Compare commits
20 Commits
v1.0.1
...
dcb6cd1ec7
| Author | SHA1 | Date | |
|---|---|---|---|
| dcb6cd1ec7 | |||
| 3b251c8174 | |||
| 8d3a47bd91 | |||
| 073f2cf9ca | |||
| 36bfeb057e | |||
| 7a3c119f36 | |||
| 813dfd952c | |||
| 693e6736de | |||
| 33295a7aaf | |||
| 755cba6b78 | |||
| fe2a3e66c7 | |||
| b070b74929 | |||
| c9670ca309 | |||
| 5c1c2a8591 | |||
| 9a4bb5efa1 | |||
| d6c110fc3b | |||
| c1390bfe06 | |||
| e38b3a5d5e | |||
| e6999011d1 | |||
| f446a3dda1 |
55
.gitea/workflows/prod.yml
Normal file
55
.gitea/workflows/prod.yml
Normal file
@@ -0,0 +1,55 @@
|
||||
name: Deploy site (production)
|
||||
|
||||
# Déploie le site vitrine (packages/site) sur Plesk via FTPS (lftp), à l'identique
|
||||
# de lidge_web / tracksniff-web. Ne se déclenche que sur un changement du site.
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- 'packages/site/**'
|
||||
- '.gitea/workflows/prod.yml'
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: deploy-site
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
build-and-deploy:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: node:22-bookworm
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
# Install scopé au workspace du site : pas de build des deps natives du
|
||||
# serveur (node-pty / node:sqlite) qui n'ont rien à faire ici.
|
||||
- name: Install deps (@arboretum/site)
|
||||
run: npm install -w @arboretum/site --no-audit --no-fund
|
||||
|
||||
- name: Build site
|
||||
run: npm run build:site
|
||||
|
||||
- name: Check build output
|
||||
run: ls -la packages/site/dist
|
||||
|
||||
- name: Deploy via FTPS (lftp)
|
||||
run: |
|
||||
if [ -z "$REMOTE_PATH" ]; then
|
||||
echo "::error::Secret SITE_REMOTE_PATH manquant (chemin docroot du vhost git-arboretum.com)."
|
||||
exit 1
|
||||
fi
|
||||
apt-get update && apt-get install -y lftp
|
||||
lftp -c "
|
||||
open -u \"$FTP_USER\",\"$FTP_PASSWORD\" \"$FTP_HOST\"
|
||||
set ssl:verify-certificate no
|
||||
mirror -R --delete --verbose packages/site/dist \"$REMOTE_PATH\"
|
||||
"
|
||||
env:
|
||||
FTP_HOST: ${{ secrets.FTP_HOST }}
|
||||
FTP_USER: ${{ secrets.FTP_USER }}
|
||||
FTP_PASSWORD: ${{ secrets.FTP_PASSWORD }}
|
||||
# Chemin docroot du vhost git-arboretum.com sur Plesk (ex. /httpdocs/arboretum/public).
|
||||
REMOTE_PATH: ${{ secrets.SITE_REMOTE_PATH }}
|
||||
23
.github/workflows/ci.yml
vendored
23
.github/workflows/ci.yml
vendored
@@ -27,6 +27,7 @@ jobs:
|
||||
- run: npm ci
|
||||
- run: npm run typecheck
|
||||
- run: npm run build
|
||||
- run: npm run build:site
|
||||
- run: npx vitest run
|
||||
|
||||
pack-smoke:
|
||||
@@ -41,20 +42,26 @@ jobs:
|
||||
cache: npm
|
||||
- run: npm ci
|
||||
- run: npm run build
|
||||
# @arboretum/shared (dépendance runtime non publiée) est embarquée dans le tarball
|
||||
# via bundleDependencies (matérialisée au prepack). On packe donc UN SEUL tarball
|
||||
# et on l'installe seul, comme un vrai consommateur depuis le registre.
|
||||
# @arboretum/shared (paquet workspace NON publié) est INLINÉ dans dist/_shared au prepack
|
||||
# (scripts/inline-shared.mjs) : le tarball est 100 % autonome — aucun node_modules embarqué,
|
||||
# aucune bundleDependency, aucun symlink. On packe en mode workspace (-w), EXACTEMENT comme
|
||||
# le fait « npm publish » dans release.yml, puis on l'installe seul comme un vrai consommateur.
|
||||
- name: Pack tarball
|
||||
run: |
|
||||
mkdir -p /tmp/tarballs
|
||||
rm -rf /tmp/tarballs && mkdir -p /tmp/tarballs
|
||||
npm pack -w @johanleroy/git-arboretum --pack-destination /tmp/tarballs
|
||||
ls -l /tmp/tarballs
|
||||
- name: Assert @arboretum/shared is bundled in the tarball
|
||||
- name: Assert the package is self-contained (@arboretum/shared inlined)
|
||||
run: |
|
||||
tgz=$(ls /tmp/tarballs/*.tgz)
|
||||
tar -tzf "$tgz" | grep -q 'node_modules/@arboretum/shared/dist/index.js' \
|
||||
|| { echo "ERREUR: @arboretum/shared non embarqué dans $tgz"; exit 1; }
|
||||
echo "OK: bundleDependency @arboretum/shared présente dans $tgz"
|
||||
rm -rf /tmp/inspect && mkdir -p /tmp/inspect && tar -xzf "$tgz" -C /tmp/inspect
|
||||
test -f /tmp/inspect/package/dist/_shared/index.js \
|
||||
|| { echo "ERREUR: dist/_shared/index.js absent de $tgz — inline-shared n'a pas tourné ?"; exit 1; }
|
||||
if grep -rq '@arboretum/shared' /tmp/inspect/package/dist; then
|
||||
echo "ERREUR: import bare '@arboretum/shared' encore présent dans le JS publié"
|
||||
grep -rn '@arboretum/shared' /tmp/inspect/package/dist; exit 1
|
||||
fi
|
||||
echo "OK: paquet autonome — shared inliné dans dist/_shared, aucun import externe"
|
||||
- name: Install tarball in an empty project
|
||||
run: |
|
||||
mkdir /tmp/smoke
|
||||
|
||||
37
.github/workflows/release.yml
vendored
37
.github/workflows/release.yml
vendored
@@ -35,8 +35,39 @@ jobs:
|
||||
exit 1
|
||||
fi
|
||||
echo "OK: tag $tag == version $pkg"
|
||||
- run: npm publish -w @johanleroy/git-arboretum
|
||||
# Publication idempotente : le signal faisant autorité d'une version déjà présente est le
|
||||
# 409 « already exists » renvoyé par npm publish lui-même (npm view est non fiable contre le
|
||||
# registre npm de Gitea — faux négatif masqué par >/dev/null). On tente toujours le publish ;
|
||||
# un 409 = succès idempotent, tout autre échec reste fatal. Le shell Actions tourne en
|
||||
# `bash -eo pipefail` : on isole l'échec attendu dans la condition d'un `if` pour ne pas
|
||||
# déclencher `set -e`. Le secret du registre est mappé sur NODE_AUTH_TOKEN lu par le .npmrc
|
||||
# de setup-node.
|
||||
- name: Publish (idempotent — tolère un 409 « already exists »)
|
||||
run: |
|
||||
if out="$(npm publish -w @johanleroy/git-arboretum 2>&1)"; then
|
||||
printf '%s\n' "$out"
|
||||
echo "Publication réussie."
|
||||
else
|
||||
code=$?
|
||||
printf '%s\n' "$out"
|
||||
if printf '%s' "$out" | grep -qiE 'E409|409 Conflict|already exists'; then
|
||||
echo "::notice::Version déjà présente sur le registre (409) — publication idempotente, étape ignorée."
|
||||
else
|
||||
echo "::error::Échec de la publication (code $code)."
|
||||
exit "$code"
|
||||
fi
|
||||
fi
|
||||
env:
|
||||
# Mapper le secret du registre (PAT Gitea write:package, ou le token auto
|
||||
# GITEA_TOKEN s'il a ce scope) sur NODE_AUTH_TOKEN lu par le .npmrc de setup-node.
|
||||
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||
# SBOM (transparence supply-chain entreprise) : généré pour le paquet publié et exposé en
|
||||
# artefact. C'est un bonus : un échec de génération/upload ne doit jamais faire rougir une
|
||||
# release dont le publish a réussi → continue-on-error.
|
||||
# upload-artifact@v3 : Gitea Actions (GHES-like) ne supporte pas @v4 (@actions/artifact v2+).
|
||||
- name: Generate SBOM (CycloneDX)
|
||||
continue-on-error: true
|
||||
run: npx --yes @cyclonedx/cyclonedx-npm --omit dev --output-format JSON --output-file sbom.json -w @johanleroy/git-arboretum || npx --yes @cyclonedx/cyclonedx-npm --omit dev --output-format JSON --output-file sbom.json
|
||||
- uses: actions/upload-artifact@v3
|
||||
continue-on-error: true
|
||||
with:
|
||||
name: sbom
|
||||
path: sbom.json
|
||||
|
||||
69
README.fr.md
69
README.fr.md
@@ -10,7 +10,7 @@
|
||||
<a href="README.md">English</a> · <strong>Français</strong>
|
||||
</p>
|
||||
|
||||
**Statut : MVP.** Le dashboard worktree-first, la découverte et la reprise de sessions, le cycle de vie des worktrees multi-repo, les états de session en temps réel, le terminal web et la supervision mobile (PWA installable, Web Push quand une session vous attend, valider/refuser sans ouvrir de terminal) sont implémentés et testés.
|
||||
**Statut : MVP.** Le dashboard worktree-first, la découverte et la reprise de sessions, le cycle de vie des worktrees multi-repo, les états de session en temps réel, le terminal web, la supervision mobile (PWA installable, Web Push quand une session vous attend, valider/refuser sans ouvrir de terminal) et les groupes de travail (piloter plusieurs repos liés à la fois) sont implémentés et testés.
|
||||
|
||||
---
|
||||
|
||||
@@ -31,6 +31,7 @@ Un unique daemon Node.js que vous lancez sur votre machine de dev (`npx @johanle
|
||||
- **Découverte & reprise de sessions** — les sessions lancées dans votre propre terminal apparaissent automatiquement ; reprenez les sessions mortes, observez ou forkez les vivantes. Ne corrompt jamais une session vivante.
|
||||
- **Terminal web** — terminal xterm.js complet vers chaque session managée, qui survit aux déconnexions du navigateur.
|
||||
- **Supervision depuis votre téléphone** — PWA installable avec notifications push quand une session vous attend ; validez ou refusez une demande sans ouvrir de terminal.
|
||||
- **Groupes de travail** — regroupez des repos liés (ex. une API, son frontend web et une lib partagée) dans un groupe nommé pour travailler sur tous à la fois : une vue unifiée de leurs worktrees et sessions, une grille multi-terminaux côte à côte, et une action « feature cross-repo » en un clic qui crée le même worktree de branche (et au besoin une session Claude) dans chaque repo du groupe.
|
||||
|
||||
---
|
||||
|
||||
@@ -42,6 +43,11 @@ Un unique daemon Node.js que vous lancez sur votre machine de dev (`npx @johanle
|
||||
|
||||
## Démarrage rapide
|
||||
|
||||
Deux chemins, selon ce que vous voulez :
|
||||
|
||||
- **Juste l'utiliser (la plupart des gens).** Arboretum est un paquet npm publié — vous **n'avez pas besoin de cloner ce dépôt**. Pointez npm vers le registre et lancez-le (ci-dessous). À faire sur la machine où tournent vos sessions Claude Code.
|
||||
- **Lancer depuis les sources.** Ne clonez le dépôt que pour développer Arboretum ou lancer une version non publiée.
|
||||
|
||||
### Le lancer (recommandé)
|
||||
|
||||
Arboretum est publié sur un registre npm Gitea auto-hébergé. Pointez le scope `@johanleroy` dessus une fois par machine — ajoutez à `~/.npmrc` :
|
||||
@@ -70,8 +76,17 @@ Au premier démarrage, Arboretum affiche un **token d'accès** unique et l'URL
|
||||
|
||||
Ouvrez l'URL, collez le token pour vous connecter, et c'est parti. Le token est stocké **hashé** — il n'est affiché qu'une seule fois, alors gardez-le en lieu sûr (un gestionnaire de mots de passe). Vous pourrez gérer vos tokens plus tard depuis les **Réglages**.
|
||||
|
||||
`npx` télécharge et lance la dernière version publiée à chaque fois. Pour l'installer une bonne fois — et obtenir la commande `arboretum` sur votre `PATH`, dont se sert le [service d'arrière-plan](#le-faire-tourner-en-service-darrière-plan) —, installez-le plutôt globalement :
|
||||
|
||||
```bash
|
||||
npm i -g @johanleroy/git-arboretum
|
||||
arboretum # identique à la commande npx, depuis le binaire installé
|
||||
```
|
||||
|
||||
### Lancer depuis les sources
|
||||
|
||||
Nécessaire uniquement pour **développer** Arboretum ou lancer une version non publiée — pas pour simplement l'utiliser. Clonez le dépôt, installez les dépendances, buildez, puis démarrez le daemon :
|
||||
|
||||
```bash
|
||||
git clone https://git.lidge.fr/johanleroy/arboretum.git
|
||||
cd arboretum
|
||||
@@ -110,7 +125,26 @@ Ouvrez `https://<machine>.<tailnet>.ts.net` depuis n'importe quel appareil de vo
|
||||
|
||||
## Le faire tourner en service d'arrière-plan
|
||||
|
||||
Pour un daemon qui survit à la déconnexion et redémarre au boot, lancez-le via un **service systemd utilisateur**. Installez une version figée globalement (`npm i -g @johanleroy/git-arboretum`), puis créez `~/.config/systemd/user/arboretum.service` :
|
||||
Le plus rapide pour faire tourner Arboretum en service qui survit à la déconnexion et redémarre au boot, c'est l'installeur intégré. Installez une version figée globalement, puis lancez `install` — il détecte votre OS, écrit le fichier de service, le démarre et affiche le token unique :
|
||||
|
||||
```bash
|
||||
npm i -g @johanleroy/git-arboretum
|
||||
arboretum install --allow-origin https://MACHINE.TAILNET.ts.net
|
||||
```
|
||||
|
||||
Cela met en place un **service systemd utilisateur** sous Linux (`~/.config/systemd/user/arboretum.service`) ou un **LaunchAgent launchd** sous macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`). Tous les flags du daemon (`--port`, `--allow-origin`, `--db`, …) sont propagés au service. Gérez-le avec :
|
||||
|
||||
```bash
|
||||
arboretum status # état du service (+ où lire les logs)
|
||||
arboretum uninstall # arrête et supprime le service
|
||||
```
|
||||
|
||||
Les logs vivent dans `journalctl --user -u arboretum -f` (Linux) ou `~/Library/Logs/arboretum/` (macOS). Lancez d'abord `arboretum install --dry-run …` pour afficher le unit/plist et les commandes exactes sans rien modifier.
|
||||
|
||||
<details>
|
||||
<summary>Vous préférez configurer systemd à la main ? (Linux)</summary>
|
||||
|
||||
Créez `~/.config/systemd/user/arboretum.service` :
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
@@ -137,12 +171,15 @@ systemctl --user enable --now arboretum
|
||||
loginctl enable-linger "$USER" # démarre le service au boot, sans session ouverte
|
||||
journalctl --user -u arboretum -f # logs
|
||||
```
|
||||
</details>
|
||||
|
||||
> Le **token d'accès** unique n'est affiché qu'au tout premier démarrage (base vierge). En service, récupérez-le depuis `journalctl`, ou faites un lancement manuel avant d'activer le service. Le token est hashé et n'est jamais réaffiché.
|
||||
> Le **token d'accès** unique est affiché par `arboretum install` (et au tout premier lancement manuel sur base vierge). Le token est hashé et n'est jamais réaffiché — conservez-le en lieu sûr.
|
||||
|
||||
## Configuration
|
||||
|
||||
Toutes les options sont des flags CLI :
|
||||
Commandes : `arboretum` démarre le daemon (par défaut), `arboretum serve` en est un alias explicite, `arboretum install` / `uninstall` / `status` gèrent le service d'arrière-plan, et `arboretum help` affiche l'aide.
|
||||
|
||||
Les options du daemon sont des flags CLI :
|
||||
|
||||
| Flag | Défaut | Description |
|
||||
|---|---|---|
|
||||
@@ -154,6 +191,15 @@ Toutes les options sont des flags CLI :
|
||||
| `--print-token` | `false` | Indication sur le réaffichage du token (les tokens sont hashés et ne peuvent pas être réaffichés). |
|
||||
| `--i-know-this-exposes-a-terminal` | `false` | Reconnaître le bind sur une adresse non-loopback. **À éviter** — préférez Tailscale Serve. |
|
||||
|
||||
`arboretum install` accepte tous les flags du daemon ci-dessus (propagés tels quels au service), plus :
|
||||
|
||||
| Flag | Description |
|
||||
|---|---|
|
||||
| `--bin-path <path>` | Utilise ce binaire dans le service au lieu de `node` + le script embarqué. |
|
||||
| `--label <id>` | Label launchd (macOS uniquement, défaut `fr.lidge.arboretum`). |
|
||||
| `--dry-run` | Affiche le unit/plist et les commandes sans rien appliquer. |
|
||||
| `--no-enable` | Écrit le fichier de service sans l'activer/le démarrer. |
|
||||
|
||||
L'état (la base SQLite) vit dans `$XDG_DATA_HOME/arboretum` (par défaut `~/.local/share/arboretum`).
|
||||
|
||||
## Modèle de sécurité
|
||||
@@ -162,9 +208,13 @@ Un terminal web, c'est de l'exécution de code à distance *par conception*. Les
|
||||
|
||||
- Se bind sur `127.0.0.1` par défaut ; refuse les binds non-loopback sans flag explicite.
|
||||
- Authentifie **chaque** requête `/api/**` **et** chaque upgrade `/ws` avec des tokens révocables, et applique un **check `Origin` strict** (le cookie `SameSite=Strict` ne couvre pas les upgrades WebSocket — c'est le garde-fou anti cross-site hijacking).
|
||||
- Les tokens sont stockés **hashés** (sha256) et comparés en temps constant ; le bootstrap token n'est affiché qu'une seule fois. Le cookie de session est un payload signé HMAC. Le login est rate-limité avec backoff exponentiel.
|
||||
- Les tokens sont stockés **hashés** (sha256) et comparés en temps constant ; le bootstrap token n'est affiché qu'une seule fois. Le cookie de session est un payload signé HMAC, `HttpOnly` et `SameSite=Strict`, et reçoit automatiquement le flag `Secure` quand la requête arrive en HTTPS (p. ex. derrière Tailscale Serve). Le login est rate-limité avec backoff exponentiel.
|
||||
- Envoie des en-têtes HTTP durcis (CSP, `X-Frame-Options`, `nosniff`, `Referrer-Policy`, HSTS conditionnel, `no-store` sur l'API), restreint le dossier de données à `0o700` et la base à `0o600`, et **chiffre les secrets sensibles au repos** (AES-256-GCM).
|
||||
- Tient un **journal d'audit** des opérations sensibles et offre l'**export/effacement RGPD** des données (Réglages → Sécurité & conformité).
|
||||
|
||||
La façon recommandée d'atteindre Arboretum depuis d'autres appareils est Tailscale Serve (HTTPS valide, identité tailnet, aucun port ouvert). Ne l'exposez jamais directement sur internet.
|
||||
Tailscale Serve est **la** façon d'atteindre Arboretum depuis d'autres appareils — pas seulement une recommandation : HTTPS valide, identité tailnet, aucun port ouvert. Le flag `--i-know-this-exposes-a-terminal` est une trappe de secours, pas un mode de déploiement ; n'exposez jamais Arboretum directement sur internet.
|
||||
|
||||
Voir [`SECURITY.md`](SECURITY.md) pour le modèle de menace complet et [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md) pour le durcissement en environnement réglementé.
|
||||
|
||||
## Ce qui le distingue
|
||||
|
||||
@@ -202,8 +252,15 @@ node packages/server/scripts/acceptance-p1.mjs # cœur : daemon + client WS r
|
||||
node packages/server/scripts/acceptance-p2.mjs # découverte & reprise de sessions
|
||||
node packages/server/scripts/acceptance-p3.mjs # worktrees & corrélation de sessions
|
||||
node packages/server/scripts/acceptance-p4.mjs # Web Push + commande WS `answer`
|
||||
node packages/server/scripts/acceptance-p5.mjs # groupes de travail : CRUD + broadcast WS + CASCADE
|
||||
```
|
||||
|
||||
## Soutenir le projet
|
||||
|
||||
Arboretum est un projet personnel libre et auto-financé. S'il vous fait gagner du temps, vous pouvez soutenir son développement :
|
||||
|
||||
[](https://buymeacoffee.com/johanleroy)
|
||||
|
||||
## Licence
|
||||
|
||||
MIT — voir [LICENSE](LICENSE).
|
||||
|
||||
69
README.md
69
README.md
@@ -10,7 +10,7 @@
|
||||
<strong>English</strong> · <a href="README.fr.md">Français</a>
|
||||
</p>
|
||||
|
||||
**Status: MVP.** The worktree-first dashboard, session discovery & resume, multi-repo worktree lifecycle, live session states, the web terminal, and mobile supervision (installable PWA, Web Push when a session needs you, approve/deny without opening a terminal) are implemented and tested.
|
||||
**Status: MVP.** The worktree-first dashboard, session discovery & resume, multi-repo worktree lifecycle, live session states, the web terminal, and mobile supervision (installable PWA, Web Push when a session needs you, approve/deny without opening a terminal), and work groups (run several related repos at once) are implemented and tested.
|
||||
|
||||
---
|
||||
|
||||
@@ -31,6 +31,7 @@ A single Node.js daemon you run on your dev machine (`npx @johanleroy/git-arbore
|
||||
- **Session discovery & resume** — sessions you launched in your own terminal show up automatically; resume dead ones, observe or fork live ones. Never corrupts a live session.
|
||||
- **Web terminal** — full xterm.js terminal to every managed session, surviving browser disconnects.
|
||||
- **Supervision from your phone** — installable PWA with push notifications when a session needs you; approve/deny a prompt without opening a terminal.
|
||||
- **Work groups** — bundle related repos (e.g. an API, its web frontend and a shared library) into a named group to work on them at once: a unified view of all their worktrees and sessions, a side-by-side multi-terminal grid, and a one-click "cross-repo feature" that creates the same branch worktree (and optionally a Claude session) across every repo in the group.
