From 6f7add7ce4b5d5f796617f3fab671cc345ba1120 Mon Sep 17 00:00:00 2001 From: Codeman maintainer Date: Fri, 4 Sep 2026 20:46:19 +0200 Subject: [PATCH] chore: version packages --- .changeset/docker-self-update.md | 37 -------------------------------- CHANGELOG.md | 15 +++++++++++++ CLAUDE.md | 2 +- package-lock.json | 4 ++-- package.json | 2 +- 5 files changed, 19 insertions(+), 41 deletions(-) delete mode 100644 .changeset/docker-self-update.md diff --git a/.changeset/docker-self-update.md b/.changeset/docker-self-update.md deleted file mode 100644 index 00c2ccc3..00000000 --- a/.changeset/docker-self-update.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -'aicodeman': minor ---- - -Restore in-app self-update for the Docker Compose deployment. - -App Settings → Updates now works in the container, using the same updater, -status file and progress UI as a bare-host install. The Compose file mounts the -checkout it builds from at `/opt/codeman`, so an update's `git checkout` and -rebuild land on the host and survive container recreation, and the restart is -the server exiting — `restart: unless-stopped` relaunches it on the new build. - -An in-place container update applies application code only, since a restarted -container reuses its existing image and configuration. The updater therefore -refuses a release that changes `docker/server.Dockerfile` or -`docker/docker-compose.yaml`, or that adds keys to `docker/.env.example` the -user's `.env` has no value for, naming what changed and pointing at -`docker/Start-Codeman.sh` on the host. It also refuses when the container's -restart policy would not bring it back. The missing-key check matters most: -Compose resolves an unset `${VAR}` to the empty string and starts anyway, so a -new required setting would otherwise arrive as a silently blank variable. - -Supporting changes: - -- The runtime image keeps devDependencies and gains `python3`/`make`/`g++`, so - `npm install` and `npm run build` can run inside the container. This makes the - image larger; that is the cost of updating in place. -- Build artefacts live in `codeman-node-modules` and `codeman-dist` named - volumes so container-compiled native modules never land in the host checkout. -- The four global agent CLIs are pinned, so a release needing newer CLI - behaviour becomes a Dockerfile change the environment gate can detect. -- `docker/Start-Codeman.sh` records the Dockerfile and compose fingerprints the - container was created from, which is the baseline the gate compares against. -- New CI guard: `test/docker-compose-env-parity.test.ts` fails when a compose - variable has no `.env.example` entry, or the reverse. - -Documented in `docs/docker-self-update.md`. diff --git a/CHANGELOG.md b/CHANGELOG.md index eabd355e..f055d023 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,20 @@ # aicodeman +## 1.24.7 + +### Patch Changes + +- The web-tab proxy refuses link-local and cloud-metadata targets. Its Test probe, the proxy itself and the WebSocket relay accepted any http(s) host, so a saved dashboard URL could reach `169.254.169.254` (in decimal, hex, IPv6-mapped or DNS-name form) through a capability and no cookie. Loopback and RFC1918 addresses stay allowed on purpose, since a localhost Grafana is the feature; only link-local and the fixed cloud-metadata addresses are refused, at the schema, at every connect site, and through a DNS lookup hook that judges the resolved addresses, which is what closes DNS rebinding. Adds `undici` so the proxy runs its fetch through its own agent. + + Proxy capabilities are revoked on logout. `revokeOwner()` had shipped with no caller, so a leaked proxy URL stayed valid for as long as anything kept polling it. `POST /api/logout`, the admin forced logout and user deletion now revoke the capabilities they should, and proxied responses carry `Referrer-Policy: same-origin` with the upstream's own policy dropped, so a dashboard on a loose referrer policy cannot hand the capability to a third-party host it links to. + + The Docker Compose deployment updates itself from App Settings again (#373, @opticon454). The checkout Compose builds from is bind-mounted at `/opt/codeman`, so an update's `git checkout` and rebuild land on the host and survive container recreation; build artefacts live in named volumes so container-compiled native modules never enter the host checkout; the image keeps devDependencies and a build toolchain; and the restart is the server exiting under `restart: unless-stopped`. An in-place update applies code only, so the updater refuses a release that changes `server.Dockerfile` or `docker-compose.yaml`, or that adds keys to `.env.example` the user's `.env` has no value for (Compose interpolates an unset variable to the empty string and starts anyway), and points at `docker/Start-Codeman.sh` on the host instead. The four global agent CLIs in the image are pinned. A follow-up makes the final step fail safe: the server exits only when the Compose file declares `CODEMAN_RESTART_BY_EXIT=1` or the daemon confirms an auto-restart policy, and otherwise the build is staged for a manual restart, so a container nothing would restart is never taken down. Details in `docs/docker-self-update.md`. + + The test suite strips `CODEMAN_INSTANCE`, `CODEMAN_DATA_DIR` and `CODEMAN_TMUX_SOCKET` before any application module loads (#371, @opticon454), with a two-half test whose static half reads `test/setup.ts` so a dropped line fails everywhere. This replaces the throwaway data dir #356 had set for the same variable. + + ### Thanks + - @opticon454 for the Compose self-update (#373) and the test isolation fix (#371). + ## 1.24.6 ### Patch Changes diff --git a/CLAUDE.md b/CLAUDE.md index bbbbef02..a2fdb8de 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -75,7 +75,7 @@ When user says "COM": CI runs `npm run check:lockfile` on every push/PR, so lockfile drift fails the build even if the `version-packages` script is bypassed. -**Version**: 1.24.6 (must match `package.json`) +**Version**: 1.24.7 (must match `package.json`) ## Project Overview diff --git a/package-lock.json b/package-lock.json index b08891bd..32ef8018 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "aicodeman", - "version": "1.24.6", + "version": "1.24.7", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "aicodeman", - "version": "1.24.6", + "version": "1.24.7", "hasInstallScript": true, "license": "MIT", "workspaces": [ diff --git a/package.json b/package.json index efd66bba..b26242e9 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "aicodeman", - "version": "1.24.6", + "version": "1.24.7", "description": "Mission control for AI coding agents - run 20 autonomous agents with real-time monitoring and session persistence", "type": "module", "main": "dist/index.js",