mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 07:59:42 +02:00
feat(cases): clone a Git repository as a new case (#236)
Adds an Add Case -> "Clone Repo" tab plus two endpoints, implementing @DodgyBadger's proposal in #236: clone a public repository straight into codeman-cases/<name> and register it as a normal local case. POST /api/cases/clone is synchronous by design (request held open, bounded by GIT_CLONE_TIMEOUT_MS): no job store, no polling, no cancellation surface. Success broadcasts the usual case:created event, so the case still appears when a proxy idle-timeout kills the request mid-clone. POST /api/cases/clone-preflight runs `git ls-remote --symref` so the UI can say, while the user is still typing, whether the URL is cloneable without credentials, what its default branch is, and which branches/tags exist. Core lives in src/git-clone.ts, split into a pure half (URL parse, argv/env, ls-remote parse, stderr classification) and a thin IO half, so every security decision is unit-testable without spawning anything: - `<name>::<payload>` transports are refused as a family, not by name: ext:: is the famous one, but any of them dispatches to git-remote-<name> and turns a clone into arbitrary command execution. - A leading `-` is refused AND every spawn puts `--` before the operands. Either alone is one edit away from being a hole. - argv arrays, never a shell. URLs carrying user:password@ are refused. - gitNonInteractiveEnv() closes all four ways git can block on a prompt with no terminal attached (terminal prompt, askpass/GUI, ssh, GCM). HOME/PATH stay inherited, so a user's own credential helper or ssh agent keeps working; Codeman itself collects and stores nothing. - The timeout signals the process GROUP, since clone fans out into git-remote-https/index-pack children that outlive a signal to the parent. - Bounded output (redacted stderr tail, capped ls-remote stdout, 500 refs each) and a global 2-op pool, so N large clones cannot exhaust the host. Repository contents beat scaffolding: an existing CLAUDE.md is kept, hooks are merged into whatever .claude/settings.local.json the repo shipped, and a repo that ships its own Claude settings is reported back as a warning (those hooks run locally as soon as a session starts there). A failed clone removes only the directory the attempt created, and refuses a pre-existing destination outright, so it can never squat on a case name. Not admin-gated in multi-user mode, unlike /api/cases/link: it writes only inside the caller's own case space. Local-path/file:// sources are the exception and stay admin-only there. UI: live verdict under the URL field, case name filled from the parsed repo until the user types their own, branch/tag as a datalist of the remote's real refs, optional shallow clone, and a Brain picker (installed CLIs only) that points the Run button at the chosen agent. Starting a session stays opt-in. The tab hides itself when the server reports no git. Tests: the pure half exhaustively (every refusal has a case), plus real git against a real local bare repo for clone/ref/timeout/cleanup, and a route-level suite with unmocked fs that clones through the endpoint. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1772,6 +1772,11 @@ Object.assign(CodemanApp.prototype, {
|
||||
const el = document.getElementById(id);
|
||||
if (el) el.value = '';
|
||||
});
|
||||
this._resetCloneForm();
|
||||
// Cloning needs git ON THE SERVER: hide the whole tab rather than let it fail
|
||||
// at submit. Unknown reads as available (isCliAvailable's rule).
|
||||
const cloneTabBtn = document.getElementById('caseCloneTabBtn');
|
||||
if (cloneTabBtn) cloneTabBtn.style.display = this.isCliAvailable('git') ? '' : 'none';
|
||||
// Reset to first tab
|
||||
this.caseModalTab = 'case-create';
|
||||
this.switchCaseModalTab('case-create');
|
||||
@@ -1817,15 +1822,19 @@ Object.assign(CodemanApp.prototype, {
|
||||
submitBtn.textContent =
|
||||
tabName === 'case-create'
|
||||
? 'Create'
|
||||
: tabName === 'case-remote'
|
||||
? 'Link Remote'
|
||||
: tabName === 'case-docker'
|
||||
? 'Link Docker'
|
||||
: 'Link';
|
||||
: tabName === 'case-clone'
|
||||
? 'Clone'
|
||||
: tabName === 'case-remote'
|
||||
? 'Link Remote'
|
||||
: tabName === 'case-docker'
|
||||
? 'Link Docker'
|
||||
: 'Link';
|
||||
}
|
||||
// Focus appropriate input
|
||||
if (tabName === 'case-create') {
|
||||
document.getElementById('newCaseName').focus();
|
||||
} else if (tabName === 'case-clone') {
|
||||
document.getElementById('cloneRepoUrl').focus();
|
||||
} else if (tabName === 'case-link') {
|
||||
document.getElementById('linkCaseName').focus();
|
||||
} else if (tabName === 'case-remote') {
|
||||
@@ -1843,10 +1852,16 @@ Object.assign(CodemanApp.prototype, {
|
||||
const btn = document.getElementById('caseModalSubmit');
|
||||
const originalText = btn.textContent;
|
||||
btn.classList.add('loading');
|
||||
btn.textContent = this.caseModalTab === 'case-create' ? 'Creating...' : 'Linking...';
|
||||
btn.textContent =
|
||||
this.caseModalTab === 'case-create' ? 'Creating...' : this.caseModalTab === 'case-clone' ? 'Cloning...' : 'Linking...';
|
||||
// A clone holds this request open for minutes; without disabling the button a
|
||||
// second click fires a second clone (the loser then fails on ALREADY_EXISTS).
