mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-02 13:39:41 +02:00
codeman@1.16.2
4
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
6cc7b4328b |
feat(cases): clone a Git repository as a new case (#236)
Adds an Add Case -> "Clone Repo" tab plus two endpoints, implementing @DodgyBadger's proposal in #236: clone a public repository straight into codeman-cases/<name> and register it as a normal local case. POST /api/cases/clone is synchronous by design (request held open, bounded by GIT_CLONE_TIMEOUT_MS): no job store, no polling, no cancellation surface. Success broadcasts the usual case:created event, so the case still appears when a proxy idle-timeout kills the request mid-clone. POST /api/cases/clone-preflight runs `git ls-remote --symref` so the UI can say, while the user is still typing, whether the URL is cloneable without credentials, what its default branch is, and which branches/tags exist. Core lives in src/git-clone.ts, split into a pure half (URL parse, argv/env, ls-remote parse, stderr classification) and a thin IO half, so every security decision is unit-testable without spawning anything: - `<name>::<payload>` transports are refused as a family, not by name: ext:: is the famous one, but any of them dispatches to git-remote-<name> and turns a clone into arbitrary command execution. - A leading `-` is refused AND every spawn puts `--` before the operands. Either alone is one edit away from being a hole. - argv arrays, never a shell. URLs carrying user:password@ are refused. - gitNonInteractiveEnv() closes all four ways git can block on a prompt with no terminal attached (terminal prompt, askpass/GUI, ssh, GCM). HOME/PATH stay inherited, so a user's own credential helper or ssh agent keeps working; Codeman itself collects and stores nothing. - The timeout signals the process GROUP, since clone fans out into git-remote-https/index-pack children that outlive a signal to the parent. - Bounded output (redacted stderr tail, capped ls-remote stdout, 500 refs each) and a global 2-op pool, so N large clones cannot exhaust the host. Repository contents beat scaffolding: an existing CLAUDE.md is kept, hooks are merged into whatever .claude/settings.local.json the repo shipped, and a repo that ships its own Claude settings is reported back as a warning (those hooks run locally as soon as a session starts there). A failed clone removes only the directory the attempt created, and refuses a pre-existing destination outright, so it can never squat on a case name. Not admin-gated in multi-user mode, unlike /api/cases/link: it writes only inside the caller's own case space. Local-path/file:// sources are the exception and stay admin-only there. UI: live verdict under the URL field, case name filled from the parsed repo until the user types their own, branch/tag as a datalist of the remote's real refs, optional shallow clone, and a Brain picker (installed CLIs only) that points the Run button at the chosen agent. Starting a session stays opt-in. The tab hides itself when the server reports no git. Tests: the pure half exhaustively (every refusal has a case), plus real git against a real local bare repo for clone/ref/timeout/cleanup, and a route-level suite with unmocked fs that clones through the endpoint. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
5d2899907e |
fix(cli-gating): gate the tunnel button instead of deleting it, and cover antigravity
Follow-up to #200 and #201, which gate the welcome buttons and the run-mode
dropdown on whether the CLI is actually installed. Four corrections:
1. #200 also DELETED the Cloudflare Tunnel welcome button and the QR widget
outright. Its rationale is right (offering a tunnel where cloudflared is not
installed is a bad default) but the conclusion overshoots: the welcome QR is
the whole scan-to-connect-from-your-phone flow, and deleting it left a large
block of live tunnel code in settings-ui.js driving elements that no longer
existed. Both are restored and the button is gated on cloudflared, which is
what the stated rationale actually asks for. New cloudflared-resolver.ts
mirrors the CLI resolvers, and TunnelManager now shares its search path so
the button and the spawn can never disagree about where cloudflared lives.
2. Antigravity was missing from the run-mode gating, the one run mode LEAST
likely to be installed. It slipped past because #201 predates it. Covered
now, plus a static test that fails if a sixth mode reaches the dropdown
without being gated, so the next one cannot slip the same way.
3. The per-surface fetches are replaced by the injected availability object
already used for the Codex settings tab, so the codebase has one mechanism
rather than two. The status routes buy nothing as a gating source: every
resolver memoizes its PATH probe server-side, so a fetch is exactly as stale
as an injected value while costing a round trip every time the dropdown opens
and leaving the welcome buttons to flicker in after paint. The routes
themselves stay, including the /api/claude/status that #200 adds.
4. Unknown availability now reads as AVAILABLE for run buttons. Both PRs hid the
button on a failed fetch, so a blip left a working install with nothing to
click; a genuinely missing CLI only ever produced an error toast. The Codex
settings TAB keeps the opposite default, since hiding it costs nothing.
The dropdown query is also scoped to the menu: `.run-mode-option` is the class
the saved-dashboard and history rows use too, and a document-wide querySelector
would have found whichever came first in the DOM.
Fixes a latent environment-sensitivity in
|
||
|
|
816d900857 |
feat(settings): show the Codex CLI tab only where codex is installed
Both settings on the App Settings "Codex CLI" tab (bypass approvals, animated status effects) are handed to `codex` at launch, so on an instance where the binary does not resolve the tab offers choices nothing can act on. Gate it on availability instead. renderIndexHtml injects window.__codemanCodexAvailable, mirroring the existing gesture-availability flag, and settings-ui.js hides the tab button when it is absent. Injected rather than fetched on modal open so the tab cannot flicker in and back out; isCodexAvailable() memoizes its PATH probe, so the per-render cost is nil. Installing codex later needs a restart, exactly like the /api/codex/status route that already backs the Run menu. Solo popups skip the probe since they have no settings modal. Only the tab BUTTON is toggled. The panel already carries .modal-tab-content.hidden unless it is the selected tab and openAppSettings() always reopens on Display, so an unreachable button keeps the panel unreachable. The inputs stay in the DOM and are still populated and read back on save, so a user without codex cannot silently wipe the codex preferences of an instance that has it. Animations stay off by default for new local Codex sessions. Verified in a browser on this host, which has no codex: the flag is absent, the Codex tab is hidden while the other tabs are unaffected, and saving App Settings with the tab hidden leaves codexAnimationsEnabled/codexDangerouslyBypassApprovals untouched. With the flag forced on, the tab appears, its panel opens, and toggling the visible slider persists. The openAppSettings coupling test was checked to fail when the call is removed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
29d3fd48c1 |
fix(web): address self-review findings on #105 (settings cache + brittle reveal)
- Fix the gesture enable-reload race: PUT /api/settings writes settings.json without invalidating WebServer's 2s _settingsCache, and the toggle reloads ~400ms after save — within the TTL — so renderIndexHtml could render the pre-toggle state (bundle not injected until a 2nd reload). renderIndexHtml now reads settings via readSettings(true), a fresh read that bypasses the cache; readSettings gains a forceFresh param. - Replace the brittle multi-monitor reveal (string match on the button's aria-label + inline style) with a stable `btn-multimonitor--hidden` class marker: the template carries the class, the server strips it when the setting is on, and applyHeaderVisibilitySettings()/solo-mode CSS toggle the same class. Editing the button's copy no longer silently breaks the reveal. - Test: test/render-index-html.test.ts (reveal, solo injection + escaping, gesture availability vs. enablement, fresh-read wiring). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |