Compare commits

..
27 Commits
Author SHA1 Message Date
Johan LEROYandClaude Opus 4.8 7ac933ca9a release: @johanleroy/git-arboretum 1.0.2
CI / Build & test (Node 22) (push) Successful in 9m47s
CI / Build & test (Node 24) (push) Successful in 9m41s
Release / Publish to Gitea npm registry (push) Successful in 9m38s
CI / Pack & boot smoke (Node 22) (push) Failing after 4m56s
Cookie de session Secure conditionnel (x-forwarded-proto) + sous-commande
`arboretum install` (service systemd/launchd, --dry-run), routeur de sous-commandes
avec rétrocompat daemon stricte.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 16:23:28 +02:00
Johan LEROYandClaude Opus 4.8 7f42743fce feat: cookie Secure conditionnel + sous-commande d'installation de service
CI / Build & test (Node 24) (push) Has been cancelled
CI / Pack & boot smoke (Node 22) (push) Has been cancelled
CI / Build & test (Node 22) (push) Has been cancelled
Cookie: routes/auth.ts pose `secure` sur le cookie de session quand la requête
arrive en HTTPS (x-forwarded-proto), sans trustProxy — durcit le cookie derrière
Tailscale Serve sans casser le localhost http.

Install: nouveau cli/install.ts + routeur de sous-commandes dans index.ts
(install/uninstall/status/serve). Service utilisateur systemd (Linux) ou launchd
(macOS), bootstrap du token, --dry-run/--no-enable. Rétrocompat stricte du daemon
par défaut (runDaemon extrait).

Tests: app.e2e (cookie Secure local vs HTTPS) + cli-install (fonctions pures).
203/203 verts, acceptation P1/P4 vertes.

Docs: README.md + README.fr.md (installeur multi-OS, distinction utiliser/cloner,
modèle de sécurité durci).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 16:17:08 +02:00
Johan LEROYandClaude Opus 4.8 e2147e369b release: @johanleroy/git-arboretum 1.0.1
CI / Build & test (Node 22) (push) Successful in 9m43s
CI / Build & test (Node 24) (push) Successful in 9m41s
Release / Publish to Gitea npm registry (push) Successful in 9m33s
CI / Pack & boot smoke (Node 22) (push) Failing after 4m56s
Republie pour rafraîchir le README embarqué (page du paquet) :
- doc d'install sans token (paquet public)
- README français + sélecteur de langue
- copy-meta réécrit le lien FR en absolu (page du paquet)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 14:32:28 +02:00
Johan LEROYandClaude Opus 4.8 6b343bcc4b docs: retire la ligne _authToken des instructions d'install
CI / Build & test (Node 24) (push) Has been cancelled
CI / Pack & boot smoke (Node 22) (push) Has been cancelled
CI / Build & test (Node 22) (push) Has been cancelled
Le paquet est en lecture publique sur le registre Gitea (install anonyme
vérifiée) : seule la redirection de scope est nécessaire, pas de token.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 14:29:22 +02:00
Johan LEROYandClaude Opus 4.8 95f0e0189f docs: README en français (README.fr.md) + sélecteur de langue
CI / Build & test (Node 24) (push) Has been cancelled
CI / Pack & boot smoke (Node 22) (push) Has been cancelled
CI / Build & test (Node 22) (push) Has been cancelled
- ajoute une traduction française complète du README
- lien de langue (English ⇄ Français) en tête des deux fichiers
- corrige une référence résiduelle `npx git-arboretum` → `@johanleroy/git-arboretum`

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 14:22:17 +02:00
Johan LEROYandClaude Opus 4.8 c78571af07 release: @johanleroy/git-arboretum 1.0.0 — publication sur le registre Gitea
CI / Build & test (Node 22) (push) Successful in 9m42s
CI / Build & test (Node 24) (push) Successful in 9m41s
CI / Pack & boot smoke (Node 22) (push) Has been cancelled
Release / Publish to Gitea npm registry (push) Successful in 9m37s
- renomme le paquet en @johanleroy/git-arboretum (scope routé vers le registre npm Gitea privé)
- embarque @arboretum/shared via bundleDependencies (scripts/vendor-shared.mjs au prepack)
- joint README/LICENSE au tarball (scripts/copy-meta.mjs) + metadata, keywords, publishConfig
- CI pack-smoke en mono-tarball avec assertion bundleDep ; nouveau workflow release.yml (publish sur tag v*)
- version 1.0.0 ; README mis à jour (install scopé + service systemd)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 13:53:30 +02:00
Johan LEROYandClaude Opus 4.8 416e5577cb feat(web): sélecteur de répertoire (parcourir au lieu de taper le chemin)
CI / Build & test (Node 22) (push) Successful in 9m45s
CI / Build & test (Node 24) (push) Successful in 9m42s
CI / Pack & boot smoke (Node 22) (push) Successful in 9m44s
Ajoute un navigateur de dossiers réutilisable sur les deux champs qui
exigeaient un chemin absolu tapé à la main : « Répertoire de travail »
(nouvelle session) et « Chemin du dépôt » (ajout de repo). Un bouton
« Parcourir… » déplie un panneau inline ; le champ texte reste pour
taper/coller un chemin connu. Pour l'ajout de repo, les sous-dossiers
qui sont des dépôts git sont signalés par un badge.

Serveur : nouvel endpoint GET /api/v1/fs/list (authentifié par le hook
preValidation global), ne renvoie que des noms de sous-dossiers (jamais
de contenu de fichier). Valide le chemin via resolve() (clampe à la
racine, neutralise « .. »), masque les dotfiles par défaut (showHidden),
annote les dépôts git (markRepos), tolère les entrées illisibles.

Tests : packages/server/test/fs-routes.test.ts (10 cas — listing, tri,
hidden, markRepos, rejets 400/404, auth 401). Suite : 185/185 verts.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 13:04:10 +02:00
Johan LEROYandClaude Opus 4.8 8c45852232 fix(ci): embarquer les fixtures de dialogue dans le paquet de test
CI / Build & test (Node 22) (push) Successful in 9m44s
CI / Build & test (Node 24) (push) Successful in 9m41s
CI / Pack & boot smoke (Node 22) (push) Successful in 9m43s
Les tests de dialog-detection lisaient leurs captures dans
spikes/s3-tui/captures/, dossier exclu du suivi git (.gitignore :
spikes/**/captures/ + la règle globale *.log). Verts en local mais
absents au checkout CI → ENOENT sur 9 tests.

Les 5 fixtures réellement utilisées sont déplacées dans
packages/server/test/fixtures/dialogs/ et renommées *.raw (sans .log)
pour échapper aux deux règles d'ignore. Le test pointe désormais ce
dossier. Suite hermétique : 175/175 verts, fixtures versionnées.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 12:11:17 +02:00
Johan LEROY d26303f36f init logo
CI / Build & test (Node 22) (push) Failing after 5m3s
CI / Build & test (Node 24) (push) Failing after 5m1s
CI / Pack & boot smoke (Node 22) (push) Has been skipped
2026-06-17 11:54:56 +02:00
Johan LEROYandClaude Opus 4.8 099e14db97 fix(build): ne plus suivre les *.tsbuildinfo
CI / Build & test (Node 22) (push) Failing after 5m5s
CI / Pack & boot smoke (Node 22) (push) Has been cancelled
CI / Build & test (Node 24) (push) Has been cancelled
Les `packages/*/tsconfig.tsbuildinfo` étaient commités alors que `dist/`
est gitignoré. Sur un checkout neuf de la CI, `tsc -b` lit ce tsbuildinfo,
juge `@arboretum/shared` déjà émis et saute la génération de `dist/` →
`TS2307: Cannot find module '@arboretum/shared'` sur tout le serveur
(+ une `TS7006` en cascade). On dé-tracke les tsbuildinfo et on les ignore.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 11:45:36 +02:00
Johan LEROYandClaude Opus 4.8 9d6ed0a2a5 docs: README propre pour visiteurs + .gitignore + sortir CLAUDE.md du suivi
CI / Build & test (Node 22) (push) Failing after 5m1s
CI / Build & test (Node 24) (push) Failing after 4m56s
CI / Pack & boot smoke (Node 22) (push) Has been skipped
- README réécrit (anglais) : setup, quick start, usage, accès Tailscale,
  flags CLI, sécurité, comparatif, section développement
- .gitignore réorganisé par sections (ajout *.tgz, coverage, .claude, .remember, CLAUDE.md)
- CLAUDE.md retiré du suivi git (reste local, non publié)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 11:19:51 +02:00
Johan LEROYandClaude Opus 4.8 1cf4d29655 docs: P4 livré (supervision mobile : answer + Web Push + PWA)
README et CLAUDE.md reflètent désormais P4 comme livré (et non plus « à venir »),
avec les caveats Web Push (HTTPS/Tailscale, PWA installée sur iOS).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 12:23:53 +02:00
Johan LEROYandClaude Opus 4.8 fbbfafae9b P4-C: PWA installable, service worker push & campagne de fiabilité dialogues
- PWA: public/manifest.webmanifest + icon.svg + meta index.html (theme-color, apple-touch-icon)
- public/sw.js: service worker push-only (push → showNotification tag=sessionId ;
  notificationclick → focus/ouvre /sessions/<id>) — pas de précache (hors périmètre)
- lib/push.ts + stores/push.ts: enable/disable, abonnement VAPID, enregistrement SW au boot
- DashboardView: toggle « Notifications » (gardé par pushSupported) + i18n en/fr
- campagne de fiabilité (verdict S3): classification de tous les types de dialogue sur captures
  réelles (trust/permission×2/question) + refus Esc (deny-esc2) + plan (synthétique)
- acceptance-p4.mjs: VAPID/auth/Origin, subscribe idempotent/unsubscribe, answer (rejets)

Choix: SW écrit à la main plutôt que vite-plugin-pwa (qui tirait ~295 paquets Workbox +
2 vulns esbuild high pour un SW push-only). Zéro dépendance front nouvelle. 175 tests verts,
acceptance p1..p4 ALL GREEN.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 12:23:00 +02:00
Johan LEROYandClaude Opus 4.8 28b9283825 P4-B: notifications Web Push (VAPID) sur passage en waiting
- db: migration id=4 `push_subscriptions` (liées au token d'auth) ; clés VAPID en settings
- PushService: bootstrap idempotent des clés VAPID, subscribe/unsubscribe/count,
  notify() best-effort (purge des abonnements 410/404 Gone) ; sender injectable pour les tests
- routes/push.ts: GET vapid-public-key, POST subscribe/unsubscribe/test (toutes sous auth globale)
- pty-manager: déclencheur push sur FRONT MONTANT vers waiting, débouncé 1500ms et annulable
  (faux positif ignoré) ; câblage app/index/config (--vapid-contact)
- shared/api.ts: types VapidKeyResponse / PushSubscribeRequest / PushUnsubscribeRequest
- deps: web-push (+ @types/web-push) côté serveur
- tests: push-service (idempotence, UPSERT, 410-purge, payload) + trigger pty-manager (169 verts)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 12:13:56 +02:00
Johan LEROYandClaude Opus 4.8 9f7c13dddb P4-A: commande WS answer — répondre aux dialogues sans clavier
Nouvelle commande WS de haut niveau `answer {channel, action, optionN?}`
traduite côté serveur en keystrokes (chiffre+Entrée / Entrée / Esc) et
validée contre le dialogue courant du tracker (anti-frappe fantôme mobile).

