mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 16:39:42 +02:00
Every run mode is now a `CliEntry` in `src/config/cli-registry/` — discovery (search dirs, version + identity probes), the launch argv template, env handling, the `capabilities` flags that replace per-CLI branching, and the `overlays` that back the remote/docker pane commands. Code that used to ask "which CLI is this?" reads the entry instead. Behaviour is unchanged. `test/cli-registry-spawn-golden.test.ts` pins every spawn command as a literal string, captured from the hand-written builders before they were deleted, and `test/location-overlay-commands.test.ts` does the same for all 20 remote and in-container pane commands. Config can never contain shell text: an entry declares typed argv tokens, literals are validated against a safe-word pattern at LOAD time (a bad literal rejects the whole entry — a silently dropped `--no-approve` is not cosmetic), and values resolve through patterns NAMED in code, so a user `clis.json` cannot widen its own validation. `~/.codeman/clis.json` overrides any entry, read-only in this release. OMP is included as a registry entry rather than a tenth hand-written builder, so `buildOmpCommand()`, the omp availability pre-flight, the omp arm of `buildPathExport()` and the omp entries in the truecolor/NO_COLOR, alt-screen and doctor ladders all drop out. Guard rails: - `test/cli-registry-no-id-branching.test.ts` fails the build if per-CLI-id branching reappears outside `stock.ts`, in any of its four shapes (`===`, `!==`, `switch`/`case`, `includes`) — an `===`-only version would miss the negated forms, which is how 36 of them survived an earlier pass. Every allowlisted branch carries its reason. - `external`, `hooks` and `altScreen` stay three INDEPENDENT capabilities; deriving one from another shipped the `until=stop`-hangs-on-shell bug. - `param` is two namespaces. `launch.params` keys, `configSetenv.fromParam` and `privilegedParams[].param` all name a LAUNCH param; the legacy `<Mode>Config` wire field is separate, bridged only by `legacyConfigAliases`. Getting `privilegedParams[].param` wrong is SILENT — it is the multi-user bypass clamp's only handle on a CLI's privilege switch, and a wrong name clamps nothing with no error and no failing test — so `schema.ts` rejects an entry naming a param it never declared. - Registry data resolves AT CALL TIME (`sessionModeSchema()`, `allowedEnvPrefixes()`, `dependencyRegistry()`, the resolvers' `searchDirs` thunks). A module-level const freezes at first import, so a CLI enabled while the server ran moved the run menu but not that surface. - Six fields are annotated DECLARED-FOR-LATER and read by nothing (`shortBadge`, `accent`, `capabilities.echo`/`wheelForward`/ `keyboardAccessory`/`maxFrameBytes`): all frontend behaviour, transcribed rather than measured. A test pins the list so it cannot quietly grow. Three user-visible changes, all deliberate and named: - `probeDockerCliVersion()` derives the in-container binary from the registry rather than assuming it equals the mode name (`antigravity` runs `agy`). - The remote CLI version probe now covers grok and deepseek, which the hardcoded map it replaces omitted while its own comment said the rule was "every mode except shell". - `codeman doctor`'s CLI rows are generated from the entries, so Claude's install hint is the install command rather than a docs URL, five CLIs gain hints they never had, and the row order follows the catalog. Also hardened along the way: `sessionModeSchema()` is bounded at 24 chars (matching the `cliId` pattern) before its failure message quotes the value back, and `deepMerge` skips `__proto__`/`constructor`/`prototype` when reading the hand-editable `clis.json`. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WQkoi1cNegqVwZHgzx5SbJ
139 lines
6.8 KiB
TypeScript
139 lines
6.8 KiB
TypeScript
/**
|
|
* @fileoverview Cron Jobs routes.
|
|
*
|
|
* CRUD + enable/disable + Run Now + run history for `CronJob`s. These are
|
|
* separate from the legacy `/api/scheduled` (ScheduledRun) endpoints — see
|
|
* docs/cron-discovery.md §0.
|
|
*/
|
|
|
|
import { FastifyInstance } from 'fastify';
|
|
import { getCli } from '../../config/cli-registry/registry.js';
|
|
import { ApiErrorCode, createErrorResponse } from '../../types.js';
|
|
import { CronJobSchema, CronJobUpdateSchema, CronJobEnabledSchema } from '../schemas.js';
|
|
import { canAccessOwned, getAuthUser, isWorkingDirAllowed, ownerFor, parseBody } from '../route-helpers.js';
|
|
import { canUsernameRunPrivilegedCommands } from '../../user-store.js';
|
|
import { isMultiUserMode } from '../../config/multiuser.js';
|
|
import type { CronJob } from '../../types/cron.js';
|
|
import type { CronPort } from '../ports/index.js';
|
|
import type { FastifyRequest } from 'fastify';
|
|
|
|
export function registerCronRoutes(app: FastifyInstance, ctx: CronPort): void {
|
|
// A job the caller may see/act on (own, or admin/single-user).
|
|
const canTouch = (req: FastifyRequest, job: CronJob | null | undefined): job is CronJob =>
|
|
!!job && canAccessOwned(getAuthUser(req), job.owner);
|
|
|
|
// ── Jobs ────────────────────────────────────────────────────────────────
|
|
|
|
app.get('/api/cron/jobs', async (req) => {
|
|
const jobs = ctx.cron.listJobs();
|
|
if (!isMultiUserMode()) return jobs;
|
|
const user = getAuthUser(req);
|
|
if (user.role === 'admin') return jobs;
|
|
return (jobs as CronJob[]).filter((j) => canAccessOwned(user, j.owner));
|
|
});
|
|
|
|
app.post('/api/cron/jobs', async (req) => {
|
|
// No custom errorMessage: surface the schema's field-specific messages
|
|
// (e.g. "runAt is required for a one-time schedule").
