Yaojia Wang
d22dcd24f7
fix: address review report across security, architecture, quality, tests
...
Implements the fixes from docs/REVIEW_REPORT.md (4-agent parallel review).
typecheck clean; 341 tests pass (16 files, +113); build:web ok; coverage
thresholds (80%) enforced in vitest.config.ts.
Critical:
- multi-device approval race: release held approval only when the last
client detaches (closing one mirror no longer cancels another's prompt)
- unbounded session creation (DoS): Config.maxSessions cap (env MAX_SESSIONS),
enforced in manager via the existing M4 exit(-1) path
- signal-handler leak: named SIGINT/SIGTERM/uncaughtException refs removed in close()
- terminal-session initialInput timer tracked + cleared on dispose
- tabs.addEntry null-as-cast type hole removed (build session before entry)
Should-fix:
- security-headers middleware + Origin/CSRF guard on DELETE /live-sessions[/:id]
- history.ts converted to fs/promises (async /sessions handler)
- removed dead clientDims map + blur protocol message end-to-end
- per-connection WS message rate limit (Config.maxMsgsPerSec)
- /sessions behavior kept; documented as accepted LAN risk (TECH_DOC §7)
Tests:
- new tmux / preview-grid / terminal-session (jsdom) / tabs (jsdom) suites
- extended history/config/manager/integration coverage incl. regressions
Hygiene:
- parsePositiveInt -> parseNonNegativeInt; ALLOWED_ORIGINS scheme validation
- log-injection sanitize; isLoopback handles 127.0.0.0/8 + IPv4-mapped
- operational constants moved into Config
- extracted public/preview-grid.ts (DRY launcher/manage)
- doc sweeps: ARCHITECTURE §8 runtime-handle exception, stale comments
2026-06-20 18:27:45 +02:00
Yaojia Wang
97d57326fd
docs: record v0.5 home session chooser (no auto tabs)
2026-06-19 14:52:33 +02:00
Yaojia Wang
9466bf4b6e
docs: record manage-page live preview thumbnail grid
2026-06-19 11:37:57 +02:00
Yaojia Wang
199e29d15b
docs: record latest-writer-wins PTY sizing (full-screen per device)
2026-06-19 11:17:26 +02:00
Yaojia Wang
d782ec8488
docs: record mirror size-clamp fix + 🗂 session manager page
2026-06-19 11:05:28 +02:00
Yaojia Wang
22210fadbc
docs: record v0.4 multi-device session sharing (relaxes invariant #5 )
2026-06-19 10:31:28 +02:00
Yaojia Wang
bae4d72929
docs: log UI refresh + keybar captions + ⌨ cheat-sheet
2026-06-19 09:42:39 +02:00
Yaojia Wang
c5a70a2f36
docs: log O2 done + tech-debt cleared; only O1 + F4/F7(device) remain
2026-06-18 08:10:33 +02:00
Yaojia Wang
99bae333f3
chore: clear tech-debt — *.css module decl removes the @ts-ignore; tick F-table
...
- public/css.d.ts: declare module '*.css' so tsc resolves CSS side-effect
imports; removed the @ts-ignore in main.ts
- PROGRESS_LOG F1-F9 table ticked to match what's actually verified (F4/F7 still
need a physical device)
2026-06-18 08:06:03 +02:00
Yaojia Wang
5b357e67df
docs: mark v0.3 cockpit complete; only optional O1/O2 remain
2026-06-18 07:28:55 +02:00
Yaojia Wang
915a51e4bb
docs: log v0.3 medium batch M3/M6/M7
2026-06-18 07:15:35 +02:00
Yaojia Wang
dcb1bf4845
docs: log v0.3 H1 tmux keepalive
2026-06-17 19:49:30 +02:00
Yaojia Wang
af2a0879e3
docs: log v0.3 H3 remote approve/reject
2026-06-17 19:13:38 +02:00
Yaojia Wang
04355f05e9
docs: log v0.3 H2/H4 Claude status feature
2026-06-17 19:01:10 +02:00
Yaojia Wang
8c2a6825cc
docs: log v0.3 step 1 (FE quick wins)
2026-06-17 18:33:31 +02:00
Yaojia Wang
110c1752d4
docs: log tab-switching fix
2026-06-17 15:46:17 +02:00
Yaojia Wang
bf21ac0ab7
docs: log folder-name tab titles
2026-06-17 15:38:09 +02:00
Yaojia Wang
459a27eda8
docs: log status dot + activity + drag-reorder
2026-06-17 14:55:48 +02:00
Yaojia Wang
064330f8d9
docs: log v0.2 multi-tab + titles + keybar feature
2026-06-17 12:13:17 +02:00
Yaojia Wang
f3b6ad5a68
docs: W5 acceptance — browser smoke (F1/F2/F3/F8) + log v0.1 status
...
7/9 acceptance criteria auto-verified: F1/F2/F3/F8 via headless browser
(xterm renders, echo round-trips, exit prompt, resize survives), F5/F6/F9 via
integration tests. F4 (LAN) + F7 (phone keybar) need physical devices -> user.
gitignore .gstack/.
2026-06-17 11:18:13 +02:00
Yaojia Wang
86c7e3de02
docs: log W2-W4 (T12-T15 done, 187 tests, real-PTY E2E verified)
2026-06-17 10:37:01 +02:00
Yaojia Wang
c27aaa1ac2
docs: log W1 frontend batch (T8-T11 done, 141 tests)
2026-06-16 18:49:01 +02:00
Yaojia Wang
de8c366ab2
docs: log W1 backend batch (T3-T7 done, 128 tests)
2026-06-16 08:10:38 +02:00
Yaojia Wang
0e10dc21c3
feat: T2 freeze src/types.ts (shared contracts)
...
- All ARCHITECTURE §3 interfaces as pure types; dependency-free (no ws/node/DOM)
so both backend and frontend can import it
- Refinements vs §3 (documented): EnvLike (not NodeJS.ProcessEnv), WebSocketLike +
WS_OPEN (not ws.WebSocket), added Config.wsPath (invariant 8)
- ARCHITECTURE §3.1/§3.4 reconciled to match (anti-drift)
- tsc --noEmit passes
T2 of docs/PLAN.md
2026-06-16 07:58:52 +02:00
Yaojia Wang
409b208928
build: adopt esbuild for frontend bundling (build:web → public/build/)
...
- esbuild dev dep; build:web/dev:web bundle public/main.ts → public/build/main.js
- gitignore public/build/; tsconfig.web.json now typecheck-only
- frontend build convention documented in PLAN §1, DISPATCH, ARCHITECTURE §5
- resolves the T1 deferred decision
2026-06-16 07:36:01 +02:00
Yaojia Wang
987cab8eb7
docs: log T1 done; flag frontend-bundling decision for T11/T14
2026-06-16 07:22:33 +02:00
Yaojia Wang
91d0a7189f
docs: add subagent dispatch kit (per-task prompts + templates)
2026-06-16 07:08:54 +02:00
Yaojia Wang
dda09ef2c6
docs: web-terminal v0.1 spec, plan, and multi-agent dev config
...
- TECH_DOC + ARCHITECTURE (cross-validated, 12 fixes M1-M7/L1-L5)
- PLAN: waves W0-W5, tasks T1-T21 for multi-agent parallel dev
- PROGRESS_LOG: orchestrator-owned cross-session memory
- CLAUDE.md: required-reading + orchestrator-worker workflow
- .claude/agents: module-builder, module-reviewer
2026-06-16 06:54:57 +02:00