- protocol.ts : message `answer` + validation parseClientMessage + ErrorCode INVALID_ANSWER
- pty-manager.answer() : mappe l'intention en write PTY, réutilise le modèle mono-utilisateur
- gateway : case `answer` (NOT_CONTROLLING / SESSION_EXITED / INVALID_ANSWER)
- web : Attachment.answer(), DialogPrompt.vue (attache interactive légère sink no-op),
  intégré dans SessionView, SessionsListView, WorktreeCard + i18n en/fr
- tests : parseClientMessage (answer valide/malformé + fuzz), pty-manager.answer (163 verts)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 12:05:27 +02:00
Johan LEROYandClaude Opus 4.8 8b41140af7 docs: statut MVP atteint (P1–P3 livrés, P4 en cours) + ignore .idea/
README et CLAUDE.md reflètent désormais la réalité : découverte/reprise,
worktrees multi-repo, états fins et dashboard sont livrés et testés. La
prochaine phase est P4 (supervision mobile : answer + Web Push + PWA).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 11:57:28 +02:00
Johan LEROYandClaude Opus 4.8 04583ea25a P3-C: badges de session live sur le dashboard (résolus depuis le store sessions)
Les badges busy/waiting/idle des sessions affichées dans les cartes worktree
sont désormais résolus depuis le store des sessions (mis à jour en temps réel),
au lieu de l'instantané embarqué dans le worktree — pour que « quelle session
attend une réponse » reste live sans attendre un worktree_update.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 18:48:07 +02:00
Johan LEROYandClaude Opus 4.8 c224abe108 P3-C: dashboard worktree-first + acceptance P3 (MVP complet)
Vue racine consolidée : repos → worktrees avec état git ET état de session
corrélé. Complète le MVP (P2 découverte/reprise + P3-A worktrees + P3-B états fins).

- web/lib/ws-client: abonnement multi-topics (sessions + worktrees), subscribeWorktrees.
- web/stores/worktrees: repos + worktrees, CRUD, temps réel (repo_update/worktree_*).
- web/views/DashboardView (route racine /), components RepoSection + WorktreeCard ;
  SessionStateBadge réutilisé pour l'état des sessions corrélées.
- router: / = dashboard, /sessions = liste à plat (sessions hors worktree), nav croisée.
- i18n EN/FR (dashboard/repos/worktrees).
- fix: @xterm/headless est CommonJS → chargé via createRequire (l'import nommé ESM
  échouait sous Node natif, masqué par esbuild en test) ; détecté par l'acceptation.
- scripts/acceptance-p3.mjs: repo git tmp → enregistrement, worktree + hook, broadcast
  WS worktree_update, corrélation session bash, suppression (409 sans force, 200 avec).

Vérifs : typecheck, 159 tests, build (vue-tsc), acceptations P1/P2/P3 ALL GREEN.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 18:46:45 +02:00
Johan LEROYandClaude Opus 4.8 33a41e7a30 P3-B: claude-adapter — états fins busy/waiting/idle
Détection de l'état fin d'une session claude et du dialogue en cours, pour
savoir « quelle session attend une réponse ». Source primaire = registre
~/.claude/sessions (stable) ; l'écran reconstruit via @xterm/headless TYPE le
dialogue (trust/permission/question/plan) et couvre le cas Trust (avant registre).

- dép: @xterm/headless ^6.0.0 (aligné sur @xterm/xterm du front).
- core/screen-reader.ts: terminal headless persistant par session, alimenté
  par le flux PTY ; snapshotLines() préserve les espaces (bat le strip ANSI naïf).
- core/dialog-classifier.ts: typage pur (texte aplati + regex tolérante inter-
  versions) + extraction des options numérotées (❯ = sélection).
- core/claude-adapter.ts: SessionActivityTracker par session (registre + écran
  → activity + dialog), évaluation débouncée sur output + poll registre léger,
  émission sur changement effectif uniquement.
- shared: SessionSummary += activity?/waitingFor?/dialog? (optionnels, additif).
- pty-manager: tracker instancié pour claude, feed dans handleOutput, summarize
  enrichi, resize propagé, dispose à l'exit.
- web: composant SessionStateBadge (busy/waiting/idle colorés) réutilisable.
- tests: screen-reader + classifier sur fixtures réelles S3 (perm-write/ask/
  trust), claude-adapter (machine à états). 159 verts.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 18:39:38 +02:00
Johan LEROYandClaude Opus 4.8 bad1230a21 P3-A: worktrees multi-repo & cycle de vie (backend)
Enregistrement de repos et gestion de leurs worktrees git, source de vérité
= git (worktrees dérivés + cache court par repo), corrélation worktree ↔
sessions par cwd, mutations sérialisées par repo.

- shared: RepoSummary, PostCreateHook, WorktreeSummary, WorktreeGitStatus ;
  messages WS repo_update/worktree_update/*_removed ; topic sub 'worktrees'
  (+ parseClientMessage) ; DTOs REST repos/worktrees.
- db: migration id:3 (table repos).
- core/git.ts: couche git sûre (execFile, jamais de shell, -- avant chemins,
  GIT_OPTIONAL_LOCKS=0), parseWorktreePorcelain, list/add/remove/prune/status/
  ahead-behind, validation branche + chemin.
- core/claude-trust.ts: pré-trust atomique de ~/.claude.json (spike S3).
- core/worktree-manager.ts: repos CRUD, create (worktree add + pré-trust +
  hooks post-create + startSession optionnel), adopt, delete (garde-fous 409
  dirty / 400 main / 409 session live), prune ; events.
- routes/repos.ts + routes/worktrees.ts, câblage app.ts, gateway topic worktrees.
- tests: git (repos tmp réels), claude-trust, worktree-manager (146 verts).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 18:31:06 +02:00
Johan LEROYandClaude Opus 4.8 c177eeea07 P2: découverte & reprise des sessions Claude
Arboretum découvre désormais toutes les sessions Claude de la machine
(scan ~/.claude/projects + registre ~/.claude/sessions), distingue
vivantes/mortes par pid+procStart, et permet de reprendre une morte
(--resume dans son cwd d'origine) ou forker une vivante sans la corrompre.

- shared: SessionSummary enrichi (source, claudeSessionId, pid, resumable,
  attachable, registryStatus) — additif, PROTOCOL_VERSION inchangé ;
  types REST resume/fork.
- db: migration id:2 (claude_session_id, resumed_from).
- core: jsonl-discovery (parseur tolérant, scan asynchrone non bloquant),
  session-registry (vivacité pid+procStart), discovery-service (cache +
  refresh périodique + diff/broadcast), pty-manager (resume/fork + capture
  du claudeSessionId via le registre).
- routes: /sessions/:id/resume (garde-fou 409 anti-corruption sur session
  vivante) et /fork ; GET fusionné managées + découvertes ; relais WS.
- web: badges managed/discovered + busy/idle/waiting, actions conditionnelles
  (Open/Observe/Kill vs Fork/View vs Resume/Fork), vue read-only des sessions
  externes, i18n EN/FR.
- tests: jsonl-discovery, session-registry, discovery-service + resume/fork
  (130 verts) ; acceptation E2E acceptance-p2.mjs (sans quota) ALL GREEN.

