chore: bump version to 0.1531

This commit is contained in:
arkon
2026-02-18 10:23:10 +01:00
parent e05811d69a
commit 62ddfdea36
9 changed files with 298 additions and 45 deletions
+2 -2
View File
@@ -35,7 +35,7 @@ When user says "COM":
1. Increment version in BOTH `package.json` AND `CLAUDE.md` (verify they match with `grep version package.json && grep Version CLAUDE.md`)
2. Run: `git add -A && git commit -m "chore: bump version to X.XXXX" && git push && npm run build && systemctl --user restart claudeman-web`
**Version**: 0.1530 (must match `package.json` for npm publish)
**Version**: 0.1531 (must match `package.json` for npm publish)
## Project Overview
@@ -311,7 +311,7 @@ Use `LRUMap` for bounded caches with eviction, `StaleExpirationMap` for TTL-base
| **SSE events** | Search `broadcast(` in `server.ts` |
| **CLI commands** | `claudeman --help` |
| **Frontend patterns** | `src/web/public/app.js` (subagent windows, notifications) |
| **Session modes** | `SessionMode` type in `src/types.ts` |
| **Session statuses** | `SessionStatus` type in `src/types.ts` |
| **Error codes** | `createErrorResponse()` in `src/types.ts` |
| **Test utilities** | `test/respawn-test-utils.ts` |
| **Memory leak patterns** | `test/memory-leak-prevention.test.ts` |
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "claudeman",
"version": "0.1530",
"version": "0.1531",
"description": "The missing control plane for Claude Code - run 20 autonomous agents with real-time monitoring and session persistence",
"type": "module",
"main": "dist/index.js",
+31 -9
View File
@@ -12,7 +12,7 @@
*/
import { spawn, ChildProcess } from 'node:child_process';
import { existsSync, statSync } from 'node:fs';
import { existsSync, statSync, realpathSync } from 'node:fs';
import { resolve, relative, isAbsolute } from 'node:path';
import { homedir } from 'node:os';
import { EventEmitter } from 'node:events';
@@ -158,7 +158,7 @@ export class FileStreamManager extends EventEmitter {
return { success: false, error: validationResult.error };
}
const absolutePath = validationResult.absolutePath!;
let absolutePath = validationResult.absolutePath!;
// Check file exists and size
try {
@@ -175,6 +175,22 @@ export class FileStreamManager extends EventEmitter {
return { success: false, error: 'File not found or not accessible' };
}
// Re-resolve symlinks right before spawn to minimize TOCTOU window.
// A symlink could have been swapped between validatePath() and here.
try {
const resolvedPath = realpathSync(absolutePath);
if (resolvedPath !== absolutePath) {
// Symlink target changed — re-validate against allowed paths
const recheck = this.validatePath(resolvedPath, workingDir);
if (!recheck.valid) {
return { success: false, error: recheck.error };
}
absolutePath = resolvedPath;
}
} catch {
return { success: false, error: 'File not found or not accessible' };
}
// Generate stream ID
const streamId = `${sessionId}-${Date.now()}-${Math.random().toString(36).slice(2, 8)}`;
@@ -363,19 +379,27 @@ export class FileStreamManager extends EventEmitter {
}
// Resolve to absolute path
const absolutePath = isAbsolute(expandedPath)
let absolutePath = isAbsolute(expandedPath)
? resolve(expandedPath)
: resolve(workingDir, expandedPath);
// Resolve symlinks to prevent symlink attacks — validate the real target,
// not the symlink itself. Fall back to resolved path if file doesn't exist yet.
try {
absolutePath = realpathSync(absolutePath);
} catch {
// File may not exist yet (tail -f can wait); keep the resolved path
// which will be caught by the existsSync check below
}
// Normalize the working directory
const normalizedWorkingDir = resolve(workingDir);
// Check if the resolved path is within the working directory
// or common log directories
// or common log directories (/tmp intentionally excluded — world-writable)
const allowedPaths = [
normalizedWorkingDir,
'/var/log',
'/tmp',
resolve(homedir(), '.local/share'),
resolve(homedir(), '.cache'),
resolve(homedir(), 'logs'),
@@ -393,10 +417,8 @@ export class FileStreamManager extends EventEmitter {
};
}
// Check for path traversal attempts
if (absolutePath.includes('..')) {
return { valid: false, error: 'Path traversal not allowed' };
}
// Note: No need to check for '..' — resolve() already normalizes the path,
// and realpathSync() resolves symlinks. Both eliminate traversal sequences.
