From 82c31b6073766334758ceab40da3bbbc1b652c61 Mon Sep 17 00:00:00 2001 From: arkon Date: Tue, 9 Jun 2026 00:39:19 +0200 Subject: [PATCH] feat(installer): show network-security notice at end of install/update install.sh now prints the loopback-bind security notice as the final block of both the one-line fresh install and the update flow, so it stays visible. Also documents that gesture control remains opt-in / default-off (changeset). Co-Authored-By: Claude Opus 4.8 (1M context) --- CHANGELOG.md | 8 ++++++++ CLAUDE.md | 2 +- install.sh | 20 ++++++++++++++++++++ package-lock.json | 4 ++-- package.json | 2 +- 5 files changed, 32 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 74fd7f59..e3721e72 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,13 @@ # aicodeman +## 0.9.3 + +### Patch Changes + +- Installer security notice + clarify gesture control stays opt-in and default-off. + - **Installer:** `install.sh` now prints the network-security notice as the final block of both the fresh install (one-line `curl … | bash`) and the update flow, so it stays visible to the user: Codeman binds `127.0.0.1` by default (no password needed), and the safe ways to reach it remotely (`tailscale serve` / tunnel, or `--host 0.0.0.0` + `CODEMAN_PASSWORD`), noting a non-loopback bind without a password still starts but warns loudly. + - **Gesture control** is **disabled by default** and is enabled only by the per-user toggle at App Settings → Display → Input → Gesture Control (`gestureControlEnabled`, default `false`). Setting `CODEMAN_GESTURE=1` on the server only makes the feature _available_ (CSP widening + same-origin `/gesture/` assets); it does **not** turn the overlay on. There is no default-on path — the bundle is injected only when a user explicitly enables the setting. + ## 0.9.2 ### Patch Changes diff --git a/CLAUDE.md b/CLAUDE.md index b5058705..4fcc71ca 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -56,7 +56,7 @@ When user says "COM": CI runs `npm run check:lockfile` on every push/PR, so lockfile drift fails the build even if the `version-packages` script is bypassed. -**Version**: 0.9.2 (must match `package.json`) +**Version**: 0.9.3 (must match `package.json`) ## Project Overview diff --git a/install.sh b/install.sh index 4ced9a39..4380a915 100755 --- a/install.sh +++ b/install.sh @@ -99,6 +99,20 @@ die() { exit 1 } +# Security notice — printed at the very end of install/update so it is the last +# thing the user sees (the default loopback bind + how to expose it safely). +print_security_notice() { + echo "" + echo -e " ${YELLOW}${BOLD}Security:${NC}" + echo -e " Codeman binds ${BOLD}127.0.0.1${NC} (this machine only) — no password needed by default." + echo -e " To reach it from another device, do ONE of:" + echo -e " ${CYAN}•${NC} tailscale serve / cloudflared tunnel ${DIM}(recommended)${NC}, or" + echo -e " ${CYAN}•${NC} ${CYAN}codeman web --host 0.0.0.0${NC} AND set ${CYAN}CODEMAN_PASSWORD${NC}" + echo -e " A non-loopback bind without a password still starts, but warns loudly." + echo -e " ${DIM}Details: docs/security-architecture.md${NC}" + echo "" +} + # ============================================================================ # Cleanup on Failure # ============================================================================ @@ -1363,6 +1377,10 @@ main() { echo "" fi + # Security notice — last informational block so it stays visible (when not + # auto-launching below; if we exec, the server prints the same notice anyway). + print_security_notice + # Run now in foreground (must be last — exec replaces the shell) if [[ "$launch_choice" == "1" ]]; then local profile @@ -1410,6 +1428,8 @@ update() { echo -e " ${CYAN}pkill -f 'codeman.*web'; codeman web &${NC}" fi echo "" + + print_security_notice } uninstall() { diff --git a/package-lock.json b/package-lock.json index 8371ef88..6966bbfb 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "aicodeman", - "version": "0.9.2", + "version": "0.9.3", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "aicodeman", - "version": "0.9.2", + "version": "0.9.3", "hasInstallScript": true, "license": "MIT", "workspaces": [ diff --git a/package.json b/package.json index 99052425..3defb686 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "aicodeman", - "version": "0.9.2", + "version": "0.9.3", "description": "The missing control plane for AI coding agents - run 20 autonomous agents with real-time monitoring and session persistence", "type": "module", "main": "dist/index.js",