Conforme aux verdicts S1 (resume dans cwd d'origine, vivacité pid+procStart)
et S4 (munge cwd, parseur tête+queue, priorité de titre).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-12 18:20:21 +02:00
Johan LEROYandClaude Fable 5 770f58a640 P1 complete: web front, test suite, CI — acceptance ALL GREEN
Fan-out integration + fixes found by the test/acceptance pass:
- FIX ring-buffer: chunks >= capacity skipped bytes now count into the
  monotonic offset (invariant: stream byte k lives at k % capacity) —
  window order was corrupted on unaligned big chunks
- FIX auth: non-numeric cookie expiry no longer bypasses expiration
- FIX protocol: safe-integer validation on ack.bytes / hello.protocol
- FIX @fastify/websocket v11: websocket route must be registered in an
  encapsulated context after plugin load (handler got REST signature)
- FIX flow-control deadlock found by e2e acceptance: client only ACKs
  on data receipt, so pausing with an unACKed residue in (LOW,
  ACK_EVERY] stalled both sides at 0.9 MB. ACK_EVERY now 64 KiB (<=
  LOW invariant, tested) + trailing debounced ACK in the web client
- Web: Vue 3 + Vite + Pinia + Tailwind 4 + vue-i18n (EN/FR) + xterm 6
  (fit + webgl fallback), multiplexed ws-client with reconnect/backoff
  and resync epochs
- Tests: 100 vitest (protocol fuzz, ring edges, auth, pty-manager flow
  control with mocked pty, REST e2e) ; CI Node 22/24 + pack-smoke
- scripts/acceptance-p1.mjs: real daemon + real WS client — boot,
  login, attach, stdin, 10 MB flood w/ ACK (13.7 MB/1.9s, RSS bounded),
  brutal disconnect + replay resync, kill broadcast, SIGTERM drain

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 22:29:58 +02:00
Johan LEROYandClaude Fable 5 f6f73329b9 P1 spine: monorepo, shared WS protocol, server daemon
- npm workspaces (shared / server / web), TS strict, project refs
- @arboretum/shared: multiplexed WS protocol (JSON control + binary
  output frames: 1B type + u32le channel), flow-control constants
  (ACK 256K, HIGH 384K, LOW 128K, lagging 2M), REST types
- git-arboretum server: Fastify 5 + node:sqlite (single native dep:
  node-pty prebuilt), token auth (sha256 at rest, HMAC cookie, global
  login rate limit + backoff), strict Origin check on /api and /ws,
  PtyManager (2MiB ring with monotonic offset, resync replay = reset +
  256KiB tail, pause/resume only when ALL interactive clients exceed
  HIGH, observers never throttle, lagging clients resync), WS gateway
  (attach/stdin/resize/ack, heartbeat 30s), SIGTERM→SIGKILL 5s grace
- CLI: arboretum [--port 7317] [--bind 127.0.0.1] — non-loopback bind
  requires an explicit safety flag
- Smoke-tested: login/401/403-origin/spawn bash/kill/grace-SIGKILL all
  green