// Check file exists
if (!existsSync(absolutePath)) {
+84 -4
View File
@@ -136,6 +136,9 @@ export class TmuxManager extends EventEmitter implements TerminalMultiplexer {
readonly backend = 'tmux' as const;
private sessions: Map<string, MuxSession> = new Map();
private statsInterval: NodeJS.Timeout | null = null;
private mouseSyncInterval: NodeJS.Timeout | null = null;
/** Track last-known pane count per session to avoid unnecessary tmux set-option calls */
private lastPaneCount: Map<string, number> = new Map();
private trueColorConfigured = false;
@@ -298,14 +301,13 @@ export class TmuxManager extends EventEmitter implements TerminalMultiplexer {
await new Promise(resolve => setTimeout(resolve, TMUX_CREATION_WAIT_MS));
// Non-critical tmux config — run in parallel to avoid blocking event loop.
// These configure UX niceties (no status bar, mouse mode, true color).
// These configure UX niceties (no status bar, true color).
// Mouse mode is OFF by default so xterm.js handles text selection natively.
// It gets enabled dynamically when panes are split (agent teams).
const configPromises: Promise<void>[] = [
// Disable tmux status bar — Claudeman's web UI provides session info
execAsync(`tmux set-option -t "${muxName}" status off`, { timeout: EXEC_TIMEOUT_MS })
.then(() => {}).catch(() => { /* Non-critical — session still works with status bar */ }),
// Enable mouse mode — allows clicking to select tmux panes
execAsync(`tmux set-option -t "${muxName}" mouse on`, { timeout: EXEC_TIMEOUT_MS })
.then(() => {}).catch(() => { /* Non-critical — pane clicking won't work but keyboard input still does */ }),
];
// Enable 24-bit true color passthrough — server-wide, set once per lifetime
@@ -535,6 +537,7 @@ export class TmuxManager extends EventEmitter implements TerminalMultiplexer {
console.error(`[TmuxManager] Warning: Some processes may still be alive for session ${session.muxName}`);
}
this.lastPaneCount.delete(session.muxName);
this.sessions.delete(sessionId);
this.saveSessions();
this.emit('sessionKilled', { sessionId });
@@ -813,8 +816,47 @@ export class TmuxManager extends EventEmitter implements TerminalMultiplexer {
}
}
/**
* Start periodic mouse mode sync for all tracked sessions.
* Polls pane counts every 5s and toggles mouse on/off as needed.
* Only calls tmux set-option when the pane count actually changes.
*/
startMouseModeSync(intervalMs: number = 5000): void {
if (this.mouseSyncInterval) {
clearInterval(this.mouseSyncInterval);
}
this.mouseSyncInterval = setInterval(() => {
if (IS_TEST_MODE) return;
for (const session of this.sessions.values()) {
const panes = this.listPanes(session.muxName);
const count = panes.length;
const prev = this.lastPaneCount.get(session.muxName);
// Only toggle when pane count crosses the 1↔N boundary
if (prev !== count && count > 0) {
this.lastPaneCount.set(session.muxName, count);
if (count > 1) {
this.enableMouseMode(session.muxName);
} else {
this.disableMouseMode(session.muxName);
}
}
}
}, intervalMs);
}
stopMouseModeSync(): void {
if (this.mouseSyncInterval) {
clearInterval(this.mouseSyncInterval);
this.mouseSyncInterval = null;
}
this.lastPaneCount.clear();
}
destroy(): void {
this.stopStatsCollection();
this.stopMouseModeSync();
}
registerSession(session: MuxSession): void {
@@ -918,6 +960,7 @@ export class TmuxManager extends EventEmitter implements TerminalMultiplexer {
/**
* Enable mouse mode for an existing tmux session.
* Allows clicking to select panes in agent team split-pane layouts.
* When mouse mode is on, tmux intercepts mouse events (slow selection, no browser copy).
*/
enableMouseMode(muxName: string): boolean {
if (IS_TEST_MODE) return true;
@@ -937,6 +980,43 @@ export class TmuxManager extends EventEmitter implements TerminalMultiplexer {
}
}
/**
* Disable mouse mode for an existing tmux session.
* Restores native xterm.js text selection and browser clipboard copy.
