feat: workspaceHooksEnabled setting as the opt-out for workspace hook installs

Installing hooks into any workspace a Claude session runs in is the right
default, but it takes a decision away from a user who deliberately removed
them: nothing on disk distinguishes "removed on purpose" from "never had any",
so they would come back on the next session create.

Adds the synced workspaceHooksEnabled setting (App Settings -> Agents & CLIs ->
Claude), default ON. OFF restores the older behavior exactly: a Codeman hooks
block that is already present is still refreshed when stale (COD-91), but one
is never added.

Every create path routes through one applyWorkspaceHooks() helper so the gate
cannot apply to some paths only, and the boot-time recovery sweep honours it too.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-08-16 07:05:10 +02:00
parent 98fa8c00d1
commit f485085174
9 changed files with 149 additions and 26 deletions
+2
View File
@@ -19,6 +19,8 @@ export interface ConfigPort {
getTerminalHistoryConfig(): Promise<TerminalHistoryConfig>;
/** Synced `agentSkillEnabled` app setting (default OFF); gates per-case agent-skill injection. */
getAgentSkillEnabled(): Promise<boolean>;
/** Synced `workspaceHooksEnabled` app setting (default ON); gates INSTALLING hooks into a session's workspace. */
getWorkspaceHooksEnabled(): Promise<boolean>;
/** Synced `claudeVoiceEnabled` app setting (default OFF); gates the Claude voice dictation relay. */
getClaudeVoiceEnabled(): Promise<boolean>;
getDefaultClaudeMdPath(): Promise<string | undefined>;
+7
View File
@@ -1984,6 +1984,13 @@
</div>
<label class="switch switch-sm"><input type="checkbox" id="appSettingsAgentSkill"><span class="slider"></span></label>
</div>
<div class="set-row" data-search="workspace hooks alerts approvals notifications settings.local.json">
<div class="set-row-text">
<span class="set-row-label">Workspace Hooks</span>
<span class="set-row-desc">Install Codeman's hooks in each Claude workspace, so tab alerts, the Approvals Inbox and idle detection also work in linked cases and existing repos. Off leaves your repos untouched.</span>
</div>
<label class="switch switch-sm"><input type="checkbox" id="appSettingsWorkspaceHooks"><span class="slider"></span></label>
</div>
<div class="set-row" data-search="remote auto reconnect ssh">
<div class="set-row-text">
<span class="set-row-label">Remote auto-reconnect</span>
+4
View File
@@ -409,6 +409,9 @@ Object.assign(CodemanApp.prototype, {
// Claude Permissions settings
document.getElementById('appSettingsAgentTeams').checked = settings.agentTeamsEnabled ?? false;
document.getElementById('appSettingsAgentSkill').checked = settings.agentSkillEnabled ?? false;
// Default ON: an absent key is a user who has never seen this setting, and OFF
// for them means no tab alerts in any workspace Codeman did not scaffold.
document.getElementById('appSettingsWorkspaceHooks').checked = settings.workspaceHooksEnabled !== false;
document.getElementById('appSettingsClaudeModel').value = settings.claudeModel ?? '';
document.getElementById('appSettingsOpusContext1m').checked = settings.opusContext1mEnabled ?? false;
document.getElementById('appSettingsRemoteAutoReconnect').checked = settings.remoteAutoReconnect ?? true;
@@ -2017,6 +2020,7 @@ Object.assign(CodemanApp.prototype, {
// Claude Permissions settings
agentTeamsEnabled: document.getElementById('appSettingsAgentTeams').checked,
agentSkillEnabled: document.getElementById('appSettingsAgentSkill').checked,
workspaceHooksEnabled: document.getElementById('appSettingsWorkspaceHooks').checked,
claudeVoiceEnabled: document.getElementById('appSettingsClaudeVoice').checked,
claudeModel: document.getElementById('appSettingsClaudeModel').value,
opusContext1mEnabled: document.getElementById('appSettingsOpusContext1m').checked,
+38 -25
View File
@@ -626,6 +626,32 @@ async function injectAgentSkill(casePath: string): Promise<void> {
}
}
/**
* Hooks for the workspace a Claude session is about to run in. ONE decision point,
* shared by every create path, so the setting cannot apply to some of them only.