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 22:04:09 +02:00
Johan LEROYandClaude Fable 5 8733c17e44 Spike S3: TUI dialogs, keystrokes — GO (documented partial)
Response protocol: digit positions + Enter confirms (digit alone is not
enough); arrows+Enter work everywhere. Registry detects waiting state
for both permission and AskUserQuestion dialogs (same waitingFor label
— fine-grained dialog typing needs screen reading). Sandboxed bash runs
no-prompt for most commands: real waits come from edits/network/
questions. Pre-trust via ~/.claude.json projects[dir]
.hasTrustDialogAccepted captured and plausible. Esc-deny and plan
approval deferred to P4 reliability campaign.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 17:58:28 +02:00
Johan LEROYandClaude Fable 5 c98f619b25 Spike S1: resume/fork/liveness — GO; flood: pause/resume — GO
Demonstrated on CLI 2.1.173: resuming a live session interleaves both
TUIs into one transcript (no lock, no warning) — liveness detection via
registry pid+procStart is mandatory; --fork-session is safe on live
sessions; --resume must run in the session's original cwd ("No
conversation found" otherwise); registry files are cleaned on graceful
exit AND SIGTERM, may be GC'd later after SIGKILL — never reason on
file presence. ANSI-stripped TUI text loses spaces (cursor-positioned
painting) — confirms @xterm/headless for screen parsing.
Flood: 21 MB through node-pty with 10s pause => 0 bytes leaked, no
loss, 4.7 ms echo after flood.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 17:47:05 +02:00
Johan LEROYandClaude Fable 5 45dba47b8b Spike S4: JSONL discovery + sessions registry — GO
99.8% of 1318 real transcripts (449 MB) yield sessionId+cwd in 1.37s
(head+tail reads only). Munge cwd→dir validated on 100% of files.
Registry pid/procStart liveness check validated 3/3. 12 line types
inventoried, ai-title is the best title source.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 17:39:19 +02:00
Johan LEROYandClaude Fable 5 f4075e0385 Initial commit: positioning, license, project scaffold
Arboretum — self-hosted web dashboard for git worktrees and the Claude
Code sessions running on them. README states the positioning vs
GitKraken Agent Mode, Happy/CloudCLI and Anthropic Remote Control, the
security model (localhost-first + Tailscale), and the Claude usage note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 17:37:07 +02:00
10 changed files with 912 additions and 24 deletions
+254
View File
@@ -0,0 +1,254 @@
<p align="center">
<img src="brand/arboretum-logo-on-dark.png" alt="Arboretum" width="300">
</p>
<p align="center">
Un dashboard web auto-hébergé pour vos worktrees git et les sessions Claude Code qui tournent dessus — depuis n'importe quel appareil.
</p>
<p align="center">
<a href="README.md">English</a> · <strong>Français</strong>
</p>
**Statut : MVP.** Le dashboard worktree-first, la découverte et la reprise de sessions, le cycle de vie des worktrees multi-repo, les états de session en temps réel, le terminal web et la supervision mobile (PWA installable, Web Push quand une session vous attend, valider/refuser sans ouvrir de terminal) sont implémentés et testés.
---
## Le problème
Travailler avec des agents de code IA a changé notre usage de git : une feature = un worktree = une session Claude Code, plusieurs en parallèle. Mais l'outillage n'a pas suivi :
- `git worktree list` sur plusieurs repos est fastidieux, les worktrees s'accumulent, chacun a besoin de ses `node_modules` et `.env`.
- Les sessions Claude Code sont éparpillées : certaines tournent dans des terminaux, d'autres sont reprenables depuis l'historique, sans vue consolidée de *celle qui attend votre intervention*.
- Quand vous vous éloignez de votre poste, une session bloquée sur une demande de permission reste bloquée.
## Ce que fait Arboretum
Un unique daemon Node.js que vous lancez sur votre machine de dev (`npx @johanleroy/git-arboretum`), servant une interface web utilisable depuis votre ordinateur, téléphone ou tablette :
- **Dashboard worktree-first, multi-repo** — chaque worktree de chaque repo enregistré, avec son état git (branche, ahead/behind, fichiers modifiés) *et* l'état de sa session Claude Code (busy / en attente d'entrée / idle / reprenable).
- **Cycle de vie complet des worktrees** — créer (avec des hooks post-création par repo : `npm ci`, copie de `.env`…), adopter des worktrees créés à la main, supprimer avec garde-fous, élaguer les orphelins.
- **Découverte & reprise de sessions** — les sessions lancées dans votre propre terminal apparaissent automatiquement ; reprenez les sessions mortes, observez ou forkez les vivantes. Ne corrompt jamais une session vivante.
- **Terminal web** — terminal xterm.js complet vers chaque session managée, qui survit aux déconnexions du navigateur.
- **Supervision depuis votre téléphone** — PWA installable avec notifications push quand une session vous attend ; validez ou refusez une demande sans ouvrir de terminal.
---
## Prérequis
- **Node.js ≥ 22.16** — requis, pas seulement recommandé. Arboretum persiste son état avec `node:sqlite` (`DatabaseSync`), natif et stable seulement à partir de cette version. (`.nvmrc` fixe `22`.)
- **Le CLI `claude`** sur votre `PATH` si vous voulez qu'Arboretum lance et gère des sessions Claude Code. Arboretum enveloppe le CLI interactif que vous utilisez déjà — installez-le et authentifiez-le comme d'habitude.
- Un **dépôt git** (ou plusieurs) que vous voulez gérer.
## Démarrage rapide
Deux chemins, selon ce que vous voulez :
- **Juste l'utiliser (la plupart des gens).** Arboretum est un paquet npm publié — vous **n'avez pas besoin de cloner ce dépôt**. Pointez npm vers le registre et lancez-le (ci-dessous). À faire sur la machine où tournent vos sessions Claude Code.
- **Lancer depuis les sources.** Ne clonez le dépôt que pour développer Arboretum ou lancer une version non publiée.
### Le lancer (recommandé)
Arboretum est publié sur un registre npm Gitea auto-hébergé. Pointez le scope `@johanleroy` dessus une fois par machine — ajoutez à `~/.npmrc` :
```
@johanleroy:registry=https://git.lidge.fr/api/packages/johanleroy/npm/
```
Aucun token nécessaire — le paquet est en lecture publique. Puis lancez-le depuis n'importe où :
```bash
npx @johanleroy/git-arboretum
```
Au premier démarrage, Arboretum affiche un **token d'accès** unique et l'URL à ouvrir :
```
┌──────────────────────────────────────────────────────────────────┐
│ First start — your access token (shown once, store it safely): │
└──────────────────────────────────────────────────────────────────┘
<votre-token-ici>
Login at: http://127.0.0.1:7317/
```
Ouvrez l'URL, collez le token pour vous connecter, et c'est parti. Le token est stocké **hashé** — il n'est affiché qu'une seule fois, alors gardez-le en lieu sûr (un gestionnaire de mots de passe). Vous pourrez gérer vos tokens plus tard depuis les **Réglages**.
`npx` télécharge et lance la dernière version publiée à chaque fois. Pour l'installer une bonne fois — et obtenir la commande `arboretum` sur votre `PATH`, dont se sert le [service d'arrière-plan](#le-faire-tourner-en-service-darrière-plan) —, installez-le plutôt globalement :
```bash
npm i -g @johanleroy/git-arboretum
arboretum # identique à la commande npx, depuis le binaire installé
```
### Lancer depuis les sources
Nécessaire uniquement pour **développer** Arboretum ou lancer une version non publiée — pas pour simplement l'utiliser. Clonez le dépôt, installez les dépendances, buildez, puis démarrez le daemon :
```bash
git clone https://git.lidge.fr/johanleroy/arboretum.git
cd arboretum
nvm use # ou assurez-vous d'avoir Node ≥ 22.16
npm install
npm run build # build shared → server → web (l'ordre compte)
node packages/server/dist/index.js
```
## Utiliser Arboretum
1. **Ajoutez un dépôt.** Depuis le dashboard, enregistrez un repo git local par son chemin. Configurez éventuellement des **hooks post-création** (ex. `npm ci`, `cp ../.env .env`) exécutés automatiquement à chaque création d'un nouveau worktree pour ce repo.
2. **Créez ou adoptez des worktrees.** Créez un nouveau worktree + branche en un clic (les hooks s'exécutent pour vous), ou adoptez un worktree créé à la main. Chaque worktree affiche sa branche, son ahead/behind et son nombre de fichiers modifiés.
3. **Démarrez ou reprenez une session.** Lancez une session Claude Code sur un worktree, ou reprenez-en une démarrée dans votre terminal — Arboretum découvre les sessions existantes automatiquement et les reprend toujours dans leur répertoire de travail d'origine.
4. **Suivez les états en direct.** Chaque session indique si elle est *busy*, *en attente de votre entrée* ou *idle*. Ouvrez le **terminal web** pour interagir directement ; il survit aux déconnexions du navigateur (fermer l'onglet ne tue pas la session).
5. **Supervisez depuis votre téléphone.** Installez la PWA, et quand une session bascule en *attente*, vous recevez une notification push. Validez ou refusez la demande directement depuis l'interface de notification — sans terminal.
## Accès distant depuis votre téléphone
Arboretum se bind sur `127.0.0.1` par défaut et **refuse** de se binder sur une adresse non-loopback sans dérogation explicite. La façon recommandée (et sûre) de l'atteindre depuis d'autres appareils est **[Tailscale Serve](https://tailscale.com/kb/1242/tailscale-serve)** — HTTPS valide, identité tailnet, aucun port ouvert :
```bash
# Expose le daemon local en HTTPS dans votre tailnet
tailscale serve --bg 7317
```
Puis démarrez Arboretum en autorisant l'origine de votre tailnet (le check Origin strict doit la connaître) :
```bash
npx @johanleroy/git-arboretum --allow-origin https://<machine>.<tailnet>.ts.net
```
Ouvrez `https://<machine>.<tailnet>.ts.net` depuis n'importe quel appareil de votre tailnet. **Web Push exige HTTPS**, donc Tailscale Serve (ou un autre front HTTPS) est aussi ce qui active les notifications mobiles. Sur **iOS**, installez d'abord l'app à l'écran d'accueil, puis autorisez les notifications.
> ⚠️ Un terminal web, c'est de l'exécution de code à distance **par conception**. N'exposez jamais Arboretum directement sur l'internet public.
## Le faire tourner en service d'arrière-plan
Le plus rapide pour faire tourner Arboretum en service qui survit à la déconnexion et redémarre au boot, c'est l'installeur intégré. Installez une version figée globalement, puis lancez `install` — il détecte votre OS, écrit le fichier de service, le démarre et affiche le token unique :
```bash
npm i -g @johanleroy/git-arboretum
arboretum install --allow-origin https://MACHINE.TAILNET.ts.net
```
Cela met en place un **service systemd utilisateur** sous Linux (`~/.config/systemd/user/arboretum.service`) ou un **LaunchAgent launchd** sous macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`). Tous les flags du daemon (`--port`, `--allow-origin`, `--db`, …) sont propagés au service. Gérez-le avec :
```bash
arboretum status # état du service (+ où lire les logs)
