Merge pull request #310 from Ark0N/fix/files-sidebar-followups

fix: file-link and session-sidebar review follow-ups from 1.19.0
This commit is contained in:
Ark0N
2026-08-16 20:44:14 +02:00
committed by GitHub
9 changed files with 209 additions and 13 deletions
+22 -6
View File
@@ -3831,7 +3831,6 @@ class CodemanApp {
// Collapse/expand changes whether the filter is reachable, so re-evaluate it
// here too — not only at the render tails.
this.applySidebarFilter(this._sidebarFilter);
this.updateSidebarCount();
this.updateConnectionLines();
// The desktop home rail defers to the sidebar (both dock the session list
// flush left), so a layout flip while the welcome screen is up has to
@@ -3876,9 +3875,22 @@ class CodemanApp {
this.toggleSessionSidebar();
}
/**
* The count is what is actually ON the list: session rows plus web-tab rows,
* minus whatever the sidebar filter is hiding. `this.sessions.size` was the
* original source and disagreed with the screen twice over — web tabs render
* in the same list but are not sessions (3 sessions + 2 dashboards read "3"
* above 5 rows), and a filter hides rows without touching the map. Counting
* the rendered rows keeps one source of truth: the list itself.
*/
updateSidebarCount() {
const el = document.getElementById('sessionSidebarCount');
if (el) el.textContent = String(this.sessions?.size ?? 0);
if (!el) return;
const container = this.$('sessionTabs');
const count = container
? container.querySelectorAll('.session-tab:not(.tab-filtered-out)').length
: (this.sessions?.size ?? 0);
el.textContent = String(count);
}
/**
@@ -3911,6 +3923,9 @@ class CodemanApp {
const haystack = `${tab.getAttribute('aria-label') || ''} ${tab.getAttribute('title') || ''}`.toLowerCase();
tab.classList.toggle('tab-filtered-out', !haystack.includes(needle));
}
// The count shows visible rows, so it moves with every filter change —
// including keystrokes in the filter box, which call this directly.
this.updateSidebarCount();
}
// ═══════════════════════════════════════════════════════════════
@@ -4267,11 +4282,13 @@ class CodemanApp {
// The full-render path already redraws the connection SVG; this incremental
// one does not, and a badge appearing widens a tab and shifts every tab after
// it, sliding the lineage arcs off their anchors. Only pay for it when there
// is an arc to keep anchored.
if (this._lineageEdgeCount > 0) this.updateConnectionLines();
// is something anchored to tab rects: lineage arcs, or — in sidebar layout,
// where lineage is skipped and the edge count stays 0 — the subagent/
// ultracode connectors, whose rows a badge changes the HEIGHT of. Same
// widening as the strip-scroll listener in session-lineage.js.
if (this._lineageEdgeCount > 0 || this.isSessionSidebarActive()) this.updateConnectionLines();
this.applySidebarFilter(this._sidebarFilter);
this.updateSidebarCount();
}
// Auto-wrap desktop session tabs to a second row when they overflow one row,
@@ -4472,7 +4489,6 @@ class CodemanApp {
// innerHTML was rebuilt wholesale, so the sidebar filter classes are gone —
// re-apply them or filtered-out sessions flicker back on every SSE tick.
this.applySidebarFilter(this._sidebarFilter);
this.updateSidebarCount();
}
// Set up arrow key navigation for session tabs (accessibility)
+11 -3
View File
@@ -997,13 +997,16 @@ function computeRewriteScrollLine(input) {
* never match) and terminated by a known extension (so the end of the path is
* unambiguous — a trailing `)` or `.` after the extension stays out). Longer
* extensions come first in each family (`tsx|ts`), so the trailing `\b` cannot
* be satisfied by the shorter branch mid-word.
* be satisfied by the shorter branch mid-word. `/etc` is deliberately NOT a
* root: DEFAULT_BLOCKED_TREES (config/attachment-guard.ts) refuses the whole
* tree server-side, so every `/etc/...` link was a guaranteed 403 — a link
* that renders clickable and then dies is worse than plain text.
*
* ⚠ Consumers must never share one instance: `lastIndex` is per-object state on
* a `/g` regex, so {@link absoluteFilePathPattern} mints a fresh one per call.
