Consolidate duplicated MockSession/MockStateStore into test/mocks/,
migrate respawn tests to shared mocks, and add 58 route tests for
session, system, and respawn endpoints using Fastify app.inject().
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds ephemeral single-use QR tokens for passwordless tunnel login.
Scanning the QR auto-authenticates; bare tunnel URL requires Basic Auth.
Backend:
- TunnelManager: 60s token rotation, 90s grace, rejection-sampled 6-char
base62 short codes, Map-based O(1) lookup, SVG caching, global rate limit
- Auth middleware: /q/ bypass, separate qrAuthFailures counter, enhanced
AuthSessionRecord with device context (ip, ua, createdAt, method)
- Routes: GET /q/:code (consume + cookie + redirect), POST /api/tunnel/qr/
regenerate, POST /api/auth/revoke, updated GET /api/tunnel/qr with cache
- SSE: tunnel:qrRotated, tunnel:qrRegenerated, tunnel:qrAuthUsed events
- Audit: qr_auth lifecycle log entries
Frontend:
- Auto-refresh QR via inline SVG in SSE (fallback fetch if absent)
- 60s countdown indicator on QR badge
- Regenerate QR button
- QRLjacking detection toast with [Revoke All] action button (10s duration)
- showToast enhanced with optional duration and action button support
Fixes:
- /api/logout now invalidates server-side session token (was only clearing
browser cookie, leaving token valid for replay)
Tests: 20 new tests in test/qr-auth.test.ts covering token lifecycle,
bias check, rate limiting, SVG caching, and full server integration.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add _isStopped guard to OpenCode 3s readiness timeout (session.ts)
- Block respawn for opencode sessions on interactive-respawn and
respawn/enable routes (server.ts)
- Fail fast in direct PTY fallback for OpenCode mode (session.ts)
- Validate configContent as JSON at schema level (schemas.ts)
- Update JSDoc example for createSession options API (tmux-manager.ts)
- Un-hide Context tab for OpenCode sessions (index.html)
- Add OpenCode UI tests (opencode-resize.test.ts)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Root cause bugs fixed in local echo overlay:
1. Stored flushed text as string (_flushedText, _flushedTexts Map) to avoid reading stale terminal buffer
2. Overlay stays visible when pendingText empties but flushed > 0
3. Backspace into flushed text has immediate visual feedback
4. _flushedTexts.delete() added alongside _flushedOffsets.delete() in Enter/Ctrl+C/cleanup
5. OSC terminal responses (xterm color queries) no longer clear flushed text state —
was triggered by _handleColorEvent → triggerDataEvent during buffer load after tab switch
Added comprehensive test suite (test/local-echo-user-test.mjs): 39 tests across 9 groups
including line wrapping, tab switch round-trips, backspace into flushed text, and more.
All 6 test suites pass (133 total assertions).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Strip localEchoEnabled from server PUT payload (stays in device-specific
localStorage only). Add to displayKeys as safety net for stale server values.
chore: bump version to 0.1588
Bug 1 (CRITICAL): canonicalCount >= 1 always fired on first <promise> tag
(prompt echo). Changed to >= 2 so only 2nd+ occurrence triggers completion.
Bug 2: checkMultiLinePatterns() re-detected complete tags already handled
by processLine(), double-counting. Now only tries completion when partial
buffer is non-empty (cross-chunk scenario).
Bug 3: TodoWrite ✔ patterns required "Task #N" but real Claude Code output
is plain "✔ content". Added TODO_PLAIN_CHECKMARK_PATTERN fallback.
Includes 71 new deep tests + real-life verification.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1. handleInit crash: commit cdc822d removed Map initializations for
teammateTerminals, teammatePanesByName, teams, teamTasks, teammateMap
from the constructor but left cleanup code that iterates them.
cleanupAllFloatingWindows() crashed on "not iterable", preventing
ALL frontend data (sessions, subagents) from loading.
2. claudeSessionId null on recovered sessions: only set inside
startInteractive(), never in constructor or persisted. After server
restart, recovered sessions had null claudeSessionId, so the
hasMatchingTab check always failed → no subagent windows.
Fixes:
- Re-add all 5 missing Map initializations in app.js constructor
- Set _claudeSessionId = this.id in Session constructor (Claudeman
always passes --session-id to Claude, so they always match)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Added IS_TEST_MODE (process.env.VITEST) guards to every method in TmuxManager and
ScreenManager that touches real tmux/screen sessions. Tests can never create, kill,
discover, or send input to real sessions. Removed broken E2E test suite entirely.