|
||||
|
||||
---
|
||||
|
||||
@@ -42,6 +43,11 @@ A single Node.js daemon you run on your dev machine (`npx @johanleroy/git-arbore
|
||||
|
||||
## Quick start
|
||||
|
||||
Two paths, depending on what you want:
|
||||
|
||||
- **Just use it (most people).** Arboretum is a published npm package — you **don't need to clone this repo**. Point npm at the registry and run it (below). Do this on the machine where your Claude Code sessions run.
|
||||
- **Run from source.** Clone the repo only to hack on Arboretum or run an unreleased build.
|
||||
|
||||
### Run it (recommended)
|
||||
|
||||
Arboretum is published to a self-hosted Gitea npm registry. Point the `@johanleroy` scope at it once per machine — add to `~/.npmrc`:
|
||||
@@ -70,8 +76,17 @@ On first start, Arboretum prints a one-time **access token** and the URL to open
|
||||
|
||||
Open the URL, paste the token to log in, and you're in. The token is stored **hashed** — it is shown only once, so save it somewhere safe (a password manager). You can manage tokens later from **Settings**.
|
||||
|
||||
`npx` fetches and runs the latest published version each time. To install it once — and get the `arboretum` command on your `PATH`, which the [background service](#running-it-as-a-background-service) relies on — install it globally instead:
|
||||
|
||||
```bash
|
||||
npm i -g @johanleroy/git-arboretum
|
||||
arboretum # identical to the npx command, from the installed binary
|
||||
```
|
||||
|
||||
### Run from source
|
||||
|
||||
Only needed to **develop** Arboretum or run an unreleased build — not required just to use it. Clone the repo, install dependencies, build, then start the daemon:
|
||||
|
||||
```bash
|
||||
git clone https://git.lidge.fr/johanleroy/arboretum.git
|
||||
cd arboretum
|
||||
@@ -110,7 +125,26 @@ Open `https://<machine>.<tailnet>.ts.net` from any device on your tailnet. **Web
|
||||
|
||||
## Running it as a background service
|
||||
|
||||
For a daemon that survives logout and restarts on boot, run it under a **systemd user service**. Install a pinned version globally (`npm i -g @johanleroy/git-arboretum`), then create `~/.config/systemd/user/arboretum.service`:
|
||||
The quickest way to run Arboretum as a service that survives logout and restarts on boot is the built-in installer. Install a pinned version globally, then run `install` — it detects your OS, writes the service file, starts it, and prints the one-time token:
|
||||
|
||||
```bash
|
||||
npm i -g @johanleroy/git-arboretum
|
||||
arboretum install --allow-origin https://MACHINE.TAILNET.ts.net
|
||||
```
|
||||
|
||||
This sets up a **systemd user service** on Linux (`~/.config/systemd/user/arboretum.service`) or a **launchd LaunchAgent** on macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`). Every daemon flag (`--port`, `--allow-origin`, `--db`, …) is propagated to the service. Manage it with:
|
||||
|
||||
```bash
|
||||
arboretum status # service status (+ where to read logs)
|
||||
arboretum uninstall # stop and remove the service
|
||||
```
|
||||
|
||||
Logs live in `journalctl --user -u arboretum -f` (Linux) or `~/Library/Logs/arboretum/` (macOS). Run `arboretum install --dry-run …` first to print the unit/plist and the exact commands without touching anything.
|
||||
|
||||
<details>
|
||||
<summary>Prefer to set up systemd by hand? (Linux)</summary>
|
||||
|
||||
Create `~/.config/systemd/user/arboretum.service`:
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
@@ -137,12 +171,15 @@ systemctl --user enable --now arboretum
|
||||
loginctl enable-linger "$USER" # start the service at boot, without an open session
|
||||
journalctl --user -u arboretum -f # logs
|
||||
```
|
||||
</details>
|
||||
|
||||
> The one-time **access token is printed only on the very first run** (empty database). When running as a service, capture it from `journalctl`, or do one manual run before enabling the service. The token is hashed and never shown again.
|
||||
> The one-time **access token is printed by `arboretum install`** (and on the very first manual run with an empty database). The token is hashed and never shown again — store it safely.
|
||||
|
||||
## Configuration
|
||||
|
||||
All options are CLI flags:
|
||||
Commands: `arboretum` starts the daemon (the default), `arboretum serve` is an explicit alias, `arboretum install` / `uninstall` / `status` manage the background service, and `arboretum help` prints usage.
|
||||
|
||||
Daemon options are CLI flags:
|
||||
|
||||
| Flag | Default | Description |
|
||||
|---|---|---|
|
||||
@@ -154,6 +191,15 @@ All options are CLI flags:
|
||||
| `--print-token` | `false` | Hint about token re-printing (tokens are hashed and cannot be re-shown). |
|
||||
| `--i-know-this-exposes-a-terminal` | `false` | Acknowledge binding to a non-loopback address. **Avoid** — prefer Tailscale Serve. |
|
||||
|
||||
`arboretum install` accepts every daemon flag above (propagated verbatim to the service) plus:
|
||||
|
||||
| Flag | Description |
|
||||
|---|---|
|
||||
| `--bin-path <path>` | Use this binary in the service instead of `node` + the bundled script. |
|
||||
| `--label <id>` | launchd label (macOS only, default `fr.lidge.arboretum`). |
|
||||
| `--dry-run` | Print the unit/plist and commands without applying anything. |
|
||||
| `--no-enable` | Write the service file but do not enable/start it. |
|
||||
|
||||
State (the SQLite database) lives in `$XDG_DATA_HOME/arboretum` (default `~/.local/share/arboretum`).
|
||||
|
||||
## Security model
|
||||
@@ -162,9 +208,13 @@ A web terminal is remote code execution *by design*. Arboretum's guardrails are
|
||||
|
||||
- Binds to `127.0.0.1` by default; refuses non-loopback binds without an explicit flag.
|
||||
- Authenticates **every** `/api/**` request **and** every `/ws` upgrade with revocable tokens, and applies a **strict `Origin` check** (the `SameSite=Strict` cookie does not cover WebSocket upgrades — this is the anti cross-site hijacking guard).
|
||||
- Tokens are stored **hashed** (sha256) and compared in constant time; the bootstrap token is shown only once. The session cookie is an HMAC-signed payload. Login is rate-limited with exponential backoff.
|
||||
- Tokens are stored **hashed** (sha256) and compared in constant time; the bootstrap token is shown only once. The session cookie is an HMAC-signed payload, `HttpOnly` and `SameSite=Strict`, and it automatically gains the `Secure` flag when the request arrives over HTTPS (e.g. behind Tailscale Serve). Login is rate-limited with exponential backoff.
|
||||
- Sends hardened HTTP headers (CSP, `X-Frame-Options`, `nosniff`, `Referrer-Policy`, conditional HSTS, `no-store` on the API), restricts the data directory to `0o700` and the database to `0o600`, and **encrypts sensitive secrets at rest** (AES-256-GCM).
|
||||
- Keeps an **audit log** of sensitive operations and offers **GDPR** data export/erasure (Settings → Security & compliance).
|
||||
|
||||
The recommended way to reach Arboretum from other devices is Tailscale Serve (valid HTTPS, tailnet identity, no open ports). Never expose it directly to the internet.
|
||||
Tailscale Serve is **the** way to reach Arboretum from other devices — not just a recommendation: valid HTTPS, tailnet identity, no open ports. The `--i-know-this-exposes-a-terminal` flag is an escape hatch, not a deployment mode; never expose Arboretum directly to the internet.
|
||||
|
||||
See [`SECURITY.md`](SECURITY.md) for the full threat model and [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md) for hardening in regulated environments.
|
||||
|
||||
## What makes it different
|
||||
|
||||
@@ -202,8 +252,15 @@ node packages/server/scripts/acceptance-p1.mjs # core: daemon + real WS client
|
||||
node packages/server/scripts/acceptance-p2.mjs # session discovery & resume
|
||||
node packages/server/scripts/acceptance-p3.mjs # worktrees & session correlation
|
||||
node packages/server/scripts/acceptance-p4.mjs # Web Push + WS `answer` command
|
||||
node packages/server/scripts/acceptance-p5.mjs # work groups: CRUD + WS broadcast + CASCADE
|
||||
```
|
||||
|
||||
## Support
|
||||
|
||||
Arboretum is a free, self-funded side project. If it saves you time, you can support its development:
|
||||
|
||||
[](https://buymeacoffee.com/johanleroy)
|
||||
|
||||
## License
|
||||
|
||||
MIT — see [LICENSE](LICENSE).
|
||||
|
||||
61
SECURITY.md
Normal file
61
SECURITY.md
Normal file
@@ -0,0 +1,61 @@
|
||||
# Security Policy
|
||||
|
||||
Arboretum is a self-hosted daemon that serves a web dashboard to drive git worktrees and the
|
||||
Claude Code sessions running on them. **A web terminal is remote code execution by design** — that
|
||||
is the product, not a bug. Arboretum's security model is therefore built on *structural* guards
|
||||
(loopback-only binding, authenticated access, strict Origin checks) far more than on cryptography
|
||||
alone.
|
||||
|
||||
This document describes the threat model, the controls that are implemented, the deliberate
|
||||
trade-offs, and how to report a vulnerability. For hardening a deployment in a regulated
|
||||
environment, see [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md).
|
||||
|
||||
## Threat model
|
||||
|
||||
- **Single-user by design.** Arboretum runs on the owner's machine and is meant for one operator.
|
||||
There is no multi-tenant isolation and no RBAC — and none is claimed.
|
||||
- **Loopback by default.** The server binds `127.0.0.1`; `config.ts` *refuses* any non-loopback bind
|
||||
unless you pass `--i-know-this-exposes-a-terminal`. Remote access is expected via **Tailscale Serve**
|
||||
(TLS + tailnet identity), never by opening a port.
|
||||
- **The terminal is RCE.** Anyone who can authenticate can run code. The controls below exist to make
|
||||
sure only the authenticated operator reaches it, and that the surrounding surface (cookies, headers,
|
||||
data at rest) is hardened.
|
||||
|
||||
## Implemented controls
|
||||
|
||||
| Area | Control | Where |
|
||||
| --- | --- | --- |
|
||||
| Network | Loopback-only default; non-loopback refused without explicit flag | `packages/server/src/config.ts` |
|
||||
| AuthN | Global guard on **all** `/api/**` and `/ws` (only login is public, and rate-limited) | `packages/server/src/app.ts` |
|
||||
| AuthN | Tokens stored **hashed** (SHA-256), compared in constant time; bootstrap token shown once | `packages/server/src/auth/service.ts` |
|
||||
| Sessions | Cookie is an HMAC-SHA256 signed payload, `HttpOnly` + `SameSite=Strict`, `Secure` when HTTPS | `packages/server/src/routes/auth.ts` |
|
||||
| CSRF / WS | Strict `Origin` check on every `/api/**` and `/ws` request (anti cross-site WS hijacking) | `packages/server/src/app.ts` |
|
||||
| CSRF | Mutations carrying a body must be `application/json` | `packages/server/src/app.ts` |
|
||||
| Rate limit | Global login rate limit with exponential backoff (not per-IP — Tailscale fronts everything as 127.0.0.1) | `packages/server/src/auth/service.ts` |
|
||||
| HTTP headers | CSP, `X-Frame-Options: DENY`, `X-Content-Type-Options: nosniff`, `Referrer-Policy`, `Permissions-Policy`, conditional HSTS, `Cache-Control: no-store` on API; `Server` header stripped | `packages/server/src/app.ts` |
|
||||
| Injection | All SQL is parameterized; all git calls use `execFile` (no shell); path-traversal guards | `packages/server/src/**` |
|
||||
| Data at rest | DB file/dir forced to `0o600`/`0o700`; sensitive secrets (server secret, VAPID private key) encrypted with AES-256-GCM | `packages/server/src/db/index.ts`, `core/secret-box.ts` |
|
||||
| Audit | Persistent audit log of sensitive mutations (tokens, settings, secrets, push, groups) | `packages/server/src/core/audit-log.ts` |
|
||||
| Privacy | GDPR export (`/api/v1/data/export`) and erasure (`/api/v1/data/delete-my-data`) | `packages/server/src/routes/data.ts` |
|
||||
| Install | Runs as a **user** service (systemd user unit / launchd LaunchAgent), never root | `packages/server/src/cli/install.ts` |
|
||||
|
||||
## Deliberate trade-offs
|
||||
|
||||
- **Long-lived API tokens.** Tokens do not expire by age (CLI automation stability) but can be revoked
|
||||
instantly, and `last_used_at` is tracked. Review and rotate tokens periodically.
|
||||
- **Encryption-at-rest key management.** With no `ARBORETUM_SECRET_KEY` set, the encryption key lives in
|
||||
`dataDir/secret.key` (`0o600`) next to the database — this protects a leaked database *copy* (backup,
|
||||
WAL) but not a full `dataDir` compromise. For strong protection, set `ARBORETUM_SECRET_KEY` and store it
|
||||
separately from database backups. Full-DB SQLCipher is intentionally avoided (it breaks the `npx`
|
||||
prebuilt portability).
|
||||
- **No multi-user model.** If you need multiple operators with isolation, Arboretum is not the right tool.
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
Please report security issues **privately** — do not open a public issue.
|
||||
|
||||
- Email: **security@johanleroy.fr** (or `contact@johanleroy.fr`).
|
||||
- Include a description, affected version, and reproduction steps.
|
||||
- Expect an acknowledgement within **7 days** and a coordinated disclosure window of up to **90 days**.
|
||||
|
||||
Thank you for helping keep Arboretum users safe.
|
||||
95
docs/ENTERPRISE_DEPLOYMENT.md
Normal file
95
docs/ENTERPRISE_DEPLOYMENT.md
Normal file
@@ -0,0 +1,95 @@
|
||||
# Enterprise deployment guide
|
||||
|
||||
This guide complements [`../SECURITY.md`](../SECURITY.md) with the operational steps a regulated or
|
||||
security-conscious organization needs to deploy Arboretum with confidence.
|
||||
|
||||
## 1. Remote access: Tailscale Serve (recommended)
|
||||
|
||||
Never open a public port. Keep the default `127.0.0.1` bind and put Arboretum behind Tailscale Serve:
|
||||
|
||||
```bash
|
||||
# on the host running arboretum (default bind 127.0.0.1:7317)
|
||||
tailscale serve --bg 7317
|
||||
```
|
||||
|
||||
This gives you TLS, a stable `*.ts.net` hostname, and tailnet identity. Then add that origin to the
|
||||
allow-list so the strict Origin check accepts it:
|
||||
|
||||
```bash
|
||||
arboretum --allow-origin https://my-host.tailnet.ts.net
|
||||
```
|
||||
|
||||
The `--i-know-this-exposes-a-terminal` flag exists only as an escape hatch for non-loopback binds; it
|
||||
is **never** a deployment mode and is never injected automatically by `arboretum install`.
|
||||
|
||||
## 2. Encryption at rest
|
||||
|
||||
Sensitive secrets (the HMAC server secret and the VAPID private key) are encrypted with AES-256-GCM
|
||||
before being stored in SQLite. Token values are never stored — only their SHA-256 hashes.
|
||||
|
||||
For **strong** protection (key not co-located with the database), provide a passphrase via the
|
||||
environment instead of the on-disk key file:
|
||||
|
||||
```bash
|
||||
ARBORETUM_SECRET_KEY='<a long random passphrase from your secrets manager>' arboretum
|
||||
```
|
||||
|
||||
- Store this passphrase in your secrets manager / KMS, **separately** from database backups.
|
||||
- Without it, the key is auto-generated in `dataDir/secret.key` (`0o600`). This still protects a leaked
|
||||
database copy, but not a full `dataDir` compromise.
|
||||
- Rotating the passphrase requires re-encrypting existing values; the simplest path is to revoke and
|
||||
recreate the bootstrap token after rotation.
|
||||
|
||||
## 3. Filesystem permissions
|
||||
|
||||
On startup Arboretum forces `dataDir` to `0o700` and the database files (`*.db`, `-wal`, `-shm`) to
|
||||
`0o600`. Verify after first run:
|
||||
|
||||
```bash
|
||||
stat -c '%a %n' ~/.local/share/arboretum ~/.local/share/arboretum/*.db
|
||||
# expect: 700 …/arboretum and 600 …/arboretum.db
|
||||
```
|
||||
|
||||
Keep `$HOME` private (standard `0o700`). If you relocate data with `--db` or `XDG_DATA_HOME`, make sure
|
||||
the target directory is not world-readable.
|
||||
|
||||
## 4. Audit logging
|
||||
|
||||
All sensitive mutations are recorded in an append-only `audit_logs` table: token create/revoke, login
|
||||
success/failure, settings changes, secret generation, push subscribe/unsubscribe, group CRUD, and data
|
||||
erasure. Query it via the API (paginated):
|
||||
|
||||
```bash
|
||||
curl -s -H "Authorization: Bearer $TOKEN" \
|
||||
'http://127.0.0.1:7317/api/v1/audit-logs?limit=100'
|
||||
```
|
||||
|
||||
The audit log never contains secret values — only non-sensitive metadata (ids, labels, counters). It is
|
||||
also visible in the dashboard under **Settings → Security & compliance**.
|
||||
|
||||
## 5. GDPR (data subject requests)
|
||||
|
||||
- **Export**: `GET /api/v1/data/export` returns every record tied to the authenticated token (token
|
||||
metadata, push subscriptions, session history, settings) as JSON. Also available as a one-click
|
||||
download in **Settings → Security & compliance**.
|
||||
- **Erasure**: `POST /api/v1/data/delete-my-data` is a two-step call — the first response returns a
|
||||
`confirm` code that must be POSTed back to execute. It purges the token's push subscriptions and
|
||||
revokes the token (unless it is the last active one).
|
||||
|
||||
## 6. Backups & retention
|
||||
|
||||
- Back up the SQLite database (`arboretum.db`) with the WAL checkpointed. Treat backups as sensitive.
|
||||
- If you use `ARBORETUM_SECRET_KEY`, back the key up **separately** — a database backup is useless (and
|
||||
safe) without it, which is the point.
|
||||
- Session history is retained until the database is reset. To start clean, stop the service and remove
|
||||
the database file.
|
||||
|
||||
## 7. Logging hygiene
|
||||
|
||||
The log level is controlled by `ARBORETUM_LOG` (default `info`). Do **not** run `debug`/`trace` in
|
||||
production: verbose levels may log request metadata. Keep `info` or higher.
|
||||
|
||||
## 8. Supply chain
|
||||
|
||||
Each published release ships with a CycloneDX SBOM (`sbom.json`) generated in CI, so you can scan the
|
||||
dependency tree for known vulnerabilities before deploying.
|
||||
301
package-lock.json
generated
301
package-lock.json
generated
@@ -23,6 +23,10 @@
|
||||
"resolved": "packages/shared",
|
||||
"link": true
|
||||
},
|
||||
"node_modules/@arboretum/site": {
|
||||
"resolved": "packages/site",
|
||||
"link": true
|
||||
},
|
||||
"node_modules/@arboretum/web": {
|
||||
"resolved": "packages/web",
|
||||
"link": true
|
||||
@@ -720,9 +724,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@fastify/static": {
|
||||
"version": "8.3.0",
|
||||
"resolved": "https://registry.npmjs.org/@fastify/static/-/static-8.3.0.tgz",
|
||||
"integrity": "sha512-yKxviR5PH1OKNnisIzZKmgZSus0r2OZb8qCSbqmw34aolT4g3UlzYfeBRym+HJ1J471CR8e2ldNub4PubD1coA==",
|
||||
"version": "9.1.3",
|
||||
"resolved": "https://registry.npmjs.org/@fastify/static/-/static-9.1.3.tgz",
|
||||
"integrity": "sha512-aXrYtsiryLhRxRNaxNqsn7FUISeb7rB9q4eHUPIot5aeQBLNahnz1m6thzm7JWC1poSGXS9XrX8DvuMivp2hkQ==",
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
@@ -737,10 +741,10 @@
|
||||
"dependencies": {
|
||||
"@fastify/accept-negotiator": "^2.0.0",
|
||||
"@fastify/send": "^4.0.0",
|
||||
"content-disposition": "^0.5.4",
|
||||
"content-disposition": "^1.0.1",
|
||||
"fastify-plugin": "^5.0.0",
|
||||
"fastq": "^1.17.1",
|
||||
"glob": "^11.0.0"
|
||||
"glob": "^13.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@fastify/websocket": {
|
||||
@@ -764,6 +768,16 @@
|
||||
"ws": "^8.16.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@fontsource/jetbrains-mono": {
|
||||
"version": "5.2.8",
|
||||
"resolved": "https://registry.npmjs.org/@fontsource/jetbrains-mono/-/jetbrains-mono-5.2.8.tgz",
|
||||
"integrity": "sha512-6w8/SG4kqvIMu7xd7wt6x3idn1Qux3p9N62s6G3rfldOUYHpWcc2FKrqf+Vo44jRvqWj2oAtTHrZXEP23oSKwQ==",
|
||||
"dev": true,
|
||||
"license": "OFL-1.1",
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/ayuhito"
|
||||
}
|
||||
},
|
||||
"node_modules/@homebridge/node-pty-prebuilt-multiarch": {
|
||||
"version": "0.13.1",
|
||||
"resolved": "https://registry.npmjs.org/@homebridge/node-pty-prebuilt-multiarch/-/node-pty-prebuilt-multiarch-0.13.1.tgz",
|
||||
@@ -839,15 +853,6 @@
|
||||
"url": "https://github.com/sponsors/kazupon"
|
||||
}
|
||||
},
|
||||
"node_modules/@isaacs/cliui": {
|
||||
"version": "9.0.0",
|
||||
"resolved": "https://registry.npmjs.org/@isaacs/cliui/-/cliui-9.0.0.tgz",
|
||||
"integrity": "sha512-AokJm4tuBHillT+FpMtxQ60n8ObyXBatq7jD2/JA9dxbDDokKQm8KMht5ibGzLVU9IJDIKK4TPKgMHEYMn3lMg==",
|
||||
"license": "BlueOak-1.0.0",
|
||||
"engines": {
|
||||
"node": ">=18"
|
||||
}
|
||||
},
|
||||
"node_modules/@johanleroy/git-arboretum": {
|
||||
"resolved": "packages/server",
|
||||
"link": true
|
||||
@@ -914,6 +919,15 @@
|
||||
"@jridgewell/sourcemap-codec": "^1.4.14"
|
||||
}
|
||||
},
|
||||
"node_modules/@lucide/vue": {
|
||||
"version": "1.21.0",
|
||||
"resolved": "https://registry.npmjs.org/@lucide/vue/-/vue-1.21.0.tgz",
|
||||
"integrity": "sha512-eoFn3tppjKAc12ZqdnRSMFdtwQ1ZMRQFb6SV1Eub6Y8kU28ccnqKeSFdnur9hMg8gIbosU2Y3WFJr/J/xS/IlQ==",
|
||||
"license": "ISC",
|
||||
"peerDependencies": {
|
||||
"vue": ">=3.0.1"
|
||||
}
|
||||
},
|
||||
"node_modules/@lukeed/ms": {
|
||||
"version": "2.0.2",
|
||||
"resolved": "https://registry.npmjs.org/@lukeed/ms/-/ms-2.0.2.tgz",
|
||||
@@ -2542,15 +2556,16 @@
|
||||
"peer": true
|
||||
},
|
||||
"node_modules/content-disposition": {
|
||||
"version": "0.5.4",
|
||||
"resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-0.5.4.tgz",
|
||||
"integrity": "sha512-FveZTNuGw04cxlAiWbzi6zTAL/lhehaWbTtgluJh4/E95DqMwTmha3KZN1aAWA8cFIhHzMZUvLevkw5Rqk+tSQ==",
|
||||
"version": "1.1.0",
|
||||
"resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-1.1.0.tgz",
|
||||
"integrity": "sha512-5jRCH9Z/+DRP7rkvY83B+yGIGX96OYdJmzngqnw2SBSxqCFPd0w2km3s5iawpGX8krnwSGmF0FW5Nhr0Hfai3g==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"safe-buffer": "5.2.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 0.6"
|
||||
"node": ">=18"
|
||||
},
|
||||
"funding": {
|
||||
"type": "opencollective",
|
||||
"url": "https://opencollective.com/express"
|
||||
}
|
||||
},
|
||||
"node_modules/cookie": {
|
||||
@@ -2581,20 +2596,6 @@
|
||||
"url": "https://github.com/sponsors/mesqueeb"
|
||||
}
|
||||
},
|
||||
"node_modules/cross-spawn": {
|
||||
"version": "7.0.6",
|
||||
"resolved": "https://registry.npmjs.org/cross-spawn/-/cross-spawn-7.0.6.tgz",
|
||||
"integrity": "sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"path-key": "^3.1.0",
|
||||
"shebang-command": "^2.0.0",
|
||||
"which": "^2.0.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 8"
|
||||
}
|
||||
},
|
||||
"node_modules/csstype": {
|
||||
"version": "3.2.3",
|
||||
"resolved": "https://registry.npmjs.org/csstype/-/csstype-3.2.3.tgz",
|
||||
@@ -2970,22 +2971,6 @@
|
||||
"node": ">=20"
|
||||
}
|
||||
},
|
||||
"node_modules/foreground-child": {
|
||||
"version": "3.3.1",
|
||||
"resolved": "https://registry.npmjs.org/foreground-child/-/foreground-child-3.3.1.tgz",
|
||||
"integrity": "sha512-gIXjKqtFuWEgzFRJA9WCQeSJLZDjgJUOMCMzxtvFq/37KojM1BFGufqsCy0r4qSQmYLsZYMeyRqzIWOMup03sw==",
|
||||
"license": "ISC",
|
||||
"dependencies": {
|
||||
"cross-spawn": "^7.0.6",
|
||||
"signal-exit": "^4.0.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=14"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/isaacs"
|
||||
}
|
||||
},
|
||||
"node_modules/fs-constants": {
|
||||
"version": "1.0.0",
|
||||
"resolved": "https://registry.npmjs.org/fs-constants/-/fs-constants-1.0.0.tgz",
|
||||
@@ -3014,24 +2999,17 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/glob": {
|
||||
"version": "11.1.0",
|
||||
"resolved": "https://registry.npmjs.org/glob/-/glob-11.1.0.tgz",
|
||||
"integrity": "sha512-vuNwKSaKiqm7g0THUBu2x7ckSs3XJLXE+2ssL7/MfTGPLLcrJQ/4Uq1CjPTtO5cCIiRxqvN6Twy1qOwhL0Xjcw==",
|
||||
"deprecated": "Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me",
|
||||
"version": "13.0.6",
|
||||
"resolved": "https://registry.npmjs.org/glob/-/glob-13.0.6.tgz",
|
||||
"integrity": "sha512-Wjlyrolmm8uDpm/ogGyXZXb1Z+Ca2B8NbJwqBVg0axK9GbBeoS7yGV6vjXnYdGm6X53iehEuxxbyiKp8QmN4Vw==",
|
||||
"license": "BlueOak-1.0.0",
|
||||
"dependencies": {
|
||||
"foreground-child": "^3.3.1",
|
||||
"jackspeak": "^4.1.1",
|
||||
"minimatch": "^10.1.1",
|
||||
"minipass": "^7.1.2",
|
||||
"package-json-from-dist": "^1.0.0",
|
||||
"path-scurry": "^2.0.0"
|
||||
},
|
||||
"bin": {
|
||||
"glob": "dist/esm/bin.mjs"
|
||||
"minimatch": "^10.2.2",
|
||||
"minipass": "^7.1.3",
|
||||
"path-scurry": "^2.0.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": "20 || >=22"
|
||||
"node": "18 || 20 || >=22"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/isaacs"
|
||||
@@ -3145,27 +3123,6 @@
|
||||
"url": "https://github.com/sponsors/mesqueeb"
|
||||
}
|
||||
},
|
||||
"node_modules/isexe": {
|
||||
"version": "2.0.0",
|
||||
"resolved": "https://registry.npmjs.org/isexe/-/isexe-2.0.0.tgz",
|
||||
"integrity": "sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw==",
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/jackspeak": {
|
||||
"version": "4.2.3",
|
||||
"resolved": "https://registry.npmjs.org/jackspeak/-/jackspeak-4.2.3.tgz",
|
||||
"integrity": "sha512-ykkVRwrYvFm1nb2AJfKKYPr0emF6IiXDYUaFx4Zn9ZuIH7MrzEZ3sD5RlqGXNRpHtvUHJyOnCEFxOlNDtGo7wg==",
|
||||
"license": "BlueOak-1.0.0",
|
||||
"dependencies": {
|
||||
"@isaacs/cliui": "^9.0.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": "20 || >=22"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/isaacs"
|
||||
}
|
||||
},
|
||||
"node_modules/jiti": {
|
||||
"version": "2.7.0",
|
||||
"resolved": "https://registry.npmjs.org/jiti/-/jiti-2.7.0.tgz",
|
||||
@@ -3711,12 +3668,6 @@
|
||||
"wrappy": "1"
|
||||
}
|
||||
},
|
||||
"node_modules/package-json-from-dist": {
|
||||
"version": "1.0.1",
|
||||
"resolved": "https://registry.npmjs.org/package-json-from-dist/-/package-json-from-dist-1.0.1.tgz",
|
||||
"integrity": "sha512-UEZIS3/by4OC8vL3P2dTXRETpebLI2NiI5vIrjaD/5UtrkFX/tNbwjTSRAGC/+7CAo2pIcBaRgWmcBBHcsaCIw==",
|
||||
"license": "BlueOak-1.0.0"
|
||||
},
|
||||
"node_modules/path-browserify": {
|
||||
"version": "1.0.1",
|
||||
"resolved": "https://registry.npmjs.org/path-browserify/-/path-browserify-1.0.1.tgz",
|
||||
@@ -3724,15 +3675,6 @@
|
||||
"dev": true,
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/path-key": {
|
||||
"version": "3.1.1",
|
||||
"resolved": "https://registry.npmjs.org/path-key/-/path-key-3.1.1.tgz",
|
||||
"integrity": "sha512-ojmeN0qd+y0jszEtoY48r0Peq5dwMEkIlCOu6Q5f41lfkswXuKtYrhgoTpLnyIcHm24Uhqx+5Tqm2InSwLhE6Q==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=8"
|
||||
}
|
||||
},
|
||||
"node_modules/path-scurry": {
|
||||
"version": "2.0.2",
|
||||
"resolved": "https://registry.npmjs.org/path-scurry/-/path-scurry-2.0.2.tgz",
|
||||
@@ -4184,27 +4126,6 @@
|
||||
"integrity": "sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==",
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/shebang-command": {
|
||||
"version": "2.0.0",
|
||||
"resolved": "https://registry.npmjs.org/shebang-command/-/shebang-command-2.0.0.tgz",
|
||||
"integrity": "sha512-kHxr2zZpYtdmrN1qDjrrX/Z1rR1kG8Dx+gkpK1G4eXmvXswmcE1hTWBWYUzlraYw1/yZp6YuDY77YtvbN0dmDA==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"shebang-regex": "^3.0.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=8"
|
||||
}
|
||||
},
|
||||
"node_modules/shebang-regex": {
|
||||
"version": "3.0.0",
|
||||
"resolved": "https://registry.npmjs.org/shebang-regex/-/shebang-regex-3.0.0.tgz",
|
||||
"integrity": "sha512-7++dFhtcx3353uBaq8DDR4NuxBetBzC7ZQOhmTQInHEd6bSrXdiEyzCvG07Z44UYdLShWUyXt5M/yhz8ekcb1A==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=8"
|
||||
}
|
||||
},
|
||||
"node_modules/siginfo": {
|
||||
"version": "2.0.0",
|
||||
"resolved": "https://registry.npmjs.org/siginfo/-/siginfo-2.0.0.tgz",
|
||||
@@ -4212,18 +4133,6 @@
|
||||
"dev": true,
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/signal-exit": {
|
||||
"version": "4.1.0",
|
||||
"resolved": "https://registry.npmjs.org/signal-exit/-/signal-exit-4.1.0.tgz",
|
||||
"integrity": "sha512-bzyZ1e88w9O1iNJbKnOlvYTrWPDl46O1bG0D3XInv+9tkPrxrN8jUUTiFlDkkmKWgn1M6CfIA13SuGqOa9Korw==",
|
||||
"license": "ISC",
|
||||
"engines": {
|
||||
"node": ">=14"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/sponsors/isaacs"
|
||||
}
|
||||
},
|
||||
"node_modules/simple-concat": {
|
||||
"version": "1.0.1",
|
||||
"resolved": "https://registry.npmjs.org/simple-concat/-/simple-concat-1.0.1.tgz",
|
||||
@@ -4899,21 +4808,6 @@
|
||||
"node": ">= 16"
|
||||
}
|
||||
},
|
||||
"node_modules/which": {
|
||||
"version": "2.0.2",
|
||||
"resolved": "https://registry.npmjs.org/which/-/which-2.0.2.tgz",
|
||||
"integrity": "sha512-BLI3Tl1TW3Pvl70l3yq3Y64i+awpwXqsGBYWkkqMtnbXgrMD+yj7rhW0kuEDxzJaYXGjEW5ogapKNMEKNMjibA==",
|
||||
"license": "ISC",
|
||||
"dependencies": {
|
||||
"isexe": "^2.0.0"
|
||||
},
|
||||
"bin": {
|
||||
"node-which": "bin/node-which"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 8"
|
||||
}
|
||||
},
|
||||
"node_modules/why-is-node-running": {
|
||||
"version": "2.3.0",
|
||||
"resolved": "https://registry.npmjs.org/why-is-node-running/-/why-is-node-running-2.3.0.tgz",
|
||||
@@ -4960,15 +4854,11 @@
|
||||
},
|
||||
"packages/server": {
|
||||
"name": "@johanleroy/git-arboretum",
|
||||
"version": "1.0.1",
|
||||
"bundleDependencies": [
|
||||
"@arboretum/shared"
|
||||
],
|
||||
"version": "1.4.1",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@arboretum/shared": "0.1.0",
|
||||
"@fastify/cookie": "^11.0.0",
|
||||
"@fastify/static": "^8.0.0",
|
||||
"@fastify/static": "^9.0.0",
|
||||
"@fastify/websocket": "^11.0.0",
|
||||
"@homebridge/node-pty-prebuilt-multiarch": "^0.13.0",
|
||||
"@xterm/headless": "^6.0.0",
|
||||
@@ -4979,22 +4869,123 @@
|
||||
"arboretum": "dist/index.js"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@arboretum/shared": "0.1.0",
|
||||
"@types/web-push": "^3.6.4",
|
||||
"@types/ws": "^8.5.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=22.16"
|
||||
},
|
||||
"funding": {
|
||||
"type": "buymeacoffee",
|
||||
"url": "https://buymeacoffee.com/johanleroy"
|
||||
}
|
||||
},
|
||||
"packages/shared": {
|
||||
"name": "@arboretum/shared",
|
||||
"version": "0.1.0"
|
||||
},
|
||||
"packages/site": {
|
||||
"name": "@arboretum/site",
|
||||
"version": "0.1.0",
|
||||
"dependencies": {
|
||||
"vue": "^3.5.38",
|
||||
"vue-i18n": "^11.4.5"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@fontsource/jetbrains-mono": "^5.1.0",
|
||||
"@tailwindcss/vite": "^4.3.0",
|
||||
"@vitejs/plugin-vue": "^6.0.7",
|
||||
"tailwindcss": "^4.3.0",
|
||||
"typescript": "^5.7.0",
|
||||
"vite": "^8.0.16",
|
||||
"vue-tsc": "^3.3.4"
|
||||
}
|
||||
},
|
||||
"packages/site/node_modules/vite": {
|
||||
"version": "8.0.16",
|
||||
"resolved": "https://registry.npmjs.org/vite/-/vite-8.0.16.tgz",
|
||||
"integrity": "sha512-h9bXPmJichP5fLmVQo3PyaGSDE2n3aPuomeAlVRm0JLmt4rY6zmPKd59HYI4LNW8oTK7tlTsuC7l/m7awx9Jcw==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"lightningcss": "^1.32.0",
|
||||
"picomatch": "^4.0.4",
|
||||
"postcss": "^8.5.15",
|
||||
"rolldown": "1.0.3",
|
||||
"tinyglobby": "^0.2.17"
|
||||
},
|
||||
"bin": {
|
||||
"vite": "bin/vite.js"
|
||||
},
|
||||
"engines": {
|
||||
"node": "^20.19.0 || >=22.12.0"
|
||||
},
|
||||
"funding": {
|
||||
"url": "https://github.com/vitejs/vite?sponsor=1"
|
||||
},
|
||||
"optionalDependencies": {
|
||||
"fsevents": "~2.3.3"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@types/node": "^20.19.0 || >=22.12.0",
|
||||
"@vitejs/devtools": "^0.1.18",
|
||||
"esbuild": "^0.27.0 || ^0.28.0",
|
||||
"jiti": ">=1.21.0",
|
||||
"less": "^4.0.0",
|
||||
"sass": "^1.70.0",
|
||||
"sass-embedded": "^1.70.0",
|
||||
"stylus": ">=0.54.8",
|
||||
"sugarss": "^5.0.0",
|
||||
"terser": "^5.16.0",
|
||||
"tsx": "^4.8.1",
|
||||
"yaml": "^2.4.2"
|
||||
},
|
||||
"peerDependenciesMeta": {
|
||||
"@types/node": {
|
||||
"optional": true
|
||||
},
|
||||
"@vitejs/devtools": {
|
||||
"optional": true
|
||||
},
|
||||
"esbuild": {
|
||||
"optional": true
|
||||
},
|
||||
"jiti": {
|
||||
"optional": true
|
||||
},
|
||||
"less": {
|
||||
"optional": true
|
||||
},
|
||||
"sass": {
|
||||
"optional": true
|
||||
},
|
||||
"sass-embedded": {
|
||||
"optional": true
|
||||
},
|
||||
"stylus": {
|
||||
"optional": true
|
||||
},
|
||||
"sugarss": {
|
||||
"optional": true
|
||||
},
|
||||
"terser": {
|
||||
"optional": true
|
||||
},
|
||||
"tsx": {
|
||||
"optional": true
|
||||
},
|
||||
"yaml": {
|
||||
"optional": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"packages/web": {
|
||||
"name": "@arboretum/web",
|
||||
"version": "0.1.0",
|
||||
"dependencies": {
|
||||
"@arboretum/shared": "*",
|
||||
"@lucide/vue": "^1.21.0",
|
||||
"@xterm/addon-fit": "^0.11.0",
|
||||
"@xterm/addon-webgl": "^0.19.0",
|
||||
"@xterm/xterm": "^6.0.0",
|
||||
|
||||
@@ -15,7 +15,10 @@
|
||||
"pack": "npm run build && npm pack -w @johanleroy/git-arboretum",
|
||||
"test": "vitest run",
|
||||
"dev:server": "npm run dev -w @johanleroy/git-arboretum",
|
||||
"dev:web": "npm run dev -w @arboretum/web"
|
||||
"dev:web": "npm run dev -w @arboretum/web",
|
||||
"build:site": "npm run build -w @arboretum/site",
|
||||
"dev:site": "npm run dev -w @arboretum/site",
|
||||
"preview:site": "npm run preview -w @arboretum/site"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@types/node": "^22.10.0",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "@johanleroy/git-arboretum",
|
||||
"version": "1.0.1",
|
||||
"version": "1.4.1",
|
||||
"description": "Self-hosted web dashboard for git worktrees and the Claude Code sessions running on them",
|
||||
"license": "MIT",
|
||||
"type": "module",
|
||||
@@ -14,6 +14,10 @@
|
||||
"bugs": {
|
||||
"url": "https://git.lidge.fr/johanleroy/arboretum/issues"
|
||||
},
|
||||
"funding": {
|
||||
"type": "buymeacoffee",
|
||||
"url": "https://buymeacoffee.com/johanleroy"
|
||||
},
|
||||
"keywords": [
|
||||
"git",
|
||||
"worktree",
|
||||
@@ -44,16 +48,12 @@
|
||||
"scripts": {
|
||||
"build": "tsc -b",
|
||||
"dev": "tsc -b --watch & node --watch dist/index.js",
|
||||
"prepack": "node scripts/copy-web.mjs && node scripts/vendor-shared.mjs && node scripts/copy-meta.mjs",
|
||||
"prepack": "node scripts/copy-web.mjs && node scripts/inline-shared.mjs && node scripts/copy-meta.mjs",
|
||||
"test": "vitest run"
|
||||
},
|
||||
"bundleDependencies": [
|
||||
"@arboretum/shared"
|
||||
],
|
||||
"dependencies": {
|
||||
"@arboretum/shared": "0.1.0",
|
||||
"@fastify/cookie": "^11.0.0",
|
||||
"@fastify/static": "^8.0.0",
|
||||
"@fastify/static": "^9.0.0",
|
||||
"@fastify/websocket": "^11.0.0",
|
||||
"@homebridge/node-pty-prebuilt-multiarch": "^0.13.0",
|
||||
"@xterm/headless": "^6.0.0",
|
||||
@@ -61,6 +61,7 @@
|
||||
"web-push": "^3.6.7"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@arboretum/shared": "0.1.0",
|
||||
"@types/web-push": "^3.6.4",
|
||||
"@types/ws": "^8.5.0"
|
||||
}
|
||||
|
||||
@@ -23,7 +23,7 @@ const check = (name, ok, detail = '') => {
|
||||
};
|
||||
|
||||
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-'));
|
||||
const srv = spawn('node', [join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db')], {
|
||||
const srv = spawn('node', [join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--no-discover'], {
|
||||
env: { ...process.env, ARBORETUM_LOG: 'warn' },
|
||||
stdio: ['ignore', 'pipe', 'pipe'],
|
||||
});
|
||||
|
||||
@@ -62,7 +62,7 @@ writeFileSync(
|
||||
|
||||
const srv = spawn(
|
||||
'node',
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', claudeHome],
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', claudeHome, '--no-discover'],
|
||||
{ env: { ...process.env, ARBORETUM_LOG: 'warn', PATH: `${fakeBin}:${process.env.PATH}` }, stdio: ['ignore', 'pipe', 'pipe'] },
|
||||
);
|
||||
let srvOut = '';
|
||||
|
||||
@@ -36,7 +36,7 @@ git('commit', '-m', 'init');
|
||||
|
||||
const srv = spawn(
|
||||
'node',
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude')],
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
|
||||
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
|
||||
);
|
||||
let srvOut = '';
|
||||
|
||||
@@ -27,7 +27,7 @@ const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p4-'));
|
||||
|
||||
const srv = spawn(
|
||||
'node',
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude')],
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
|
||||
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
|
||||
);
|
||||
let srvOut = '';
|
||||
|
||||
146
packages/server/scripts/acceptance-p5.mjs
Normal file
146
packages/server/scripts/acceptance-p5.mjs
Normal file
@@ -0,0 +1,146 @@
|
||||
#!/usr/bin/env node
|
||||
// Acceptation P5 (sans navigateur, sans quota Claude) : groupes de travail.
|
||||
// Vrai daemon + vrai repo git tmp. Couvre : CRUD groupe via REST, broadcast WS group_update/
|
||||
// group_removed sur le topic 'groups', ajout/retrait de repo, et purge CASCADE de la membership
|
||||
// quand le repo est supprimé (PRAGMA foreign_keys = ON).