|
||||
btn.disabled = true;
|
||||
try {
|
||||
if (this.caseModalTab === 'case-create') {
|
||||
await this.createCase();
|
||||
} else if (this.caseModalTab === 'case-clone') {
|
||||
await this.cloneCase();
|
||||
} else if (this.caseModalTab === 'case-remote') {
|
||||
await this.linkRemoteCase();
|
||||
} else if (this.caseModalTab === 'case-docker') {
|
||||
@@ -1856,6 +1871,7 @@ Object.assign(CodemanApp.prototype, {
|
||||
}
|
||||
} finally {
|
||||
btn.classList.remove('loading');
|
||||
btn.disabled = false;
|
||||
btn.textContent = originalText;
|
||||
}
|
||||
},
|
||||
@@ -1997,6 +2013,231 @@ Object.assign(CodemanApp.prototype, {
|
||||
}
|
||||
},
|
||||
|
||||
// ═══════════════════════════════════════════════════════════════
|
||||
// Clone Repo tab (issue #236)
|
||||
// ═══════════════════════════════════════════════════════════════
|
||||
|
||||
/** Clear the Clone tab and drop any preflight state. Called from showCreateCaseModal(). */
|
||||
_resetCloneForm() {
|
||||
const set = (id, value) => {
|
||||
const el = document.getElementById(id);
|
||||
if (el) el.value = value;
|
||||
};
|
||||
set('cloneRepoUrl', '');
|
||||
set('cloneCaseName', '');
|
||||
set('cloneRepoRef', '');
|
||||
const shallow = document.getElementById('cloneShallow');
|
||||
if (shallow) shallow.checked = false;
|
||||
const start = document.getElementById('cloneStartSession');
|
||||
if (start) start.checked = false;
|
||||
const refs = document.getElementById('cloneRepoRefOptions');
|
||||
if (refs) refs.replaceChildren();
|
||||
const refHint = document.getElementById('cloneRefHint');
|
||||
if (refHint) refHint.textContent = "Leave blank for the repository's default branch.";
|
||||
this._cloneNameEdited = false;
|
||||
this._clonePreflight = null;
|
||||
clearTimeout(this._clonePreflightTimer);
|
||||
this._clonePreflightAbort?.abort();
|
||||
this._clonePreflightAbort = null;
|
||||
this._setCloneStatus('Public repositories only: Codeman clones with no credentials.', '');
|
||||
// The brain picker mirrors the toolbar run menu: never offer a CLI this box
|
||||
// lacks (#201's rule), and preselect whatever Run is currently pointing at.
|
||||
const brain = document.getElementById('cloneCaseBrain');
|
||||
if (brain) {
|
||||
for (const option of brain.options) {
|
||||
const cli = option.dataset.cli;
|
||||
option.hidden = !!cli && !this.isCliAvailable(cli);
|
||||
}
|
||||
const current = this.runMode || 'claude';
|
||||
brain.value = [...brain.options].some((o) => o.value === current && !o.hidden) ? current : '';
|
||||
}
|
||||
},
|
||||
|
||||
_setCloneStatus(message, kind) {
|
||||
const el = document.getElementById('cloneRepoStatus');
|
||||
if (!el) return;
|
||||
el.textContent = message;
|
||||
el.className = `form-hint clone-status${kind ? ' clone-status-' + kind : ''}`;
|
||||
},
|
||||
|
||||
/**
|
||||
* Best-effort repo name out of a URL, for filling the case name as you type.