Rewrote test/setup.ts from 459 lines to minimal cleanup. Rewrote tmux-related tests
to verify test-mode safety behavior.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
feat: interactive teammate tmux pane windows with xterm.js terminals
feat: auto-cleanup teams/subagents/pane windows on session delete
fix: only show agent/teammate windows when matching Claudeman tab exists
fix: UTF-8 encoding in teammate pane terminal output (Uint8Array)
fix: standalone pane window cleanup via subagentParentMap lookup
fix: xterm.js dimensions crash with deferred init + null-safe dispose
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add comprehensive tests for the cleanup patterns used to prevent
memory leaks in long-running sessions:
- Task description cache with TTL expiration
- Promise callback null-after-rejection pattern
- Event listener tracking and removal
- DOM handler storage for frontend cleanup
- Timer/interval management
- Map cleanup patterns and safe iteration
- WeakRef/WeakMap usage patterns
- Cleanup order verification (LIFO)
Update CLAUDE.md with reference to new test file.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Previously killOrphanedTestScreens() would kill ANY detached claudeman
screen that wasn't in preExistingScreens. This was dangerous because:
- User screens can become temporarily detached (web server reconnect)
- Tests might start before user creates sessions
- Race conditions between screen status and cleanup timing
Now we ONLY kill screens that tests explicitly register via
registerTestScreen(). Orphaned screens are warned about but not killed.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Remove TUI from git (moved to .gitignore for local development)
- Remove React/Ink dependencies (unused in published version)
- Remove tui command from CLI
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Implements the Execution Optimizer Rework plan that enables the system
to actually use the optimizer metadata (parallelGroups, agentType,
recommendedModel, requiresFreshContext, estimatedTokens) that was
previously generated but ignored.
New components:
- ExecutionBridge: Central coordinator that loads optimized plans,
manages parallel execution within groups, and coordinates with
SpawnOrchestrator for session-based execution
- ModelSelector: Routes tasks to appropriate models (opus/sonnet/haiku)
based on user defaults and agent type overrides. Optimizer
recommendations are advisory only - user preferences always win
- GroupScheduler: Builds topologically ordered execution groups,
manages dependencies, determines execution mode (session vs task-tool)
- ContextManager: Handles fresh context requirements via /clear+/init
or new session spawning
Features:
- Parallel task execution within groups (configurable limit)
- Group-level dependency tracking (lower groups complete first)
- Partial failure handling (continue with non-dependent tasks)
- Model configuration in App Settings > Models tab
- Agent type overrides (explore, implement, test, review)
- Execution control API endpoints (start, pause, resume, cancel)
- SSE events for real-time execution progress visibility
- Execution history tracking
API endpoints:
- GET/POST/PUT /api/execution/* for execution control
- GET/PUT /api/execution/model-config for model settings
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
setTimeout isn't exact, so the remaining TTL after 100ms wait may be
slightly more than expected (901ms instead of ≤900ms). Adding 10ms
tolerance to prevent flaky test failures.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Automatically removes entries not accessed within TTL
- Periodic cleanup with configurable interval
- Optional onExpire callback for cleanup notifications
- Refresh TTL on get (configurable)
- Touch, peek, getAge, getRemainingTtl methods
- Full iteration support
- Implements Disposable interface
Useful for caching ephemeral data like pending tool calls, subagent activity.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add Disposable, BufferConfig, MemoryMetrics, CleanupRegistration types
- Create src/config/buffer-limits.ts with consolidated buffer size constants
- Create src/config/map-limits.ts with Map size limits to prevent unbounded growth
- Implement BufferAccumulator utility with configurable trim and onTrim callback
- Implement LRUMap with automatic eviction and O(1) operations
- Implement CleanupManager for unified resource cleanup with isStopped guard
- Add comprehensive tests for all new utilities
This lays the foundation for memory leak prevention and performance improvements.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The plan generation API (/api/generate-plan-detailed) was incorrectly
detecting client disconnection because it listened to req.raw.on('close')
which fires when the HTTP request body finishes parsing, not when the
actual TCP connection closes.
This caused the error "Failed to parse plan - no JSON array found" because
the server would cancel all subagent sessions almost immediately after
starting them.
Fix:
- Changed from req.raw.on('close') to socket.on('close')
- Added responseSent flag to only cancel if response hasn't been sent
- Added E2E test to verify the fix
Tested with:
- Simple plan generation: 61 items, 138.5s, quality 0.82
- Smartphone app plan: 53 items, 93.4s, quality 0.75
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add /api/sessions/:id/ralph-prompt/write endpoint to write prompt to @ralph_prompt.md
- Wizard now writes full prompt to file, then sends simple read command to Claude
- Fix session readiness check to wait for prompt character instead of notWorking flag
- Add E2E test infrastructure for ralph-loop workflow (port 3190)
- Add ralph-wizard-prod.mjs script for production testing
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- restoreSubagentWindowStates now discovers parent sessions before restoring
- closeSubagentWindow discovers parent before minimizing to prevent wrong tab
- Fixed async handling in subagent:completed event handler
chore: bump version to 0.1389
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>