|
||||
import { spawn, execFileSync } from 'node:child_process';
|
||||
import { mkdtempSync, rmSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join, dirname } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { createRequire } from 'node:module';
|
||||
|
||||
const require = createRequire(import.meta.url);
|
||||
const WebSocket = require('ws');
|
||||
|
||||
const PORT = 7545;
|
||||
const ORIGIN = `http://127.0.0.1:${PORT}`;
|
||||
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
|
||||
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
|
||||
const results = [];
|
||||
const check = (name, ok, detail = '') => {
|
||||
results.push({ name, ok, detail });
|
||||
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? ` — ${detail}` : ''}`);
|
||||
};
|
||||
|
||||
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p5-'));
|
||||
const repo = join(tmp, 'demo-repo');
|
||||
execFileSync('mkdir', ['-p', repo]);
|
||||
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
|
||||
git('init', '-b', 'main');
|
||||
git('config', 'user.email', 'test@arboretum.dev');
|
||||
git('config', 'user.name', 'Test');
|
||||
execFileSync('bash', ['-lc', 'echo "# demo" > README.md'], { cwd: repo });
|
||||
git('add', '-A');
|
||||
git('commit', '-m', 'init');
|
||||
|
||||
const srv = spawn(
|
||||
'node',
|
||||
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
|
||||
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
|
||||
);
|
||||
let srvOut = '';
|
||||
srv.stdout.on('data', (d) => (srvOut += d));
|
||||
srv.stderr.on('data', (d) => (srvOut += d));
|
||||
|
||||
function wsClient(cookie) {
|
||||
const ws = new WebSocket(`ws://127.0.0.1:${PORT}/ws`, { headers: { Origin: ORIGIN, Cookie: cookie } });
|
||||
const state = { msgs: [] };
|
||||
ws.on('message', (data, isBinary) => {
|
||||
if (!isBinary) state.msgs.push(JSON.parse(String(data)));
|
||||
});
|
||||
const waitMsg = async (pred, timeout = 8000) => {
|
||||
const t0 = Date.now();
|
||||
while (Date.now() - t0 < timeout) {
|
||||
const m = state.msgs.find(pred);
|
||||
if (m) return m;
|
||||
await sleep(50);
|
||||
}
|
||||
return null;
|
||||
};
|
||||
return { ws, state, waitMsg, send: (m) => ws.send(JSON.stringify(m)) };
|
||||
}
|
||||
|
||||
const j = (path, method, cookie, body) =>
|
||||
fetch(`${ORIGIN}${path}`, {
|
||||
method,
|
||||
headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) },
|
||||
...(body ? { body: JSON.stringify(body) } : {}),
|
||||
});
|
||||
|
||||
try {
|
||||
await sleep(1500);
|
||||
const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0];
|
||||
check('boot + token bootstrap', !!token);
|
||||
|
||||
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
|
||||
body: JSON.stringify({ token }),
|
||||
});
|
||||
const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? '';
|
||||
check('login → cookie', login.status === 200);
|
||||
|
||||
const c = wsClient(cookie);
|
||||
await new Promise((res, rej) => (c.ws.on('open', res), c.ws.on('error', rej)));
|
||||
c.send({ type: 'hello', protocol: 1 });
|
||||
await c.waitMsg((m) => m.type === 'hello_ok');
|
||||
c.send({ type: 'sub', topics: ['sessions', 'worktrees', 'groups'] });
|
||||
|
||||
// Enregistrement d'un repo (cible de la membership).
|
||||
const addRepo = await j('/api/v1/repos', 'POST', cookie, { path: repo });
|
||||
const repoSummary = (await addRepo.json()).repo;
|
||||
check('POST /repos → 201', addRepo.status === 201 && repoSummary?.valid === true);
|
||||
|
||||
// Création d'un groupe vide via REST → broadcast WS group_update.
|
||||
const created = await j('/api/v1/groups', 'POST', cookie, { label: 'Sprint 42', color: '#4f46e5' });
|
||||
const group = (await created.json()).group;
|
||||
check('POST /groups → 201', created.status === 201 && group?.label === 'Sprint 42' && group?.repoIds.length === 0);
|
||||
const pushedCreate = await c.waitMsg((m) => m.type === 'group_update' && m.group?.id === group.id);
|
||||
check('broadcast WS group_update (création)', !!pushedCreate);
|
||||
|
||||
const list = await (await j('/api/v1/groups', 'GET', cookie)).json();
|
||||
check('GET /groups → groupe présent', list.groups?.some((g) => g.id === group.id));
|
||||
|
||||
// Ajout du repo au groupe → group_update avec repoIds peuplé.
|
||||
const added = await j(`/api/v1/groups/${group.id}/repos`, 'POST', cookie, { repoId: repoSummary.id });
|
||||
const addedBody = await added.json();
|
||||
check('POST /groups/:id/repos → repoIds', added.status === 200 && addedBody.group?.repoIds.includes(repoSummary.id));
|
||||
const pushedAdd = await c.waitMsg((m) => m.type === 'group_update' && m.group?.repoIds?.includes(repoSummary.id));
|
||||
check('broadcast WS group_update (ajout repo)', !!pushedAdd);
|
||||
|
||||
// Renommage via PATCH.
|
||||
const patched = await j(`/api/v1/groups/${group.id}`, 'PATCH', cookie, { label: 'Renamed' });
|
||||
check('PATCH /groups/:id → 200 (renommé)', patched.status === 200 && (await patched.json()).group?.label === 'Renamed');
|
||||
|
||||
// repoId inexistant → 404.
|
||||
const bad = await j(`/api/v1/groups/${group.id}/repos`, 'POST', cookie, { repoId: 'does-not-exist' });
|
||||
check('POST repo inexistant → 404', bad.status === 404);
|
||||
|
||||
// Suppression du repo → CASCADE purge la membership.
|
||||
const delRepo = await j(`/api/v1/repos/${repoSummary.id}`, 'DELETE', cookie);
|
||||
check('DELETE /repos/:id → 200', delRepo.status === 200);
|
||||
await sleep(200);
|
||||
const afterCascade = await (await j(`/api/v1/groups/${group.id}`, 'GET', cookie)).json();
|
||||
check('CASCADE : membership purgée à la suppression du repo', afterCascade.group?.repoIds.length === 0);
|
||||
|
||||
// Suppression du groupe → broadcast WS group_removed.
|
||||
const delGroup = await j(`/api/v1/groups/${group.id}`, 'DELETE', cookie);
|
||||
check('DELETE /groups/:id → 200', delGroup.status === 200);
|
||||
const removed = await c.waitMsg((m) => m.type === 'group_removed' && m.groupId === group.id);
|
||||
check('broadcast WS group_removed', !!removed);
|
||||
const delAgain = await j(`/api/v1/groups/${group.id}`, 'DELETE', cookie);
|
||||
check('DELETE groupe inconnu → 404', delAgain.status === 404);
|
||||
|
||||
c.ws.close();
|
||||
} catch (err) {
|
||||
check('exception', false, String(err));
|
||||
} finally {
|
||||
srv.kill('SIGTERM');
|
||||
await sleep(1500);
|
||||
check('arrêt propre du daemon (SIGTERM)', srv.exitCode === 0 || srv.signalCode === null || srv.exitCode === null);
|
||||
rmSync(tmp, { recursive: true, force: true });
|
||||
const failed = results.filter((r) => !r.ok);
|
||||
console.log(failed.length === 0 ? '\nACCEPTANCE P5: ALL GREEN' : `\nACCEPTANCE P5: ${failed.length} FAILURE(S)`);
|
||||
process.exit(failed.length === 0 ? 0 : 1);
|
||||
}
|
||||
71
packages/server/scripts/inline-shared.mjs
Normal file
71
packages/server/scripts/inline-shared.mjs
Normal file
@@ -0,0 +1,71 @@
|
||||
#!/usr/bin/env node
|
||||
// Inline @arboretum/shared (paquet workspace NON publié) directement dans le dist du serveur,
|
||||
// pour que le tarball npm soit 100 % autonome. Branché sur le hook "prepack".
|
||||
//
|
||||
// Pourquoi PAS bundleDependencies : embarquer une dépendance qui est aussi un *workspace* via
|
||||
// bundleDependencies est instable selon l'environnement npm (mode -w, exécution en root sur un
|
||||
// runner CI, version d'arborist) — npm voit le nœud comme un lien workspace et n'embarque parfois
|
||||
// AUCUN fichier ("bundled files: 0"), produisant un paquet cassé chez le consommateur. On élimine
|
||||
// donc toute magie de bundling : on copie le JS compilé de shared dans dist/_shared et on réécrit
|
||||
// l'import bare '@arboretum/shared' du serveur vers ce chemin relatif. Zéro node_modules embarqué,
|
||||
// zéro symlink, résultat identique partout.
|
||||
import { cpSync, existsSync, mkdirSync, readdirSync, readFileSync, rmSync, writeFileSync } from 'node:fs';
|
||||
import { join, dirname, relative, sep } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
|
||||
const serverDist = join(serverDir, 'dist');
|
||||
const sharedDist = join(serverDir, '..', 'shared', 'dist');
|
||||
const inlineDir = join(serverDist, '_shared');
|
||||
|
||||
for (const [label, p] of [['dist serveur', serverDist], ['dist shared', sharedDist]]) {
|
||||
if (!existsSync(p)) {
|
||||
console.error(`inline-shared: ${label} introuvable (${p}) — lance "npm run build" avant le pack.`);
|
||||
process.exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
// 1) Copier le JS compilé de shared dans dist/_shared (uniquement *.js : seul le runtime compte ;
|
||||
// les .d.ts/.map ne sont de toute façon pas publiés via le glob `files`). index.js réexporte
|
||||
// ./protocol.js et ./api.js en relatif → la copie complète préserve la résolution interne.
|
||||
rmSync(inlineDir, { recursive: true, force: true });
|
||||
mkdirSync(inlineDir, { recursive: true });
|
||||
let copied = 0;
|
||||
for (const name of readdirSync(sharedDist)) {
|
||||
if (name.endsWith('.js')) {
|
||||
cpSync(join(sharedDist, name), join(inlineDir, name));
|
||||
copied++;
|
||||
}
|
||||
}
|
||||
if (copied === 0) {
|
||||
console.error(`inline-shared: aucun .js dans ${sharedDist} — shared n'est pas compilé.`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
// 2) Réécrire l'import bare '@arboretum/shared' de chaque .js du serveur vers le chemin relatif
|
||||
// (POSIX) pointant sur dist/_shared/index.js, calculé par fichier (profondeur variable).
|
||||
const walk = (dir) =>
|
||||
readdirSync(dir, { withFileTypes: true }).flatMap((e) => {
|
||||
const p = join(dir, e.name);
|
||||
if (e.isDirectory()) return p === inlineDir ? [] : walk(p); // ne pas se réécrire soi-même
|
||||
return e.name.endsWith('.js') ? [p] : [];
|
||||
});
|
||||
|
||||
let rewritten = 0;
|
||||
for (const file of walk(serverDist)) {
|
||||
const src = readFileSync(file, 'utf8');
|
||||
if (!src.includes('@arboretum/shared')) continue;
|
||||
let rel = relative(dirname(file), join(inlineDir, 'index.js')).split(sep).join('/');
|
||||
if (!rel.startsWith('.')) rel = `./${rel}`;
|
||||
const out = src.replaceAll(`'@arboretum/shared'`, `'${rel}'`).replaceAll(`"@arboretum/shared"`, `"${rel}"`);
|
||||
if (out !== src) {
|
||||
writeFileSync(file, out);
|
||||
rewritten++;
|
||||
}
|
||||
}
|
||||
if (rewritten === 0) {
|
||||
console.error(`inline-shared: aucun import '@arboretum/shared' réécrit dans ${serverDist} — build manquant ?`);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
console.log(`inline-shared: ${copied} fichier(s) shared -> dist/_shared, import réécrit dans ${rewritten} fichier(s) serveur`);
|
||||
@@ -1,43 +0,0 @@
|
||||
#!/usr/bin/env node
|
||||
// Embarque @arboretum/shared (dépendance runtime non publiée) DANS le tarball npm.
|
||||
// Branché sur le hook "prepack", aux côtés de bundleDependencies dans package.json.
|
||||
//
|
||||
// Pourquoi un vrai dossier et pas le symlink workspace : sous npm workspaces, shared
|
||||
// est seulement symlinké dans le node_modules racine ; `npm pack` n'embarque une
|
||||
// bundleDependency que si elle existe comme VRAI dossier dans le node_modules du
|
||||
// paquet packé (packages/server/node_modules/@arboretum/shared). On le matérialise ici.
|
||||
import { cpSync, existsSync, mkdirSync, readFileSync, rmSync, writeFileSync } from 'node:fs';
|
||||
import { join, dirname } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
|
||||
const sharedDir = join(serverDir, '..', 'shared');
|
||||
const sharedDist = join(sharedDir, 'dist');
|
||||
const target = join(serverDir, 'node_modules', '@arboretum', 'shared');
|
||||
|
||||
if (!existsSync(sharedDist)) {
|
||||
console.error(
|
||||
`vendor-shared: ${sharedDist} introuvable — lance "npm run build" (shared doit être compilé) avant le pack.`,
|
||||
);
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
// package.json minimal et déterministe : on reprend les champs de résolution réels de
|
||||
// shared (version incluse, pour rester synchro), sans scripts ni files inutiles au runtime.
|
||||
const shared = JSON.parse(readFileSync(join(sharedDir, 'package.json'), 'utf8'));
|
||||
const minimal = {
|
||||
name: shared.name,
|
||||
version: shared.version,
|
||||
type: shared.type,
|
||||
main: shared.main,
|
||||
types: shared.types,
|
||||
exports: shared.exports,
|
||||
};
|
||||
|
||||
// Idempotent : on repart d'un dossier propre à chaque pack.
|
||||
rmSync(target, { recursive: true, force: true });
|
||||
mkdirSync(target, { recursive: true });
|
||||
writeFileSync(join(target, 'package.json'), JSON.stringify(minimal, null, 2) + '\n');
|
||||
cpSync(sharedDist, join(target, 'dist'), { recursive: true });
|
||||
|
||||
console.log(`vendor-shared: embarqué ${shared.name}@${shared.version} -> ${target}`);
|
||||
@@ -1,4 +1,4 @@
|
||||
import Fastify, { type FastifyInstance, type FastifyRequest } from 'fastify';
|
||||
import Fastify, { type FastifyError, type FastifyInstance, type FastifyRequest } from 'fastify';
|
||||
import fastifyCookie from '@fastify/cookie';
|
||||
import fastifyWebsocket from '@fastify/websocket';
|
||||
import fastifyStatic from '@fastify/static';
|
||||
@@ -11,14 +11,49 @@ import { AuthService, LoginRateLimiter, type AuthContext } from './auth/service.
|
||||
import { PtyManager } from './core/pty-manager.js';
|
||||
import { DiscoveryService } from './core/discovery-service.js';
|
||||
import { WorktreeManager } from './core/worktree-manager.js';
|
||||
import { RepoDiscoveryService } from './core/repo-discovery.js';
|
||||
import { GroupManager } from './core/group-manager.js';
|
||||
import { PushService } from './core/push-service.js';
|
||||
import { loadSecretBox } from './core/secret-box.js';
|
||||
import { registerAuthRoutes } from './routes/auth.js';
|
||||
import { registerSessionRoutes } from './routes/sessions.js';
|
||||
import { registerRepoRoutes } from './routes/repos.js';
|
||||
import { registerGroupRoutes } from './routes/groups.js';
|
||||
import { registerWorktreeRoutes } from './routes/worktrees.js';
|
||||
import { registerPushRoutes } from './routes/push.js';
|
||||
import { registerSettingsRoutes } from './routes/settings.js';
|
||||
import { registerFsRoutes } from './routes/fs.js';
|
||||
import { registerAuditRoutes } from './routes/audit.js';
|
||||
import { registerDataRoutes } from './routes/data.js';
|
||||
import { registerWsGateway } from './ws/gateway.js';
|
||||
import { isHttpsRequest } from './routes/auth.js';
|
||||
|
||||
// En-têtes de sécurité posés sur TOUTES les réponses (defense-in-depth + conformité scanners
|
||||
// entreprise). Le terminal web reste du RCE par conception : ces en-têtes durcissent la SPA et
|
||||
// le transport, ils ne remplacent pas le modèle loopback + auth + Origin.
|
||||
const SECURITY_HEADERS: Record<string, string> = {
|
||||
'X-Content-Type-Options': 'nosniff',
|
||||
'X-Frame-Options': 'DENY',
|
||||
'Referrer-Policy': 'no-referrer',
|
||||
'Cross-Origin-Opener-Policy': 'same-origin',
|
||||
'Permissions-Policy': 'geolocation=(), microphone=(), camera=(), payment=()',
|
||||
// CSP calibrée pour la SPA : Tailwind/xterm injectent du style inline ; le WebSocket impose
|
||||
// ws:/wss: en connect-src ; le service worker push impose worker-src 'self'.
|
||||
'Content-Security-Policy': [
|
||||
"default-src 'self'",
|
||||
"script-src 'self'",
|
||||
"style-src 'self' 'unsafe-inline'",
|
||||
"img-src 'self' data:",
|
||||
"font-src 'self' data:",
|
||||
"connect-src 'self' ws: wss:",
|
||||
"worker-src 'self'",
|
||||
"manifest-src 'self'",
|
||||
"frame-ancestors 'none'",
|
||||
"base-uri 'self'",
|
||||
"object-src 'none'",
|
||||
"form-action 'self'",
|
||||
].join('; '),
|
||||
};
|
||||
|
||||
declare module 'fastify' {
|
||||
interface FastifyRequest {
|
||||
@@ -34,15 +69,19 @@ export interface AppBundle {
|
||||
auth: AuthService;
|
||||
manager: PtyManager;
|
||||
discovery: DiscoveryService;
|
||||
repoDiscovery: RepoDiscoveryService;
|
||||
worktrees: WorktreeManager;
|
||||
groups: GroupManager;
|
||||
push: PushService;
|
||||
}
|
||||
|
||||
export function buildApp(config: Config, db: Db, serverVersion: string): AppBundle {
|
||||
const app = Fastify({ logger: { level: process.env.ARBORETUM_LOG ?? 'info' } });
|
||||
const auth = new AuthService(db);
|
||||
// Chiffrement au repos des secrets (server_secret, clé privée VAPID) dans la base.
|
||||
const box = loadSecretBox(config.dataDir);
|
||||
const auth = new AuthService(db, box);
|
||||
const limiter = new LoginRateLimiter();
|
||||
const push = new PushService(db, config.vapidContact);
|
||||
const push = new PushService(db, config.vapidContact, undefined, box);
|
||||
const manager = new PtyManager(db, config.claudeSessionsDir, push);
|
||||
const discovery = new DiscoveryService({
|
||||
ptyManager: manager,
|
||||
@@ -50,6 +89,46 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
|
||||
sessionsDir: config.claudeSessionsDir,
|
||||
});
|
||||
const worktrees = new WorktreeManager(db, manager, discovery);
|
||||
// Démarré dans runDaemon() (jamais ici) → le scan ne tourne pas pendant les tests qui appellent buildApp.
|
||||
const repoDiscovery = new RepoDiscoveryService(db, worktrees);
|
||||
const groups = new GroupManager(db);
|
||||
|
||||
// En-têtes de sécurité sur toute réponse + no-store sur les réponses sensibles (API/WS).
|
||||
// onSend DOIT retourner le payload (sinon Fastify vide la réponse).
|
||||
app.addHook('onSend', async (req, reply, payload) => {
|
||||
reply.removeHeader('Server'); // anti-fingerprinting (no-op si absent)
|
||||
for (const [k, v] of Object.entries(SECURITY_HEADERS)) reply.header(k, v);
|
||||
if (isHttpsRequest(req)) {
|
||||
reply.header('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
|
||||
}
|
||||
if (req.url.startsWith('/api/') || req.url.startsWith('/ws')) {
|
||||
reply.header('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0');
|
||||
}
|
||||
return payload;
|
||||
});
|
||||
|
||||
// Garde CSRF defense-in-depth : une mutation porteuse d'un corps DOIT être en application/json
|
||||
// (bloque les soumissions de formulaire cross-site en text/plain, que Fastify parserait sinon).
|
||||
app.addHook('preHandler', async (req, reply) => {
|
||||
if (!['POST', 'PATCH', 'PUT', 'DELETE'].includes(req.method)) return;
|
||||
const len = req.headers['content-length'];
|
||||
if (!len || len === '0') return; // pas de corps : rien à valider
|
||||
const ct = (req.headers['content-type'] ?? '').toLowerCase();
|
||||
if (!ct.startsWith('application/json')) {
|
||||
return reply.status(415).send({ error: { code: 'UNSUPPORTED_MEDIA_TYPE', message: 'Content-Type must be application/json' } });
|
||||
}
|
||||
});
|
||||
|
||||
// Handler d'erreur : ne jamais fuiter de stack/chemin au client ; détail complet côté logs.
|
||||
app.setErrorHandler((err: FastifyError, req, reply) => {
|
||||
const status = err.statusCode && err.statusCode >= 400 && err.statusCode < 600 ? err.statusCode : 500;
|
||||
if (status >= 500) {
|
||||
req.log.error({ err }, 'unhandled error');
|
||||
return reply.status(status).send({ error: { code: 'INTERNAL', message: 'Internal Server Error' } });
|
||||
}
|
||||
// erreurs client (4xx) : code générique, message court non sensible.
|
||||
return reply.status(status).send({ error: { code: err.code ?? 'BAD_REQUEST', message: err.message } });
|
||||
});
|
||||
|
||||
void app.register(fastifyCookie);
|
||||
void app.register(fastifyWebsocket, {
|
||||
@@ -88,16 +167,20 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
|
||||
}
|
||||
});
|
||||
|
||||
registerAuthRoutes(app, auth, limiter, serverVersion);
|
||||
registerAuthRoutes(app, auth, limiter, serverVersion, db);
|
||||
registerSessionRoutes(app, manager, discovery);
|
||||
registerRepoRoutes(app, worktrees);
|
||||
registerRepoRoutes(app, worktrees, db);
|
||||
registerGroupRoutes(app, groups, db);
|
||||
registerWorktreeRoutes(app, worktrees);
|
||||
registerPushRoutes(app, push);
|
||||
registerPushRoutes(app, push, db);
|
||||
registerSettingsRoutes(app, db, config, serverVersion, push);
|
||||
registerFsRoutes(app);
|
||||
registerAuditRoutes(app, db);
|
||||
registerDataRoutes(app, db, auth);
|
||||
// La route websocket doit être déclarée APRÈS le chargement du plugin (contexte
|
||||
// encapsulé) — sinon le handler reçoit la signature REST (request, reply).
|
||||
void app.register(async (scoped) => {
|
||||
registerWsGateway(scoped, manager, discovery, worktrees, serverVersion);
|
||||
registerWsGateway(scoped, manager, discovery, worktrees, groups, serverVersion);
|
||||
});
|
||||
|
||||
// SPA buildée embarquée dans le paquet npm (public/) — absente en dev (vite dev sert le front)
|
||||
@@ -112,5 +195,5 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
|
||||
});
|
||||
}
|
||||
|
||||
return { app, auth, manager, discovery, worktrees, push };
|
||||
return { app, auth, manager, discovery, repoDiscovery, worktrees, groups, push };
|
||||
}
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
import { createHash, createHmac, randomBytes, randomUUID, timingSafeEqual } from 'node:crypto';
|
||||
import { type Db, getSetting, setSetting } from '../db/index.js';
|
||||
import type { SecretBox } from '../core/secret-box.js';
|
||||
import { recordAudit } from '../core/audit-log.js';
|
||||
|
||||
const COOKIE_NAME = 'arb_session';
|
||||
const COOKIE_TTL_MS = 30 * 24 * 3600 * 1000;
|
||||
@@ -12,11 +14,21 @@ export interface AuthContext {
|
||||
export class AuthService {
|
||||
private readonly secret: Buffer;
|
||||
|
||||
constructor(private readonly db: Db) {
|
||||
let secretHex = getSetting(db, 'server_secret');
|
||||
if (!secretHex) {
|
||||
constructor(
|
||||
private readonly db: Db,
|
||||
box?: SecretBox,
|
||||
) {
|
||||
// server_secret chiffré au repos quand un SecretBox est fourni (prod). Migration douce :
|
||||
// une valeur en clair pré-existante est re-chiffrée à la lecture.
|
||||
const stored = getSetting(db, 'server_secret');
|
||||
let secretHex: string;
|
||||
if (!stored) {
|
||||
secretHex = randomBytes(32).toString('hex');
|
||||
setSetting(db, 'server_secret', secretHex);
|
||||
setSetting(db, 'server_secret', box ? box.encrypt(secretHex) : secretHex);
|
||||
recordAudit(db, { actor: 'system', action: 'secret.generate', resourceId: 'server_secret' });
|
||||
} else {
|
||||
secretHex = box ? box.decrypt(stored) : stored;
|
||||
if (box && !box.isEncrypted(stored)) setSetting(db, 'server_secret', box.encrypt(secretHex));
|
||||
}
|
||||
this.secret = Buffer.from(secretHex, 'hex');
|
||||
}
|
||||
@@ -35,11 +47,60 @@ export class AuthService {
|
||||
}
|
||||
|
||||
createToken(label: string): string {
|
||||
return this.createTokenRecord(label).token;
|
||||
}
|
||||
|
||||
/** Comme createToken mais renvoie aussi l'id (pour l'API de gestion des tokens). */
|
||||
createTokenRecord(label: string): { id: string; token: string } {
|
||||
const id = randomUUID();
|
||||
const raw = `arb_${randomBytes(24).toString('hex')}`;
|
||||
this.db
|
||||
.prepare('INSERT INTO auth_tokens (id, label, token_hash, created_at) VALUES (?, ?, ?, ?)')
|
||||
.run(randomUUID(), label, sha256(raw), new Date().toISOString());
|
||||
return raw;
|
||||
.run(id, label, sha256(raw), new Date().toISOString());
|
||||
return { id, token: raw };
|
||||
}
|
||||
|
||||
/** Tokens actifs (non révoqués), du plus ancien au plus récent. Ne renvoie JAMAIS le hash. */
|
||||
listTokens(): Array<{ id: string; label: string; createdAt: string; lastUsedAt: string | null }> {
|
||||
return this.db
|
||||
.prepare(
|
||||
'SELECT id, label, created_at AS createdAt, last_used_at AS lastUsedAt FROM auth_tokens WHERE revoked_at IS NULL ORDER BY created_at',
|
||||
)
|
||||
.all() as Array<{ id: string; label: string; createdAt: string; lastUsedAt: string | null }>;
|
||||
}
|
||||
|
||||
/** Nombre de tokens actifs (non révoqués). */
|
||||
countActiveTokens(): number {
|
||||
return (this.db.prepare('SELECT COUNT(*) AS n FROM auth_tokens WHERE revoked_at IS NULL').get() as { n: number }).n;
|
||||
}
|
||||
|
||||
/**
|
||||
* Révoque un token. Refuse de révoquer le DERNIER token actif (sinon lock-out total) → 'last'.
|
||||
* 'ok' = révoqué ; 'not_found' = id inconnu ou déjà révoqué.
|
||||
*/
|
||||
revokeToken(id: string): 'ok' | 'last' | 'not_found' {
|
||||
// Transaction : le check « dernier token » et l'UPDATE doivent être atomiques (garde
|
||||
// anti lock-out robuste, même si un refactor futur introduisait de la concurrence).
|
||||
this.db.exec('BEGIN IMMEDIATE');
|
||||
try {
|
||||
const row = this.db.prepare('SELECT id FROM auth_tokens WHERE id = ? AND revoked_at IS NULL').get(id) as
|
||||
| { id: string }
|
||||
| undefined;
|
||||
let result: 'ok' | 'last' | 'not_found';
|
||||
if (!row) {
|
||||
result = 'not_found';
|
||||
} else if (this.countActiveTokens() <= 1) {
|
||||
result = 'last';
|
||||
} else {
|
||||
this.db.prepare('UPDATE auth_tokens SET revoked_at = ? WHERE id = ?').run(new Date().toISOString(), id);
|
||||
result = 'ok';
|
||||
}
|
||||
this.db.exec('COMMIT');
|
||||
return result;
|
||||
} catch (err) {
|
||||
this.db.exec('ROLLBACK');
|
||||
throw err;
|
||||
}
|
||||
}
|
||||
|
||||
verifyRawToken(raw: string): AuthContext | null {
|
||||
|
||||
363
packages/server/src/cli/install.ts
Normal file
363
packages/server/src/cli/install.ts
Normal file
@@ -0,0 +1,363 @@
|
||||
import { parseArgs } from 'node:util';
|
||||
import { spawnSync } from 'node:child_process';
|
||||
import { mkdirSync, writeFileSync, rmSync, existsSync } from 'node:fs';
|
||||
import { homedir } from 'node:os';
|
||||
import { join, dirname } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { loadConfig } from '../config.js';
|
||||
import { openDb } from '../db/index.js';
|
||||
import { AuthService } from '../auth/service.js';
|
||||
|
||||
// Nom de l'unit systemd (Linux) et label launchd par défaut (macOS, surchargeable via --label).
|
||||
const SERVICE_NAME = 'arboretum';
|
||||
const LAUNCHD_LABEL = 'fr.lidge.arboretum';
|
||||
|
||||
export type SupportedPlatform = 'linux' | 'darwin';
|
||||
|
||||
export interface InstallFlags {
|
||||
port?: string | undefined;
|
||||
bind?: string | undefined;
|
||||
allowOrigin: string[];
|
||||
db?: string | undefined;
|
||||
vapidContact?: string | undefined;
|
||||
claudeHome?: string | undefined;
|
||||
binPath?: string | undefined;
|
||||
label: string;
|
||||
dryRun: boolean;
|
||||
noEnable: boolean;
|
||||
}
|
||||
|
||||
// ─── Fonctions pures (génération de contenu / chemins) ────────────────────────────────
|
||||
|
||||
/** macOS (launchd) et Linux (systemd) uniquement ; sinon throw avec un message pédagogique. */
|
||||
export function detectPlatform(platform: NodeJS.Platform = process.platform): SupportedPlatform {
|
||||
if (platform === 'linux' || platform === 'darwin') return platform;
|
||||
throw new Error(
|
||||
`Automatic service installation is supported on Linux (systemd) and macOS (launchd) only.\n` +
|
||||
`On ${platform}, run \`arboretum\` manually or set up your own supervisor.`,
|
||||
);
|
||||
}
|
||||
|
||||
export function parseInstallArgs(argv: string[]): InstallFlags {
|
||||
const { values } = parseArgs({
|
||||
args: argv,
|
||||
options: {
|
||||
port: { type: 'string' },
|
||||
bind: { type: 'string' },
|
||||
'allow-origin': { type: 'string', multiple: true },
|
||||
db: { type: 'string' },
|
||||
'vapid-contact': { type: 'string' },
|
||||
'claude-home': { type: 'string' },
|
||||
'bin-path': { type: 'string' },
|
||||
label: { type: 'string' },
|
||||
'dry-run': { type: 'boolean', default: false },
|
||||
'no-enable': { type: 'boolean', default: false },
|
||||
},
|
||||
strict: true,
|
||||
});
|
||||
return {
|
||||
port: values.port,
|
||||
bind: values.bind,
|
||||
allowOrigin: values['allow-origin'] ?? [],
|
||||
db: values.db,
|
||||
vapidContact: values['vapid-contact'],
|
||||
claudeHome: values['claude-home'],
|
||||
binPath: values['bin-path'],
|
||||
label: values.label ?? LAUNCHD_LABEL,
|
||||
dryRun: values['dry-run'] ?? false,
|
||||
noEnable: values['no-enable'] ?? false,
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Flags propagés au service : UNIQUEMENT ceux fournis par l'utilisateur (ordre stable,
|
||||
* ExecStart déterministe). On n'ajoute JAMAIS --i-know-this-exposes-a-terminal automatiquement
|
||||
* (cf. modèle de sécurité : un service exposé doit être un choix conscient et explicite).
|
||||
*/
|
||||
export function buildServiceArgs(flags: InstallFlags): string[] {
|
||||
const args: string[] = [];
|
||||
if (flags.port) args.push('--port', flags.port);
|
||||
if (flags.bind) args.push('--bind', flags.bind);
|
||||
for (const origin of flags.allowOrigin) args.push('--allow-origin', origin);
|
||||
if (flags.db) args.push('--db', flags.db);
|
||||
if (flags.vapidContact) args.push('--vapid-contact', flags.vapidContact);
|
||||
if (flags.claudeHome) args.push('--claude-home', flags.claudeHome);
|
||||
return args;
|
||||
}
|
||||
|
||||
/** Le `dist/index.js` réellement installé (depuis dist/cli/install.js). */
|
||||
export function resolveScriptPath(): string {
|
||||
return fileURLToPath(new URL('../index.js', import.meta.url));
|
||||
}
|
||||
|
||||
/**
|
||||
* Cible exécutable du service. Par défaut node + script (immunisé contre un PATH minimal sous
|
||||
* systemd/launchd) ; --bin-path force le wrapper `arboretum` global (suit les upgrades npm i -g).
|
||||
*/
|
||||
export function resolveBin(flags: Pick<InstallFlags, 'binPath'>): { exec: string; args: string[] } {
|
||||
if (flags.binPath) return { exec: flags.binPath, args: [] };
|
||||
return { exec: process.execPath, args: [resolveScriptPath()] };
|
||||
}
|
||||
|
||||
export function systemdUnitPath(): string {
|
||||
const configHome = process.env.XDG_CONFIG_HOME ?? join(homedir(), '.config');
|
||||
return join(configHome, 'systemd', 'user', `${SERVICE_NAME}.service`);
|
||||
}
|
||||
|
||||
export function launchAgentPlistPath(label: string): string {
|
||||
return join(homedir(), 'Library', 'LaunchAgents', `${label}.plist`);
|
||||
}
|
||||
|
||||
export function launchdLogPaths(): { dir: string; out: string; err: string } {
|
||||
const dir = join(homedir(), 'Library', 'Logs', 'arboretum');
|
||||
return { dir, out: join(dir, 'out.log'), err: join(dir, 'err.log') };
|
||||
}
|
||||
|
||||
export function xmlEscape(s: string): string {
|
||||
return s.replace(/&/g, '&').replace(/</g, '<').replace(/>/g, '>');
|
||||
}
|
||||
|
||||
// systemd accepte les doubles quotes dans ExecStart ; on ne quote que les tokens à espaces.
|
||||
function quoteIfNeeded(token: string): string {
|
||||
return /\s/.test(token) ? `"${token}"` : token;
|
||||
}
|
||||
|
||||
export function renderSystemdUnit(input: { exec: string; scriptArgs: string[] }): string {
|
||||
const execStart = [input.exec, ...input.scriptArgs].map(quoteIfNeeded).join(' ');
|
||||
// KillSignal=SIGTERM + TimeoutStopSec=10 collent au drain de runDaemon (SIGTERM → drain 1s → close).
|
||||
return `[Unit]
|
||||
Description=Arboretum — git worktree & Claude Code dashboard
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
ExecStart=${execStart}
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
KillSignal=SIGTERM
|
||||
TimeoutStopSec=10
|
||||
Environment=NODE_ENV=production
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
`;
|
||||
}
|
||||
|
||||
export function renderLaunchAgentPlist(input: {
|
||||
label: string;
|
||||
programArguments: string[];
|
||||
stdoutPath: string;
|
||||
stderrPath: string;
|
||||
}): string {
|
||||
const args = input.programArguments.map((a) => ` <string>${xmlEscape(a)}</string>`).join('\n');
|
||||
// KeepAlive/SuccessfulExit=false ≈ Restart=on-failure (ne relance pas après un drain volontaire).
|
||||
return `<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>Label</key>
|
||||
<string>${xmlEscape(input.label)}</string>
|
||||
<key>ProgramArguments</key>
|
||||
<array>
|
||||
${args}
|
||||
</array>
|
||||
<key>RunAtLoad</key>
|
||||
<true/>
|
||||
<key>KeepAlive</key>
|
||||
<dict>
|
||||
<key>SuccessfulExit</key>
|
||||
<false/>
|
||||
</dict>
|
||||
<key>StandardOutPath</key>
|
||||
<string>${xmlEscape(input.stdoutPath)}</string>
|
||||
<key>StandardErrorPath</key>
|
||||
<string>${xmlEscape(input.stderrPath)}</string>
|
||||
<key>EnvironmentVariables</key>
|
||||
<dict>
|
||||
<key>NODE_ENV</key>
|
||||
<string>production</string>
|
||||
</dict>
|
||||
</dict>
|
||||
</plist>
|
||||
`;
|
||||
}
|
||||
|
||||
export function printTokenBanner(token: string, url: string): void {
|
||||
console.log('\n┌──────────────────────────────────────────────────────────────────┐');
|
||||
console.log('│ First start — your access token (shown once, store it safely): │');
|
||||
console.log('└──────────────────────────────────────────────────────────────────┘');
|
||||
console.log(`\n ${token}\n`);
|
||||
console.log(` Login at: ${url}/\n`);
|
||||
}
|
||||
|
||||
export function printUsage(version: string): void {
|
||||
console.log(`Arboretum v${version} — git worktree & Claude Code dashboard
|
||||
|
||||
Usage:
|
||||
arboretum [flags] Start the daemon (default)
|
||||
arboretum serve [flags] Start the daemon (explicit alias)
|
||||
arboretum install [flags] Install & start a user service (systemd on Linux, launchd on macOS)
|
||||
arboretum uninstall Stop & remove the user service
|
||||
arboretum status Show the service status
|
||||
arboretum help Show this help
|
||||
|
||||
Daemon flags:
|
||||
--port <n> Port to listen on (default 7317)
|
||||
--bind <addr> Bind address (default 127.0.0.1)
|
||||
--allow-origin <url> Additional allowed Origin (repeatable)
|
||||
--db <path> SQLite database path
|
||||
--vapid-contact <mailto|url> VAPID contact subject for Web Push
|
||||
--i-know-this-exposes-a-terminal Acknowledge a non-loopback bind (avoid — prefer Tailscale Serve)
|
||||
|
||||
Install flags (daemon flags above are propagated to the service):
|
||||
--bin-path <path> Use this binary in the service instead of node + script
|
||||
--label <id> launchd label (macOS only, default ${LAUNCHD_LABEL})
|
||||
--dry-run Print the unit/plist and commands without applying anything
|
||||
--no-enable Write the service file but do not enable/start it
|
||||
`);
|
||||
}
|
||||
|
||||
// ─── Effets de bord (fs + exec) ───────────────────────────────────────────────────────
|
||||
|
||||
function run(cmd: string, args: string[], opts?: { check?: boolean }): number {
|
||||
const res = spawnSync(cmd, args, { stdio: 'inherit' });
|
||||
if (res.error) {
|
||||
if ((res.error as NodeJS.ErrnoException).code === 'ENOENT') {
|
||||
throw new Error(`Command not found: ${cmd}. Is it installed and on your PATH?`);
|
||||
}
|
||||
throw res.error;
|
||||
}
|
||||
const code = res.status ?? 0;
|
||||
if (opts?.check && code !== 0) {
|
||||
throw new Error(`Command failed (exit ${code}): ${cmd} ${args.join(' ')}`);
|
||||
}
|
||||
return code;
|
||||
}
|
||||
|
||||
/**
|
||||
* Bootstrap du token avec EXACTEMENT les flags du service (même db). Valide aussi le bind
|
||||
* (garde-fou de loadConfig). Affiche le token une fois, puis ferme la db avant que le service
|
||||
* ne l'ouvre. Skippé en --dry-run par l'appelant.
|
||||
*/
|
||||
function bootstrapToken(serviceArgs: string[]): void {
|
||||
const config = loadConfig(serviceArgs);
|
||||
const url = `http://${config.bind === '0.0.0.0' ? '127.0.0.1' : config.bind}:${config.port}`;
|
||||
const db = openDb(config.dbPath);
|
||||
try {
|
||||
const token = new AuthService(db).ensureBootstrapToken();
|
||||
if (token) printTokenBanner(token, url);
|
||||
else console.log('\nAn access token already exists in this database — manage tokens from Settings.\n');
|
||||
} finally {
|
||||
db.close();
|
||||
}
|
||||
}
|
||||
|
||||
export async function runInstall(argv: string[]): Promise<void> {
|
||||
const platform = detectPlatform();
|
||||
const flags = parseInstallArgs(argv);
|
||||
const serviceArgs = buildServiceArgs(flags);
|
||||
const { exec, args: binArgs } = resolveBin(flags);
|
||||
const scriptArgs = [...binArgs, ...serviceArgs];
|
||||
|
||||
if (platform === 'linux') {
|
||||
const unit = renderSystemdUnit({ exec, scriptArgs });
|
||||
const unitPath = systemdUnitPath();
|
||||
if (flags.dryRun) {
|
||||
console.log(`# ${unitPath}\n${unit}\n# commands:`);
|
||||
console.log('systemctl --user daemon-reload');
|
||||
if (!flags.noEnable) {
|
||||
console.log(`systemctl --user enable --now ${SERVICE_NAME}`);
|
||||
console.log(`loginctl enable-linger ${process.env.USER ?? '$USER'}`);
|
||||
}
|
||||
return;
|
||||
}
|
||||
bootstrapToken(serviceArgs);
|
||||
mkdirSync(dirname(unitPath), { recursive: true });
|
||||
writeFileSync(unitPath, unit);
|
||||
console.log(`Wrote ${unitPath}`);
|
||||
run('systemctl', ['--user', 'daemon-reload'], { check: true });
|
||||
if (!flags.noEnable) {
|
||||
run('systemctl', ['--user', 'enable', '--now', SERVICE_NAME], { check: true });
|
||||
// enable-linger best-effort : absent en CI / sans session loginctl, non bloquant.
|
||||
if (run('loginctl', ['enable-linger', process.env.USER ?? '']) !== 0) {
|
||||
console.warn('Warning: could not enable linger — the service may not start at boot.');
|
||||
}
|
||||
}
|
||||
console.log(`\nArboretum service installed. Logs: journalctl --user -u ${SERVICE_NAME} -f`);
|
||||
return;
|
||||
}
|
||||
|
||||
// macOS (launchd)
|
||||
const logs = launchdLogPaths();
|
||||
const programArguments = [exec, ...scriptArgs];
|
||||
const plist = renderLaunchAgentPlist({
|
||||
label: flags.label,
|
||||
programArguments,
|
||||
stdoutPath: logs.out,
|
||||
stderrPath: logs.err,
|
||||
});
|
||||
const plistPath = launchAgentPlistPath(flags.label);
|
||||
const uid = process.getuid?.() ?? 0;
|
||||
const target = `gui/${uid}/${flags.label}`;
|
||||
if (flags.dryRun) {
|
||||
console.log(`# ${plistPath}\n${plist}\n# commands:`);
|
||||
console.log(`launchctl bootout ${target} # best-effort`);
|
||||
if (!flags.noEnable) {
|
||||
console.log(`launchctl bootstrap gui/${uid} ${plistPath}`);
|
||||
console.log(`launchctl enable ${target}`);
|
||||
console.log(`launchctl kickstart -k ${target}`);
|
||||
}
|
||||
return;
|
||||
}
|
||||
bootstrapToken(serviceArgs);
|
||||
mkdirSync(dirname(plistPath), { recursive: true });
|
||||
mkdirSync(logs.dir, { recursive: true });
|
||||
writeFileSync(plistPath, plist);
|
||||
console.log(`Wrote ${plistPath}`);
|
||||
if (!flags.noEnable) {
|
||||
run('launchctl', ['bootout', target]); // best-effort : ignore "not loaded" (rend bootstrap idempotent)
|
||||
run('launchctl', ['bootstrap', `gui/${uid}`, plistPath], { check: true });
|
||||
run('launchctl', ['enable', target]);
|
||||
run('launchctl', ['kickstart', '-k', target]);
|
||||
}
|
||||
console.log(`\nArboretum service installed. Logs: ${logs.out}`);
|
||||
}
|
||||
|
||||
export async function runUninstall(argv: string[]): Promise<void> {
|
||||
const platform = detectPlatform();
|
||||
const flags = parseInstallArgs(argv);
|
||||
if (platform === 'linux') {
|
||||
const unitPath = systemdUnitPath();
|
||||
run('systemctl', ['--user', 'disable', '--now', SERVICE_NAME]); // best-effort
|
||||
if (existsSync(unitPath)) {
|
||||
rmSync(unitPath);
|
||||
console.log(`Removed ${unitPath}`);
|
||||
}
|
||||
run('systemctl', ['--user', 'daemon-reload']);
|
||||
console.log('Arboretum service removed.');
|
||||
return;
|
||||
}
|
||||
const plistPath = launchAgentPlistPath(flags.label);
|
||||
const uid = process.getuid?.() ?? 0;
|
||||
run('launchctl', ['bootout', `gui/${uid}/${flags.label}`]); // best-effort
|
||||
if (existsSync(plistPath)) {
|
||||
rmSync(plistPath);
|
||||
console.log(`Removed ${plistPath}`);
|
||||
}
|
||||
console.log('Arboretum service removed.');
|
||||
}
|
||||
|
||||
export async function runStatus(argv: string[]): Promise<void> {
|
||||
const platform = detectPlatform();
|
||||
const flags = parseInstallArgs(argv);
|
||||
if (platform === 'linux') {
|
||||
const code = run('systemctl', ['--user', 'status', SERVICE_NAME, '--no-pager']);
|
||||
console.log(`\nLogs: journalctl --user -u ${SERVICE_NAME} -f`);
|
||||
process.exitCode = code;
|
||||
return;
|
||||
}
|
||||
const uid = process.getuid?.() ?? 0;
|
||||
const code = run('launchctl', ['print', `gui/${uid}/${flags.label}`]);
|
||||
console.log(`\nLogs: ${launchdLogPaths().out}`);
|
||||
process.exitCode = code;
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
import { parseArgs } from 'node:util';
|
||||
import { join } from 'node:path';
|
||||
import { homedir } from 'node:os';
|
||||
import { mkdirSync } from 'node:fs';
|
||||
import { chmodSync, mkdirSync } from 'node:fs';
|
||||
|
||||
export interface Config {
|
||||
port: number;
|
||||
@@ -17,6 +17,8 @@ export interface Config {
|
||||
claudeSessionsDir: string;
|
||||
/** sujet VAPID des notifications Web Push (mailto: ou URL). */
|
||||
vapidContact: string;
|
||||
/** découverte auto des repos au démarrage + périodique (désactivable via --no-discover). */
|
||||
autoDiscover: boolean;
|
||||
}
|
||||
|
||||
export function loadConfig(argv = process.argv.slice(2)): Config {
|
||||
@@ -33,6 +35,8 @@ export function loadConfig(argv = process.argv.slice(2)): Config {
|
||||
'claude-home': { type: 'string' },
|
||||
// sujet VAPID des notifications push (contact requis par la spec Web Push).
|
||||
'vapid-contact': { type: 'string' },
|
||||
// désactive la découverte auto des repos (boot + périodique) — utilisé par les tests d'acceptation.
|
||||
'no-discover': { type: 'boolean', default: false },
|
||||
},
|
||||
strict: true,
|
||||
});
|
||||
@@ -49,6 +53,14 @@ export function loadConfig(argv = process.argv.slice(2)): Config {
|
||||
|
||||
const dataDir = join(process.env.XDG_DATA_HOME ?? join(homedir(), '.local', 'share'), 'arboretum');
|
||||
mkdirSync(dataDir, { recursive: true });
|
||||
// La DB contient des secrets (server_secret, clé privée VAPID, hashs de tokens) : le dossier de
|
||||
// données ne doit jamais être lisible par d'autres utilisateurs du système. chmod best-effort
|
||||
// (peut échouer sur certains FS Windows/montés ; le démarrage avertit alors sans bloquer).
|
||||
try {
|
||||
chmodSync(dataDir, 0o700);
|
||||
} catch {
|
||||
/* FS sans permissions POSIX : ignoré, cf. avertissement dans db.openDb */
|
||||
}
|
||||
const claudeHome = values['claude-home'] ?? join(homedir(), '.claude');
|
||||
return {
|
||||
port: Number(values.port),
|
||||
@@ -60,5 +72,6 @@ export function loadConfig(argv = process.argv.slice(2)): Config {
|
||||
claudeProjectsDir: join(claudeHome, 'projects'),
|
||||
claudeSessionsDir: join(claudeHome, 'sessions'),
|
||||
vapidContact: values['vapid-contact'] ?? 'mailto:arboretum@localhost',
|
||||
autoDiscover: !(values['no-discover'] ?? false),
|
||||
};
|
||||
}
|
||||
|
||||
65
packages/server/src/core/audit-log.ts
Normal file
65
packages/server/src/core/audit-log.ts
Normal file
@@ -0,0 +1,65 @@
|
||||
// Journal d'audit : trace persistante des opérations sensibles (création/révocation de tokens,
|
||||
// changements de réglages, génération de secrets, abonnements push, CRUD groupes). Exigence de
|
||||
// conformité entreprise (GDPR/SOX/ISO 27001). Règle ABSOLUE : ne JAMAIS journaliser un secret en
|
||||
// clair — `details` ne contient que des métadonnées non sensibles (ids, labels, compteurs).
