fix(web): usable past-conversation list, and search that finds past sessions

Two home-screen reports from @jordan8037310, both about history that is
present but unreachable.

#260 — "Resume Conversation" rendered 4 rows, then a button that appended
every remaining row into a `max-height: 240px` box, so 35 conversations
landed in a four-row scroll well with no ordering or filtering. Rendering
now goes through `_renderHistoryList()` over a cached corpus: 10 rows to
start, Show more/Show less that grows and shrinks the box (the height cap
is class-driven, `.history-list.expanded`), plus a filter box (name,
folder, #case label, prompts), a sort control (recent / name / folder,
pinned rows still first) and a shown-of-total count. A filter implies
expansion, so every match is visible, and the whole header hides as one
unit while a federated search is active. The A-Z sort keys off the same
string the row renders, since most rows are transcript-backed and carry
no session name at all.

#261 — the search box could not match a past project by folder name:
`harvestSources()` built its session corpus from the live in-memory map,
while past sessions come from `/api/sessions/unified` (lifecycle log +
transcript scan). Folding that scan into the request path would have cost
the search its no-filesystem-reads property, so the corpus arrives via a
bounded snapshot instead: `session-history-index.ts` is published as a
side effect of `/api/sessions/unified` (the home screen fetches it on
open, which is the same screen the search box lives on) and rebuilt
fire-and-forget, single-flight and TTL-guarded when a search finds it
stale. A result for a closed session now resumes the conversation rather
than selecting a tab that no longer exists, and is badged RESUME.

The snapshot is stored unscoped with a per-row owner and re-filtered
through canAccessOwned() on read, so multi-user sees exactly what
/api/sessions/unified exposes: own sessions only, host-wide transcript
history admin-only. Live rows are harvested first and win the dedupe.