*
* ON (`workspaceHooksEnabled`, the default): INSTALL Codeman's hooks block, merging
* so a user's own hook entries and every other settings key survive. Hooks were
* previously written only when Codeman CREATED the case DIRECTORY, so a linked case
* or any pre-existing repo — where most sessions actually run — had none, and every
* hook-driven surface was silently dead there: no tab alert or phone-overview row
* when a dialog blocks the pane, no Approvals Inbox item, no push, no definitive
* `stop`/`idle_prompt` for respawn, and no `stop`/`blocked` for the wait endpoints.
* Measured 2026-08-15 in a linked case: an AskUserQuestion dialog on screen with the
* tab reporting a calm `idle`. Claude Code re-reads the file, so a session already
* running in that workspace starts firing hooks without a restart (verified live).
*
* OFF: the older, narrower behavior. A Codeman block that is already there is still
* refreshed when stale (COD-91: a pre-secret block 401s once the hook-secret gate
* went unconditional), but one is never added, so Codeman leaves the repo alone.
*
* Best-effort either way: a refusal or a thrown error must never fail the create.
*/
async function applyWorkspaceHooks(ctx: ConfigPort, workspace: string): Promise<void> {
const install = await ctx.getWorkspaceHooksEnabled();
await (install ? ensureCodemanHooks(workspace) : refreshStaleCodemanHooks(workspace)).catch(() => {});
}
export function registerSessionRoutes(
app: FastifyInstance,
ctx: SessionPort & EventPort & ConfigPort & InfraPort & AuthPort
@@ -766,21 +792,10 @@ export function registerSessionRoutes(
await applyStatusLineConfig(workingDir, true);
}
// Hooks for the workspace this session runs in. ADD-ONLY and merge-based:
// Codeman's own handlers are (re)written, a user's own hook entries are kept.
//
// This used to be `refreshStaleCodemanHooks`, which deliberately never ADDS —
// and `writeHooksConfig` only runs when Codeman CREATES a case directory. So a
// session in a LINKED case or any pre-existing repo (where most sessions live)
// got no hooks block at all, and every hook-driven surface was silently dead
// there: no permission/question tab alert, no Approvals Inbox item, no push,
// no definitive `stop`/`idle_prompt` for respawn, and no `stop`/`blocked` for
// the agent wait endpoints. Measured 2026-08-15 on a linked case: an
// AskUserQuestion dialog sat on screen with the tab showing plain `idle`.
// Claude Code re-reads the file, so a session already running in that
// workspace starts firing hooks too (verified live, same day).
// Hooks for the workspace this session runs in (install vs refresh-only is the
// `workspaceHooksEnabled` setting; see applyWorkspaceHooks).
if ((body.mode ?? 'claude') === 'claude') {
await ensureCodemanHooks(workingDir).catch(() => {});
await applyWorkspaceHooks(ctx, workingDir);
// Agent skill (docs/agent-control-plan.md §2): ADD-ONLY on create, same shared-
// .claude rationale as the statusLine above: a create must never remove the
// skill from under other live sessions in the repo. Marker-guarded, so a
@@ -2911,15 +2926,13 @@ export function registerSessionRoutes(
}
} else if (!remote && !docker && mode !== 'opencode') {
// EXISTING case directory (a linked case, a cloned repo, anything Codeman did
// not scaffold). Claude mode INSTALLS the hooks block when it is missing and
// refreshes ours when it is stale — a linked case never got one otherwise, which
// left every hook-driven surface dead there (see POST /api/sessions above).
// Other modes keep the narrower COD-91 self-heal: only claude reads `.claude`
// hooks, so a shell/codex quick-start should not author a block of its own.
// Skipped for remote cases — resolvedCasePath is a REMOTE path that doesn't
// exist on the local filesystem.
// not scaffold): install-or-refresh per the setting (see applyWorkspaceHooks).
