mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-02 21:49:42 +02:00
Follow-ups from the PR #175/#176 reviews: - Rewake helper self-terminates on its own 6h deadline and when orphaned, instead of relying on Claude Code to reap the poller - Rewake marker versioned (V2) with a version-agnostic ownership prefix, so future script updates replace older handlers instead of duplicating them; regression test covers the V1 to V2 swap - HOOK_TIMEOUT_MS renamed to HOOK_TIMEOUT_SECONDS = 10: the hook timeout field is seconds (the CLI multiplies by 1000), so the curl hooks have effectively had a ~2.8h timeout since COD-54 - Test echo PTY switches to raw mode: each input byte echoes exactly once (tty line discipline doubled every line and buffered until Enter) - test/setup.ts: drain in-flight console-log rpc forwards before environment teardown (fixes the EnvironmentTeardownError that failed CI twice on the merge commit with all 3820 tests passing), clean the temp home on process exit (fully-skipped files leaked it), fix the Windows Playwright cache fallback path - test/webview-proxy.test.ts: stop naming the vitest environment directive in prose; vitest matches it inside comments and silently ran the whole file under the jsdom environment while the comment claimed node - CLAUDE.md: document the temp-HOME and echo-PTY test isolation Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
41 lines
1.5 KiB
TypeScript
41 lines
1.5 KiB
TypeScript
/**
|
|
* @fileoverview Authentication, rate limiting, and hook security constants.
|
|
*
|
|
* Controls auth session lifecycle, brute-force protection,
|
|
* and Claude Code hook timeouts.
|
|
*
|
|
* @module config/auth-config
|
|
*/
|
|
|
|
// ============================================================================
|
|
// Session Cookies
|
|
// ============================================================================
|
|
|
|
/** Auth session cookie TTL — matches autonomous run length (ms) */
|
|
export const AUTH_SESSION_TTL_MS = 24 * 60 * 60 * 1000;
|
|
|
|
/** Max concurrent auth sessions per server */
|
|
export const MAX_AUTH_SESSIONS = 100;
|
|
|
|
// ============================================================================
|
|
// Rate Limiting
|
|
// ============================================================================
|
|
|
|
/** Max failed auth attempts per IP before 429 rejection */
|
|
export const AUTH_FAILURE_MAX = 10;
|
|
|
|
/** Failed auth attempt tracking window (ms) */
|
|
export const AUTH_FAILURE_WINDOW_MS = 15 * 60 * 1000;
|
|
|
|
// ============================================================================
|
|
// Hooks
|
|
// ============================================================================
|
|
|
|
/**
|
|
* Timeout for Claude Code hook curl commands, in SECONDS: the hook `timeout`
|
|
* field is seconds (the CLI multiplies by 1000). The predecessor constant
|
|
* `HOOK_TIMEOUT_MS = 10000` fed the same field, so those hooks effectively had a
|
|
* ~2.8-hour timeout; 10 seconds is the originally intended budget.
|
|
*/
|
|
export const HOOK_TIMEOUT_SECONDS = 10;
|