|
||||
*
|
||||
* Deliberately a THIN mirror of `suggestCaseNameFromRepo` (git-clone.ts) rather
|
||||
* than a second URL parser: it only ever suggests a name, and the server's parse
|
||||
* is the authority on whether the URL is cloneable at all. The preflight reply
|
||||
* overwrites whatever this guessed.
|
||||
*/
|
||||
_repoNameFromUrl(url) {
|
||||
const trimmed = (url || '').trim().replace(/\/+$/, '');
|
||||
if (!trimmed) return '';
|
||||
const segment = trimmed
|
||||
.replace(/^[a-zA-Z][a-zA-Z0-9+.-]*:\/\//, '')
|
||||
.replace(/^[^@/]*@/, '')
|
||||
.split(/[/:]/)
|
||||
.filter(Boolean)
|
||||
.pop() || '';
|
||||
return segment
|
||||
.replace(/\.git$/i, '')
|
||||
.replace(/[^a-zA-Z0-9_-]+/g, '-')
|
||||
.replace(/-{2,}/g, '-')
|
||||
.replace(/^[-_]+|[-_]+$/g, '')
|
||||
.slice(0, 64);
|
||||
},
|
||||
|
||||
onCloneNameEdited() {
|
||||
// Once the user types a name, autofill stops fighting them.
|
||||
this._cloneNameEdited = !!document.getElementById('cloneCaseName')?.value.trim();
|
||||
},
|
||||
|
||||
onCloneUrlInput() {
|
||||
const url = document.getElementById('cloneRepoUrl')?.value.trim() || '';
|
||||
const nameInput = document.getElementById('cloneCaseName');
|
||||
if (nameInput && !this._cloneNameEdited) nameInput.value = this._repoNameFromUrl(url);
|
||||
clearTimeout(this._clonePreflightTimer);
|
||||
this._clonePreflightAbort?.abort();
|
||||
this._clonePreflightAbort = null;
|
||||
if (!url) {
|
||||
this._setCloneStatus('Public repositories only: Codeman clones with no credentials.', '');
|
||||
return;
|
||||
}
|
||||
if (this.isCliAvailable('git') === false) {
|
||||
this._setCloneStatus('git is not installed on the Codeman host, so cloning is unavailable.', 'err');
|
||||
return;
|
||||
}
|
||||
this._setCloneStatus('Checking the repository…', '');
|
||||
this._clonePreflightTimer = setTimeout(() => this._runClonePreflight(url), 450);
|
||||
},
|
||||
|
||||
/**
|
||||
* Ask the server to parse the URL and (if it survives) query the remote, so the
|
||||
* user learns "private repo" / "typo" / "3 tags" BEFORE waiting on a clone.
|
||||
* Stale replies are dropped: only the response for the URL currently in the
|
||||
* field is allowed to paint.
|
||||
*/
|
||||
async _runClonePreflight(url) {
|
||||
const controller = new AbortController();
|
||||
this._clonePreflightAbort = controller;
|
||||
try {
|
||||
const res = await fetch('/api/cases/clone-preflight', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ repository: url }),
|
||||
signal: controller.signal,
|
||||
});
|
||||
const env = await res.json();
|
||||
if (document.getElementById('cloneRepoUrl')?.value.trim() !== url) return;
|
||||
if (!env.success) {
|
||||
this._setCloneStatus(env.error || 'Could not check that URL.', 'err');
|
||||
return;
|
||||
}
|
||||
this._applyClonePreflight(env.data, url);
|
||||
} catch (err) {
|
||||
if (err.name === 'AbortError') return;
|
||||
this._setCloneStatus('Could not reach Codeman to check that URL.', 'err');
|
||||
}
|
||||
},
|
||||
|
||||
_applyClonePreflight(data, url) {
|
||||
this._clonePreflight = data;
|
||||
const parse = data?.parse;
|
||||
if (!parse?.cloneable) {
|
||||
this._setCloneStatus(parse?.message || 'That URL cannot be cloned.', 'err');
|
||||
return;
|
||||
}
|
||||
// The server's suggestion wins over the local guess (it is the same function
|
||||
// the case name is validated against), but never over a name the user typed.
