Consolidate duplicated MockSession/MockStateStore into test/mocks/,
migrate respawn tests to shared mocks, and add 58 route tests for
session, system, and respawn endpoints using Fastify app.inject().
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds ephemeral single-use QR tokens for passwordless tunnel login.
Scanning the QR auto-authenticates; bare tunnel URL requires Basic Auth.
Backend:
- TunnelManager: 60s token rotation, 90s grace, rejection-sampled 6-char
base62 short codes, Map-based O(1) lookup, SVG caching, global rate limit
- Auth middleware: /q/ bypass, separate qrAuthFailures counter, enhanced
AuthSessionRecord with device context (ip, ua, createdAt, method)
- Routes: GET /q/:code (consume + cookie + redirect), POST /api/tunnel/qr/
regenerate, POST /api/auth/revoke, updated GET /api/tunnel/qr with cache
- SSE: tunnel:qrRotated, tunnel:qrRegenerated, tunnel:qrAuthUsed events
- Audit: qr_auth lifecycle log entries
Frontend:
- Auto-refresh QR via inline SVG in SSE (fallback fetch if absent)
- 60s countdown indicator on QR badge
- Regenerate QR button
- QRLjacking detection toast with [Revoke All] action button (10s duration)
- showToast enhanced with optional duration and action button support
Fixes:
- /api/logout now invalidates server-side session token (was only clearing
browser cookie, leaving token valid for replay)
Tests: 20 new tests in test/qr-auth.test.ts covering token lifecycle,
bias check, rate limiting, SVG caching, and full server integration.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Split 6,710-line server.ts into focused route modules using port
interfaces for dependency injection. 107/109 routes extracted into
12 domain files with auth middleware, 5 port interfaces, and shared
helpers. Server.ts retains orchestration (SSE, lifecycle, state).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- TaskTracker.getTaskTreeLight(): strips large `output` strings from tasks
in SSE broadcasts (was serializing 5-10MB every 500ms with many subagents)
- session:created broadcasts now use toLightDetailedState() (consistent with
session:updated which already did)
- GET /api/sessions/:id returns light state (no 2-3MB terminal+text buffers)
- Ralph wizard polls /terminal?tail=2048 instead of full session endpoint
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Local echo now sends every keystroke to the PTY in the background (50ms
debounce) while the overlay continues providing instant visual feedback.
This unlocks Tab completion, preserves PTY state across tab switches,
and protects against input loss on session crashes — making the mobile
typing experience feel as responsive and capable as a native terminal.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
handleInit() called KeyboardHandler.cleanup() and MobileDetection.cleanup()
on every SSE connect but never re-initialized them, breaking keyboard
scroll-into-view and the /init /clear accessory bar on mobile.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Renamed "Two-Row Tabs" to "Tall Tabs (Name + Folder)" for clarity
- Tab folder path now only rendered in JS when setting is ON (not just CSS hidden)
- CSS specificity fix: mobile.css now matches .tabs-two-rows specificity (0,2,0)
- Server settings sync: display keys seed from server on fresh localStorage
- Bumped cache buster versions to 0.1534 to force browser reload
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix input submission: add \r and useScreen:true for reliable input
- Link to real codebase instead of empty test case
- Select correct session tab before sending input
- Filter subagents by session for accurate tracking
- Screenshots now show real subagent windows with activity
- Optimized GIF to 3.9MB (was 62MB)
Commit from flight QR118 in an Airbus A350-1000, stable connection thanks to Starlink!
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add scripts/capture-subagent-screenshots.mjs for automated capture
- Creates real Claude sessions that spawn Task tool subagents
- Records video and converts to optimized GIF via FFmpeg
- Add subagent-spawn.png, subagent-demo.gif to docs/images
- Update README Live Agent Visualization with real screenshots
- Replace ASCII diagram with actual subagent window screenshots
- Add capture:subagents npm script
- Document both screenshot scripts in CLAUDE.md
Commit from flight QR118 in an Airbus A350-1000, stable connection thanks to Starlink!
