mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 07:59:42 +02:00
COD-37 add server-side attachment pipeline (registry, magic-link, path guard)
Adds the foundation for serving local files to the browser as live external attachments with a stable id, so requests never carry arbitrary absolute paths. - attachment-registry: in-memory, session-scoped registry. registerExternalAttachment validates an absolute path, resolves symlinks, enforces the path guard, and mints an `att_<uuid>` id; records are cleared when the session is removed. - attachment path guard: a configurable blocklist (secret locations + /root,/etc trees, extendable via attachmentBlockedPaths / CODEMAN_ATTACHMENT_BLOCKED_PATHS) plus an optional, default-off workspace-confinement mode. Shares one sensitive-path blocklist (web/sensitive-path.ts) with /api/download, which is refactored to use the extracted module instead of an inline copy. - terminal magic links: the session scans output for codeman://attach?path=... and emits `attachmentRequested`; the web server registers the file and broadcasts an `attachment:detected` SSE event. `codeman attach <path>` (CLI) prints the magic link or POSTs directly when a session id is known. - image watcher: detects png/pdf/docx/pptx dropped into a session's working dir and emits `attachment:detected`. - routes: POST /api/sessions/:id/attachments (register) and GET /api/sessions/:id/attachments/:attachmentId/raw (serve), both re-checking the guard before streaming. Document previews/thumbnails and the attachment-history drawer build on this foundation and land separately. Verified: tsc --noEmit, lint, format, frontend-syntax, full test:ci (2846 passed), and a server boot smoke (/api/status 200).
This commit is contained in:
+37
-1
@@ -7,13 +7,14 @@
|
||||
* - ActiveBashTool — a live bash command with extracted file paths and status
|
||||
* - ActiveBashToolStatus — 'running' | 'completed'
|
||||
* - ImageDetectedEvent — screenshot/image file detection trigger for UI popup
|
||||
* - AttachmentDetectedEvent — document/image file detection trigger for attachment cards
|
||||
*
|
||||
* Cross-domain relationships:
|
||||
* - ActiveBashTool.sessionId links to SessionState.id (session domain)
|
||||
* - ImageDetectedEvent.sessionId links to SessionState.id (session domain)
|
||||
*
|
||||
* Both types are in-memory only (not persisted). Broadcast via SSE events
|
||||
* `subagent:tool_call` and `image:detected`. Parsed by BashToolParser
|
||||
* `subagent:tool_call`, `image:detected`, and `attachment:detected`. Parsed by BashToolParser
|
||||
* (`src/bash-tool-parser.ts`).
|
||||
*/
|
||||
|
||||
@@ -61,3 +62,38 @@ export interface ImageDetectedEvent {
|
||||
/** File size in bytes */
|
||||
size: number;
|
||||
}
|
||||
|
||||
export type AttachmentDetectedType = 'image' | 'pdf' | 'document' | 'presentation' | 'markdown' | 'text';
|
||||
|
||||
/**
|
||||
* Event emitted when a new previewable attachment file is detected in a session's
|
||||
* working directory. Used to render a compact attachment card in the web UI.
|
||||
*/
|
||||
export interface AttachmentDetectedEvent {
|
||||
/** Codeman session ID where the attachment was detected */
|
||||
sessionId: string;
|
||||
/** Full path to the detected attachment file */
|
||||
filePath: string;
|
||||
/** Path relative to the session's working directory (for file-raw/file-preview endpoints) */
|
||||
relativePath: string;
|
||||
/** Attachment file name (basename) */
|
||||
fileName: string;
|
||||
/** Lowercase extension without a leading dot */
|
||||
extension: string;
|
||||
/** Viewer category used by the web UI */
|
||||
attachmentType: AttachmentDetectedType;
|
||||
/** Timestamp when the attachment was detected */
|
||||
timestamp: number;
|
||||
/** File size in bytes */
|
||||
size: number;
|
||||
/** Registered attachment id for explicit live external attachments */
|
||||
attachmentId?: string;
|
||||
/** Source of the attachment card request */
|
||||
source?: 'detected' | 'external';
|
||||
/** Raw file route for explicit attachments */
|
||||
rawUrl?: string;
|
||||
/** Inline preview route for explicit attachments */
|
||||
previewUrl?: string;
|
||||
/** First-page thumbnail route for card previews */
|
||||
thumbnailUrl?: string;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user