arboretum uninstall # arrête et supprime le service
```
Les logs vivent dans `journalctl --user -u arboretum -f` (Linux) ou `~/Library/Logs/arboretum/` (macOS). Lancez d'abord `arboretum install --dry-run …` pour afficher le unit/plist et les commandes exactes sans rien modifier.
<details>
<summary>Vous préférez configurer systemd à la main ? (Linux)</summary>
Créez `~/.config/systemd/user/arboretum.service` :
```ini
[Unit]
Description=Arboretum — git worktree & Claude Code dashboard
After=network-online.target
Wants=network-online.target
[Service]
ExecStart=%h/.local/bin/arboretum --port 7317 --allow-origin https://MACHINE.TAILNET.ts.net
Restart=on-failure
RestartSec=5
KillSignal=SIGTERM
TimeoutStopSec=10
Environment=NODE_ENV=production
[Install]
WantedBy=default.target
```
```bash
which arboretum # ajustez ExecStart au vrai chemin si besoin
systemctl --user daemon-reload
systemctl --user enable --now arboretum
loginctl enable-linger "$USER" # démarre le service au boot, sans session ouverte
journalctl --user -u arboretum -f # logs
```
</details>
> Le **token d'accès** unique est affiché par `arboretum install` (et au tout premier lancement manuel sur base vierge). Le token est hashé et n'est jamais réaffiché — conservez-le en lieu sûr.
## Configuration
Commandes : `arboretum` démarre le daemon (par défaut), `arboretum serve` en est un alias explicite, `arboretum install` / `uninstall` / `status` gèrent le service d'arrière-plan, et `arboretum help` affiche l'aide.
Les options du daemon sont des flags CLI :
| Flag | Défaut | Description |
|---|---|---|
| `--port <n>` | `7317` | Port d'écoute. |
| `--bind <addr>` | `127.0.0.1` | Adresse de bind. Une adresse non-loopback est refusée sauf si `--i-know-this-exposes-a-terminal` est défini. |
| `--allow-origin <url>` | — | Origine `Origin` autorisée supplémentaire (répétable). Nécessaire pour l'accès Tailscale/HTTPS. |
| `--db <path>` | `<data>/arboretum.db` | Chemin de la base SQLite. |
| `--vapid-contact <mailto/url>` | `mailto:arboretum@localhost` | Sujet de contact VAPID pour le Web Push. |
| `--print-token` | `false` | Indication sur le réaffichage du token (les tokens sont hashés et ne peuvent pas être réaffichés). |
| `--i-know-this-exposes-a-terminal` | `false` | Reconnaître le bind sur une adresse non-loopback. **À éviter** — préférez Tailscale Serve. |
`arboretum install` accepte tous les flags du daemon ci-dessus (propagés tels quels au service), plus :
| Flag | Description |
|---|---|
| `--bin-path <path>` | Utilise ce binaire dans le service au lieu de `node` + le script embarqué. |
| `--label <id>` | Label launchd (macOS uniquement, défaut `fr.lidge.arboretum`). |
| `--dry-run` | Affiche le unit/plist et les commandes sans rien appliquer. |
| `--no-enable` | Écrit le fichier de service sans l'activer/le démarrer. |
L'état (la base SQLite) vit dans `$XDG_DATA_HOME/arboretum` (par défaut `~/.local/share/arboretum`).
## Modèle de sécurité
Un terminal web, c'est de l'exécution de code à distance *par conception*. Les garde-fous d'Arboretum sont structurants :
- Se bind sur `127.0.0.1` par défaut ; refuse les binds non-loopback sans flag explicite.
- Authentifie **chaque** requête `/api/**` **et** chaque upgrade `/ws` avec des tokens révocables, et applique un **check `Origin` strict** (le cookie `SameSite=Strict` ne couvre pas les upgrades WebSocket — c'est le garde-fou anti cross-site hijacking).
- Les tokens sont stockés **hashés** (sha256) et comparés en temps constant ; le bootstrap token n'est affiché qu'une seule fois. Le cookie de session est un payload signé HMAC, `HttpOnly` et `SameSite=Strict`, et reçoit automatiquement le flag `Secure` quand la requête arrive en HTTPS (p. ex. derrière Tailscale Serve). Le login est rate-limité avec backoff exponentiel.
Tailscale Serve est **la** façon d'atteindre Arboretum depuis d'autres appareils — pas seulement une recommandation : HTTPS valide, identité tailnet, aucun port ouvert. Le flag `--i-know-this-exposes-a-terminal` est une trappe de secours, pas un mode de déploiement ; n'exposez jamais Arboretum directement sur internet.
## Ce qui le distingue
| | Arboretum | GitKraken Agent Mode / Conductor / Nimbalyst | Happy / CloudCLI | Anthropic Remote Control |
|---|---|---|---|---|
| Interface web, tout appareil | ✅ | ❌ apps desktop | ✅ | ✅ |
| Gestion visuelle des worktrees (multi-repo) | ✅ | ✅ (mono-repo, desktop) | ❌ | ❌ |
| Découvre & reprend les sessions de terminal *existantes* | ✅ | ❌ | partiel | ❌ |
| 100 % auto-hébergé — zéro trafic via des serveurs tiers | ✅ | ✅ | serveur relais | ❌ relayé via Anthropic |
| Linux-first | ✅ | variable | ✅ | l'app desktop n'a pas de build Linux |
| Open source | MIT | ❌ / partiel | MIT / AGPL | ❌ |
Le Remote Control d'Anthropic est excellent pour piloter *une* session depuis votre téléphone. Arboretum est la couche qu'il ne fournit pas : le tableau consolidé et auto-hébergé de tous vos worktrees et sessions, à travers tous vos repos.
## Une note sur l'usage de Claude
Arboretum enveloppe le CLI Claude Code **interactif** dans un PTY — la même chose que vous lancez dans votre terminal, affichée dans votre navigateur. Il n'utilise pas l'Agent SDK ni le mode headless. Les politiques d'usage d'Anthropic autour de l'usage programmatique peuvent évoluer ; Arboretum suivra les sorties du CLI et documentera tout impact de façon transparente.
## Développement
Arboretum est un monorepo npm workspaces : `@arboretum/shared` (protocole WS/REST, source de vérité), `@johanleroy/git-arboretum` (le daemon Fastify, le paquet publié) et `@arboretum/web` (la SPA Vue 3).
```bash
npm run build # build shared → server → web (l'ordre compte)
npm run typecheck # tsc -b shared + server
npm test # vitest sur les packages
npm run dev:server # daemon en watch
npm run dev:web # serveur de dev Vite (proxifie /api et /ws vers le daemon sur :7317)
```
Scripts d'acceptation end-to-end (lancez `npm run build` d'abord) :
```bash
node packages/server/scripts/acceptance-p1.mjs # cœur : daemon + client WS réel
node packages/server/scripts/acceptance-p2.mjs # découverte & reprise de sessions
node packages/server/scripts/acceptance-p3.mjs # worktrees & corrélation de sessions
node packages/server/scripts/acceptance-p4.mjs # Web Push + commande WS `answer`
```
## Licence
MIT — voir [LICENSE](LICENSE).
+57 -9
View File
@@ -6,6 +6,10 @@
A self-hosted web dashboard for your git worktrees and the Claude Code sessions running on them — from any device. A self-hosted web dashboard for your git worktrees and the Claude Code sessions running on them — from any device.
</p> </p>
<p align="center">
<strong>English</strong> · <a href="README.fr.md">Français</a>
</p>
**Status: MVP.** The worktree-first dashboard, session discovery & resume, multi-repo worktree lifecycle, live session states, the web terminal, and mobile supervision (installable PWA, Web Push when a session needs you, approve/deny without opening a terminal) are implemented and tested. **Status: MVP.** The worktree-first dashboard, session discovery & resume, multi-repo worktree lifecycle, live session states, the web terminal, and mobile supervision (installable PWA, Web Push when a session needs you, approve/deny without opening a terminal) are implemented and tested.
--- ---
@@ -20,7 +24,7 @@ Working with AI coding agents changed how we use git: one feature = one worktree
## What Arboretum does ## What Arboretum does
A single Node.js daemon you run on your dev machine (`npx git-arboretum`), serving a web UI usable from your desktop, phone or tablet: A single Node.js daemon you run on your dev machine (`npx @johanleroy/git-arboretum`), serving a web UI usable from your desktop, phone or tablet:
- **Worktree-first, multi-repo dashboard** — every worktree of every registered repo, with its git state (branch, ahead/behind, dirty files) *and* the state of its Claude Code session (busy / waiting for input / idle / resumable). - **Worktree-first, multi-repo dashboard** — every worktree of every registered repo, with its git state (branch, ahead/behind, dirty files) *and* the state of its Claude Code session (busy / waiting for input / idle / resumable).
- **Full worktree lifecycle** — create (with per-repo post-create hooks: `npm ci`, copy `.env`…), adopt worktrees created by hand, delete with guardrails, prune orphans. - **Full worktree lifecycle** — create (with per-repo post-create hooks: `npm ci`, copy `.env`…), adopt worktrees created by hand, delete with guardrails, prune orphans.
@@ -38,16 +42,20 @@ A single Node.js daemon you run on your dev machine (`npx git-arboretum`), servi
## Quick start ## Quick start
Two paths, depending on what you want:
- **Just use it (most people).** Arboretum is a published npm package — you **don't need to clone this repo**. Point npm at the registry and run it (below). Do this on the machine where your Claude Code sessions run.
- **Run from source.** Clone the repo only to hack on Arboretum or run an unreleased build.
### Run it (recommended) ### Run it (recommended)
Arboretum is published to a private Gitea npm registry. Point the `@johanleroy` scope at it once per machine — add to `~/.npmrc`: Arboretum is published to a self-hosted Gitea npm registry. Point the `@johanleroy` scope at it once per machine — add to `~/.npmrc`:
``` ```
@johanleroy:registry=https://git.lidge.fr/api/packages/johanleroy/npm/ @johanleroy:registry=https://git.lidge.fr/api/packages/johanleroy/npm/
//git.lidge.fr/api/packages/johanleroy/npm/:_authToken=<your-gitea-token>
``` ```
(The `_authToken` line is only needed if the package is private.) Then run it from anywhere: No token needed — the package is publicly readable. Then run it from anywhere:
```bash ```bash
npx @johanleroy/git-arboretum npx @johanleroy/git-arboretum
@@ -67,8 +75,17 @@ On first start, Arboretum prints a one-time **access token** and the URL to open
Open the URL, paste the token to log in, and you're in. The token is stored **hashed** — it is shown only once, so save it somewhere safe (a password manager). You can manage tokens later from **Settings**. Open the URL, paste the token to log in, and you're in. The token is stored **hashed** — it is shown only once, so save it somewhere safe (a password manager). You can manage tokens later from **Settings**.
`npx` fetches and runs the latest published version each time. To install it once — and get the `arboretum` command on your `PATH`, which the [background service](#running-it-as-a-background-service) relies on — install it globally instead:
```bash
npm i -g @johanleroy/git-arboretum
arboretum # identical to the npx command, from the installed binary
```
### Run from source ### Run from source
Only needed to **develop** Arboretum or run an unreleased build — not required just to use it. Clone the repo, install dependencies, build, then start the daemon:
```bash ```bash
git clone https://git.lidge.fr/johanleroy/arboretum.git git clone https://git.lidge.fr/johanleroy/arboretum.git
