Commit Graph
573 Commits
Author SHA1 Message Date
arkonandClaude Opus 4.6 746004c461 feat: implement QR code authentication for tunnel access
Adds ephemeral single-use QR tokens for passwordless tunnel login.
Scanning the QR auto-authenticates; bare tunnel URL requires Basic Auth.

Backend:
- TunnelManager: 60s token rotation, 90s grace, rejection-sampled 6-char
  base62 short codes, Map-based O(1) lookup, SVG caching, global rate limit
- Auth middleware: /q/ bypass, separate qrAuthFailures counter, enhanced
  AuthSessionRecord with device context (ip, ua, createdAt, method)
- Routes: GET /q/:code (consume + cookie + redirect), POST /api/tunnel/qr/
  regenerate, POST /api/auth/revoke, updated GET /api/tunnel/qr with cache
- SSE: tunnel:qrRotated, tunnel:qrRegenerated, tunnel:qrAuthUsed events
- Audit: qr_auth lifecycle log entries

Frontend:
- Auto-refresh QR via inline SVG in SSE (fallback fetch if absent)
- 60s countdown indicator on QR badge
- Regenerate QR button
- QRLjacking detection toast with [Revoke All] action button (10s duration)
- showToast enhanced with optional duration and action button support

Fixes:
- /api/logout now invalidates server-side session token (was only clearing
  browser cookie, leaving token valid for replay)

Tests: 20 new tests in test/qr-auth.test.ts covering token lifecycle,
bias check, rate limiting, SVG caching, and full server integration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-01 06:05:26 +01:00
arkonandClaude Opus 4.6 295190cc72 docs: update CLAUDE.md with new files from recent refactors
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-01 05:04:14 +01:00
arkonandClaude Opus 4.6 f44f0a912f refactor: split app.js into focused frontend modules (phase 5)
Extract 8 modules from the 15K-line app.js monolith:
- constants.js: shared constants, timing, escapeHtml(), extractSyncSegments()
- mobile-handlers.js: MobileDetection, KeyboardHandler, SwipeHandler
- voice-input.js: DeepgramProvider, VoiceInput
- notification-manager.js: NotificationManager class
- keyboard-accessory.js: KeyboardAccessoryBar, FocusTrap
- api-client.js: _api(), _apiJson(), _apiPost(), _apiDelete() helpers
- subagent-windows.js: 13 subagent window methods (open, close, drag, lines)
- vendor/xterm-zerolag-input.js: IIFE build replacing inlined copy

app.js reduced from ~15,200 to ~11,500 lines. All modules use global
scope with <script defer> ordering. Prototype extensions use
Object.assign(CodemanApp.prototype, {...}) pattern.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-01 04:57:37 +01:00
arkonandClaude Opus 4.6 e7a9cbe442 refactor: split god files into focused modules (phase 4, steps 2-4)
Split 3 large files into 11 focused sub-modules via composition:

ralph-tracker.ts (3,868 → ~2,400 LOC):
- ralph-plan-tracker.ts: plan task tracking, checkpoints, history
- ralph-fix-plan-watcher.ts: @fix_plan.md file watching
- ralph-stall-detector.ts: iteration stall detection
- ralph-status-parser.ts: RALPH_STATUS block parsing, circuit breaker

respawn-controller.ts (3,611 → ~3,200 LOC):
- respawn-patterns.ts: pure pattern detection functions
- respawn-adaptive-timing.ts: adaptive timing with percentile calc
- respawn-metrics.ts: cycle metrics tracking + aggregation
- respawn-health.ts: pure health scoring functions

session.ts (2,418 → ~1,800 LOC):
- session-cli-builder.ts: CLI argument construction
- session-auto-ops.ts: auto-compact/clear automation
- session-task-cache.ts: task description LRU cache

All external APIs preserved via delegation. Events forwarded
through parent classes. Zero behavioral changes — all 436 tests pass.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-01 04:04:35 +01:00
arkonandClaude Opus 4.6 db8ee8458c chore: version packages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 14:45:39 +01:00
arkonandClaude Opus 4.6 88098adc1c fix: revert npm package name to aicodeman
codemanager rejected by npm (too similar to code-manager).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 02:28:31 +01:00
arkonandClaude Opus 4.6 c4cdab03e2 fix: rename npm package to codemanager
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 02:26:19 +01:00
arkonandClaude Opus 4.6 75765589ca fix: rename npm package to aicodeman
"codeman" is already taken on npm registry.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 02:22:20 +01:00
arkonandClaude Opus 4.6 f2e1e986bd chore: version packages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 02:02:04 +01:00
arkonandClaude Opus 4.6 9d9f4d323c chore: version packages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 01:35:37 +01:00
arkonandClaude Opus 4.6 ec7244fa5b chore: version packages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 00:55:16 +01:00
arkonandClaude Opus 4.6 6053593813 chore: version packages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 17:54:59 +01:00
arkonandClaude Opus 4.6 93ebe3f07e fix: tunnel button stuck on "Connecting..." due to settings validation
Root cause: toggleTunnelFromWelcome() sent the entire settings object
back to PUT /api/settings, but the Zod schema uses .strict() which
rejects unknown fields (lastUsedCase, localEchoEnabled, etc.). The PUT
silently failed, so the tunnel never started.

