From 88e3faa456cdbc23f33b9b78d8c9a73479f74d3a Mon Sep 17 00:00:00 2001 From: Codeman maintainer Date: Tue, 15 Sep 2026 00:07:19 +0200 Subject: [PATCH] chore: version packages --- .changeset/fix-webview-route-masking.md | 18 ------ .changeset/remote-file-access.md | 34 ---------- .changeset/tidy-codex-shift-arrows.md | 5 -- .changeset/xterm6-selection-background.md | 5 -- .claude-plugin/marketplace.json | 2 +- CHANGELOG.md | 75 ++++++++++++++++++++++ CLAUDE.md | 2 +- package-lock.json | 4 +- package.json | 2 +- plugins/codeman/.claude-plugin/plugin.json | 2 +- 10 files changed, 81 insertions(+), 68 deletions(-) delete mode 100644 .changeset/fix-webview-route-masking.md delete mode 100644 .changeset/remote-file-access.md delete mode 100644 .changeset/tidy-codex-shift-arrows.md delete mode 100644 .changeset/xterm6-selection-background.md diff --git a/.changeset/fix-webview-route-masking.md b/.changeset/fix-webview-route-masking.md deleted file mode 100644 index 6f542d7a..00000000 --- a/.changeset/fix-webview-route-masking.md +++ /dev/null @@ -1,18 +0,0 @@ ---- -"aicodeman": patch ---- - -fix(webview): let a proxied single-page app route on its own path, and recover a frame that reloads - -A dashboard served through a web tab saw `/webview//` as its `location.pathname`, and -no app has a route for that: a React Router, Vue Router or Vite dev-server page painted its -HTML and CSS and then replaced them with its own "page not found" the moment its script ran. -The proxy's runtime shim now rewrites the history entry to the path the page would see on its -own origin before any page script runs, while every URL the page emits still goes through -the existing rewrite layers (plus `Worker`, `sendBeacon` and `window.open`, which the masked -Referer can no longer rescue). A navigation the page starts itself afterwards — a dev -server's full-reload HMR, a root-absolute `location.href` — lands on Codeman's root with no -capability; it is recognised by shape (an iframe navigation asking for HTML for a path Codeman -does not serve), answered with a static page that tells the owning tab which path was lost, -and the tab remounts the frame inside the prefix at that path. That answer is served before -the credential checks, so it never counts as a failed login. diff --git a/.changeset/remote-file-access.md b/.changeset/remote-file-access.md deleted file mode 100644 index bd399c09..00000000 --- a/.changeset/remote-file-access.md +++ /dev/null @@ -1,34 +0,0 @@ ---- -"aicodeman": patch ---- - -File previews, downloads and text reads now work in a **remote (SSH) case**. - -A remote case's working directory is an absolute path on the *remote* host, but the -file routes resolved it with local `fs` — so a clicked path (or the File Viewer) always -failed as "File not found" even though the file existed and the session was clearly -working in that directory. `GET /api/sessions/:id/file-raw`, `file-content`, -`file-preview` and `file-thumbnail` now resolve and read through the same -`buildSshConnectionArgs()` connection the launch uses (`src/remote-files.ts`, one -`realpath`+`stat` probe per request returning both the file and the workspace root). - -Clicked paths that point OUTSIDE the case directory (a remote `/tmp` scratchpad capture, -a screenshot elsewhere in the remote home) go through the attachment routes, which had -the same local-`fs` assumption: registration, the by-id `raw` stream, the metadata poll -and the attachment history list now resolve over ssh as well, so the click-path works -whether the file sits inside or outside the case. Which host a record is read from -follows the SESSION, never the path string — the same absolute path means a different -file on each host, and a remote session never falls back to a local file. - -The guards are unchanged in strength: the workspace boundary is still enforced (now -resolved on the host that can actually resolve it), the sensitive-path blocklist and -the size cap (`CODEMAN_MAX_DOWNLOAD_BYTES`) still apply before any bytes are read, and -`Range` requests keep working, so remote `