*/
const FILE_PATH_LINK_PATTERN =
/(\/(?:home|Users|tmp|var|private|etc|opt|mnt|srv|media|data|workspace)\/[^\s"'<>|;&\n\x00-\x1f]*\.(?:log|txt|json|md|ya?ml|csv|xml|sh|py|tsx|ts|jsx|js|mjs|cjs|css|html|toml|ini|sql|png|jpe?g|gif|webp|bmp|svg|pdf|docx|pptx|mp4|webm|mov|mp3|wav))\b/g;
/(\/(?:home|Users|tmp|var|private|opt|mnt|srv|media|data|workspace)\/[^\s"'<>|;&\n\x00-\x1f]*\.(?:log|txt|json|md|ya?ml|csv|xml|sh|py|tsx|ts|jsx|js|mjs|cjs|css|html|toml|ini|sql|png|jpe?g|gif|webp|bmp|svg|pdf|docx|pptx|mp4|webm|mov|mp3|wav))\b/g;
/** A fresh, zero-state instance of {@link FILE_PATH_LINK_PATTERN}. */
function absoluteFilePathPattern() {
@@ -1014,9 +1017,14 @@ function absoluteFilePathPattern() {
* Extensions the file-preview overlay renders itself. Everything else a link
* points at goes to the tail/log viewer, which is the right home for a growing
* text file and the wrong one for bytes (tailing a PNG shows binary noise).
*
* The media entries mirror VIDEO_ATTACHMENT_EXTENSIONS/AUDIO_ATTACHMENT_EXTENSIONS
* (src/attachment-registry.ts, the single source) — they diverged once and an
* in-workspace `.m4a` opened as binary noise in the log viewer while the same
* file in /tmp played fine. test/media-extension-parity.test.ts pins the sync.
*/
const FILE_PREVIEW_EXTENSIONS = new Set(
('png jpg jpeg gif webp bmp svg pdf docx pptx mp4 webm mov mp3 wav').split(' ')
('png jpg jpeg gif webp bmp svg pdf docx pptx mp4 webm mov m4v ogv mp3 wav ogg oga m4a aac flac opus').split(' ')
);
/** Whether a path's extension is one {@link FILE_PREVIEW_EXTENSIONS} covers. */
+3
View File
@@ -3346,6 +3346,9 @@ Object.assign(CodemanApp.prototype, {
if (attachmentId) {
const base = `/api/sessions/${sessionId}/attachments/${encodeURIComponent(attachmentId)}`;
const IMAGE_EXTS = new Set(['png', 'jpg', 'jpeg', 'gif', 'webp', 'bmp', 'svg']);
// VIDEO/AUDIO mirror VIDEO_ATTACHMENT_EXTENSIONS/AUDIO_ATTACHMENT_EXTENSIONS
// (src/attachment-registry.ts, the single source); the frontend cannot import
// it, so test/media-extension-parity.test.ts pins the copies equal.
const VIDEO_EXTS = new Set(['mp4', 'webm', 'mov', 'm4v', 'ogv']);
const AUDIO_EXTS = new Set(['mp3', 'wav', 'ogg', 'oga', 'm4a', 'aac', 'flac', 'opus']);
// Size when we just registered the file ourselves, so a path opened from a
+20 -1
View File
@@ -29,6 +29,9 @@
* symlink pointing at a sensitive target is also caught.
*/
import { homedir } from 'node:os';
import { join } from 'node:path';
const SENSITIVE_PATTERNS: RegExp[] = [
// System account databases.
/^\/etc\/shadow$/,
@@ -99,10 +102,26 @@ const SENSITIVE_PATTERNS: RegExp[] = [
/\/\.codeman[^/]*\/intents\.json$/,
];
/**
* Claude config members that are credential-bearing ONLY under the user's real
* home directory: `~/.claude/settings.json` can hold `env.ANTHROPIC_API_KEY`
* and `apiKeyHelper` by schema (settings.local.json shares that schema), and
* `~/.claude.json` holds account/OAuth-adjacent state. A blanket
* `/\.claude\/settings\.json$/` would also block every CASE-level
* `.claude/settings.json`, which users legitimately view and edit in the File
* Viewer (model override, hooks) — so these are anchored to homedir(), read at
* CHECK time inside isSensitivePath, never captured at module load (wrong for
* anything that changes HOME later, e.g. per-file test fixtures — same
* reasoning as the `.ssh/` note above).
*/
const HOME_SENSITIVE_MEMBERS = ['.claude.json', '.claude/settings.json', '.claude/settings.local.json'];
/**
* Returns true if the given ABSOLUTE, symlink-resolved path matches the
* sensitive-file blocklist and must not be served to the browser.
*/
export function isSensitivePath(absPath: string): boolean {
return SENSITIVE_PATTERNS.some((pattern) => pattern.test(absPath));
if (SENSITIVE_PATTERNS.some((pattern) => pattern.test(absPath))) return true;
const home = homedir();
return HOME_SENSITIVE_MEMBERS.some((member) => absPath === join(home, member));
}