mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 20:49:41 +02:00
Review fixes for COD-54: - Generated hook curl commands now present X-Codeman-Hook-Secret, read from the secret file AT EXECUTION TIME via $CODEMAN_HOOK_SECRET_FILE (exported into every managed session's env by tmux buildEnvExports / the direct-PTY env builders). Without this, every local hook 401'd the moment a managed tunnel came up — the enforcement existed but nothing presented the secret. Path-not-value keeps the secret off command lines and out of config files, and running sessions pick up a newly generated secret with no respawn; server.start() ensures the file exists up front. - Hook-secret failures now count into a DEDICATED per-IP bucket (hookSecretFailures) instead of the shared authFailures map. Legacy (pre-secret) hook configs fire constantly from 127.0.0.1; counting their 401s against the shared bucket would 429 every cookie-less loopback request — locking out the Basic-Auth login path (and, through a tunnel, every client, since tunneled traffic also arrives as 127.0.0.1). - docs/security-architecture.md: secret-gated hook exemption, dedicated bucket, COD-55 refusal, and the residual caveat for EXTERNAL loopback proxies (user-run cloudflared / tailscale serve), which the managed-tunnel probe cannot see. - test/cod54-hook-event-auth.test.ts: +3 tests — login path unaffected after hook-bucket exhaustion; generated hooks reference the header + $CODEMAN_HOOK_SECRET_FILE without embedding the value; env builders export the path only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
159 lines
5.3 KiB
TypeScript
159 lines
5.3 KiB
TypeScript
/**
|
|
* @fileoverview Pure functions for building CLI arguments and environment variables
|
|
* for Claude and OpenCode CLI spawning.
|
|
*
|
|
* Extracted from Session to keep argument construction logic testable and
|
|
* separate from PTY lifecycle management.
|
|
*
|
|
* @module session-cli-builder
|
|
*/
|
|
|
|
import type { ClaudeMode, EffortLevel } from './types.js';
|
|
import { isEffortLevel } from './types.js';
|
|
import { getAugmentedPath } from './utils/index.js';
|
|
import { dataPath } from './config/instance.js';
|
|
|
|
/**
|
|
* Build Claude CLI permission flags based on the configured mode.
|
|
* Returns an array of args to pass to the CLI.
|
|
*/
|
|
function buildPermissionArgs(claudeMode: ClaudeMode, allowedTools?: string): string[] {
|
|
switch (claudeMode) {
|
|
case 'dangerously-skip-permissions':
|
|
return ['--dangerously-skip-permissions'];
|
|
case 'allowedTools':
|
|
if (allowedTools) {
|
|
return ['--allowedTools', allowedTools];
|
|
}
|
|
// Fall back to normal mode if no tools specified
|
|
return [];
|
|
case 'normal':
|
|
default:
|
|
return [];
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Build the CLI args carrying the effort level as a SOFT default (switchable
|
|
* in-session via /effort). The CLAUDE_CODE_EFFORT_LEVEL env var is deliberately
|
|
* avoided — it hard-locks effort and blocks in-session `/effort` switching.
|
|
*
|
|
* Two carriers are needed because neither covers all levels:
|
|
* - regular levels (incl. `max`) → `--effort <level>` (the settings `effortLevel`
|
|
* key is enum(["low","medium","high","xhigh"]) with .catch(undefined), so `max`
|
|
* would be SILENTLY dropped there)
|
|
* - `ultracode` → `--settings '{"ultracode":true}'` (its own boolean settings key,
|
|
* claude >= 2.1.154; rejected by the --effort flag)
|
|
*/
|
|
export function buildEffortCliArgs(effort?: EffortLevel): string[] {
|
|
if (!effort || !isEffortLevel(effort)) return [];
|
|
return effort === 'ultracode' ? ['--settings', '{"ultracode":true}'] : ['--effort', effort];
|
|
}
|
|
|
|
/**
|
|
* Build args for an interactive Claude CLI session (direct PTY, non-mux fallback).
|
|
*
|
|
* @param sessionId - The Codeman session ID (passed as --session-id to Claude)
|
|
* @param claudeMode - Permission mode for the CLI
|
|
* @param model - Optional model override (e.g., 'opus', 'sonnet')
|
|
* @param allowedTools - Optional comma-separated allowed tools list
|
|
* @param effort - Optional effort level, injected via --settings (overridable in-session)
|
|
* @returns Array of CLI arguments
|
|
*/
|
|
export function buildInteractiveArgs(
|
|
sessionId: string,
|
|
claudeMode: ClaudeMode,
|
|
model?: string,
|
|
allowedTools?: string,
|
|
effort?: EffortLevel
|
|
): string[] {
|
|
const args = [...buildPermissionArgs(claudeMode, allowedTools), '--session-id', sessionId];
|
|
if (model) args.push('--model', model);
|
|
args.push(...buildEffortCliArgs(effort));
|
|
return args;
|
|
}
|
|
|
|
/**
|
|
* Build args for a one-shot Claude CLI prompt (runPrompt mode).
|
|
*
|
|
* @param prompt - The prompt text to send
|
|
* @param model - Optional model override
|
|
* @returns Array of CLI arguments
|
|
*/
|
|
export function buildPromptArgs(prompt: string, model?: string): string[] {
|
|
const args = ['-p', '--verbose', '--dangerously-skip-permissions', '--output-format', 'stream-json'];
|
|
if (model) {
|
|
args.push('--model', model);
|
|
}
|
|
args.push(prompt);
|
|
return args;
|
|
}
|
|
|
|
/**
|
|
* Build environment variables for Claude CLI processes (direct PTY, non-mux).
|
|
*
|
|
* Augments process.env with:
|
|
* - UTF-8 locale settings
|
|
* - Augmented PATH (includes Claude CLI directory)
|
|
* - xterm-256color terminal type
|
|
* - Codeman session identification vars
|
|
*
|
|
* @param sessionId - The Codeman session ID
|
|
* @returns Environment variables object for pty.spawn
|
|
*/
|
|
export function buildClaudeEnv(sessionId: string): Record<string, string | undefined> {
|
|
return {
|
|
...process.env,
|
|
LANG: 'en_US.UTF-8',
|
|
LC_ALL: 'en_US.UTF-8',
|
|
PATH: getAugmentedPath(),
|
|
TERM: 'xterm-256color',
|
|
COLORTERM: undefined,
|
|
CLAUDECODE: undefined,
|
|
// Inform Claude it's running within Codeman (helps prevent self-termination)
|
|
CODEMAN_MUX: '1',
|
|
CODEMAN_SESSION_ID: sessionId,
|
|
CODEMAN_API_URL: process.env.CODEMAN_API_URL || 'http://localhost:3000',
|
|
// Path only (not the secret value) — hook curls cat it at execution time (COD-54)
|
|
CODEMAN_HOOK_SECRET_FILE: dataPath('hook-secret'),
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Build environment variables for mux-attached PTY sessions (tmux attach).
|
|
* Lighter than buildClaudeEnv — no PATH augmentation or Codeman vars needed
|
|
* since the mux session already has those set.
|
|
*
|
|
* @returns Environment variables object for pty.spawn
|
|
*/
|
|
export function buildMuxAttachEnv(): Record<string, string | undefined> {
|
|
return {
|
|
...process.env,
|
|
LANG: 'en_US.UTF-8',
|
|
LC_ALL: 'en_US.UTF-8',
|
|
TERM: 'xterm-256color',
|
|
COLORTERM: undefined,
|
|
CLAUDECODE: undefined,
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Build environment variables for a direct shell session (non-mux fallback).
|
|
*
|
|
* @param sessionId - The Codeman session ID
|
|
* @returns Environment variables object for pty.spawn
|
|
*/
|
|
export function buildShellEnv(sessionId: string): Record<string, string | undefined> {
|
|
return {
|
|
...process.env,
|
|
LANG: 'en_US.UTF-8',
|
|
LC_ALL: 'en_US.UTF-8',
|
|
TERM: 'xterm-256color',
|
|
CODEMAN_MUX: '1',
|
|
CODEMAN_SESSION_ID: sessionId,
|
|
CODEMAN_API_URL: process.env.CODEMAN_API_URL || 'http://localhost:3000',
|
|
// Path only (not the secret value) — hook curls cat it at execution time (COD-54)
|
|
CODEMAN_HOOK_SECRET_FILE: dataPath('hook-secret'),
|
|
};
|
|
}
|