*/
disableMouseMode(muxName: string): boolean {
if (IS_TEST_MODE) return true;
if (!isValidMuxName(muxName)) {
console.error('[TmuxManager] Invalid session name in disableMouseMode:', muxName);
return false;
}
try {
execSync(
`tmux set-option -t "${muxName}" mouse off`,
{ encoding: 'utf-8', timeout: EXEC_TIMEOUT_MS }
);
return true;
} catch {
return false;
}
}
/**
* Sync mouse mode based on pane count: enable if split (>1 pane), disable if single.
* Called by TeamWatcher when teammates spawn/despawn panes.
* Uses `tmux list-panes` for bulletproof detection — counts actual panes, not config.
*/
syncMouseMode(muxName: string): boolean {
if (IS_TEST_MODE) return true;
const panes = this.listPanes(muxName);
if (panes.length > 1) {
return this.enableMouseMode(muxName);
} else {
return this.disableMouseMode(muxName);
}
}
/**
* List all panes in a tmux session.
* Returns structured info for each pane.
+39 -22
View File
@@ -1545,6 +1545,7 @@ class ClaudemanApp {
this.initTerminal();
this.loadFontSize();
this.applyHeaderVisibilitySettings();
this.applyTabWrapSettings();
this.applyMonitorVisibility();
// Remove mobile-init class now that JS has applied visibility settings.
// The inline <script> in <head> added this to prevent flash-of-content on mobile.
@@ -1569,6 +1570,7 @@ class ClaudemanApp {
// Load server-stored settings (async, re-applies visibility after load)
this.loadAppSettingsFromServer().then(() => {
this.applyHeaderVisibilitySettings();
this.applyTabWrapSettings();
this.applyMonitorVisibility();
});
}
@@ -5034,10 +5036,11 @@ class ClaudemanApp {
prompt += '## If Stuck\n';
prompt += 'Output `<promise>BLOCKED</promise>` with explanation';
// Show preview with highlighting
const highlightedPrompt = prompt
.replace(/<promise>/g, '<span class="preview-highlight">&lt;promise&gt;')
.replace(/<\/promise>/g, '&lt;/promise&gt;</span>')
// Show preview with highlighting (escape first, then apply formatting)
const escapedPrompt = this.escapeHtml(prompt);
const highlightedPrompt = escapedPrompt
.replace(/&lt;promise&gt;/g, '<span class="preview-highlight">&lt;promise&gt;')
.replace(/&lt;\/promise&gt;/g, '&lt;/promise&gt;</span>')
.replace(/`([^`]+)`/g, '<code>$1</code>');
preview.innerHTML = highlightedPrompt;
@@ -5411,7 +5414,7 @@ class ClaudemanApp {
if (metadata.synthesisStats?.sourceBreakdown) {
const sources = metadata.synthesisStats.sourceBreakdown;
const sourceList = Object.entries(sources)
.map(([src, count]) => `${src}: ${count}`)
.map(([src, count]) => `${this.escapeHtml(src)}: ${count}`)
.join(', ');
statsText += ` · Sources: ${sourceList}`;
}
@@ -5426,10 +5429,10 @@ class ClaudemanApp {
if (metadata?.verificationWarnings?.length > 0 || metadata?.verificationGaps?.length > 0) {
let warningsHtml = '';
if (metadata.verificationGaps?.length > 0) {
warningsHtml += `<div class="plan-gaps"><strong>Gaps identified:</strong> ${metadata.verificationGaps.join('; ')}</div>`;
warningsHtml += `<div class="plan-gaps"><strong>Gaps identified:</strong> ${metadata.verificationGaps.map(g => this.escapeHtml(g)).join('; ')}</div>`;
}
if (metadata.verificationWarnings?.length > 0) {
warningsHtml += `<div class="plan-warnings"><strong>Warnings:</strong> ${metadata.verificationWarnings.join('; ')}</div>`;
warningsHtml += `<div class="plan-warnings"><strong>Warnings:</strong> ${metadata.verificationWarnings.map(w => this.escapeHtml(w)).join('; ')}</div>`;
}
warningsEl.innerHTML = warningsHtml;
warningsEl.classList.remove('hidden');
@@ -6005,9 +6008,9 @@ class ClaudemanApp {
win.innerHTML = `
<div class="plan-subagent-header">
<span class="plan-subagent-prompt-link" data-agent-id="${agentId}" data-agent-type="${agentType}" title="Click to view prompt">