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import type { AuditLogEntry } from '@arboretum/shared';
|
||||
import type { Db } from '../db/index.js';
|
||||
|
||||
export type AuditResult = 'ok' | 'denied' | 'error';
|
||||
|
||||
export interface AuditEntry {
|
||||
/** tokenId de l'acteur, ou 'system' (opérations automatiques), ou 'anonymous' (avant auth). */
|
||||
actor: string;
|
||||
/** verbe.objet, ex. 'token.create', 'settings.update', 'login.failure'. */
|
||||
action: string;
|
||||
resourceId?: string | null;
|
||||
details?: Record<string, unknown> | null;
|
||||
result?: AuditResult;
|
||||
}
|
||||
|
||||
/** Enregistre une entrée d'audit. Best-effort : une erreur d'écriture ne casse jamais l'opération métier. */
|
||||
export function recordAudit(db: Db, e: AuditEntry): void {
|
||||
try {
|
||||
db.prepare(
|
||||
'INSERT INTO audit_logs (id, ts, actor, action, resource_id, details, result) VALUES (?, ?, ?, ?, ?, ?, ?)',
|
||||
).run(
|
||||
randomUUID(),
|
||||
new Date().toISOString(),
|
||||
e.actor,
|
||||
e.action,
|
||||
e.resourceId ?? null,
|
||||
e.details ? JSON.stringify(e.details) : null,
|
||||
e.result ?? 'ok',
|
||||
);
|
||||
} catch {
|
||||
/* l'audit ne doit jamais faire échouer l'action auditée */
|
||||
}
|
||||
}
|
||||
|
||||
/** Liste paginée par date décroissante (curseur `before` = ts strictement inférieur). */
|
||||
export function listAudit(db: Db, opts: { limit: number; before?: string | null }): AuditLogEntry[] {
|
||||
const limit = Math.min(Math.max(Math.trunc(opts.limit) || 50, 1), 200);
|
||||
const rows = (
|
||||
opts.before
|
||||
? db
|
||||
.prepare(
|
||||
'SELECT id, ts, actor, action, resource_id AS resourceId, details, result FROM audit_logs WHERE ts < ? ORDER BY ts DESC LIMIT ?',
|
||||
)
|
||||
.all(opts.before, limit)
|
||||
: db
|
||||
.prepare(
|
||||
'SELECT id, ts, actor, action, resource_id AS resourceId, details, result FROM audit_logs ORDER BY ts DESC LIMIT ?',
|
||||
)
|
||||
.all(limit)
|
||||
) as Array<{ id: string; ts: string; actor: string; action: string; resourceId: string | null; details: string | null; result: string }>;
|
||||
return rows.map((r) => ({ ...r, details: r.details ? safeParse(r.details) : null }));
|
||||
}
|
||||
|
||||
function safeParse(s: string): unknown {
|
||||
try {
|
||||
return JSON.parse(s);
|
||||
} catch {
|
||||
return s;
|
||||
}
|
||||
}
|
||||
201
packages/server/src/core/group-manager.ts
Normal file
201
packages/server/src/core/group-manager.ts
Normal file
@@ -0,0 +1,201 @@
|
||||
// Gestion des groupes de travail (P5) : un groupe = collection nommée de repos (many-to-many).
|
||||
// Membership légère et persistée ; les worktrees/sessions du groupe ne sont PAS stockés ici —
|
||||
// ils restent servis par WorktreeManager/PtyManager et filtrés côté client par repoId.
|
||||
// Tout est synchrone : aucune I/O git/fs, node:sqlite est synchrone.
|
||||
import { EventEmitter } from 'node:events';
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import type { GroupSummary } from '@arboretum/shared';
|
||||
import type { Db } from '../db/index.js';
|
||||
|
||||
const LABEL_MAX = 100;
|
||||
const DESCRIPTION_MAX = 2000;
|
||||
const COLOR_RE = /^#[0-9a-fA-F]{6}$/;
|
||||
|
||||
interface GroupRow {
|
||||
id: string;
|
||||
label: string;
|
||||
description: string | null;
|
||||
color: string | null;
|
||||
position: number;
|
||||
created_at: string;
|
||||
updated_at: string;
|
||||
}
|
||||
|
||||
export interface GroupManagerEvents {
|
||||
group_update: [GroupSummary];
|
||||
group_removed: [string];
|
||||
}
|
||||
|
||||
/** Erreur portant un statusCode + code pour mapping HTTP direct par les routes (cf. sendManagerError). */
|
||||
function httpError(statusCode: number, code: string, message: string): Error {
|
||||
return Object.assign(new Error(message), { statusCode, code });
|
||||
}
|
||||
|
||||
/** Valide un label : non vide après trim, borné. */
|
||||
function normLabel(label: unknown): string {
|
||||
if (typeof label !== 'string') throw httpError(400, 'BAD_REQUEST', 'label is required');
|
||||
const v = label.trim();
|
||||
if (v === '') throw httpError(400, 'BAD_REQUEST', 'label must not be empty');
|
||||
if (v.length > LABEL_MAX) throw httpError(400, 'BAD_REQUEST', `label must be at most ${LABEL_MAX} characters`);
|
||||
return v;
|
||||
}
|
||||
|
||||
/** Normalise une description : vide/absente → null, bornée sinon. */
|
||||
function normDescription(description: string | null | undefined): string | null {
|
||||
if (description === null || description === undefined) return null;
|
||||
const v = description.trim();
|
||||
if (v === '') return null;
|
||||
if (v.length > DESCRIPTION_MAX) throw httpError(400, 'BAD_REQUEST', `description must be at most ${DESCRIPTION_MAX} characters`);
|
||||
return v;
|
||||
}
|
||||
|
||||
/** Normalise une couleur : vide/absente → null, doit être un hex `#rrggbb` sinon. */
|
||||
function normColor(color: string | null | undefined): string | null {
|
||||
if (color === null || color === undefined) return null;
|
||||
const v = color.trim();
|
||||
if (v === '') return null;
|
||||
if (!COLOR_RE.test(v)) throw httpError(400, 'BAD_REQUEST', 'color must be a hex string like #4f46e5');
|
||||
return v;
|
||||
}
|
||||
|
||||
export class GroupManager extends EventEmitter<GroupManagerEvents> {
|
||||
constructor(private readonly db: Db) {
|
||||
super();
|
||||
}
|
||||
|
||||
private getGroupRow(id: string): GroupRow | null {
|
||||
return (this.db.prepare('SELECT * FROM groups WHERE id = ?').get(id) as unknown as GroupRow | undefined) ?? null;
|
||||
}
|
||||
|
||||
private repoIdsFor(groupId: string): string[] {
|
||||
const rows = this.db
|
||||
.prepare('SELECT repo_id FROM group_repos WHERE group_id = ? ORDER BY position ASC, created_at ASC')
|
||||
.all(groupId) as Array<{ repo_id: string }>;
|
||||
return rows.map((r) => r.repo_id);
|
||||
}
|
||||
|
||||
private rowToSummary(row: GroupRow): GroupSummary {
|
||||
return {
|
||||
id: row.id,
|
||||
label: row.label,
|
||||
description: row.description,
|
||||
color: row.color,
|
||||
repoIds: this.repoIdsFor(row.id),
|
||||
createdAt: row.created_at,
|
||||
updatedAt: row.updated_at,
|
||||
};
|
||||
}
|
||||
|
||||
/** Garde-fou : le repo doit exister (meilleur message que de laisser la FK lever une contrainte opaque). */
|
||||
private assertRepoExists(repoId: string): void {
|
||||
if (typeof repoId !== 'string' || repoId === '') throw httpError(400, 'BAD_REQUEST', 'repoId is required');
|
||||
const exists = this.db.prepare('SELECT 1 FROM repos WHERE id = ?').get(repoId);
|
||||
if (!exists) throw httpError(404, 'REPO_NOT_FOUND', 'No repo with this id');
|
||||
}
|
||||
|
||||
/** Position d'insertion suivante dans un groupe (append en queue). */
|
||||
private nextPosition(groupId: string): number {
|
||||
const row = this.db.prepare('SELECT COALESCE(MAX(position), -1) + 1 AS pos FROM group_repos WHERE group_id = ?').get(groupId) as {
|
||||
pos: number;
|
||||
};
|
||||
return row.pos;
|
||||
}
|
||||
|
||||
listGroups(): GroupSummary[] {
|
||||
const rows = this.db.prepare('SELECT * FROM groups ORDER BY position ASC, created_at ASC').all() as unknown as GroupRow[];
|
||||
return rows.map((r) => this.rowToSummary(r));
|
||||
}
|
||||
|
||||
getGroup(id: string): GroupSummary {
|
||||
const row = this.getGroupRow(id);
|
||||
if (!row) throw httpError(404, 'NOT_FOUND', 'No group with this id');
|
||||
return this.rowToSummary(row);
|
||||
}
|
||||
|
||||
createGroup(opts: { label: string; description?: string; color?: string; repoIds?: string[] }): GroupSummary {
|
||||
const label = normLabel(opts.label);
|
||||
const description = normDescription(opts.description);
|
||||
const color = normColor(opts.color);
|
||||
const repoIds = opts.repoIds ?? [];
|
||||
if (!Array.isArray(repoIds)) throw httpError(400, 'BAD_REQUEST', 'repoIds must be an array');
|
||||
for (const repoId of repoIds) this.assertRepoExists(repoId);
|
||||
|
||||
const now = new Date().toISOString();
|
||||
const id = randomUUID();
|
||||
const position = this.db.prepare('SELECT COALESCE(MAX(position), -1) + 1 AS pos FROM groups').get() as { pos: number };
|
||||
|
||||
this.db.exec('BEGIN');
|
||||
try {
|
||||
this.db
|
||||
.prepare('INSERT INTO groups (id, label, description, color, position, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?)')
|
||||
.run(id, label, description, color, position.pos, now, now);
|
||||
const insertRepo = this.db.prepare('INSERT OR IGNORE INTO group_repos (group_id, repo_id, position, created_at) VALUES (?, ?, ?, ?)');
|
||||
let pos = 0;
|
||||
const seen = new Set<string>();
|
||||
for (const repoId of repoIds) {
|
||||
if (seen.has(repoId)) continue;
|
||||
seen.add(repoId);
|
||||
insertRepo.run(id, repoId, pos++, now);
|
||||
}
|
||||
this.db.exec('COMMIT');
|
||||
} catch (err) {
|
||||
this.db.exec('ROLLBACK');
|
||||
throw err;
|
||||
}
|
||||
|
||||
const summary = this.getGroup(id);
|
||||
this.emit('group_update', summary);
|
||||
return summary;
|
||||
}
|
||||
|
||||
updateGroup(id: string, patch: { label?: string; description?: string | null; color?: string | null }): GroupSummary {
|
||||
const row = this.getGroupRow(id);
|
||||
if (!row) throw httpError(404, 'NOT_FOUND', 'No group with this id');
|
||||
if (patch.label !== undefined) row.label = normLabel(patch.label);
|
||||
if (patch.description !== undefined) row.description = normDescription(patch.description);
|
||||
if (patch.color !== undefined) row.color = normColor(patch.color);
|
||||
const now = new Date().toISOString();
|
||||
this.db
|
||||
.prepare('UPDATE groups SET label = ?, description = ?, color = ?, updated_at = ? WHERE id = ?')
|
||||
.run(row.label, row.description, row.color, now, id);
|
||||
const summary = this.getGroup(id);
|
||||
this.emit('group_update', summary);
|
||||
return summary;
|
||||
}
|
||||
|
||||
deleteGroup(id: string): boolean {
|
||||
// CASCADE (PRAGMA foreign_keys = ON) purge group_repos.
|
||||
const res = this.db.prepare('DELETE FROM groups WHERE id = ?').run(id);
|
||||
if (res.changes === 0) return false;
|
||||
this.emit('group_removed', id);
|
||||
return true;
|
||||
}
|
||||
|
||||
addRepo(groupId: string, repoId: string): GroupSummary {
|
||||
if (!this.getGroupRow(groupId)) throw httpError(404, 'NOT_FOUND', 'No group with this id');
|
||||
this.assertRepoExists(repoId);
|
||||
const now = new Date().toISOString();
|
||||
// INSERT OR IGNORE → idempotent (PRIMARY KEY (group_id, repo_id)).
|
||||
this.db
|
||||
.prepare('INSERT OR IGNORE INTO group_repos (group_id, repo_id, position, created_at) VALUES (?, ?, ?, ?)')
|
||||
.run(groupId, repoId, this.nextPosition(groupId), now);
|
||||
this.touch(groupId, now);
|
||||
const summary = this.getGroup(groupId);
|
||||
this.emit('group_update', summary);
|
||||
return summary;
|
||||
}
|
||||
|
||||
removeRepo(groupId: string, repoId: string): GroupSummary {
|
||||
if (!this.getGroupRow(groupId)) throw httpError(404, 'NOT_FOUND', 'No group with this id');
|
||||
// DELETE no-op si absent → idempotent.
|
||||
this.db.prepare('DELETE FROM group_repos WHERE group_id = ? AND repo_id = ?').run(groupId, repoId);
|
||||
this.touch(groupId, new Date().toISOString());
|
||||
const summary = this.getGroup(groupId);
|
||||
this.emit('group_update', summary);
|
||||
return summary;
|
||||
}
|
||||
|
||||
private touch(groupId: string, now: string): void {
|
||||
this.db.prepare('UPDATE groups SET updated_at = ? WHERE id = ?').run(now, groupId);
|
||||
}
|
||||
}
|
||||
@@ -4,6 +4,8 @@
|
||||
import { randomUUID } from 'node:crypto';
|
||||
import { createRequire } from 'node:module';
|
||||
import { type Db, getSetting, setSetting } from '../db/index.js';
|
||||
import type { SecretBox } from './secret-box.js';
|
||||
import { recordAudit } from './audit-log.js';
|
||||
|
||||
// web-push est publié en CommonJS : on le charge via require (verbatimModuleSyntax + NodeNext),
|
||||
// typé par l'import type — même pattern que @xterm/headless dans screen-reader.ts.
|
||||
@@ -47,16 +49,22 @@ export class PushService {
|
||||
private readonly db: Db,
|
||||
private readonly contact: string = 'mailto:arboretum@localhost',
|
||||
sender?: PushSender,
|
||||
box?: SecretBox,
|
||||
) {
|
||||
this.send = sender ?? ((sub, payload, options) => webpush.sendNotification(sub, payload, options as Parameters<typeof webpush.sendNotification>[2]));
|
||||
let pub = getSetting(db, 'vapid_public');
|
||||
let priv = getSetting(db, 'vapid_private');
|
||||
let pub = getSetting(db, 'vapid_public'); // clé publique : jamais chiffrée (sûre à exposer)
|
||||
const storedPriv = getSetting(db, 'vapid_private');
|
||||
let priv = storedPriv ? (box ? box.decrypt(storedPriv) : storedPriv) : null;
|
||||
if (!pub || !priv) {
|
||||
const keys = webpush.generateVAPIDKeys();
|
||||
pub = keys.publicKey;
|
||||
priv = keys.privateKey;
|
||||
setSetting(db, 'vapid_public', pub);
|
||||
setSetting(db, 'vapid_private', priv);
|
||||
setSetting(db, 'vapid_private', box ? box.encrypt(priv) : priv);
|
||||
recordAudit(db, { actor: 'system', action: 'secret.generate', resourceId: 'vapid' });
|
||||
} else if (box && storedPriv && !box.isEncrypted(storedPriv)) {
|
||||
// migration douce : clé privée pré-existante en clair → re-chiffrée.
|
||||
setSetting(db, 'vapid_private', box.encrypt(priv));
|
||||
}
|
||||
this.vapidPublic = pub;
|
||||
this.vapidPrivate = priv;
|
||||
|
||||
42
packages/server/src/core/repo-discovery.ts
Normal file
42
packages/server/src/core/repo-discovery.ts
Normal file
@@ -0,0 +1,42 @@
|
||||
// Planificateur de la découverte auto des repos : scan au démarrage + re-scan périodique.
|
||||
// Calqué sur DiscoveryService (sessions) — start()/stop() avec timer .unref(). Démarré depuis
|
||||
// runDaemon() UNIQUEMENT (jamais buildApp), ce qui isole naturellement les tests vitest du scan.
|
||||
// Lui-même sans état : il lit les racines/l'intervalle dans `settings` et délègue à WorktreeManager.
|
||||
import type { Db } from '../db/index.js';
|
||||
import type { WorktreeManager } from './worktree-manager.js';
|
||||
import { readScanIntervalMin, readScanRoots } from './scan-settings.js';
|
||||
|
||||
export class RepoDiscoveryService {
|
||||
private timer: NodeJS.Timeout | null = null;
|
||||
|
||||
constructor(
|
||||
private readonly db: Db,
|
||||
private readonly worktrees: WorktreeManager,
|
||||
) {}
|
||||
|
||||
start(): void {
|
||||
if (this.timer) return;
|
||||
void this.refresh(); // scan initial asynchrone : ne bloque pas le boot
|
||||
const intervalMin = readScanIntervalMin(this.db);
|
||||
if (intervalMin > 0) {
|
||||
this.timer = setInterval(() => void this.refresh(), intervalMin * 60_000);
|
||||
this.timer.unref(); // ne maintient pas le process en vie
|
||||
}
|
||||
}
|
||||
|
||||
stop(): void {
|
||||
if (this.timer) {
|
||||
clearInterval(this.timer);
|
||||
this.timer = null;
|
||||
}
|
||||
}
|
||||
|
||||
/** Relit les racines (changement effectif sans redémarrage) et lance un scan. Ne lève jamais. */
|
||||
private async refresh(): Promise<void> {
|
||||
try {
|
||||
await this.worktrees.discoverRepos({ roots: readScanRoots(this.db) });
|
||||
} catch {
|
||||
/* scan tolérant : une erreur ne doit pas tuer le timer */
|
||||
}
|
||||
}
|
||||
}
|
||||
97
packages/server/src/core/repo-scanner.ts
Normal file
97
packages/server/src/core/repo-scanner.ts
Normal file
@@ -0,0 +1,97 @@
|
||||
// Découverte auto des dépôts git : marche bornée du système de fichiers à la recherche de `.git`.
|
||||
// Fonction PURE et tolérante (ne lève jamais) — testable isolément comme parseWorktreePorcelain.
|
||||
// N'appelle JAMAIS git (détection par présence de `.git`) : la validation réelle (isRepo) et la
|
||||
// résolution de default_branch se font paresseusement à l'enregistrement, pas par dépôt scanné.
|
||||
import { readdir } from 'node:fs/promises';
|
||||
import { existsSync } from 'node:fs';
|
||||
import { join } from 'node:path';
|
||||
|
||||
export interface ScanLimits {
|
||||
/** profondeur maximale de descente sous chaque racine (la racine = 0). */
|
||||
maxDepth: number;
|
||||
/** nombre maximal de repos retournés (garde-fou anti-explosion d'un FS pathologique). */
|
||||
maxRepos: number;
|
||||
/** noms de dossiers à ne jamais ouvrir (en plus des dotdirs, toujours exclus). */
|
||||
excludeDirs?: Set<string>;
|
||||
}
|
||||
|
||||
/** Dossiers jamais explorés : grosses arborescences sans repos racine, ou bruit de build. */
|
||||
export const DEFAULT_EXCLUDE_DIRS = new Set<string>([
|
||||
'node_modules',
|
||||
'vendor',
|
||||
'target',
|
||||
'dist',
|
||||
'build',
|
||||
'.cache',
|
||||
'venv',
|
||||
'.venv',
|
||||
'__pycache__',
|
||||
]);
|
||||
|
||||
interface Frame {
|
||||
dir: string;
|
||||
depth: number;
|
||||
}
|
||||
|
||||
/**
|
||||
* Parcours itératif (pile explicite, jamais de récursion non bornée) des `roots`.
|
||||
* Règles :
|
||||
* - un dossier contenant `.git` (fichier OU dossier → couvre les worktrees liés) est un repo :
|
||||
* on l'enregistre ; en profondeur on NE descend PAS dedans (sous-modules/worktrees imbriqués
|
||||
* ignorés). EXCEPTION : une racine fournie (depth 0) qui est elle-même un repo est aussi un
|
||||
* conteneur — on l'enregistre ET on continue de descendre pour trouver les repos internes ;
|
||||
* - on n'empile que les vrais sous-dossiers (`d.isDirectory()`), donc les symlinks ne sont PAS
|
||||
* suivis (anti-cycle + anti-sortie de racine), et on saute dotdirs + excludeDirs ;
|
||||
* - bornes : `maxDepth`, `maxRepos`, et un éventuel `signal` (timeout global) ;
|
||||
* - tolérance : un `readdir` qui échoue (EACCES/ENOENT) est ignoré, le scan continue ;
|
||||
* - racine inexistante/illisible : ignorée silencieusement.
|
||||
* Retourne les chemins absolus dédupliqués des racines de repos, et `truncated` si une borne a coupé.
|
||||
*/
|
||||
export async function scanForRepos(
|
||||
roots: string[],
|
||||
limits: ScanLimits,
|
||||
signal?: AbortSignal,
|
||||
): Promise<{ paths: string[]; truncated: boolean }> {
|
||||
const excludes = limits.excludeDirs ?? DEFAULT_EXCLUDE_DIRS;
|
||||
const found = new Set<string>();
|
||||
const seen = new Set<string>(); // ceinture-bretelles anti-cycle (chemins déjà visités)
|
||||
let truncated = false;
|
||||
|
||||
// pile partagée entre toutes les racines : un seul plafond global maxRepos.
|
||||
const stack: Frame[] = [];
|
||||
for (const root of roots) stack.push({ dir: root, depth: 0 });
|
||||
|
||||
while (stack.length > 0) {
|
||||
if (signal?.aborted || found.size >= limits.maxRepos) {
|
||||
truncated = true;
|
||||
break;
|
||||
}
|
||||
const { dir, depth } = stack.pop() as Frame;
|
||||
if (seen.has(dir)) continue;
|
||||
seen.add(dir);
|
||||
|
||||
// Un dossier avec `.git` est un repo. En PROFONDEUR (depth > 0) c'est une feuille : on
|
||||
// l'enregistre sans descendre (on n'ouvre pas les sous-modules/worktrees imbriqués). Mais une
|
||||
// RACINE fournie explicitement (depth 0) est un CONTENEUR de scan : si elle est elle-même un
|
||||
// repo on l'enregistre, puis on CONTINUE de descendre pour découvrir les dépôts qu'elle contient.
|
||||
if (existsSync(join(dir, '.git'))) {
|
||||
found.add(dir);
|
||||
if (depth > 0) continue;
|
||||
}
|
||||
if (depth >= limits.maxDepth) continue;
|
||||
|
||||
let entries;
|
||||
try {
|
||||
entries = await readdir(dir, { withFileTypes: true });
|
||||
} catch {
|
||||
continue; // EACCES/ENOENT/… : dossier ignoré, on poursuit
|
||||
}
|
||||
for (const e of entries) {
|
||||
if (!e.isDirectory()) continue; // symlinks non suivis (isDirectory() est false pour un lien)
|
||||
if (e.name.startsWith('.') || excludes.has(e.name)) continue;
|
||||
stack.push({ dir: join(dir, e.name), depth: depth + 1 });
|
||||
}
|
||||
}
|
||||
|
||||
return { paths: [...found], truncated };
|
||||
}
|
||||
66
packages/server/src/core/scan-settings.ts
Normal file
66
packages/server/src/core/scan-settings.ts
Normal file
@@ -0,0 +1,66 @@
|
||||
// Réglages de la découverte auto des repos, persistés dans la table `settings` (clé/valeur).
|
||||
// Frontière de sécurité : ces clés sont NON sensibles et n'entrent dans l'allow-list du PATCH
|
||||
// /api/v1/settings que via les validateurs ci-dessous. Aucun secret ne transite par ici.
|
||||
import { getSetting } from '../db/index.js';
|
||||
import type { Db } from '../db/index.js';
|
||||
import { isSafeAbsolutePath } from './git.js';
|
||||
|
||||
export const SCAN_ROOTS_KEY = 'scan_roots';
|
||||
export const SCAN_INTERVAL_KEY = 'scan_interval_min';
|
||||
|
||||
/** Intervalle par défaut du re-scan périodique (minutes). 0 = désactivé. */
|
||||
export const DEFAULT_SCAN_INTERVAL_MIN = 5;
|
||||
/** Borne haute de l'intervalle (24 h) et nombre maximal de racines. */
|
||||
export const MAX_SCAN_INTERVAL_MIN = 1440;
|
||||
export const MAX_SCAN_ROOTS = 16;
|
||||
|
||||
/**
|
||||
* Racines à scanner. Défaut : AUCUNE racine → aucun scan (clean install).
|
||||
* L'utilisateur ajoute ses racines via Réglages → Découverte. Lecture tolérante (JSON malformé → []).
|
||||
*/
|
||||
export function readScanRoots(db: Db): string[] {
|
||||
const raw = getSetting(db, SCAN_ROOTS_KEY);
|
||||
if (!raw) return [];
|
||||
return normalizeScanRoots(safeParse(raw)) ?? [];
|
||||
}
|
||||
|
||||
/** Intervalle périodique en minutes (0 = désactivé). Défaut DEFAULT_SCAN_INTERVAL_MIN. */
|
||||
export function readScanIntervalMin(db: Db): number {
|
||||
const raw = getSetting(db, SCAN_INTERVAL_KEY);
|
||||
if (raw === null) return DEFAULT_SCAN_INTERVAL_MIN;
|
||||
const n = Number(raw);
|
||||
return Number.isInteger(n) && n >= 0 && n <= MAX_SCAN_INTERVAL_MIN ? n : DEFAULT_SCAN_INTERVAL_MIN;
|
||||
}
|
||||
|
||||
/**
|
||||
* Valide/normalise une liste de racines : tableau de chemins absolus normalisés (isSafeAbsolutePath),
|
||||
* jamais `/` (scan catastrophique), dédupliqués, ≤ MAX_SCAN_ROOTS. Retourne null si invalide (⇒ 400).
|
||||
* Une liste vide est valide (revient au défaut côté lecture).
|
||||
*/
|
||||
export function normalizeScanRoots(raw: unknown): string[] | null {
|
||||
if (!Array.isArray(raw)) return null;
|
||||
if (raw.length > MAX_SCAN_ROOTS) return null;
|
||||
const out: string[] = [];
|
||||
for (const item of raw) {
|
||||
if (typeof item !== 'string') return null;
|
||||
const p = item.trim();
|
||||
if (!isSafeAbsolutePath(p) || p === '/') return null;
|
||||
if (!out.includes(p)) out.push(p);
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
/** Valide un intervalle (entier 0–MAX_SCAN_INTERVAL_MIN). Retourne null si invalide. */
|
||||
export function normalizeScanIntervalMin(raw: unknown): number | null {
|
||||
if (typeof raw !== 'number' || !Number.isInteger(raw)) return null;
|
||||
if (raw < 0 || raw > MAX_SCAN_INTERVAL_MIN) return null;
|
||||
return raw;
|
||||
}
|
||||
|
||||
function safeParse(raw: string): unknown {
|
||||
try {
|
||||
return JSON.parse(raw);
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
69
packages/server/src/core/secret-box.ts
Normal file
69
packages/server/src/core/secret-box.ts
Normal file
@@ -0,0 +1,69 @@
|
||||
// Chiffrement au repos des secrets applicatifs (server_secret HMAC, clé privée VAPID) stockés dans
|
||||
// la table `settings`. node:sqlite (DatabaseSync) ne supporte pas sqlcipher → on chiffre au niveau
|
||||
// applicatif les VALEURS sensibles, en AES-256-GCM (authentifié), avant insertion.
|
||||
//
|
||||
// Gestion de clé (par ordre de priorité) :
|
||||
// 1. ARBORETUM_SECRET_KEY (variable d'env) → vraie protection : la clé ne vit pas sur le disque,
|
||||
// donc une fuite de la base seule (backup, WAL) ne révèle pas les secrets ;
|
||||
// 2. sinon, fichier clé `dataDir/secret.key` (0o600), généré au 1er démarrage. Protection partielle :
|
||||
// couvre la fuite de la base seule, PAS celle du dossier de données complet (clé + base ensemble).
|
||||
// Compromis assumé et documenté (docs/ENTERPRISE_DEPLOYMENT.md) : pour une protection forte, fournir
|
||||
// ARBORETUM_SECRET_KEY et sauvegarder cette clé séparément des backups de la base.
|
||||
import { createCipheriv, createDecipheriv, randomBytes, scryptSync } from 'node:crypto';
|
||||
import { chmodSync, existsSync, readFileSync, writeFileSync } from 'node:fs';
|
||||
import { join } from 'node:path';
|
||||
|
||||
const PREFIX = 'v1:'; // versionne le format ; absence de préfixe = valeur en clair (legacy → migration douce)
|
||||
const SCRYPT_SALT = 'arboretum-secret-box-v1'; // sel fixe : l'entropie vient de la passphrase fournie
|
||||
|
||||
export class SecretBox {
|
||||
constructor(private readonly key: Buffer) {}
|
||||
|
||||
/** Chiffre en `v1:<iv>:<tag>:<ciphertext>` (hex). */
|
||||
encrypt(plaintext: string): string {
|
||||
const iv = randomBytes(12);
|
||||
const cipher = createCipheriv('aes-256-gcm', this.key, iv);
|
||||
const ct = Buffer.concat([cipher.update(plaintext, 'utf8'), cipher.final()]);
|
||||
const tag = cipher.getAuthTag();
|
||||
return `${PREFIX}${iv.toString('hex')}:${tag.toString('hex')}:${ct.toString('hex')}`;
|
||||
}
|
||||
|
||||
/** Déchiffre une valeur `v1:` ; une valeur sans préfixe est retournée telle quelle (clair legacy). */
|
||||
decrypt(stored: string): string {
|
||||
if (!this.isEncrypted(stored)) return stored;
|
||||
const [, ivHex, tagHex, ctHex] = stored.split(':');
|
||||
if (!ivHex || !tagHex || !ctHex) throw new Error('secret-box: format chiffré invalide');
|
||||
const decipher = createDecipheriv('aes-256-gcm', this.key, Buffer.from(ivHex, 'hex'));
|
||||
decipher.setAuthTag(Buffer.from(tagHex, 'hex'));
|
||||
return Buffer.concat([decipher.update(Buffer.from(ctHex, 'hex')), decipher.final()]).toString('utf8');
|
||||
}
|
||||
|
||||
isEncrypted(stored: string): boolean {
|
||||
return stored.startsWith(PREFIX);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Construit le SecretBox de production : clé dérivée d'ARBORETUM_SECRET_KEY si fournie, sinon
|
||||
* d'un fichier clé `dataDir/secret.key` (0o600) généré au besoin.
|
||||
*/
|
||||
export function loadSecretBox(dataDir: string): SecretBox {
|
||||
const passphrase = process.env.ARBORETUM_SECRET_KEY;
|
||||
if (passphrase && passphrase.length > 0) {
|
||||
return new SecretBox(scryptSync(passphrase, SCRYPT_SALT, 32));
|
||||
}
|
||||
const keyPath = join(dataDir, 'secret.key');
|
||||
let keyHex: string;
|
||||
if (existsSync(keyPath)) {
|
||||
keyHex = readFileSync(keyPath, 'utf8').trim();
|
||||
} else {
|
||||
keyHex = randomBytes(32).toString('hex');
|
||||
writeFileSync(keyPath, keyHex + '\n', { mode: 0o600 });
|
||||
}
|
||||
try {
|
||||
chmodSync(keyPath, 0o600);
|
||||
} catch {
|
||||
/* FS sans permissions POSIX : ignoré */
|
||||
}
|
||||
return new SecretBox(Buffer.from(keyHex, 'hex'));
|
||||
}
|
||||
@@ -7,6 +7,7 @@ import { randomUUID } from 'node:crypto';
|
||||
import { basename, dirname, join, resolve } from 'node:path';
|
||||
import { existsSync } from 'node:fs';
|
||||
import type {
|
||||
DiscoverReposResponse,
|
||||
HookRunResult,
|
||||
PostCreateHook,
|
||||
RepoSummary,
|
||||
@@ -17,6 +18,7 @@ import type {
|
||||
import type { Db } from '../db/index.js';
|
||||
import type { PtyManager } from './pty-manager.js';
|
||||
import { DiscoveryService, mergeSessions } from './discovery-service.js';
|
||||
import { scanForRepos } from './repo-scanner.js';
|
||||
import { preTrustProject } from './claude-trust.js';
|
||||
import {
|
||||
addWorktree,
|
||||
@@ -35,6 +37,10 @@ import {
|
||||
const FACTS_TTL_MS = 2500;
|
||||
const HOOK_TIMEOUT_MS = 5 * 60_000;
|
||||
const HOOK_OUTPUT_MAX = 64 * 1024;
|
||||
// Bornes du scan de découverte (anti-explosion sur un home volumineux).
|
||||
const SCAN_MAX_DEPTH = 6;
|
||||
const SCAN_MAX_REPOS = 2000;
|
||||
const SCAN_TIMEOUT_MS = 30_000;
|
||||
|
||||
interface RepoRow {
|
||||
id: string;
|
||||
@@ -44,6 +50,7 @@ interface RepoRow {
|
||||
post_create_hooks: string;
|
||||
pre_trust: number;
|
||||
created_at: string;
|
||||
hidden: number;
|
||||
}
|
||||
|
||||
export interface WorktreeManagerEvents {
|
||||
@@ -96,6 +103,8 @@ function runHook(cwd: string, hook: PostCreateHook): Promise<HookRunResult> {
|
||||
export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
|
||||
private readonly factsCache = new Map<string, { facts: Array<{ w: ParsedWorktree; status: WorktreeGitStatus }>; at: number }>();
|
||||
private readonly locks = new Map<string, Promise<unknown>>();
|
||||
/** Scan de découverte en cours : coalesce boot + bouton + périodique sur un seul scan. */
|
||||
private scanInFlight: Promise<DiscoverReposResponse> | null = null;
|
||||
|
||||
constructor(
|
||||
private readonly db: Db,
|
||||
@@ -121,6 +130,7 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
|
||||
preTrust: row.pre_trust === 1,
|
||||
createdAt: row.created_at,
|
||||
valid: await isRepo(row.path),
|
||||
hidden: row.hidden === 1,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -143,24 +153,35 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
|
||||
post_create_hooks: JSON.stringify(opts.postCreateHooks ?? []),
|
||||
pre_trust: opts.preTrust ? 1 : 0,
|
||||
created_at: new Date().toISOString(),
|
||||
hidden: 0,
|
||||
};
|
||||
try {
|
||||
this.db
|
||||
.prepare('INSERT INTO repos (id, path, label, default_branch, post_create_hooks, pre_trust, created_at) VALUES (?, ?, ?, ?, ?, ?, ?)')
|
||||
.run(row.id, row.path, row.label, row.default_branch, row.post_create_hooks, row.pre_trust, row.created_at);
|
||||
.prepare('INSERT INTO repos (id, path, label, default_branch, post_create_hooks, pre_trust, created_at, hidden) VALUES (?, ?, ?, ?, ?, ?, ?, ?)')
|
||||
.run(row.id, row.path, row.label, row.default_branch, row.post_create_hooks, row.pre_trust, row.created_at, row.hidden);
|
||||
} catch (err) {
|
||||
// Course possible avec un scan concurrent qui aurait inséré le même path entre le SELECT
|
||||
// d'unicité et cet INSERT (contrainte UNIQUE sur path) → on rend le même 409 explicite.
|
||||
if (String((err as { code?: string }).code).includes('CONSTRAINT')) {
|
||||
throw httpError(409, 'ALREADY_REGISTERED', 'This repository is already registered');
|
||||
}
|
||||
throw err;
|
||||
}
|
||||
const summary = await this.rowToSummary(row);
|
||||
this.emit('repo_update', summary);
|
||||
return summary;
|
||||
}
|
||||
|
||||
async updateRepo(id: string, patch: { label?: string; postCreateHooks?: PostCreateHook[]; preTrust?: boolean }): Promise<RepoSummary> {
|
||||
async updateRepo(id: string, patch: { label?: string; postCreateHooks?: PostCreateHook[]; preTrust?: boolean; hidden?: boolean }): Promise<RepoSummary> {
|
||||
const row = this.getRepoRow(id);
|
||||
if (!row) throw httpError(404, 'NOT_FOUND', 'No repo with this id');
|
||||
if (patch.label !== undefined) row.label = patch.label.trim() || row.label;
|
||||
if (patch.postCreateHooks !== undefined) row.post_create_hooks = JSON.stringify(patch.postCreateHooks);
|
||||
if (patch.preTrust !== undefined) row.pre_trust = patch.preTrust ? 1 : 0;
|
||||
if (patch.hidden !== undefined) row.hidden = patch.hidden ? 1 : 0;
|
||||
this.db
|
||||
.prepare('UPDATE repos SET label = ?, post_create_hooks = ?, pre_trust = ? WHERE id = ?')
|
||||
.run(row.label, row.post_create_hooks, row.pre_trust, id);
|
||||
.prepare('UPDATE repos SET label = ?, post_create_hooks = ?, pre_trust = ?, hidden = ? WHERE id = ?')
|
||||
.run(row.label, row.post_create_hooks, row.pre_trust, row.hidden, id);
|
||||
const summary = await this.rowToSummary(row);
|
||||
this.emit('repo_update', summary);
|
||||
return summary;
|
||||
@@ -174,6 +195,53 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Découvre les repos git sous `roots` et auto-enregistre les NOUVEAUX (path absent de la DB).
|
||||
* Idempotent et anti-résurrection : un path déjà présent — visible OU masqué — n'est jamais
|
||||
* réécrit (INSERT ... ON CONFLICT DO NOTHING). Les scans concurrents sont coalescés. Tolérant :
|
||||
* ne lève pas (le scanner avale les erreurs FS). N'appelle aucun git pendant le scan
|
||||
* (default_branch=NULL, résolu paresseusement par rowToSummary à l'affichage).
|
||||
*/
|
||||
discoverRepos(opts: { roots: string[]; maxDepth?: number; maxRepos?: number }): Promise<DiscoverReposResponse> {
|
||||
if (this.scanInFlight) return this.scanInFlight;
|
||||
this.scanInFlight = this.runDiscovery(opts).finally(() => {
|
||||
this.scanInFlight = null;
|
||||
});
|
||||
return this.scanInFlight;
|
||||
}
|
||||
|
||||
private async runDiscovery(opts: { roots: string[]; maxDepth?: number; maxRepos?: number }): Promise<DiscoverReposResponse> {
|
||||
const t0 = Date.now();
|
||||
const { paths, truncated } = await scanForRepos(
|
||||
opts.roots,
|
||||
{ maxDepth: opts.maxDepth ?? SCAN_MAX_DEPTH, maxRepos: opts.maxRepos ?? SCAN_MAX_REPOS },
|
||||
AbortSignal.timeout(SCAN_TIMEOUT_MS),
|
||||
);
|
||||
const insert = this.db.prepare(
|
||||
`INSERT INTO repos (id, path, label, default_branch, post_create_hooks, pre_trust, created_at, hidden)
|
||||
VALUES (?, ?, ?, NULL, '[]', 0, ?, 0) ON CONFLICT(path) DO NOTHING`,
|
||||
);
|
||||
let added = 0;
|
||||
for (const path of paths) {
|
||||
const row: RepoRow = {
|
||||
id: randomUUID(),
|
||||
path,
|
||||
label: basename(path),
|
||||
default_branch: null,
|
||||
post_create_hooks: '[]',
|
||||
pre_trust: 0,
|
||||
created_at: new Date().toISOString(),
|
||||
hidden: 0,
|
||||
};
|
||||
const res = insert.run(row.id, row.path, row.label, row.created_at);
|
||||
if (res.changes === 1) {
|
||||
added++;
|
||||
this.emit('repo_update', await this.rowToSummary(row)); // nouveaux uniquement
|
||||
}
|
||||
}
|
||||
return { scanned: paths.length, added, durationMs: Date.now() - t0, truncated };
|
||||
}
|
||||
|
||||
// ---- worktrees ----
|
||||
|
||||
/** Sessions (managées + découvertes) dont le cwd correspond à ce chemin de worktree. */
|
||||
@@ -214,8 +282,13 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
|
||||
}
|
||||
|
||||
async listAllWorktrees(): Promise<WorktreeSummary[]> {
|
||||
const rows = this.db.prepare('SELECT id FROM repos ORDER BY created_at ASC').all() as Array<{ id: string }>;
|
||||
const lists = await Promise.all(rows.map((r) => this.listRepoWorktrees(r.id)));
|
||||
// Les repos masqués sont exclus du dashboard : inutile de calculer leurs worktrees (sous-process
|
||||
// git par repo). Le front charge paresseusement ceux d'un repo masqué via listRepoWorktrees
|
||||
// quand l'utilisateur active « afficher les masqués ».
|
||||
const rows = this.db.prepare('SELECT id FROM repos WHERE hidden = 0 ORDER BY created_at ASC').all() as Array<{ id: string }>;
|
||||
// Tolérance par repo : avec la découverte auto, un repo douteux (git en échec, chemin disparu,
|
||||
// permission) ne doit JAMAIS faire planter tout l'endpoint — il ne contribue alors aucun worktree.
|
||||
const lists = await Promise.all(rows.map((r) => this.listRepoWorktrees(r.id).catch(() => [])));
|
||||
return lists.flat();
|
||||
}
|
||||
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
import { DatabaseSync } from 'node:sqlite';
|
||||
import { chmodSync, existsSync } from 'node:fs';
|
||||
|
||||
const MIGRATIONS: Array<{ id: number; sql: string }> = [
|
||||
{
|
||||
@@ -68,6 +69,55 @@ const MIGRATIONS: Array<{ id: number; sql: string }> = [
|
||||
CREATE INDEX idx_push_subs_token ON push_subscriptions(token_id);
|
||||
`,
|
||||
},
|
||||
{
|
||||
// P5 — groupes de travail. Un groupe = collection de repos (many-to-many).
