docs: clarify HTTP is fine for localhost, HTTPS only for remote

Localhost is treated as a secure context by browsers, so notifications
and all browser APIs work without HTTPS. Updated README, CLI help,
install script, and systemd service to default to HTTP.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
arkon
2026-01-29 11:47:24 +01:00
co-authored by Claude Opus 4.5
parent 8c908ec5e4
commit d040722d1d
7 changed files with 16 additions and 14 deletions
+2 -2
View File
@@ -16,7 +16,7 @@ When user says "COM":
1. Increment version in BOTH `package.json` AND `CLAUDE.md`
2. Run: `git add -A && git commit -m "chore: bump version to X.XXXX" && git push && npm run build && systemctl --user restart claudeman-web`
**Version**: 0.1423 (must match `package.json`)
**Version**: 0.1424 (must match `package.json`)
## Project Overview
@@ -35,7 +35,7 @@ Claudeman is a Claude Code session manager with web interface and autonomous Ral
```bash
# Development
npx tsx src/index.ts web # Dev server (RECOMMENDED)
npx tsx src/index.ts web --https # With TLS for notifications
npx tsx src/index.ts web --https # With TLS (only needed for remote access)
npm run typecheck # Type check
# Testing
+5 -3
View File
@@ -48,7 +48,7 @@ Real-time desktop notifications when sessions need attention — never miss a pe
- Tab blinking alerts: red for action-required, yellow for idle
- Notifications include actual context (tool name, command, question text)
- Hooks are auto-configured per case directory (`.claude/settings.local.json`)
- Requires `--https` flag for browser notification API support
- Works on HTTP for local use (localhost is a secure context)
---
@@ -298,11 +298,13 @@ npm install -g claudeman
## Getting Started
```bash
claudeman web --https
# Open https://localhost:3000
claudeman web
# Open http://localhost:3000
# Press Ctrl+Enter to start your first session
```
> **Note:** HTTP works fine for local use since `localhost` is treated as a secure context by browsers. Use `--https` only when accessing from another machine on your network.
---
## Keyboard Shortcuts
+3 -3
View File
@@ -612,7 +612,7 @@ After=network.target
[Service]
Type=simple
ExecStart=$node_path $INSTALL_DIR/dist/index.js web --https
ExecStart=$node_path $INSTALL_DIR/dist/index.js web
WorkingDirectory=$HOME
Restart=always
RestartSec=10
@@ -863,11 +863,11 @@ main() {
echo -e " ${CYAN}# Start the web server${NC}"
echo -e " claudeman web"
echo ""
echo -e " ${CYAN}# Start with HTTPS (enables browser notifications)${NC}"
echo -e " ${CYAN}# Start with HTTPS (only needed for remote access)${NC}"
echo -e " claudeman web --https"
echo ""
echo -e " ${CYAN}# Open in browser${NC}"
echo -e " https://localhost:3000"
echo -e " http://localhost:3000"
echo ""
if [[ "$os" == "linux" ]] && [[ -f "$HOME/.config/systemd/user/claudeman-web.service" ]]; then
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "claudeman",
"version": "0.1423",
"version": "0.1424",
"description": "The missing control plane for Claude Code - run 20 autonomous agents with real-time monitoring and session persistence",
"type": "module",
"main": "dist/index.js",
+2 -2
View File
@@ -1,11 +1,11 @@
[Unit]
Description=Claudeman Web Server (HTTPS)
Description=Claudeman Web Server
After=network.target
[Service]
Type=simple
WorkingDirectory=/home/arkon/default/claudeman
ExecStart=/usr/bin/node dist/index.js web --https
ExecStart=/usr/bin/node dist/index.js web
Restart=always
RestartSec=5
KillMode=process
+2 -2
View File
@@ -185,8 +185,8 @@ if (hasErrors) {
console.log(colors.bold('Next steps:'));
console.log(colors.dim(' 1. Build: ') + colors.cyan('npm run build'));
console.log(colors.dim(' 2. Start: ') + colors.cyan('claudeman web --https'));
console.log(colors.dim(' 3. Open: ') + colors.cyan('https://localhost:3000'));
console.log(colors.dim(' 2. Start: ') + colors.cyan('claudeman web'));
console.log(colors.dim(' 3. Open: ') + colors.cyan('http://localhost:3000'));
if (hasWarnings) {
console.log('');
+1 -1
View File
@@ -493,7 +493,7 @@ program
.command('web')
.description('Start the web interface')
.option('-p, --port <port>', 'Port to listen on', '3000')
.option('--https', 'Enable HTTPS with a self-signed certificate (enables browser Notifications API)')
.option('--https', 'Enable HTTPS with self-signed certificate (only needed for remote access, not localhost)')
.action(async (options) => {
const { startWebServer } = await import('./web/server.js');
const port = parseInt(options.port, 10);