// Other modes keep the narrower COD-91 self-heal unconditionally: only claude
// reads `.claude` hooks, so a shell/codex quick-start should not author a block
// of its own. Skipped for remote cases — resolvedCasePath is a REMOTE path that
// doesn't exist on the local filesystem.
if (mode === 'claude') {
await ensureCodemanHooks(resolvedCasePath).catch(() => {});
await applyWorkspaceHooks(ctx, resolvedCasePath);
} else {
await refreshStaleCodemanHooks(resolvedCasePath).catch(() => {});
}
@@ -2956,9 +2969,9 @@ export function registerSessionRoutes(
await writeHooksConfig(resolvedCasePath);
} else {
// A settings file with no hooks in it is the same dead-surface case as a
// linked case: this branch is already gated on `docker.hooksEnabled`, so
// install ours rather than only refreshing an existing block.
await ensureCodemanHooks(resolvedCasePath).catch(() => {});
// linked case. This branch is already gated on `docker.hooksEnabled`, and
// applyWorkspaceHooks adds the user-level gate on top.
await applyWorkspaceHooks(ctx, resolvedCasePath);
}
} catch {
/* non-fatal — the session still runs, hooks may be degraded */
+11
View File
@@ -906,6 +906,17 @@ export const SettingsUpdateSchema = z
* add-only at create; a marker keeps user-authored copies untouched.
*/
agentSkillEnabled: z.boolean().optional(),
/**
* Install Codeman's hooks block into the workspace of every Claude session,
* not only into cases Codeman scaffolded itself. SYNCED, default ON: without
* it a linked case or an existing repo runs with no hooks at all, and each
* hook-driven surface is silently dead there (tab alert, Approvals Inbox,
* push, respawn's definitive idle signals, the wait endpoints' stop/blocked).
* Turning it OFF restores the older, narrower behavior — a Codeman hooks
* block that is already present is still refreshed when stale, but one is
* never added — for a user who wants Codeman to leave their repos alone.
*/
workspaceHooksEnabled: z.boolean().optional(),
/**
* Let browser dictation transcribe through this machine's Claude Code login,
* the same speech-to-text service the CLI's own `/voice` mode uses
+16
View File
@@ -637,6 +637,7 @@ export class WebServer extends EventEmitter {
getClaudeModeConfig: this.getClaudeModeConfig.bind(this),
getTerminalHistoryConfig: this.getTerminalHistoryConfig.bind(this),
getAgentSkillEnabled: this.getAgentSkillEnabled.bind(this),
getWorkspaceHooksEnabled: this.getWorkspaceHooksEnabled.bind(this),
getClaudeVoiceEnabled: this.getClaudeVoiceEnabled.bind(this),
getDefaultClaudeMdPath: this.getDefaultClaudeMdPath.bind(this),
getLightState: this.getLightState.bind(this),
@@ -1711,6 +1712,16 @@ export class WebServer extends EventEmitter {
return settings.agentSkillEnabled === true;
}
// Whether a Claude session installs Codeman's hooks block into its workspace
// (synced `workspaceHooksEnabled` setting). Default ON — an absent key means a
// user who has never seen this setting, and OFF for them would mean no tab
// alerts, no Approvals Inbox and no respawn idle signals in every workspace
// Codeman did not scaffold itself.
private async getWorkspaceHooksEnabled(): Promise<boolean> {
const settings = await this.readSettings();
return settings.workspaceHooksEnabled !== false;
}
// Whether browser dictation may use this machine's Claude Code credentials
// (synced `claudeVoiceEnabled` setting, default OFF; docs/claude-voice-plan.md).
// OFF by default because turning it on spends the operator's Claude subscription
@@ -2866,8 +2877,13 @@ export class WebServer extends EventEmitter {
* Failures are swallowed per workspace: `ensureCodemanHooks` already refuses
* unsafe targets with a warning, and a workspace we cannot write to must not
* stop the rest of recovery.
*
* Skipped entirely when `workspaceHooksEnabled` is OFF: that setting exists so a
* user can keep Codeman out of their repos, and a boot-time sweep is the last
* place that should ignore it.
*/
private async ensureHooksForRecoveredWorkspaces(): Promise<void> {
if (!(await this.getWorkspaceHooksEnabled())) return;
const workspaces = new Set<string>();
for (const session of this.sessions.values()) {
if (session.mode !== 'claude' || session.remote) continue;