cd arboretum cd arboretum
@@ -107,7 +124,26 @@ Open `https://<machine>.<tailnet>.ts.net` from any device on your tailnet. **Web
## Running it as a background service ## Running it as a background service
For a daemon that survives logout and restarts on boot, run it under a **systemd user service**. Install a pinned version globally (`npm i -g @johanleroy/git-arboretum`), then create `~/.config/systemd/user/arboretum.service`: The quickest way to run Arboretum as a service that survives logout and restarts on boot is the built-in installer. Install a pinned version globally, then run `install` — it detects your OS, writes the service file, starts it, and prints the one-time token:
```bash
npm i -g @johanleroy/git-arboretum
arboretum install --allow-origin https://MACHINE.TAILNET.ts.net
```
This sets up a **systemd user service** on Linux (`~/.config/systemd/user/arboretum.service`) or a **launchd LaunchAgent** on macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`). Every daemon flag (`--port`, `--allow-origin`, `--db`, …) is propagated to the service. Manage it with:
```bash
arboretum status # service status (+ where to read logs)
arboretum uninstall # stop and remove the service
```
Logs live in `journalctl --user -u arboretum -f` (Linux) or `~/Library/Logs/arboretum/` (macOS). Run `arboretum install --dry-run …` first to print the unit/plist and the exact commands without touching anything.
<details>
<summary>Prefer to set up systemd by hand? (Linux)</summary>
Create `~/.config/systemd/user/arboretum.service`:
```ini ```ini
[Unit] [Unit]
@@ -134,12 +170,15 @@ systemctl --user enable --now arboretum
loginctl enable-linger "$USER" # start the service at boot, without an open session loginctl enable-linger "$USER" # start the service at boot, without an open session
journalctl --user -u arboretum -f # logs journalctl --user -u arboretum -f # logs
``` ```
</details>
> The one-time **access token is printed only on the very first run** (empty database). When running as a service, capture it from `journalctl`, or do one manual run before enabling the service. The token is hashed and never shown again. > The one-time **access token is printed by `arboretum install`** (and on the very first manual run with an empty database). The token is hashed and never shown again — store it safely.
## Configuration ## Configuration
All options are CLI flags: Commands: `arboretum` starts the daemon (the default), `arboretum serve` is an explicit alias, `arboretum install` / `uninstall` / `status` manage the background service, and `arboretum help` prints usage.
Daemon options are CLI flags:
| Flag | Default | Description | | Flag | Default | Description |
|---|---|---| |---|---|---|
@@ -151,6 +190,15 @@ All options are CLI flags:
| `--print-token` | `false` | Hint about token re-printing (tokens are hashed and cannot be re-shown). | | `--print-token` | `false` | Hint about token re-printing (tokens are hashed and cannot be re-shown). |
| `--i-know-this-exposes-a-terminal` | `false` | Acknowledge binding to a non-loopback address. **Avoid** — prefer Tailscale Serve. | | `--i-know-this-exposes-a-terminal` | `false` | Acknowledge binding to a non-loopback address. **Avoid** — prefer Tailscale Serve. |
`arboretum install` accepts every daemon flag above (propagated verbatim to the service) plus:
| Flag | Description |
|---|---|
| `--bin-path <path>` | Use this binary in the service instead of `node` + the bundled script. |
| `--label <id>` | launchd label (macOS only, default `fr.lidge.arboretum`). |
| `--dry-run` | Print the unit/plist and commands without applying anything. |
| `--no-enable` | Write the service file but do not enable/start it. |
State (the SQLite database) lives in `$XDG_DATA_HOME/arboretum` (default `~/.local/share/arboretum`). State (the SQLite database) lives in `$XDG_DATA_HOME/arboretum` (default `~/.local/share/arboretum`).
## Security model ## Security model
@@ -159,9 +207,9 @@ A web terminal is remote code execution *by design*. Arboretum's guardrails are
- Binds to `127.0.0.1` by default; refuses non-loopback binds without an explicit flag. - Binds to `127.0.0.1` by default; refuses non-loopback binds without an explicit flag.
- Authenticates **every** `/api/**` request **and** every `/ws` upgrade with revocable tokens, and applies a **strict `Origin` check** (the `SameSite=Strict` cookie does not cover WebSocket upgrades — this is the anti cross-site hijacking guard). - Authenticates **every** `/api/**` request **and** every `/ws` upgrade with revocable tokens, and applies a **strict `Origin` check** (the `SameSite=Strict` cookie does not cover WebSocket upgrades — this is the anti cross-site hijacking guard).
- Tokens are stored **hashed** (sha256) and compared in constant time; the bootstrap token is shown only once. The session cookie is an HMAC-signed payload. Login is rate-limited with exponential backoff. - Tokens are stored **hashed** (sha256) and compared in constant time; the bootstrap token is shown only once. The session cookie is an HMAC-signed payload, `HttpOnly` and `SameSite=Strict`, and it automatically gains the `Secure` flag when the request arrives over HTTPS (e.g. behind Tailscale Serve). Login is rate-limited with exponential backoff.
The recommended way to reach Arboretum from other devices is Tailscale Serve (valid HTTPS, tailnet identity, no open ports). Never expose it directly to the internet. Tailscale Serve is **the** way to reach Arboretum from other devices — not just a recommendation: valid HTTPS, tailnet identity, no open ports. The `--i-know-this-exposes-a-terminal` flag is an escape hatch, not a deployment mode; never expose Arboretum directly to the internet.
## What makes it different ## What makes it different
+1 -1
View File
@@ -4960,7 +4960,7 @@
}, },
"packages/server": { "packages/server": {
"name": "@johanleroy/git-arboretum", "name": "@johanleroy/git-arboretum",
"version": "1.0.0", "version": "1.0.2",
"bundleDependencies": [ "bundleDependencies": [
"@arboretum/shared" "@arboretum/shared"
], ],
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "@johanleroy/git-arboretum", "name": "@johanleroy/git-arboretum",
"version": "1.0.0", "version": "1.0.2",
"description": "Self-hosted web dashboard for git worktrees and the Claude Code sessions running on them", "description": "Self-hosted web dashboard for git worktrees and the Claude Code sessions running on them",
"license": "MIT", "license": "MIT",
"type": "module", "type": "module",
+5 -2
View File
@@ -15,9 +15,12 @@ const rootDir = join(serverDir, '..', '..');
const readmeSrc = join(rootDir, 'README.md'); const readmeSrc = join(rootDir, 'README.md');
if (existsSync(readmeSrc)) { if (existsSync(readmeSrc)) {
const rawBase = 'https://git.lidge.fr/johanleroy/arboretum/raw/branch/main/'; const rawBase = 'https://git.lidge.fr/johanleroy/arboretum/raw/branch/main/';
const readme = readFileSync(readmeSrc, 'utf8').replaceAll('src="brand/', `src="${rawBase}brand/`); const srcBase = 'https://git.lidge.fr/johanleroy/arboretum/src/branch/main/';
const readme = readFileSync(readmeSrc, 'utf8')
.replaceAll('src="brand/', `src="${rawBase}brand/`)
.replaceAll('href="README.fr.md"', `href="${srcBase}README.fr.md"`);
writeFileSync(join(serverDir, 'README.md'), readme); writeFileSync(join(serverDir, 'README.md'), readme);
console.log('copy-meta: README.md copié (chemins images réécrits en absolu)'); console.log('copy-meta: README.md copié (chemins images + lien FR réécrits en absolu)');
} else { } else {
console.error(`copy-meta: ${readmeSrc} introuvable`); console.error(`copy-meta: ${readmeSrc} introuvable`);
process.exit(1); process.exit(1);
+363
View File
@@ -0,0 +1,363 @@
import { parseArgs } from 'node:util';
import { spawnSync } from 'node:child_process';
import { mkdirSync, writeFileSync, rmSync, existsSync } from 'node:fs';
import { homedir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import { loadConfig } from '../config.js';
import { openDb } from '../db/index.js';
import { AuthService } from '../auth/service.js';
// Nom de l'unit systemd (Linux) et label launchd par défaut (macOS, surchargeable via --label).
const SERVICE_NAME = 'arboretum';
const LAUNCHD_LABEL = 'fr.lidge.arboretum';
export type SupportedPlatform = 'linux' | 'darwin';
export interface InstallFlags {
port?: string | undefined;
bind?: string | undefined;
allowOrigin: string[];
db?: string | undefined;
vapidContact?: string | undefined;
claudeHome?: string | undefined;
binPath?: string | undefined;
label: string;
dryRun: boolean;
noEnable: boolean;
}
// ─── Fonctions pures (génération de contenu / chemins) ────────────────────────────────
/** macOS (launchd) et Linux (systemd) uniquement ; sinon throw avec un message pédagogique. */
export function detectPlatform(platform: NodeJS.Platform = process.platform): SupportedPlatform {
if (platform === 'linux' || platform === 'darwin') return platform;
throw new Error(
`Automatic service installation is supported on Linux (systemd) and macOS (launchd) only.\n` +
`On ${platform}, run \`arboretum\` manually or set up your own supervisor.`,
);
}
export function parseInstallArgs(argv: string[]): InstallFlags {
const { values } = parseArgs({
args: argv,
options: {
port: { type: 'string' },
bind: { type: 'string' },
'allow-origin': { type: 'string', multiple: true },
db: { type: 'string' },
'vapid-contact': { type: 'string' },
'claude-home': { type: 'string' },
'bin-path': { type: 'string' },
label: { type: 'string' },
'dry-run': { type: 'boolean', default: false },
'no-enable': { type: 'boolean', default: false },
},
strict: true,
});
return {
port: values.port,
bind: values.bind,
allowOrigin: values['allow-origin'] ?? [],
db: values.db,
vapidContact: values['vapid-contact'],
claudeHome: values['claude-home'],
binPath: values['bin-path'],
label: values.label ?? LAUNCHD_LABEL,
dryRun: values['dry-run'] ?? false,
noEnable: values['no-enable'] ?? false,
};
}
/**
* Flags propagés au service : UNIQUEMENT ceux fournis par l'utilisateur (ordre stable,
* ExecStart déterministe). On n'ajoute JAMAIS --i-know-this-exposes-a-terminal automatiquement
* (cf. modèle de sécurité : un service exposé doit être un choix conscient et explicite).
*/
export function buildServiceArgs(flags: InstallFlags): string[] {
const args: string[] = [];
if (flags.port) args.push('--port', flags.port);
if (flags.bind) args.push('--bind', flags.bind);
for (const origin of flags.allowOrigin) args.push('--allow-origin', origin);
if (flags.db) args.push('--db', flags.db);
if (flags.vapidContact) args.push('--vapid-contact', flags.vapidContact);
if (flags.claudeHome) args.push('--claude-home', flags.claudeHome);
return args;
}
/** Le `dist/index.js` réellement installé (depuis dist/cli/install.js). */
export function resolveScriptPath(): string {
return fileURLToPath(new URL('../index.js', import.meta.url));
}
/**
* Cible exécutable du service. Par défaut node + script (immunisé contre un PATH minimal sous
* systemd/launchd) ; --bin-path force le wrapper `arboretum` global (suit les upgrades npm i -g).
*/
export function resolveBin(flags: Pick<InstallFlags, 'binPath'>): { exec: string; args: string[] } {
if (flags.binPath) return { exec: flags.binPath, args: [] };
return { exec: process.execPath, args: [resolveScriptPath()] };
}
export function systemdUnitPath(): string {
const configHome = process.env.XDG_CONFIG_HOME ?? join(homedir(), '.config');
return join(configHome, 'systemd', 'user', `${SERVICE_NAME}.service`);
}
export function launchAgentPlistPath(label: string): string {
return join(homedir(), 'Library', 'LaunchAgents', `${label}.plist`);
}
export function launchdLogPaths(): { dir: string; out: string; err: string } {
const dir = join(homedir(), 'Library', 'Logs', 'arboretum');
return { dir, out: join(dir, 'out.log'), err: join(dir, 'err.log') };
}
export function xmlEscape(s: string): string {
return s.replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;');
}
// systemd accepte les doubles quotes dans ExecStart ; on ne quote que les tokens à espaces.
function quoteIfNeeded(token: string): string {
return /\s/.test(token) ? `"${token}"` : token;
}
export function renderSystemdUnit(input: { exec: string; scriptArgs: string[] }): string {
const execStart = [input.exec, ...input.scriptArgs].map(quoteIfNeeded).join(' ');
// KillSignal=SIGTERM + TimeoutStopSec=10 collent au drain de runDaemon (SIGTERM → drain 1s → close).
return `[Unit]
Description=Arboretum — git worktree & Claude Code dashboard
After=network-online.target
Wants=network-online.target
[Service]
ExecStart=${execStart}
Restart=on-failure
RestartSec=5
KillSignal=SIGTERM
TimeoutStopSec=10
Environment=NODE_ENV=production
[Install]
WantedBy=default.target
`;
}
export function renderLaunchAgentPlist(input: {
label: string;
programArguments: string[];
stdoutPath: string;
stderrPath: string;
}): string {
const args = input.programArguments.map((a) => ` <string>${xmlEscape(a)}</string>`).join('\n');
// KeepAlive/SuccessfulExit=false ≈ Restart=on-failure (ne relance pas après un drain volontaire).
return `<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>${xmlEscape(input.label)}</string>
<key>ProgramArguments</key>
<array>
${args}
</array>
<key>RunAtLoad</key>
<true/>
<key>KeepAlive</key>
<dict>
<key>SuccessfulExit</key>
<false/>
</dict>
<key>StandardOutPath</key>
<string>${xmlEscape(input.stdoutPath)}</string>
<key>StandardErrorPath</key>
<string>${xmlEscape(input.stderrPath)}</string>
<key>EnvironmentVariables</key>
<dict>
<key>NODE_ENV</key>
<string>production</string>
</dict>
</dict>
</plist>
`;
}
export function printTokenBanner(token: string, url: string): void {
console.log('\n┌──────────────────────────────────────────────────────────────────┐');
console.log('│ First start — your access token (shown once, store it safely): │');
console.log('└──────────────────────────────────────────────────────────────────┘');
console.log(`\n ${token}\n`);
console.log(` Login at: ${url}/\n`);
}
export function printUsage(version: string): void {
console.log(`Arboretum v${version} — git worktree & Claude Code dashboard
Usage:
arboretum [flags] Start the daemon (default)
arboretum serve [flags] Start the daemon (explicit alias)
arboretum install [flags] Install & start a user service (systemd on Linux, launchd on macOS)
arboretum uninstall Stop & remove the user service
arboretum status Show the service status
arboretum help Show this help
Daemon flags:
--port <n> Port to listen on (default 7317)
--bind <addr> Bind address (default 127.0.0.1)
--allow-origin <url> Additional allowed Origin (repeatable)
--db <path> SQLite database path
--vapid-contact <mailto|url> VAPID contact subject for Web Push
--i-know-this-exposes-a-terminal Acknowledge a non-loopback bind (avoid — prefer Tailscale Serve)
Install flags (daemon flags above are propagated to the service):
--bin-path <path> Use this binary in the service instead of node + script
--label <id> launchd label (macOS only, default ${LAUNCHD_LABEL})
--dry-run Print the unit/plist and commands without applying anything
--no-enable Write the service file but do not enable/start it
`);
}
// ─── Effets de bord (fs + exec) ───────────────────────────────────────────────────────
function run(cmd: string, args: string[], opts?: { check?: boolean }): number {
const res = spawnSync(cmd, args, { stdio: 'inherit' });
if (res.error) {
if ((res.error as NodeJS.ErrnoException).code === 'ENOENT') {
throw new Error(`Command not found: ${cmd}. Is it installed and on your PATH?`);
}
throw res.error;
}
const code = res.status ?? 0;
if (opts?.check && code !== 0) {
throw new Error(`Command failed (exit ${code}): ${cmd} ${args.join(' ')}`);
}
return code;
}
/**
* Bootstrap du token avec EXACTEMENT les flags du service (même db). Valide aussi le bind
* (garde-fou de loadConfig). Affiche le token une fois, puis ferme la db avant que le service
* ne l'ouvre. Skippé en --dry-run par l'appelant.
*/
function bootstrapToken(serviceArgs: string[]): void {
const config = loadConfig(serviceArgs);
const url = `http://${config.bind === '0.0.0.0' ? '127.0.0.1' : config.bind}:${config.port}`;
const db = openDb(config.dbPath);
try {
const token = new AuthService(db).ensureBootstrapToken();
if (token) printTokenBanner(token, url);
else console.log('\nAn access token already exists in this database — manage tokens from Settings.\n');
} finally {
db.close();
}
}
export async function runInstall(argv: string[]): Promise<void> {
const platform = detectPlatform();
const flags = parseInstallArgs(argv);
const serviceArgs = buildServiceArgs(flags);
const { exec, args: binArgs } = resolveBin(flags);
const scriptArgs = [...binArgs, ...serviceArgs];
if (platform === 'linux') {
const unit = renderSystemdUnit({ exec, scriptArgs });
const unitPath = systemdUnitPath();
if (flags.dryRun) {
console.log(`# ${unitPath}\n${unit}\n# commands:`);
console.log('systemctl --user daemon-reload');
if (!flags.noEnable) {
console.log(`systemctl --user enable --now ${SERVICE_NAME}`);
console.log(`loginctl enable-linger ${process.env.USER ?? '$USER'}`);
}
return;
}
bootstrapToken(serviceArgs);
mkdirSync(dirname(unitPath), { recursive: true });
writeFileSync(unitPath, unit);
console.log(`Wrote ${unitPath}`);
run('systemctl', ['--user', 'daemon-reload'], { check: true });
if (!flags.noEnable) {
run('systemctl', ['--user', 'enable', '--now', SERVICE_NAME], { check: true });
// enable-linger best-effort : absent en CI / sans session loginctl, non bloquant.
if (run('loginctl', ['enable-linger', process.env.USER ?? '']) !== 0) {
console.warn('Warning: could not enable linger — the service may not start at boot.');
}
}
console.log(`\nArboretum service installed. Logs: journalctl --user -u ${SERVICE_NAME} -f`);
return;
}
// macOS (launchd)
const logs = launchdLogPaths();
const programArguments = [exec, ...scriptArgs];
const plist = renderLaunchAgentPlist({
label: flags.label,
programArguments,
stdoutPath: logs.out,
stderrPath: logs.err,
});
const plistPath = launchAgentPlistPath(flags.label);
const uid = process.getuid?.() ?? 0;
const target = `gui/${uid}/${flags.label}`;
if (flags.dryRun) {
console.log(`# ${plistPath}\n${plist}\n# commands:`);
console.log(`launchctl bootout ${target} # best-effort`);
if (!flags.noEnable) {
console.log(`launchctl bootstrap gui/${uid} ${plistPath}`);
console.log(`launchctl enable ${target}`);
console.log(`launchctl kickstart -k ${target}`);
}
return;
}
bootstrapToken(serviceArgs);
mkdirSync(dirname(plistPath), { recursive: true });
mkdirSync(logs.dir, { recursive: true });
writeFileSync(plistPath, plist);
console.log(`Wrote ${plistPath}`);
if (!flags.noEnable) {
run('launchctl', ['bootout', target]); // best-effort : ignore "not loaded" (rend bootstrap idempotent)
run('launchctl', ['bootstrap', `gui/${uid}`, plistPath], { check: true });
run('launchctl', ['enable', target]);
run('launchctl', ['kickstart', '-k', target]);
}
console.log(`\nArboretum service installed. Logs: ${logs.out}`);
}
export async function runUninstall(argv: string[]): Promise<void> {
const platform = detectPlatform();
const flags = parseInstallArgs(argv);
if (platform === 'linux') {
const unitPath = systemdUnitPath();
run('systemctl', ['--user', 'disable', '--now', SERVICE_NAME]); // best-effort
if (existsSync(unitPath)) {
rmSync(unitPath);
console.log(`Removed ${unitPath}`);
}
run('systemctl', ['--user', 'daemon-reload']);
console.log('Arboretum service removed.');
return;
}
const plistPath = launchAgentPlistPath(flags.label);
const uid = process.getuid?.() ?? 0;
run('launchctl', ['bootout', `gui/${uid}/${flags.label}`]); // best-effort
if (existsSync(plistPath)) {
rmSync(plistPath);
console.log(`Removed ${plistPath}`);
}
console.log('Arboretum service removed.');
}
export async function runStatus(argv: string[]): Promise<void> {
const platform = detectPlatform();
const flags = parseInstallArgs(argv);
if (platform === 'linux') {
const code = run('systemctl', ['--user', 'status', SERVICE_NAME, '--no-pager']);
console.log(`\nLogs: journalctl --user -u ${SERVICE_NAME} -f`);
process.exitCode = code;
return;
}
const uid = process.getuid?.() ?? 0;
const code = run('launchctl', ['print', `gui/${uid}/${flags.label}`]);
console.log(`\nLogs: ${launchdLogPaths().out}`);
process.exitCode = code;
}
+35 -8
View File
@@ -2,16 +2,17 @@
import { readFileSync } from 'node:fs'; import { readFileSync } from 'node:fs';
import { join, dirname } from 'node:path'; import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url'; import { fileURLToPath } from 'node:url';
import { loadConfig } from './config.js'; import { loadConfig, type Config } from './config.js';
import { openDb } from './db/index.js'; import { openDb } from './db/index.js';
import { buildApp } from './app.js'; import { buildApp } from './app.js';
import { runInstall, runUninstall, runStatus, printUsage, printTokenBanner } from './cli/install.js';
const pkg = JSON.parse( const pkg = JSON.parse(
readFileSync(join(dirname(fileURLToPath(import.meta.url)), '..', 'package.json'), 'utf8'), readFileSync(join(dirname(fileURLToPath(import.meta.url)), '..', 'package.json'), 'utf8'),
) as { version: string }; ) as { version: string };
async function main(): Promise<void> { /** Démarre le daemon : écoute HTTP, scan des sessions, drain propre au SIGTERM/SIGINT. */
const config = loadConfig(); export async function runDaemon(config: Config): Promise<void> {
const db = openDb(config.dbPath); const db = openDb(config.dbPath);
const { app, auth, manager, discovery } = buildApp(config, db, pkg.version); const { app, auth, manager, discovery } = buildApp(config, db, pkg.version);
@@ -23,11 +24,7 @@ async function main(): Promise<void> {
app.log.info(`Arboretum v${pkg.version} — ${url}`); app.log.info(`Arboretum v${pkg.version} — ${url}`);
if (bootstrapToken) { if (bootstrapToken) {
// Affiché une seule fois : le hash seul est stocké. // Affiché une seule fois : le hash seul est stocké.