Fix: send only {tunnelEnabled: true/false} instead of the full blob.
Also added polling fallback for tunnel status and server-side re-broadcast
when tunnel is already running.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 16:45:05 +01:00
arkonandClaude Opus 4.6 1b0a540919 fix: tunnel button stuck on "Connecting..." when already running
Re-broadcast tunnel:started SSE event when tunnel is already active
and user toggles the setting, so the client receives the URL.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 16:31:31 +01:00
arkon 45aaf7f09a chore: version packages 2026-02-27 15:29:46 +01:00
480584de63 chore: project setup and tooling cleanup (#26)
* add project setup

* add tools to eslint

* remove contributing.md

* update claude md

* chore: simplify CI to single Node.js version (22)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* use node 20

* adjust formatting

* fix linting

* format

* fix layout

* fix: align CI node version to .nvmrc (22), remove redundant gotcha

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: arkon <arkon.85@hotmail.com>
2026-02-27 13:16:23 +01:00
arkon 2b2829ebde chore: version packages 2026-02-27 10:58:10 +01:00
arkon 8038145d40 chore: bump version to 0.1658 2026-02-27 08:53:30 +01:00
arkon 63d752e3cf chore: bump version to 0.1657 2026-02-27 08:45:15 +01:00
arkonandClaude Opus 4.6 c668f9bae1 chore: bump version to 0.1656
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 08:28:30 +01:00
arkonandClaude Opus 4.6 8fc0dc8c2e chore: bump version to 0.1655
Security hardening: timing-safe auth comparison, localhost-only hook bypass,
SSE client limit, TLS key permissions, strict settings schema, logout endpoint.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 01:13:58 +01:00
arkonandClaude Opus 4.6 f699002cbf chore: bump version to 0.1654
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 01:07:03 +01:00
arkon de494bbb55 chore: bump version to 0.1653 2026-02-27 00:49:32 +01:00
arkon 5f1f66bf60 chore: bump version to 0.1652 2026-02-27 00:34:38 +01:00
arkon 001676ff0f chore: bump version to 0.1651 2026-02-26 16:48:00 +01:00
arkonandClaude Opus 4.6 3795c45cc1 chore: rename Claudeman to Codeman
Full product rename across 109 files (~834 occurrences):
- Env vars: CLAUDEMAN_* → CODEMAN_*
- Data dirs: ~/.claudeman/ → ~/.codeman/, ~/claudeman-cases/ → ~/codeman-cases/
- tmux prefix: claudeman- → codeman-
- localStorage: claudeman-* → codeman-*
- Package/CLI: claudeman → codeman
- GitHub repo: Ark0N/Claudeman → Ark0N/Codeman
- systemd service: claudeman-web → codeman-web
- Class: ClaudemanApp → CodemanApp

Migration infrastructure for seamless transition:
- state-store.ts: auto-migrates data directories on startup
- tmux-manager.ts: dual-prefix detection (legacy claudeman- sessions)
- app.js: localStorage key migration (preserves old keys)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 16:44:34 +01:00
arkon 3ccd22161c chore: bump version to 0.1650 2026-02-26 16:12:41 +01:00
arkon 7af806e0c1 chore: bump version to 0.1649 2026-02-26 16:10:13 +01:00
arkon d3d44223ec chore: bump version to 0.1648 2026-02-26 16:07:33 +01:00
arkon ce9cbc9200 chore: bump version to 0.1647 2026-02-26 16:04:00 +01:00
arkon 1adcb7656b chore: bump version to 0.1646 2026-02-26 00:49:36 +01:00
arkon 209cc74514 chore: bump version to 0.1645 2026-02-25 23:53:03 +01:00
arkon 9719921c8e chore: bump version to 0.1644 2026-02-25 19:34:10 +01:00
arkon be46dfe19d chore: bump version to 0.1643 2026-02-25 18:58:34 +01:00
arkonandClaude Opus 4.6 64ad8b467b chore: bump version to 0.1641
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-25 17:14:53 +01:00
arkonandClaude Opus 4.6 fd0b75c9a5 chore: bump version to 0.1640
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-25 13:40:55 +01:00
arkon ea79d1f998 chore: bump version to 0.1639 2026-02-25 09:49:01 +01:00
arkonandClaude Opus 4.6 cf09e0e9cd chore: bump version to 0.1638
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-02-25 09:39:41 +01:00
arkonandClaude Opus 4.6 8d3ce5ef57 chore: bump version to 0.1637
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-25 09:23:18 +01:00
arkonandClaude Opus 4.6 475062f0af chore: bump version to 0.1636
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-25 09:07:16 +01:00
arkon b1672ea1fa chore: bump version to 0.1635 2026-02-25 08:19:47 +01:00
arkon 7b931a35d0 chore: bump version to 0.1634 2026-02-25 00:32:45 +01:00
arkon 57193cb1be chore: bump version to 0.1633 2026-02-25 00:21:34 +01:00
arkon a5dd4fff21 chore: bump version to 0.1632 2026-02-25 00:14:52 +01:00
arkonandClaude Opus 4.6 e4c8c7a645 chore: bump version to 0.1631
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-24 23:49:09 +01:00
arkonandClaude Opus 4.6 006f60b4a4 chore: bump version to 0.1630
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-24 20:57:58 +01:00
arkonandClaude Opus 4.6 84027cf468 chore: bump version to 0.1629
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-24 20:56:47 +01:00
arkonandClaude Opus 4.6 ce4107ef9c chore: bump version to 0.1628
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-24 20:55:36 +01:00
arkonandClaude Opus 4.6 d83bd7a992 chore: bump version to 0.1627
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-24 20:54:26 +01:00
arkonandClaude Opus 4.6 5e6f7adcb3 chore: bump version to 0.1626
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-24 20:53:18 +01:00