<span class="plan-subagent-prompt-link" data-agent-id="${this.escapeHtml(agentId)}" data-agent-type="${this.escapeHtml(agentType)}" title="Click to view prompt">
<span class="plan-subagent-icon">${typeIcons[agentType] || '🤖'}</span>
<span class="plan-subagent-title">${typeLabels[agentType] || agentType}</span>
<span class="plan-subagent-title">${typeLabels[agentType] || this.escapeHtml(agentType)}</span>
</span>
<span class="plan-subagent-model">${model}</span>
</div>
@@ -8086,8 +8089,8 @@ class ClaudemanApp {
// Shorter timer name display
const displayName = name.replace(/-/g, ' ').replace(/^\w/, c => c.toUpperCase());
html += `<div class="respawn-countdown-timer" title="${timer.reason || ''}">
<span class="timer-name">${displayName}</span>
html += `<div class="respawn-countdown-timer" title="${this.escapeHtml(timer.reason || '')}">
<span class="timer-name">${this.escapeHtml(displayName)}</span>
<span class="timer-value">${remainingSec}s</span>
<div class="respawn-timer-bar">
<div class="respawn-timer-progress" style="width: ${percent}%"></div>
@@ -8123,7 +8126,7 @@ class ClaudemanApp {
html += `<div class="respawn-action-entry${extraClass}">
<span class="action-time">${time}</span>
<span class="action-type">[${action.type}]</span>
<span class="action-detail">${action.detail}</span>
<span class="action-detail">${this.escapeHtml(action.detail)}</span>
</div>`;
}
@@ -9405,6 +9408,7 @@ class ClaudemanApp {
document.getElementById('appSettingsSubagentTracking').checked = settings.subagentTrackingEnabled ?? defaults.subagentTrackingEnabled ?? true;
document.getElementById('appSettingsSubagentActiveTabOnly').checked = settings.subagentActiveTabOnly ?? defaults.subagentActiveTabOnly ?? true;
document.getElementById('appSettingsImageWatcherEnabled').checked = settings.imageWatcherEnabled ?? defaults.imageWatcherEnabled ?? false;
document.getElementById('appSettingsTabTwoRows').checked = settings.tabTwoRows ?? defaults.tabTwoRows ?? true;
// Claude CLI settings
const claudeModeSelect = document.getElementById('appSettingsClaudeMode');
const allowedToolsRow = document.getElementById('allowedToolsRow');
@@ -9530,6 +9534,7 @@ class ClaudemanApp {
subagentTrackingEnabled: document.getElementById('appSettingsSubagentTracking').checked,
subagentActiveTabOnly: document.getElementById('appSettingsSubagentActiveTabOnly').checked,
imageWatcherEnabled: document.getElementById('appSettingsImageWatcherEnabled').checked,
tabTwoRows: document.getElementById('appSettingsTabTwoRows').checked,
// Claude CLI settings
claudeMode: document.getElementById('appSettingsClaudeMode').value,
allowedTools: document.getElementById('appSettingsAllowedTools').value.trim(),
@@ -9616,6 +9621,7 @@ class ClaudemanApp {
// Apply header visibility immediately
this.applyHeaderVisibilitySettings();
this.applyTabWrapSettings();
this._updateTokensImmediate(); // Re-render token display (picks up showCost change)
this.applyMonitorVisibility();
this.renderProjectInsightsPanel(); // Re-render to apply visibility setting
@@ -9740,6 +9746,7 @@ class ClaudemanApp {
subagentActiveTabOnly: true, // Only show subagents for active tab
imageWatcherEnabled: false,
ralphTrackerEnabled: false,
tabTwoRows: false,
};
}
// Desktop defaults - rely on ?? operators in apply functions
@@ -9811,6 +9818,16 @@ class ClaudemanApp {
}
}
applyTabWrapSettings() {
const settings = this.loadAppSettingsFromStorage();
const defaults = this.getDefaultSettings();
const twoRows = settings.tabTwoRows ?? defaults.tabTwoRows ?? true;
const tabsEl = document.getElementById('sessionTabs');
if (tabsEl) {
tabsEl.classList.toggle('tabs-single-row', !twoRows);
}
}
applyMonitorVisibility() {
const settings = this.loadAppSettingsFromStorage();
const defaults = this.getDefaultSettings();
@@ -9951,7 +9968,7 @@ class ClaudemanApp {
'showFontControls', 'showSystemStats', 'showTokenCount', 'showCost',
'showMonitor', 'showProjectInsights', 'showFileBrowser', 'showSubagents',
'subagentTrackingEnabled', 'subagentActiveTabOnly',
'imageWatcherEnabled', 'ralphTrackerEnabled',
'imageWatcherEnabled', 'ralphTrackerEnabled', 'tabTwoRows',
]);
const filteredAppSettings = {};
for (const [key, value] of Object.entries(appSettings)) {
@@ -11349,19 +11366,19 @@ class ClaudemanApp {
let html = `
<div class="ralph-status-block-header">
<span>RALPH_STATUS</span>
<span class="ralph-status-block-status ${statusClass}">${statusBlock.status}</span>
<span class="ralph-status-block-status ${statusClass}">${this.escapeHtml(statusBlock.status)}</span>
${statusBlock.exitSignal ? '<span style="color: #4caf50;">🚪 EXIT</span>' : ''}
</div>
<div class="ralph-status-block-stats">
<span>${workIcon} ${statusBlock.workType}</span>
<span>${workIcon} ${this.escapeHtml(statusBlock.workType)}</span>
<span>📁 ${statusBlock.filesModified} files</span>
<span>✓ ${statusBlock.tasksCompletedThisLoop} tasks</span>
<span>${testsIcon} Tests: ${statusBlock.testsStatus}</span>
<span>✓ ${this.escapeHtml(String(statusBlock.tasksCompletedThisLoop))} tasks</span>
<span>${testsIcon} Tests: ${this.escapeHtml(statusBlock.testsStatus)}</span>
</div>
`;
if (statusBlock.recommendation) {
html += `<div class="ralph-status-block-recommendation">${statusBlock.recommendation}</div>`;
html += `<div class="ralph-status-block-recommendation">${this.escapeHtml(statusBlock.recommendation)}</div>`;
}
container.innerHTML = html;
@@ -11765,7 +11782,7 @@ class ClaudemanApp {
const hasWindow = this.subagentWindows.has(agent.agentId);
const canKill = agent.status === 'active' || agent.status === 'idle';
const modelBadge = agent.modelShort
? `<span class="subagent-model-badge ${agent.modelShort}">${agent.modelShort}</span>`
? `<span class="subagent-model-badge ${this.escapeHtml(agent.modelShort)}">${this.escapeHtml(agent.modelShort)}</span>`
: '';
const teammateInfo = this.getTeammateInfo(agent);
@@ -11869,7 +11886,7 @@ class ClaudemanApp {
const detailTitle = agent.description || `Agent ${agent.agentId}`;
const modelBadge = agent.modelShort
? `<span class="subagent-model-badge ${agent.modelShort}">${agent.modelShort}</span>`
? `<span class="subagent-model-badge ${this.escapeHtml(agent.modelShort)}">${this.escapeHtml(agent.modelShort)}</span>`
: '';
const tokenStats = (agent.totalInputTokens || agent.totalOutputTokens)
? `<span>Tokens: ${this.formatTokenCount(agent.totalInputTokens || 0)}↓ ${this.formatTokenCount(agent.totalOutputTokens || 0)}↑</span>`
@@ -12001,14 +12018,14 @@ class ClaudemanApp {
win.document.write(`
<html>
<head>
<title>Subagent ${agentId} Transcript</title>
<title>Subagent ${this.escapeHtml(agentId)} Transcript</title>
<style>
body { background: #1a1a2e; color: #eee; font-family: monospace; padding: 20px; }
pre { white-space: pre-wrap; word-wrap: break-word; }
</style>
</head>
<body>
<h2>Subagent ${agentId} Transcript (${data.data.entryCount} entries)</h2>
<h2>Subagent ${this.escapeHtml(agentId)} Transcript (${data.data.entryCount} entries)</h2>
<pre>${this.escapeHtml(content)}</pre>
</body>
</html>
+10
View File
@@ -790,6 +790,16 @@
</label>
</div>
<!-- Tab Bar Section -->
<div class="settings-section-header">Tab Bar</div>
<div class="settings-item" title="Allow tabs to wrap into two rows when there are many sessions">
<span class="settings-item-label">Two-Row Tabs</span>
<label class="switch switch-sm">
<input type="checkbox" id="appSettingsTabTwoRows" checked>
<span class="slider"></span>
</label>
</div>
<!-- Panels Section -->
<div class="settings-section-header">Panels</div>
<div class="settings-item" title="Show Monitor panel at bottom right">