console.log('\n┌──────────────────────────────────────────────────────────────────┐'); printTokenBanner(bootstrapToken, url);
console.log('│ First start — your access token (shown once, store it safely): │');
console.log('└──────────────────────────────────────────────────────────────────┘');
console.log(`\n ${bootstrapToken}\n`);
console.log(` Login at: ${url}/\n`);
} else if (config.printToken) { } else if (config.printToken) {
console.log('Tokens are stored hashed and cannot be re-printed. Create a new one from Settings (or reset the db).'); console.log('Tokens are stored hashed and cannot be re-printed. Create a new one from Settings (or reset the db).');
} }
@@ -47,6 +44,36 @@ async function main(): Promise<void> {
process.on('SIGTERM', () => shutdown('SIGTERM')); process.on('SIGTERM', () => shutdown('SIGTERM'));
} }
// Routeur de sous-commandes. On inspecte argv[0] AVANT loadConfig (parseArgs strict throw sur
// un positionnel inconnu). Aucune sous-commande (ou un flag en tête) → daemon : rétrocompat stricte
// de `arboretum`, `arboretum --port 8080`, `npx @johanleroy/git-arboretum --allow-origin …`.
async function main(): Promise<void> {
const argv = process.argv.slice(2);
const cmd = argv[0];
switch (cmd) {
case 'install':
return runInstall(argv.slice(1));
case 'uninstall':
return runUninstall(argv.slice(1));
case 'status':
return runStatus(argv.slice(1));
case 'serve':
return runDaemon(loadConfig(argv.slice(1)));
case 'help':
case '--help':
case '-h':
printUsage(pkg.version);
return;
default:
if (cmd && !cmd.startsWith('-')) {
console.error(`Unknown command: ${cmd}\n`);
printUsage(pkg.version);
process.exit(1);
}
return runDaemon(loadConfig(argv));
}
}
main().catch((err) => { main().catch((err) => {
console.error(err instanceof Error ? err.message : err); console.error(err instanceof Error ? err.message : err);
process.exit(1); process.exit(1);
+14 -3
View File
@@ -1,7 +1,16 @@
import type { FastifyInstance } from 'fastify'; import type { FastifyInstance, FastifyRequest } from 'fastify';
import type { LoginRequest, LoginResponse, MeResponse } from '@arboretum/shared'; import type { LoginRequest, LoginResponse, MeResponse } from '@arboretum/shared';
import type { AuthService, LoginRateLimiter } from '../auth/service.js'; import type { AuthService, LoginRateLimiter } from '../auth/service.js';
// Tailscale Serve / un reverse-proxy TLS posent x-forwarded-proto. On ne sert jamais
// en TLS direct : `secure` n'est posé que derrière un front HTTPS, jamais en localhost http
// (sinon le navigateur refuserait le cookie sur http://127.0.0.1 et le login local casserait).
function isHttpsRequest(req: FastifyRequest): boolean {
const xfp = req.headers['x-forwarded-proto'];
const proto = (Array.isArray(xfp) ? xfp[0] : xfp)?.split(',')[0]?.trim();
return proto === 'https';
}
export function registerAuthRoutes( export function registerAuthRoutes(
app: FastifyInstance, app: FastifyInstance,
auth: AuthService, auth: AuthService,
@@ -24,6 +33,7 @@ export function registerAuthRoutes(
path: '/', path: '/',
httpOnly: true, httpOnly: true,
sameSite: 'strict', sameSite: 'strict',
secure: isHttpsRequest(req),
maxAge: 30 * 24 * 3600, maxAge: 30 * 24 * 3600,
}); });
const res: LoginResponse = { ok: true, label: ctx.label }; const res: LoginResponse = { ok: true, label: ctx.label };
@@ -35,8 +45,9 @@ export function registerAuthRoutes(
return reply.send(res); return reply.send(res);
}); });
app.post('/api/v1/auth/logout', async (_req, reply) => { app.post('/api/v1/auth/logout', async (req, reply) => {
void reply.clearCookie(auth.cookieName, { path: '/' }); // Les attributs doivent matcher ceux posés au login pour que le navigateur efface bien le cookie.
void reply.clearCookie(auth.cookieName, { path: '/', secure: isHttpsRequest(req) });
return reply.send({ ok: true }); return reply.send({ ok: true });
}); });
} }
+16
View File
@@ -91,9 +91,25 @@ describe('app e2e — auth, origin et sessions', () => {
expect(cookie).toBeDefined(); expect(cookie).toBeDefined();
expect(cookie?.httpOnly).toBe(true); expect(cookie?.httpOnly).toBe(true);
expect(cookie?.sameSite).toBe('Strict'); expect(cookie?.sameSite).toBe('Strict');
// Login local (http, pas de x-forwarded-proto) → pas de Secure, sinon le cookie casserait en localhost.
expect(cookie?.secure).toBeFalsy();
cookieValue = cookie!.value; cookieValue = cookie!.value;
}); });
it('cookie Secure posé derrière un front HTTPS (x-forwarded-proto)', async () => {
const res = await t.bundle.app.inject({
method: 'POST',
url: '/api/v1/auth/login',
headers: { 'x-forwarded-proto': 'https' },
payload: { token: t.token },
});
expect(res.statusCode).toBe(200);
const cookie = res.cookies.find((c) => c.name === 'arb_session');
expect(cookie?.secure).toBe(true);
expect(cookie?.httpOnly).toBe(true);
expect(cookie?.sameSite).toBe('Strict');
});
it('routes API sans auth → 401', async () => { it('routes API sans auth → 401', async () => {
for (const url of ['/api/v1/sessions', '/api/v1/auth/me']) { for (const url of ['/api/v1/sessions', '/api/v1/auth/me']) {
const res = await t.bundle.app.inject({ method: 'GET', url }); const res = await t.bundle.app.inject({ method: 'GET', url });
+166
View File
@@ -0,0 +1,166 @@
import { afterEach, describe, expect, it } from 'vitest';
import { homedir } from 'node:os';
import { join } from 'node:path';
import {
detectPlatform,
parseInstallArgs,
buildServiceArgs,
resolveBin,
resolveScriptPath,
renderSystemdUnit,
renderLaunchAgentPlist,
xmlEscape,
systemdUnitPath,
launchAgentPlistPath,
} from '../src/cli/install.js';
describe('cli install — detectPlatform', () => {
it('accepte linux et darwin', () => {
expect(detectPlatform('linux')).toBe('linux');
expect(detectPlatform('darwin')).toBe('darwin');
});
it('rejette les autres plateformes avec un message clair', () => {
expect(() => detectPlatform('win32')).toThrow(/Linux \(systemd\) and macOS \(launchd\)/);
expect(() => detectPlatform('freebsd')).toThrow(/freebsd/);
});
});
describe('cli install — buildServiceArgs', () => {
it('aucun flag → aucun argument (le service garde les défauts loopback)', () => {
expect(buildServiceArgs(parseInstallArgs([]))).toEqual([]);
});
it('propage --port et --allow-origin (répétable) dans un ordre stable', () => {
const flags = parseInstallArgs(['--port', '8080', '--allow-origin', 'a', '--allow-origin', 'b']);
expect(buildServiceArgs(flags)).toEqual(['--port', '8080', '--allow-origin', 'a', '--allow-origin', 'b']);
});
it("n'injecte JAMAIS --i-know-this-exposes-a-terminal (modèle de sécurité)", () => {
const flags = parseInstallArgs(['--bind', '0.0.0.0', '--port', '7317']);
expect(buildServiceArgs(flags)).not.toContain('--i-know-this-exposes-a-terminal');
});
it("ne propage pas les flags propres à l'install (bin-path, label, dry-run, no-enable)", () => {
const flags = parseInstallArgs(['--bin-path', '/usr/local/bin/arboretum', '--label', 'x', '--dry-run', '--no-enable']);
expect(buildServiceArgs(flags)).toEqual([]);
});
});
describe('cli install — resolveBin', () => {
it('par défaut : node (process.execPath) + dist/index.js', () => {
const { exec, args } = resolveBin({});
expect(exec).toBe(process.execPath);
expect(args).toHaveLength(1);
expect(args[0]).toBe(resolveScriptPath());
expect(args[0]).toMatch(/index\.(js|ts)$/);
});
it('--bin-path force le wrapper, sans argument de script', () => {
expect(resolveBin({ binPath: '/usr/local/bin/arboretum' })).toEqual({
exec: '/usr/local/bin/arboretum',
args: [],
});
});
});
describe('cli install — renderSystemdUnit', () => {
it('contient le ExecStart calculé et les directives clés', () => {
const unit = renderSystemdUnit({ exec: '/usr/bin/node', scriptArgs: ['/opt/arboretum/index.js', '--port', '7317'] });
expect(unit).toContain('ExecStart=/usr/bin/node /opt/arboretum/index.js --port 7317');
expect(unit).toContain('Restart=on-failure');
expect(unit).toContain('KillSignal=SIGTERM');
expect(unit).toContain('TimeoutStopSec=10');
expect(unit).toContain('WantedBy=default.target');
});
it('quote les tokens contenant un espace', () => {
const unit = renderSystemdUnit({ exec: '/path with space/node', scriptArgs: ['/s.js'] });
expect(unit).toContain('ExecStart="/path with space/node" /s.js');
});
it('snapshot du unit pour un jeu de flags fixe', () => {
const unit = renderSystemdUnit({
exec: '/usr/bin/node',
scriptArgs: ['/opt/arboretum/index.js', '--port', '7317', '--allow-origin', 'https://m.ts.net'],
});
expect(unit).toMatchInlineSnapshot(`
"[Unit]
Description=Arboretum — git worktree & Claude Code dashboard
After=network-online.target
Wants=network-online.target
[Service]
ExecStart=/usr/bin/node /opt/arboretum/index.js --port 7317 --allow-origin https://m.ts.net
Restart=on-failure
RestartSec=5
KillSignal=SIGTERM
TimeoutStopSec=10
Environment=NODE_ENV=production
[Install]
WantedBy=default.target
"
`);
});
});
describe('cli install — renderLaunchAgentPlist', () => {
const base = {
label: 'fr.lidge.arboretum',
programArguments: ['/usr/bin/node', '/opt/index.js', '--port', '7317'],
stdoutPath: '/Users/me/Library/Logs/arboretum/out.log',
stderrPath: '/Users/me/Library/Logs/arboretum/err.log',
};
it('contient le label, les ProgramArguments ordonnés et les clés launchd', () => {
const plist = renderLaunchAgentPlist(base);
expect(plist).toContain('<string>fr.lidge.arboretum</string>');
const idxNode = plist.indexOf('<string>/usr/bin/node</string>');
const idxScript = plist.indexOf('<string>/opt/index.js</string>');
expect(idxNode).toBeGreaterThan(0);
expect(idxScript).toBeGreaterThan(idxNode);
expect(plist).toContain('<key>RunAtLoad</key>');
expect(plist).toContain('<key>KeepAlive</key>');
expect(plist).toContain('<key>StandardOutPath</key>');
});
it('échappe les caractères XML dans les arguments (URL avec &)', () => {
const plist = renderLaunchAgentPlist({
...base,
programArguments: ['/usr/bin/node', '/opt/index.js', '--allow-origin', 'https://a?b&c=d'],
});
expect(plist).toContain('https://a?b&amp;c=d');
expect(plist).not.toContain('b&c=d');
});
});
describe('cli install — xmlEscape', () => {
it('échappe &, < et >', () => {
expect(xmlEscape('a & b < c > d')).toBe('a &amp; b &lt; c &gt; d');
});
});
describe('cli install — chemins', () => {
const savedXdg = process.env.XDG_CONFIG_HOME;
afterEach(() => {
if (savedXdg === undefined) delete process.env.XDG_CONFIG_HOME;
else process.env.XDG_CONFIG_HOME = savedXdg;
});
it('systemdUnitPath respecte XDG_CONFIG_HOME', () => {
process.env.XDG_CONFIG_HOME = '/tmp/xdg';
expect(systemdUnitPath()).toBe('/tmp/xdg/systemd/user/arboretum.service');
});
it('systemdUnitPath retombe sur ~/.config sans XDG_CONFIG_HOME', () => {
delete process.env.XDG_CONFIG_HOME;
expect(systemdUnitPath()).toBe(join(homedir(), '.config', 'systemd', 'user', 'arboretum.service'));
});
it('launchAgentPlistPath place le plist dans ~/Library/LaunchAgents', () => {
expect(launchAgentPlistPath('fr.lidge.arboretum')).toBe(
join(homedir(), 'Library', 'LaunchAgents', 'fr.lidge.arboretum.plist'),
);
});
});