,
fileName: `${i}.png`,
extension: 'png',
attachmentType: 'image',
size: i,
timestamp: i,
})
);
}
expect(history).toHaveLength(ATTACHMENT_HISTORY_LIMIT);
expect(history[0].fileName).toBe('104.png');
expect(history.at(-1)?.fileName).toBe('5.png');
});
it('includes attachment history in session state', () => {
const session = new Session({ workingDir: '/tmp' });
session.upsertAttachmentHistory({
id: 'detected:file.png',
sessionId: session.id,
fileName: 'file.png',
extension: 'png',
attachmentType: 'image',
size: 12,
mtimeMs: 0,
timestamp: 100,
source: 'detected',
relativePath: 'file.png',
});
expect(session.toState().attachmentHistory).toHaveLength(1);
expect(session.toState().attachmentHistory?.[0].fileName).toBe('file.png');
});
it('sanitizes external attachment paths from public session state', () => {
const session = new Session({ workingDir: '/tmp' });
session.upsertAttachmentHistory(
buildExternalAttachmentHistoryItem({
sessionId: session.id,
externalPath: '/mnt/c/private/board-update.pdf',
fileName: 'board-update.pdf',
extension: 'pdf',
size: 100,
timestamp: 100,
})
);
const publicState = session.toState();
const persistedHistory = session.getAttachmentHistoryForPersist();
expect(JSON.stringify(publicState.attachmentHistory)).not.toContain('/mnt/c/private/board-update.pdf');
expect(publicState.attachmentHistory?.[0].id).not.toContain('/mnt/c/private/board-update.pdf');
expect(persistedHistory?.[0].externalPath).toBe('/mnt/c/private/board-update.pdf');
});
});