feat(p12a): services git distants (PAT/app_password) + clone HTTPS

Modèle de données :
- migration #11 git_credentials (secrets chiffrés SecretBox : secret_encrypted ; colonnes ssh/oauth posées pour P12b/P12c) ; #12 repos ALTER remote_url/git_service/credential_id (pas de FK)
- types partagés api.ts (GitCredentialSummary sans secret + hasSecret/secretLast4, CRUD, RemoteRepoSummary, Clone*) ; protocole additif : topic 'clones' + message clone_update (CloneOperation)

Backend :
- core/git-credentials.ts (GitCredentialsManager(db, box)) : CRUD chiffré, test() (GET /user), getSecret()/authContext() internes, NULLification de repos.credential_id à la suppression
- core/git-clients/ (github/gitlab/gitea) via fetch, sans dépendance : verify()+listRepos() paginés, erreurs typées AUTH_FAILED/RATE_LIMITED/UNREACHABLE, SSRF base_url http(s)
- core/git-auth.ts : withGitAuth (GIT_ASKPASS éphémère 0o700, secret par env, GIT_TERMINAL_PROMPT=0, jamais dans l'URL/.git/config, nettoyage finally)
- core/git.ts cloneRepo (spawn git clone --progress, parse progression, timeout)
- core/clone-manager.ts (EventEmitter) : clone async, dest confiné sous scanRoots + non existant, auto-enregistrement via addRepo + métadonnées de provenance, nettoyage du clone partiel, events topic 'clones'
- routes/git-connections.ts (CRUD + /test + /:id/repos + POST /repos/clone 202 + GET /repos/clone/:id) ; app.ts câble box→GitCredentialsManager + CloneManager→gateway ; gateway relaie 'clones'

Frontend :
- ws-client subscribeClones ; stores git-connections + clone (suivi WS)
- components/settings/GitConnectionsSection (liste + formulaire pat/app_password, secret jamais ré-affiché) inséré dans SettingsView ; CloneRepoModal (connexion → repos distants paginés → dest scanRoots[0] → barre de progression WS → redirection) ; bouton « Cloner » dans DashboardView ; i18n EN+FR

Tests : git-credentials (round-trip SecretBox, résumé sans secret, NULLification) ; acceptance-p12.mjs (clone bare local file:// → clone_update done + repo enregistré + secret ABSENT de l'API, de la DB et du .git/config)

Sous-phases restantes : P12b (SSH), P12c (OAuth device flow).
This commit is contained in:
2026-06-27 14:27:18 +02:00
parent e8d10b7ec0
commit 08695a707d
22 changed files with 1583 additions and 10 deletions

View File

@@ -7,6 +7,7 @@ import {
parseClientMessage,
type GroupSummary,
type RepoSummary,
type CloneOperation,
type ServerMessage,
type SessionSummary,
type SettingsBroadcast,
@@ -18,6 +19,7 @@ import type { SessionArchiveService } from '../core/session-archive.js';
import type { WorktreeManager } from '../core/worktree-manager.js';
import type { GroupManager } from '../core/group-manager.js';
import type { SettingsBus } from '../core/settings-bus.js';
import type { CloneManager } from '../core/clone-manager.js';
const HEARTBEAT_MS = 30_000;
@@ -34,6 +36,7 @@ export function registerWsGateway(
worktrees: WorktreeManager,
groups: GroupManager,
settingsBus: SettingsBus,
clones: CloneManager,
serverVersion: string,
): void {
app.get('/ws', { websocket: true }, (socket: WebSocket, req) => {
@@ -45,6 +48,7 @@ export function registerWsGateway(
let subscribedWorktrees = false;
let subscribedGroups = false;
let subscribedSettings = false;
let subscribedClones = false;
let alive = true;
// Worktrees « regardés » par CETTE connexion (clé repoId\0path) → push ciblé de worktree_changes.
const watched = new Set<string>();
@@ -93,6 +97,10 @@ export function registerWsGateway(
const onSettingsUpdate = (settings: SettingsBroadcast): void => {
if (subscribedSettings) send({ type: 'settings_update', settings });
};
// P12 — progression d'un clone : relayée aux abonnés du topic 'clones'.
const onCloneUpdate = (operation: CloneOperation): void => {
if (subscribedClones) send({ type: 'clone_update', operation });
};
// P7 — détail d'un worktree modifié : poussé UNIQUEMENT si cette connexion le regarde.
const onWorktreeChanges = (e: { repoId: string; path: string }): void => {
if (watched.has(watchKey(e.repoId, e.path))) send({ type: 'worktree_changes', ...e });
@@ -109,6 +117,7 @@ export function registerWsGateway(
groups.on('group_update', onGroupUpdate);
groups.on('group_removed', onGroupRemoved);
settingsBus.on('settings_update', onSettingsUpdate);
clones.on('clone_update', onCloneUpdate);
const heartbeat = setInterval(() => {
if (!alive) {
@@ -149,6 +158,7 @@ export function registerWsGateway(
subscribedWorktrees = msg.topics.includes('worktrees');
subscribedGroups = msg.topics.includes('groups');
subscribedSettings = msg.topics.includes('settings');
subscribedClones = msg.topics.includes('clones');
return;
}
case 'watch': {
@@ -261,6 +271,7 @@ export function registerWsGateway(
groups.off('group_update', onGroupUpdate);
groups.off('group_removed', onGroupRemoved);
settingsBus.off('settings_update', onSettingsUpdate);
clones.off('clone_update', onCloneUpdate);
for (const [, st] of channels) manager.detach(st.sessionId, st.binding);
channels.clear();
// Libère le refcount du watcher pour chaque worktree regardé par cette connexion.