+7
View File
@@ -183,6 +183,13 @@ body {
contain: layout;
}
.session-tabs.tabs-single-row {
flex-wrap: nowrap;
overflow-x: auto;
overflow-y: hidden;
max-height: none;
}
.session-tabs::-webkit-scrollbar {
width: 4px;
}
+54 -4
View File
@@ -9,6 +9,56 @@
import { z } from 'zod';
// ========== Path Validation ==========
/** Regex to validate working directory paths (no shell metacharacters) — matches tmux-manager.ts */
const SAFE_PATH_PATTERN = /^[a-zA-Z0-9_\/\-. ~]+$/;
/** Validate a path string: no shell metacharacters, no traversal, must be absolute */
export function isValidWorkingDir(p: string): boolean {
if (!p || !p.startsWith('/')) return false;
if (p.includes(';') || p.includes('&') || p.includes('|') ||
p.includes('$') || p.includes('`') || p.includes('(') ||
p.includes(')') || p.includes('{') || p.includes('}') ||
p.includes('<') || p.includes('>') || p.includes("'") ||
p.includes('"') || p.includes('\n') || p.includes('\r')) {
return false;
}
if (p.includes('..')) return false;
return SAFE_PATH_PATTERN.test(p);
}
/** Zod refinement for safe absolute path */
const safePathSchema = z.string().max(1000).refine(isValidWorkingDir, {
message: 'Invalid path: must be absolute, no shell metacharacters or traversal',
});
// ========== Env Var Allowlist ==========
/** Allowlisted env var key prefixes */
const ALLOWED_ENV_PREFIXES = ['CLAUDE_CODE_'];
/** Env var keys that are always blocked (security-sensitive) */
const BLOCKED_ENV_KEYS = new Set([
'PATH', 'LD_PRELOAD', 'LD_LIBRARY_PATH', 'NODE_OPTIONS',
'CLAUDEMAN_SCREEN_NAME', 'CLAUDEMAN_TMUX',
]);
/** Validate that an env var key is allowed */
function isAllowedEnvKey(key: string): boolean {
if (BLOCKED_ENV_KEYS.has(key)) return false;
return ALLOWED_ENV_PREFIXES.some(prefix => key.startsWith(prefix));
}
/** Zod schema for env overrides with allowlist enforcement */
const safeEnvOverridesSchema = z.record(z.string(), z.string()).optional().refine(
(val) => {
if (!val) return true;
return Object.keys(val).every(isAllowedEnvKey);
},
{ message: 'envOverrides contains blocked or disallowed env var keys. Only CLAUDE_CODE_* keys are allowed.' },
);
// ========== Session Routes ==========
/**
@@ -16,10 +66,10 @@ import { z } from 'zod';
* Creates a new session with optional working directory, mode, and name.
*/
export const CreateSessionSchema = z.object({
workingDir: z.string().optional(),
workingDir: safePathSchema.optional(),
mode: z.enum(['claude', 'shell']).optional(),
name: z.string().max(100).optional(),
envOverrides: z.record(z.string(), z.string()).optional(),
envOverrides: safeEnvOverridesSchema,
});
/**
@@ -203,13 +253,13 @@ export const FlickerFilterSchema = z.object({
/** POST /api/run */
export const QuickRunSchema = z.object({
prompt: z.string().min(1).max(100000),
workingDir: z.string().max(1000).optional(),
workingDir: safePathSchema.optional(),
});
/** POST /api/scheduled */
export const ScheduledRunSchema = z.object({
prompt: z.string().min(1).max(100000),
workingDir: z.string().max(1000).optional(),
workingDir: safePathSchema.optional(),
durationMinutes: z.number().int().min(1).max(14400).optional(),
});
+70 -3
View File
@@ -15,7 +15,7 @@ import fastifyCompress from '@fastify/compress';
import fastifyStatic from '@fastify/static';
import path, { join, dirname, resolve, relative, isAbsolute } from 'node:path';
import { fileURLToPath } from 'node:url';
import { existsSync, mkdirSync, writeFileSync, readdirSync, readFileSync, rmSync } from 'node:fs';
import { existsSync, statSync, mkdirSync, writeFileSync, readdirSync, readFileSync, rmSync } from 'node:fs';
import fs from 'node:fs/promises';
import { execSync } from 'node:child_process';
import { homedir, totalmem, freemem, loadavg, cpus } from 'node:os';