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Use consistent 20x20px boxes for both icons
- Remove position offsets, rely on flexbox centering
- Increase gear font-size to 0.7rem for better visibility
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Fix Run Claude button being squeezed on mobile (use fit-content width)
- Remove Send button from accessory bar
- Add /init, /clear, /compact buttons with confirmation dialogs
- Center toolbar buttons instead of stretching
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Added relativePath field to ImageDetectedEvent
- Compute relative path from working directory in image-watcher
- Use relativePath in frontend URL (fixes 'Failed to load image' for subdirs)
- Minor CLAUDE.md improvements
chore: bump version to 0.1461
Phase 1 Ralph enhancement implementation:
- Parse RALPH_STATUS blocks from Claude output (status, tasks, files, tests)
- Circuit breaker state machine (CLOSED → HALF_OPEN → OPEN) for stuck detection
- Dual-condition exit gate (completion indicators >= 2 AND EXIT_SIGNAL)
- Frontend: circuit breaker badge (yellow warning, red stuck), status block display
- API: circuit breaker reset endpoint, ralph status endpoint
- Notifications when circuit breaker opens or exit gate is met
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- restoreSubagentWindowStates now discovers parent sessions before restoring
- closeSubagentWindow discovers parent before minimizing to prevent wrong tab
- Fixed async handling in subagent:completed event handler
chore: bump version to 0.1389
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add 300-char rolling window to catch working patterns split across PTY chunks
- Check completion message BEFORE working patterns (priority fix)
- Clear rolling window on completion message (transition point)
- Increase working pattern absence threshold from 3s to 8s
- Add Session.isWorking safety check before confirming idle
- Add 20+ more working patterns (Compiling, Building, Processing, etc.)
- Make AI idle checker prompt more conservative (err toward WORKING)
- Update documentation
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Implements a "what happened while you were away" view for sessions:
- Track significant events: session start/stop, respawn cycles, state changes,
idle/working transitions, token milestones, auto-compact/clear, Ralph
completions, AI check results, hook events, errors/warnings
- Stats dashboard: respawn cycles, peak tokens, active/idle time, issue counts
- Timeline view with color-coded severity and emoji icons
- Filter events by type (all/errors/warnings/respawn/idle)
- State stuck detection (warns when state unchanged for 10+ minutes)
Click the chart icon on any session tab to open the Run Summary modal.
Files:
- src/run-summary.ts: RunSummaryTracker class with event tracking
- src/types.ts: RunSummary, RunSummaryEvent types
- src/web/server.ts: Integration with session/respawn events, API endpoint
- src/web/public/: Modal UI, timeline rendering, filter controls
- docs/run-summary-plan.md: Implementation plan
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Implement multi-phase improvement to respawn controller's idle detection:
Phase 1 - Stop Hook Detection:
- Add signalStopHook() method - definitive signal when Claude finishes
- 3s confirmation timer to handle race conditions
- Skip AI check when hook received (100% confidence)
Phase 2 - idle_prompt Detection:
- Add signalIdlePrompt() method - fires after 60s+ of idle
- Immediately confirms idle (no confirmation timer needed)
Phase 3 - Transcript File Monitoring:
- New TranscriptWatcher class watches session JSONL files
- Detects: completion, tool execution, plan mode, errors
- Signals respawn controller for supporting detection
Web UI Updates:
- Hook indicator with purple styling and pulse animation
- Shows "Stop hook received" or "idle_prompt hook received"
- 100% confidence displayed with hook-confirmed style
This significantly improves idle detection reliability by using
definitive signals from Claude Code rather than parsing terminal output.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Add ai-plan-checker.ts to CLAUDE.md Key Files table
- Document test utilities (MockSession, MockAiIdleChecker, MockAiPlanChecker)
- Update port allocation (3127 reserved for respawn-integration)
- Add ai_checking state to respawn state diagram
- Document AI Plan Checker in respawn-state-machine.md
- Add references to test documentation files
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Condense CLAUDE.md by moving detailed state machine diagrams and spawn
protocol specs into docs/respawn-state-machine.md and docs/spawn-protocol.md.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- CLAUDE.md: idle detection cancellation on substantial output, API input
limits table, configure() method on RalphTracker, tighter completion
pattern description
- ralph-wiggum-guide: add configure() to tracker methods table
- Both docs: update Last Updated date to 2026-01-24
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>