mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 07:59:42 +02:00
Scopes real-time streams and the init snapshot so a multi-user client only receives what it owns. No-op in single-user mode (identity-less clients). - WS terminal (ws-routes): owner gate after the session lookup. A non-admin may only attach to their own session (close 4003); the global auth hook already ran on the upgrade and decorated req.authUser, so an unauthenticated upgrade never reaches the handler. - SSE (sse-stream-manager): per-client identity stored at addClient; broadcast() and the terminal-batch flush both enforce a routing hint via canDeliver(). WebServer.broadcast auto-derives the hint (deriveSseHint): session-scoped event families resolve the owner from the payload's session id (fail closed when the owner can't be resolved), machine-level families (docker/tunnel/update/system/ cron) + host-plan telemetry are admin-only, everything else stays global. Raw terminal bytes resolve the owner once and are withheld from non-owners. - getLightState is filtered per connection AFTER the shared cache (sessions, respawnStatus, subagents, workflowRuns by owner; scheduledRuns + planUsage admin-only); applied to both the SSE init snapshot and GET /api/status. - file-routes: getKnownSessionWorkingDir + getSessionAttachmentHistory (the preview/thumbnail/history helpers that bypass findSessionOrFail) now owner-check the session, closing a cross-user file-read path. - GET /api/search: harvestSources is owner-scoped. Deferred to a follow-up (documented in docs/multi-user-plan.md): away-digest + subagent/workflow REST list scoping, push-subscription identity + routing, per-user screenshot subdirs. The live-event versions of these are already routed by the SSE hint; only the on-demand REST aggregates remain global for admins-only follow-up. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
26 lines
1.1 KiB
TypeScript
26 lines
1.1 KiB
TypeScript
/**
|
|
* @fileoverview Config port — capabilities for app configuration and settings.
|
|
* Route modules that read or modify configuration depend on this port.
|
|
*/
|
|
|
|
import type { ClaudeMode, NiceConfig } from '../../types.js';
|
|
import type { StateStore } from '../../state-store.js';
|
|
import type { TerminalHistoryConfig } from '../../config/terminal-history.js';
|
|
|
|
export interface ConfigPort {
|
|
readonly store: StateStore;
|
|
readonly port: number;
|
|
readonly https: boolean;
|
|
readonly testMode: boolean;
|
|
readonly serverStartTime: number;
|
|
getGlobalNiceConfig(): Promise<NiceConfig | undefined>;
|
|
getModelConfig(): Promise<{ defaultModel?: string; agentTypeOverrides?: Record<string, string> } | null>;
|
|
getClaudeModeConfig(): Promise<{ claudeMode?: ClaudeMode; allowedTools?: string }>;
|
|
getTerminalHistoryConfig(): Promise<TerminalHistoryConfig>;
|
|
getDefaultClaudeMdPath(): Promise<string | undefined>;
|
|
getLightState(identity?: { username: string; role: 'admin' | 'user' }): unknown;
|
|
getLightSessionsState(): unknown[];
|
|
startTranscriptWatcher(sessionId: string, transcriptPath: string): void;
|
|
stopTranscriptWatcher(sessionId: string): void;
|
|
}
|