@@ -558,13 +558,38 @@ export class WebServer extends EventEmitter {
});
}
// Security headers on every response
this.app.addHook('onRequest', (_req, reply, done) => {
// Security headers + CORS on every response
this.app.addHook('onRequest', (req, reply, done) => {
reply.header('X-Content-Type-Options', 'nosniff');
reply.header('X-Frame-Options', 'SAMEORIGIN');
reply.header('Content-Security-Policy', "default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; img-src 'self' data: blob:; connect-src 'self'; font-src 'self' https://cdn.jsdelivr.net; frame-ancestors 'self'");
if (this.https) {
reply.header('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
}
// CORS: restrict to same-origin (localhost) only
const origin = req.headers.origin;
if (origin) {
try {
const url = new URL(origin);
if (url.hostname === 'localhost' || url.hostname === '127.0.0.1' || url.hostname === '::1') {
reply.header('Access-Control-Allow-Origin', origin);
reply.header('Access-Control-Allow-Methods', 'GET, POST, PUT, PATCH, DELETE, OPTIONS');
reply.header('Access-Control-Allow-Headers', 'Content-Type, Authorization');
reply.header('Access-Control-Max-Age', '86400');
}
} catch {
// Invalid origin header — do not set CORS headers
}
}
// Handle CORS preflight
if (req.method === 'OPTIONS') {
reply.code(204).send();
done();
return;
}
done();
});
@@ -742,6 +767,18 @@ export class WebServer extends EventEmitter {
const body = result.data;
const workingDir = body.workingDir || process.cwd();
// Validate workingDir exists and is a directory
if (body.workingDir) {
try {
const stat = statSync(workingDir);
if (!stat.isDirectory()) {
return createErrorResponse(ApiErrorCode.INVALID_INPUT, 'workingDir is not a directory');
}
} catch {
return createErrorResponse(ApiErrorCode.INVALID_INPUT, 'workingDir does not exist');
}
}
// Write env overrides to .claude/settings.local.json if provided
if (body.envOverrides && Object.keys(body.envOverrides).length > 0) {
await updateCaseEnvVars(workingDir, body.envOverrides);
@@ -2117,6 +2154,18 @@ export class WebServer extends EventEmitter {
}
const dir = workingDir || process.cwd();
// Validate workingDir exists and is a directory
if (workingDir) {
try {
const stat = statSync(dir);
if (!stat.isDirectory()) {
return createErrorResponse(ApiErrorCode.INVALID_INPUT, 'workingDir is not a directory');
}
} catch {
return createErrorResponse(ApiErrorCode.INVALID_INPUT, 'workingDir does not exist');
}
}
const session = new Session({ workingDir: dir });
this.sessions.set(session.id, session);
this.store.incrementSessionsCreated();
@@ -2149,6 +2198,18 @@ export class WebServer extends EventEmitter {
}
const { prompt, workingDir, durationMinutes } = srResult.data;
// Validate workingDir exists and is a directory
if (workingDir) {
try {
const stat = statSync(workingDir);
if (!stat.isDirectory()) {
return createErrorResponse(ApiErrorCode.INVALID_INPUT, 'workingDir is not a directory');
}
} catch {
return createErrorResponse(ApiErrorCode.INVALID_INPUT, 'workingDir does not exist');
}
}
const run = await this.startScheduledRun(prompt, workingDir || process.cwd(), durationMinutes ?? 60);
return { success: true, run };
});
@@ -5241,6 +5302,12 @@ NOW: Generate the implementation plan for the task above. Think step by step.`;
// Start stats collection to show screen info
this.mux.startStatsCollection(STATS_COLLECTION_INTERVAL_MS);
// Start mouse mode sync (tmux only) — toggles mouse on/off based on pane count.
// Mouse off = native xterm.js selection; mouse on = tmux pane clicking (split layouts).
if (this.mux.backend === 'tmux' && 'startMouseModeSync' in this.mux) {
(this.mux as { startMouseModeSync: (ms?: number) => void }).startMouseModeSync();
}
}
if (dead.length > 0) {