|
|
const body = parseBody(CronJobSchema, req.body);
|
|
// Section 6.2: confine the job's workingDir to the owner's case space (mirrors
|
|
// POST /api/sessions). No-op allow-all for admins/single-user. workingDir is
|
|
// required by CronJobSchema so it is always present here.
|
|
if (!isWorkingDirAllowed(getAuthUser(req), body.workingDir)) {
|
|
return createErrorResponse(ApiErrorCode.FORBIDDEN, 'workingDir is outside your workspace');
|
|
}
|
|
// Section 6.3: shell mode / a launchCommand is arbitrary host-account execution.
|
|
// Resolve the owner's grant from the store (AuthUser.role alone can't tell a GRANTED
|
|
// regular user from a plain one); mirrors session-routes + the cron fire-time re-check.
|
|
if (
|
|
(getCli(body.agentType)?.capabilities.privilegedCommandGate || body.launchCommand) &&
|
|
!(await canUsernameRunPrivilegedCommands(ownerFor(req)))
|
|
) {
|
|
return createErrorResponse(
|
|
ApiErrorCode.FORBIDDEN,
|
|
'Shell/launchCommand cron jobs require the can-bypass-permissions grant'
|
|
);
|
|
}
|
|
return { job: ctx.cron.createJob(body, ownerFor(req)) };
|
|
});
|
|
|
|
app.get('/api/cron/jobs/:id', async (req) => {
|
|
const { id } = req.params as { id: string };
|
|
const job = ctx.cron.getJob(id);
|
|
if (!canTouch(req, job)) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
return job;
|
|
});
|
|
|
|
app.put('/api/cron/jobs/:id', async (req) => {
|
|
const { id } = req.params as { id: string };
|
|
if (!canTouch(req, ctx.cron.getJob(id))) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
const body = parseBody(CronJobUpdateSchema, req.body);
|
|
// Section 6.2: the update body is partial, so only confine when workingDir is set.
|
|
if (body.workingDir !== undefined && !isWorkingDirAllowed(getAuthUser(req), body.workingDir)) {
|
|
return createErrorResponse(ApiErrorCode.FORBIDDEN, 'workingDir is outside your workspace');
|
|
}
|
|
if (
|
|
(getCli(body.agentType ?? 'claude')?.capabilities.privilegedCommandGate || body.launchCommand) &&
|
|
!(await canUsernameRunPrivilegedCommands(ownerFor(req)))
|
|
) {
|
|
return createErrorResponse(
|
|
ApiErrorCode.FORBIDDEN,
|
|
'Shell/launchCommand cron jobs require the can-bypass-permissions grant'
|
|
);
|
|
}
|
|
const job = ctx.cron.updateJob(id, body);
|
|
if (!job) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
return { job };
|
|
});
|
|
|
|
app.delete('/api/cron/jobs/:id', async (req) => {
|
|
const { id } = req.params as { id: string };
|
|
if (!canTouch(req, ctx.cron.getJob(id)) || !ctx.cron.deleteJob(id)) {
|
|
return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
}
|
|
return {};
|
|
});
|
|
|
|
app.put('/api/cron/jobs/:id/enabled', async (req) => {
|
|
const { id } = req.params as { id: string };
|
|
if (!canTouch(req, ctx.cron.getJob(id))) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
const { enabled } = parseBody(CronJobEnabledSchema, req.body, 'Invalid request body');
|
|
const job = ctx.cron.setEnabled(id, enabled);
|
|
if (!job) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
return { job };
|
|
});
|
|
|
|
// ── Run Now ──────────────────────────────────────────────────────────────
|
|
|
|
app.post('/api/cron/jobs/:id/run', async (req) => {
|
|
const { id } = req.params as { id: string };
|
|
const job = ctx.cron.getJob(id);
|
|
if (!canTouch(req, job)) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
const run = await ctx.cron.runNow(id);
|
|
return { run, activeAgents: ctx.cron.countActiveAgents(job.agentType, job.id) };
|
|
});
|
|
|
|
// ── Run history ──────────────────────────────────────────────────────────
|
|
|
|
app.get('/api/cron/jobs/:id/runs', async (req) => {
|
|
const { id } = req.params as { id: string };
|
|
// Owner-gate like every other :id handler so a foreign job's run history (session
|
|
// ids, names, deep links) isn't leaked; NOT_FOUND avoids disclosing existence.
|
|
if (!canTouch(req, ctx.cron.getJob(id))) return createErrorResponse(ApiErrorCode.NOT_FOUND, 'Cron job not found');
|
|
return ctx.cron.listRuns(id);
|
|
});
|
|
|
|
app.get('/api/cron/runs', async (req) => {
|
|
const runs = ctx.cron.listRuns();
|
|
if (!isMultiUserMode()) return runs;
|
|
const user = getAuthUser(req);
|
|
if (user.role === 'admin') return runs;
|
|
// Non-admin: keep only runs whose owning job the caller can access (drops runs
|
|
// whose job is absent from the map — defensive; deleteJob already cascades).
|
|
const ownerByJobId = new Map<string, string | undefined>(
|
|
ctx.cron.listJobs().map((j): [string, string | undefined] => [j.id, j.owner])
|
|
);
|
|
return runs.filter((run) => canAccessOwned(user, ownerByJobId.get(run.cronJobId)));
|
|
});
|
|
}
|