|
||||
const nameInput = document.getElementById('cloneCaseName');
|
||||
if (nameInput && !this._cloneNameEdited && parse.suggestedName) nameInput.value = parse.suggestedName;
|
||||
|
||||
const where = parse.owner ? `${parse.provider} ${parse.owner}/${parse.repo}` : `${parse.provider} ${parse.repo}`;
|
||||
if (data.gitAvailable === false) {
|
||||
this._setCloneStatus(`${where}: git is not installed on the Codeman host.`, 'err');
|
||||
return;
|
||||
}
|
||||
const remote = data.remote;
|
||||
if (remote && !remote.reachable) {
|
||||
this._setCloneStatus(`${where}: ${remote.failure?.message || 'the remote could not be read.'}`, 'err');
|
||||
return;
|
||||
}
|
||||
const refHint = document.getElementById('cloneRefHint');
|
||||
const options = document.getElementById('cloneRepoRefOptions');
|
||||
if (remote && options) {
|
||||
options.replaceChildren();
|
||||
for (const ref of [...(remote.branches || []), ...(remote.tags || [])]) {
|
||||
const option = document.createElement('option');
|
||||
option.value = ref;
|
||||
options.appendChild(option);
|
||||
}
|
||||
if (refHint) {
|
||||
const counts = `${remote.branches?.length || 0} branches, ${remote.tags?.length || 0} tags`;
|
||||
refHint.textContent = remote.defaultBranch
|
||||
? `Blank clones the default branch (${remote.defaultBranch}). ${counts} available.`
|
||||
: `Blank clones the default branch. ${counts} available.`;
|
||||
}
|
||||
}
|
||||
const warning = parse.warnings?.[0];
|
||||
this._setCloneStatus(warning ? `${where}: ${warning}` : `${where}: ready to clone.`, warning ? 'warn' : 'ok');
|
||||
},
|
||||
|
||||
async cloneCase() {
|
||||
const url = document.getElementById('cloneRepoUrl').value.trim();
|
||||
const name = document.getElementById('cloneCaseName').value.trim();
|
||||
const ref = document.getElementById('cloneRepoRef').value.trim();
|
||||
const shallow = !!document.getElementById('cloneShallow')?.checked;
|
||||
const brain = document.getElementById('cloneCaseBrain')?.value || '';
|
||||
const startSession = !!document.getElementById('cloneStartSession')?.checked;
|
||||
|
||||
if (!url) {
|
||||
this.showToast('Please enter a repository URL', 'error');
|
||||
return;
|
||||
}
|
||||
if (!name) {
|
||||
this.showToast('Please enter a case name', 'error');
|
||||
return;
|
||||
}
|
||||
if (!/^[a-zA-Z0-9_-]+$/.test(name)) {
|
||||
this.showToast('Invalid name. Use only letters, numbers, hyphens, underscores.', 'error');
|
||||
return;
|
||||
}
|
||||
|
||||
this._setCloneStatus(`Cloning ${url}… this can take a while for a large repository.`, '');
|
||||
try {
|
||||
const res = await fetch('/api/cases/clone', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
// Zod `.optional()` rejects an explicit null, and JSON.stringify keeps one
|
||||
// on the wire — omit the empty fields instead of sending null.
|
||||
body: JSON.stringify({ name, repository: url, ...(ref ? { ref } : {}), ...(shallow ? { shallow: true } : {}) }),
|
||||
});
|
||||
const data = await res.json();
|
||||
if (!data.success) {
|
||||
this._setCloneStatus(data.error || 'Clone failed.', 'err');
|
||||
this.showToast(data.error || 'Failed to clone repository', 'error');
|
||||
return;
|
||||
}
|
||||
|
||||
// Setting the brain before the tab closes means the Run button is already
|
||||
// pointing at the chosen CLI, whether or not a session starts now.
|
||||
if (brain) this.setRunMode(brain);
|
||||
this.closeCreateCaseModal();
|
||||
await this.loadQuickStartCases(name);
|
||||
await this.saveLastUsedCase(name);
|
||||
this.showToast(`Cloned into case "${name}"`, 'success');
|
||||
for (const warning of data.data?.warnings || []) this.showToast(warning, 'warning');
|
||||
if (startSession) await this.run();
|
||||
} catch (err) {
|
||||
// A proxy/idle timeout can kill the request while git keeps going: the
|
||||
// case:created broadcast is what makes the case show up regardless.
|
||||
console.error('Failed to clone repository:', err);
|
||||
this._setCloneStatus(
|
||||
`Lost the connection while cloning: ${err.message}. If git finishes, the case still appears in the list.`,
|
||||
'warn'
|
||||
);
|
||||
this.showToast('Clone request interrupted — watch the case list', 'error');
|
||||
}
|
||||
},
|
||||
|
||||
openLinkCasePathPicker() {
|
||||
const pathInput = document.getElementById('linkCasePath');
|
||||
PathPicker.open({
|
||||
|
||||
Reference in New Issue
Block a user