Verified end-to-end against a real instance with 60 past sessions: cold
process answers its first search without history and its second with it;
folder-name queries return resume targets; clicking one posts the right
resumeSessionId + workingDir.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-08-10 03:02:11 +02:00
parent c942bb5dfb
commit 5d42f64393
15 changed files with 1206 additions and 54 deletions
+34 -1
View File
@@ -3,7 +3,9 @@
*
* Registers `GET /api/search?q=&types=&limit=` — a bounded, in-memory search
* across three v1 sources, returned in the standard ApiResponse envelope:
* 1. sessions/cases — name, working directory, session id
* 1. sessions/cases — name, working directory, session id, for LIVE sessions
* plus the past-session snapshot in `session-history-index.ts` (issue #261:
* the live map alone made every closed session unfindable by folder name)
* 2. run-summary events — event title/details (from the live run-summary trackers)
* 3. file paths — per-session attachment history (workspace-relative paths only)
*
@@ -34,6 +36,7 @@ import {
} from '../../search-service.js';
import type { SearchSourceType } from '../../types/search.js';
import type { SessionPort, InfraPort } from '../ports/index.js';
import { ensureHistorySessionIndexFresh, getHistorySessionIndex } from '../session-history-index.js';
/**
* Per-source harvest caps. These bound how much in-memory data we hand to the
@@ -61,11 +64,17 @@ interface SessionLike {
/**
* Harvest the three source arrays from the live in-memory stores. Reads only
* bounded, already-loaded data — no disk I/O, no terminal buffers.
*
* Past sessions come from the `session-history-index` snapshot, which is built
* outside the request path for exactly that reason. Live rows are harvested
* first and win the dedupe, so a session that is both live and in the snapshot
* keeps its live jump-to (switch to the tab) instead of a resume.
*/
function harvestSources(ctx: SessionPort & InfraPort, canSee?: (owner?: string) => boolean): SearchSources {
const sessions: SessionSearchInput[] = [];
const events: EventSearchInput[] = [];
const files: FileSearchInput[] = [];
const seenSessionIds = new Set<string>();
for (const raw of ctx.sessions.values()) {
const s = raw as unknown as SessionLike & { owner?: string };
@@ -73,6 +82,7 @@ function harvestSources(ctx: SessionPort & InfraPort, canSee?: (owner?: string)
const sessionName = s.name ?? '';
const timestamp = s.lastActivityAt ?? s.createdAt ?? 0;
seenSessionIds.add(s.id);
sessions.push({
sessionId: s.id,
sessionName,
@@ -95,6 +105,24 @@ function harvestSources(ctx: SessionPort & InfraPort, canSee?: (owner?: string)
}
}
// Past sessions: the out-of-band snapshot of the unified list. Unscoped on
// disk, so every row goes through the same ownership check as a live one —
// host-wide transcript rows carry no owner and are therefore admin-only in
// multi-user mode, matching GET /api/sessions/unified.
for (const item of getHistorySessionIndex().items) {
if (seenSessionIds.has(item.sessionId)) continue;
if (canSee && !canSee(item.owner)) continue;
seenSessionIds.add(item.sessionId);
sessions.push({
sessionId: item.sessionId,
sessionName: item.name,
workingDir: item.workingDir,
timestamp: item.timestamp,
history: true,
claudeSessionId: item.claudeSessionId,
});
}
// Events: from the live run-summary trackers, keyed by session id.
for (const [sessionId, tracker] of ctx.runSummaryTrackers) {
const session = ctx.sessions.get(sessionId) as unknown as (SessionLike & { owner?: string }) | undefined;
@@ -134,6 +162,11 @@ export function registerSearchRoutes(app: FastifyInstance, ctx: SessionPort & In
)
: null;
// Fire-and-forget: a stale past-session snapshot is rebuilt in the
// background. This query still answers from whatever is already in memory,
// which is what keeps the request path free of disk I/O.
ensureHistorySessionIndexFresh();
const sources = harvestSources(ctx, canSee);
// Apply the optional source-type filter before searching so excluded
+68 -10
View File
@@ -94,7 +94,13 @@ import {
type LifecycleInput,
type HistoryInput,
type MuxStatInput,
type UnifiedSessionItem,
} from '../../services/unified-session-service.js';
import {
buildHistorySessionIndexItems,
setHistoryIndexRefresher,
setHistorySessionIndex,
} from '../session-history-index.js';
import type { SessionPort, EventPort, ConfigPort, InfraPort, AuthPort } from '../ports/index.js';
import { RunSummaryTracker } from '../../run-summary.js';
@@ -3539,16 +3545,20 @@ export function registerSessionRoutes(
return { sessions: results.slice(0, 50) };
});
// Unified, read-only session list: merges live + persisted + lifecycle +
// transcript history + mux stats into one de-duplicated, searchable list
// (COD-121). Pure merge/filter logic lives in unified-session-service.ts.
app.get('/api/sessions/unified', async (req) => {
const query = req.query as { q?: string; offset?: string; limit?: string };
if (ctx.testMode) {
return { sessions: [], total: 0 };
}
/**
* Gather the four read-only views the unified list is merged from, plus mux
* stats. This is the expensive half (the lifecycle log and a scan of every
* Claude transcript), factored out of the route handler because the
* past-session search index rebuilds itself from the very same inputs — off
* the request path, see session-history-index.ts.
*/
async function gatherUnifiedInputs(): Promise<{
live: LiveSessionInput[];
persisted: PersistedSessionInput[];
lifecycle: LifecycleInput[];
history: HistoryInput[];
mux: MuxStatInput[];
}> {
// Live (in-memory) sessions.
const live: LiveSessionInput[] = [...ctx.sessions.values()].map((s) => {
const st = s.toState();
@@ -3649,14 +3659,54 @@ export function registerSessionRoutes(
// Mux stats are optional.
}
return { live, persisted, lifecycle, history, mux };
}
/**
* Publish a merged unified list as the past-session search index (issue #261).
* The snapshot is stored UNSCOPED with a per-row owner, so it must only ever be
* built from an unscoped merge — `harvestSources()` in search-routes re-applies
* the ownership check on read.
*/
function publishHistorySessionIndex(merged: UnifiedSessionItem[]): void {
const ownerById = new Map<string, string | undefined>();
const stored = ctx.store.getState().sessions as Record<string, { id: string; owner?: string }>;
for (const p of Object.values(stored)) ownerById.set(p.id, p.owner);
// Live wins: a session's owner on disk can lag the running one.
for (const s of ctx.sessions.values()) ownerById.set(s.id, s.owner);
const liveIds = new Set(ctx.sessions.keys());
setHistorySessionIndex(buildHistorySessionIndexItems(merged, ownerById, liveIds));
}
// Rebuild hook for the search route: it kicks this (fire-and-forget) when the
// snapshot goes stale, so a search never pays for the scan itself.
setHistoryIndexRefresher(async () => {
if (ctx.testMode) return;
publishHistorySessionIndex(mergeUnifiedSessions(await gatherUnifiedInputs()));
});
// Unified, read-only session list: merges live + persisted + lifecycle +
// transcript history + mux stats into one de-duplicated, searchable list
// (COD-121). Pure merge/filter logic lives in unified-session-service.ts.
app.get('/api/sessions/unified', async (req) => {
const query = req.query as { q?: string; offset?: string; limit?: string };
if (ctx.testMode) {
return { sessions: [], total: 0 };
}
const { live, persisted, lifecycle, history, mux } = await gatherUnifiedInputs();
// Multi-user: a non-admin only sees their own sessions; host-wide transcript
// history (not tied to an owned session) is admin-only.
let sLive = live;
let sPersisted = persisted;
let sLifecycle = lifecycle;
let sHistory = history;
let scoped = false;
const uUser = getAuthUser(req);
if (isMultiUserMode() && uUser.role !== 'admin') {
scoped = true;
const ownedLive = new Set(
[...ctx.sessions.values()].filter((s) => canAccessOwned(uUser, s.owner)).map((s) => s.id)
);
@@ -3680,6 +3730,14 @@ export function registerSessionRoutes(
history: sHistory,
mux,
});
// Refresh the search index off the back of this request — the home screen
// fetches this endpoint whenever it opens, which is the same screen the
// search box lives on, so the snapshot is warm before anyone types. A scoped
// merge is a per-user subset and would corrupt the shared snapshot, so that
// path re-merges unscoped instead (multi-user is opt-in and rarely hit).
publishHistorySessionIndex(scoped ? mergeUnifiedSessions({ live, persisted, lifecycle, history, mux }) : merged);
const offset = query.offset !== undefined ? parseInt(query.offset, 10) : undefined;
const limit = query.limit !== undefined ? parseInt(query.limit, 10) : undefined;
return filterAndPaginate(merged, {