|
||||
// Worktrees/sessions NON persistés ici : servis par WorktreeManager/PtyManager
|
||||
// et filtrés côté client par repoId. CASCADE s'appuie sur PRAGMA foreign_keys = ON (cf. openDb).
|
||||
id: 5,
|
||||
sql: `
|
||||
CREATE TABLE groups (
|
||||
id TEXT PRIMARY KEY,
|
||||
label TEXT NOT NULL,
|
||||
description TEXT,
|
||||
color TEXT,
|
||||
position INTEGER NOT NULL DEFAULT 0,
|
||||
created_at TEXT NOT NULL,
|
||||
updated_at TEXT NOT NULL
|
||||
);
|
||||
CREATE TABLE group_repos (
|
||||
group_id TEXT NOT NULL REFERENCES groups(id) ON DELETE CASCADE,
|
||||
repo_id TEXT NOT NULL REFERENCES repos(id) ON DELETE CASCADE,
|
||||
position INTEGER NOT NULL DEFAULT 0,
|
||||
created_at TEXT NOT NULL,
|
||||
PRIMARY KEY (group_id, repo_id)
|
||||
);
|
||||
CREATE INDEX idx_group_repos_repo ON group_repos(repo_id);
|
||||
`,
|
||||
},
|
||||
{
|
||||
// Découverte auto : un repo masqué reste en DB (exclu du dashboard) pour qu'un
|
||||
// re-scan ne le ressuscite pas. hidden=1 = masqué.
|
||||
id: 6,
|
||||
sql: `ALTER TABLE repos ADD COLUMN hidden INTEGER NOT NULL DEFAULT 0;`,
|
||||
},
|
||||
{
|
||||
// Journal d'audit (conformité entreprise : GDPR/SOX/ISO 27001). Trace les mutations
|
||||
// sensibles (tokens, réglages, secrets, abonnements push, groupes). Ne contient JAMAIS
|
||||
// de secret en clair — `details` est un JSON de métadonnées non sensibles.
|
||||
id: 7,
|
||||
sql: `
|
||||
CREATE TABLE audit_logs (
|
||||
id TEXT PRIMARY KEY,
|
||||
ts TEXT NOT NULL,
|
||||
actor TEXT NOT NULL,
|
||||
action TEXT NOT NULL,
|
||||
resource_id TEXT,
|
||||
details TEXT,
|
||||
result TEXT NOT NULL
|
||||
);
|
||||
CREATE INDEX idx_audit_ts ON audit_logs(ts);
|
||||
`,
|
||||
},
|
||||
];
|
||||
|
||||
export type Db = DatabaseSync;
|
||||
@@ -76,10 +126,27 @@ export function openDb(path: string): Db {
|
||||
const db = new DatabaseSync(path);
|
||||
db.exec('PRAGMA journal_mode = WAL');
|
||||
db.exec('PRAGMA foreign_keys = ON');
|
||||
hardenDbPermissions(path);
|
||||
migrate(db);
|
||||
return db;
|
||||
}
|
||||
|
||||
/**
|
||||
* Restreint la base (et ses fichiers WAL/SHM) à 0o600 — proprio uniquement. La base contient des
|
||||
* secrets (server_secret, clé privée VAPID, hashs de tokens) : elle ne doit jamais être lisible par
|
||||
* d'autres utilisateurs du système. Best-effort : ignoré sur les FS sans permissions POSIX.
|
||||
*/
|
||||
function hardenDbPermissions(path: string): void {
|
||||
if (path === ':memory:') return;
|
||||
for (const p of [path, `${path}-wal`, `${path}-shm`]) {
|
||||
try {
|
||||
if (existsSync(p)) chmodSync(p, 0o600);
|
||||
} catch {
|
||||
/* FS sans permissions POSIX (Windows / montage) : ignoré */
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function migrate(db: DatabaseSync): void {
|
||||
db.exec('CREATE TABLE IF NOT EXISTS schema_migrations (id INTEGER PRIMARY KEY, applied_at TEXT NOT NULL)');
|
||||
const applied = new Set(
|
||||
|
||||
@@ -2,32 +2,30 @@
|
||||
import { readFileSync } from 'node:fs';
|
||||
import { join, dirname } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { loadConfig } from './config.js';
|
||||
import { loadConfig, type Config } from './config.js';
|
||||
import { openDb } from './db/index.js';
|
||||
import { buildApp } from './app.js';
|
||||
import { runInstall, runUninstall, runStatus, printUsage, printTokenBanner } from './cli/install.js';
|
||||
|
||||
const pkg = JSON.parse(
|
||||
readFileSync(join(dirname(fileURLToPath(import.meta.url)), '..', 'package.json'), 'utf8'),
|
||||
) as { version: string };
|
||||
|
||||
async function main(): Promise<void> {
|
||||
const config = loadConfig();
|
||||
/** Démarre le daemon : écoute HTTP, scan des sessions, drain propre au SIGTERM/SIGINT. */
|
||||
export async function runDaemon(config: Config): Promise<void> {
|
||||
const db = openDb(config.dbPath);
|
||||
const { app, auth, manager, discovery } = buildApp(config, db, pkg.version);
|
||||
const { app, auth, manager, discovery, repoDiscovery } = buildApp(config, db, pkg.version);
|
||||
|
||||
const bootstrapToken = auth.ensureBootstrapToken();
|
||||
await app.listen({ port: config.port, host: config.bind });
|
||||
discovery.start(); // scan initial + rafraîchissement périodique des sessions découvertes
|
||||
if (config.autoDiscover) repoDiscovery.start(); // découverte auto des repos : scan au boot + re-scan périodique
|
||||
|
||||
const url = `http://${config.bind === '0.0.0.0' ? '127.0.0.1' : config.bind}:${config.port}`;
|
||||
app.log.info(`Arboretum v${pkg.version} — ${url}`);
|
||||
if (bootstrapToken) {
|
||||
// Affiché une seule fois : le hash seul est stocké.
|
||||
console.log('\n┌──────────────────────────────────────────────────────────────────┐');
|
||||
console.log('│ First start — your access token (shown once, store it safely): │');
|
||||
console.log('└──────────────────────────────────────────────────────────────────┘');
|
||||
console.log(`\n ${bootstrapToken}\n`);
|
||||
console.log(` Login at: ${url}/\n`);
|
||||
printTokenBanner(bootstrapToken, url);
|
||||
} else if (config.printToken) {
|
||||
console.log('Tokens are stored hashed and cannot be re-printed. Create a new one from Settings (or reset the db).');
|
||||
}
|
||||
@@ -38,6 +36,7 @@ async function main(): Promise<void> {
|
||||
shuttingDown = true;
|
||||
app.log.info(`${signal} received — draining sessions then exiting`);
|
||||
discovery.stop();
|
||||
repoDiscovery.stop();
|
||||
manager.shutdown();
|
||||
setTimeout(() => {
|
||||
void app.close().then(() => process.exit(0));
|
||||
@@ -47,6 +46,36 @@ async function main(): Promise<void> {
|
||||
process.on('SIGTERM', () => shutdown('SIGTERM'));
|
||||
}
|
||||
|
||||
// Routeur de sous-commandes. On inspecte argv[0] AVANT loadConfig (parseArgs strict throw sur
|
||||
// un positionnel inconnu). Aucune sous-commande (ou un flag en tête) → daemon : rétrocompat stricte
|
||||
// de `arboretum`, `arboretum --port 8080`, `npx @johanleroy/git-arboretum --allow-origin …`.
|
||||
async function main(): Promise<void> {
|
||||
const argv = process.argv.slice(2);
|
||||
const cmd = argv[0];
|
||||
switch (cmd) {
|
||||
case 'install':
|
||||
return runInstall(argv.slice(1));
|
||||
case 'uninstall':
|
||||
return runUninstall(argv.slice(1));
|
||||
case 'status':
|
||||
return runStatus(argv.slice(1));
|
||||
case 'serve':
|
||||
return runDaemon(loadConfig(argv.slice(1)));
|
||||
case 'help':
|
||||
case '--help':
|
||||
case '-h':
|
||||
printUsage(pkg.version);
|
||||
return;
|
||||
default:
|
||||
if (cmd && !cmd.startsWith('-')) {
|
||||
console.error(`Unknown command: ${cmd}\n`);
|
||||
printUsage(pkg.version);
|
||||
process.exit(1);
|
||||
}
|
||||
return runDaemon(loadConfig(argv));
|
||||
}
|
||||
}
|
||||
|
||||
main().catch((err) => {
|
||||
console.error(err instanceof Error ? err.message : err);
|
||||
process.exit(1);
|
||||
|
||||
17
packages/server/src/routes/audit.ts
Normal file
17
packages/server/src/routes/audit.ts
Normal file
@@ -0,0 +1,17 @@
|
||||
// Consultation du journal d'audit (onglet Réglages / outils de conformité). Lecture seule, sous
|
||||
// l'auth globale. Pagination par curseur `before` (ts décroissant).
|
||||
import type { FastifyInstance } from 'fastify';
|
||||
import type { AuditLogsResponse } from '@arboretum/shared';
|
||||
import type { Db } from '../db/index.js';
|
||||
import { listAudit } from '../core/audit-log.js';
|
||||
|
||||
export function registerAuditRoutes(app: FastifyInstance, db: Db): void {
|
||||
app.get('/api/v1/audit-logs', async (req): Promise<AuditLogsResponse> => {
|
||||
const q = req.query as { limit?: string; before?: string };
|
||||
const limit = Math.min(Math.max(Math.trunc(Number(q.limit) || 50), 1), 200);
|
||||
const entries = listAudit(db, { limit, before: q.before ?? null });
|
||||
// s'il reste potentiellement des entrées (page pleine), expose le curseur suivant.
|
||||
const nextBefore = entries.length === limit ? entries[entries.length - 1]!.ts : null;
|
||||
return { entries, nextBefore };
|
||||
});
|
||||
}
|
||||
@@ -1,12 +1,31 @@
|
||||
import type { FastifyInstance } from 'fastify';
|
||||
import type { LoginRequest, LoginResponse, MeResponse } from '@arboretum/shared';
|
||||
import type { FastifyInstance, FastifyRequest } from 'fastify';
|
||||
import type {
|
||||
CreateTokenRequest,
|
||||
CreateTokenResponse,
|
||||
LoginRequest,
|
||||
LoginResponse,
|
||||
MeResponse,
|
||||
TokensListResponse,
|
||||
} from '@arboretum/shared';
|
||||
import type { AuthService, LoginRateLimiter } from '../auth/service.js';
|
||||
import type { Db } from '../db/index.js';
|
||||
import { recordAudit } from '../core/audit-log.js';
|
||||
|
||||
// Tailscale Serve / un reverse-proxy TLS posent x-forwarded-proto. On ne sert jamais
|
||||
// en TLS direct : `secure` n'est posé que derrière un front HTTPS, jamais en localhost http
|
||||
// (sinon le navigateur refuserait le cookie sur http://127.0.0.1 et le login local casserait).
|
||||
export function isHttpsRequest(req: FastifyRequest): boolean {
|
||||
const xfp = req.headers['x-forwarded-proto'];
|
||||
const proto = (Array.isArray(xfp) ? xfp[0] : xfp)?.split(',')[0]?.trim();
|
||||
return proto === 'https';
|
||||
}
|
||||
|
||||
export function registerAuthRoutes(
|
||||
app: FastifyInstance,
|
||||
auth: AuthService,
|
||||
limiter: LoginRateLimiter,
|
||||
serverVersion: string,
|
||||
db: Db,
|
||||
): void {
|
||||
app.post('/api/v1/auth/login', { config: { public: true } }, async (req, reply) => {
|
||||
const wait = limiter.check();
|
||||
@@ -17,13 +36,16 @@ export function registerAuthRoutes(
|
||||
const ctx = typeof body?.token === 'string' ? auth.verifyRawToken(body.token) : null;
|
||||
if (!ctx) {
|
||||
limiter.recordFailure();
|
||||
recordAudit(db, { actor: 'anonymous', action: 'login.failure', result: 'denied' });
|
||||
return reply.status(401).send({ error: { code: 'BAD_TOKEN', message: 'Invalid token' } });
|
||||
}
|
||||
limiter.recordSuccess();
|
||||
recordAudit(db, { actor: ctx.tokenId, action: 'login.success' });
|
||||
void reply.setCookie(auth.cookieName, auth.issueCookie(ctx), {
|
||||
path: '/',
|
||||
httpOnly: true,
|
||||
sameSite: 'strict',
|
||||
secure: isHttpsRequest(req),
|
||||
maxAge: 30 * 24 * 3600,
|
||||
});
|
||||
const res: LoginResponse = { ok: true, label: ctx.label };
|
||||
@@ -31,12 +53,53 @@ export function registerAuthRoutes(
|
||||
});
|
||||
|
||||
app.get('/api/v1/auth/me', async (req, reply) => {
|
||||
const res: MeResponse = { ok: true, tokenLabel: req.authContext?.label ?? 'unknown', serverVersion };
|
||||
const res: MeResponse = {
|
||||
ok: true,
|
||||
tokenId: req.authContext?.tokenId ?? '',
|
||||
tokenLabel: req.authContext?.label ?? 'unknown',
|
||||
serverVersion,
|
||||
};
|
||||
return reply.send(res);
|
||||
});
|
||||
|
||||
app.post('/api/v1/auth/logout', async (_req, reply) => {
|
||||
void reply.clearCookie(auth.cookieName, { path: '/' });
|
||||
app.post('/api/v1/auth/logout', async (req, reply) => {
|
||||
// Les attributs doivent matcher ceux posés au login pour que le navigateur efface bien le cookie.
|
||||
void reply.clearCookie(auth.cookieName, { path: '/', secure: isHttpsRequest(req) });
|
||||
return reply.send({ ok: true });
|
||||
});
|
||||
|
||||
// ---- Gestion des tokens d'accès (onglet Réglages) ----
|
||||
// Sous l'auth globale (preValidation). On ne renvoie jamais le hash ; la valeur en clair
|
||||
// d'un nouveau token n'est exposée qu'une seule fois, à la création.
|
||||
app.get('/api/v1/auth/tokens', async (req): Promise<TokensListResponse> => {
|
||||
const current = req.authContext?.tokenId;
|
||||
return { tokens: auth.listTokens().map((t) => ({ ...t, current: t.id === current })) };
|
||||
});
|
||||
|
||||
app.post('/api/v1/auth/tokens', async (req, reply) => {
|
||||
const body = req.body as Partial<CreateTokenRequest> | null;
|
||||
const label = typeof body?.label === 'string' ? body.label.trim() : '';
|
||||
if (label.length < 1 || label.length > 64) {
|
||||
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'label must be 1–64 characters' } });
|
||||
}
|
||||
const { id, token } = auth.createTokenRecord(label);
|
||||
recordAudit(db, { actor: req.authContext?.tokenId ?? 'unknown', action: 'token.create', resourceId: id, details: { label } });
|
||||
return reply.status(201).send({ id, label, token } satisfies CreateTokenResponse);
|
||||
});
|
||||
|
||||
app.delete('/api/v1/auth/tokens/:id', async (req, reply) => {
|
||||
const { id } = req.params as { id: string };
|
||||
const result = auth.revokeToken(id);
|
||||
const actor = req.authContext?.tokenId ?? 'unknown';
|
||||
if (result === 'not_found') {
|
||||
return reply.status(404).send({ error: { code: 'NOT_FOUND', message: 'No active token with this id' } });
|
||||
}
|
||||
if (result === 'last') {
|
||||
recordAudit(db, { actor, action: 'token.revoke', resourceId: id, result: 'denied', details: { reason: 'last_active_token' } });
|
||||
return reply.status(409).send({ error: { code: 'LAST_TOKEN', message: 'Cannot revoke the last active token' } });
|
||||
}
|
||||
recordAudit(db, { actor, action: 'token.revoke', resourceId: id });
|
||||
// 200 + corps JSON (pas 204) : le mini-client REST du front parse toujours la réponse.
|
||||
return reply.send({ ok: true });
|
||||
});
|
||||
}
|
||||
|
||||
54
packages/server/src/routes/data.ts
Normal file
54
packages/server/src/routes/data.ts
Normal file
@@ -0,0 +1,54 @@
|
||||
// RGPD (droits d'accès & d'effacement) : export et suppression des données rattachées au token
|
||||
// authentifié. Modèle mono-utilisateur → le détenteur du token EST le sujet des données. Sous l'auth
|
||||
// globale. La suppression se fait en deux temps (code de confirmation) pour éviter les clics accidentels.
|
||||
import { createHash } from 'node:crypto';
|
||||
import type { FastifyInstance } from 'fastify';
|
||||
import type { DataExportResponse, DeleteMyDataRequest, DeleteMyDataResponse } from '@arboretum/shared';
|
||||
import type { Db } from '../db/index.js';
|
||||
import type { AuthService } from '../auth/service.js';
|
||||
import { readScanIntervalMin, readScanRoots } from '../core/scan-settings.js';
|
||||
import { recordAudit } from '../core/audit-log.js';
|
||||
|
||||
export function registerDataRoutes(app: FastifyInstance, db: Db, auth: AuthService): void {
|
||||
app.get('/api/v1/data/export', async (req): Promise<DataExportResponse> => {
|
||||
const current = req.authContext!.tokenId;
|
||||
const tokens = auth.listTokens().map((t) => ({ ...t, current: t.id === current }));
|
||||
const pushSubscriptions = db
|
||||
.prepare(
|
||||
'SELECT endpoint, user_agent AS userAgent, created_at AS createdAt, last_ok_at AS lastOkAt FROM push_subscriptions WHERE token_id = ?',
|
||||
)
|
||||
.all(current) as DataExportResponse['pushSubscriptions'];
|
||||
const sessions = db
|
||||
.prepare(
|
||||
'SELECT id, cwd, command, title, created_at AS createdAt, ended_at AS endedAt, exit_code AS exitCode FROM sessions ORDER BY created_at',
|
||||
)
|
||||
.all() as DataExportResponse['sessions'];
|
||||
return {
|
||||
exportedAt: new Date().toISOString(),
|
||||
tokens,
|
||||
pushSubscriptions,
|
||||
sessions,
|
||||
settings: { scanRoots: readScanRoots(db), scanIntervalMin: readScanIntervalMin(db) },
|
||||
};
|
||||
});
|
||||
|
||||
app.post('/api/v1/data/delete-my-data', async (req, reply) => {
|
||||
const current = req.authContext!.tokenId;
|
||||
// code déterministe lié au token (sans état serveur) : renvoyé au 1er appel, exigé au 2nd.
|
||||
const code = createHash('sha256').update(`delete:${current}`).digest('hex').slice(0, 12);
|
||||
const body = (req.body as DeleteMyDataRequest | null) ?? {};
|
||||
const subsCount = (db.prepare('SELECT COUNT(*) AS n FROM push_subscriptions WHERE token_id = ?').get(current) as { n: number }).n;
|
||||
|
||||
if (body.confirm !== code) {
|
||||
const res: DeleteMyDataResponse = { status: 'pending', confirm: code, summary: { pushSubscriptions: subsCount, tokenRevoked: false } };
|
||||
return reply.send(res);
|
||||
}
|
||||
|
||||
db.prepare('DELETE FROM push_subscriptions WHERE token_id = ?').run(current);
|
||||
// révoque le token courant (sauf si c'est le dernier actif → garde anti lock-out conservée).
|
||||
const revoked = auth.revokeToken(current) === 'ok';
|
||||
recordAudit(db, { actor: current, action: 'data.delete', details: { pushSubscriptions: subsCount, tokenRevoked: revoked } });
|
||||
const res: DeleteMyDataResponse = { status: 'done', summary: { pushSubscriptions: subsCount, tokenRevoked: revoked } };
|
||||
return reply.send(res);
|
||||
});
|
||||
}
|
||||
91
packages/server/src/routes/groups.ts
Normal file
91
packages/server/src/routes/groups.ts
Normal file
@@ -0,0 +1,91 @@
|
||||
import type { FastifyInstance } from 'fastify';
|
||||
import type {
|
||||
AddRepoRequest,
|
||||
CreateGroupRequest,
|
||||
GroupResponse,
|
||||
GroupsListResponse,
|
||||
UpdateGroupRequest,
|
||||
} from '@arboretum/shared';
|
||||
import type { GroupManager } from '../core/group-manager.js';
|
||||
import type { Db } from '../db/index.js';
|
||||
import { recordAudit } from '../core/audit-log.js';
|
||||
import { sendManagerError } from './repos.js';
|
||||
|
||||
export function registerGroupRoutes(app: FastifyInstance, gm: GroupManager, db: Db): void {
|
||||
app.get('/api/v1/groups', async (): Promise<GroupsListResponse> => ({ groups: gm.listGroups() }));
|
||||
|
||||
app.get('/api/v1/groups/:id', async (req, reply) => {
|
||||
const { id } = req.params as { id: string };
|
||||
try {
|
||||
return reply.send({ group: gm.getGroup(id) } satisfies GroupResponse);
|
||||
} catch (err) {
|
||||
return sendManagerError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.post('/api/v1/groups', async (req, reply) => {
|
||||
const body = req.body as Partial<CreateGroupRequest> | null;
|
||||
if (!body || typeof body.label !== 'string') {
|
||||
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'label is required' } });
|
||||
}
|
||||
try {
|
||||
const group = gm.createGroup({
|
||||
label: body.label,
|
||||
...(body.description !== undefined ? { description: body.description } : {}),
|
||||
...(body.color !== undefined ? { color: body.color } : {}),
|
||||
...(Array.isArray(body.repoIds) ? { repoIds: body.repoIds } : {}),
|
||||
});
|
||||
recordAudit(db, { actor: req.authContext?.tokenId ?? 'unknown', action: 'group.create', resourceId: group.id, details: { label: group.label } });
|
||||
return reply.status(201).send({ group } satisfies GroupResponse);
|
||||
} catch (err) {
|
||||
return sendManagerError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.patch('/api/v1/groups/:id', async (req, reply) => {
|
||||
const { id } = req.params as { id: string };
|
||||
const body = (req.body as Partial<UpdateGroupRequest> | null) ?? {};
|
||||
try {
|
||||
const group = gm.updateGroup(id, {
|
||||
...(body.label !== undefined ? { label: body.label } : {}),
|
||||
...(body.description !== undefined ? { description: body.description } : {}),
|
||||
...(body.color !== undefined ? { color: body.color } : {}),
|
||||
});
|
||||
recordAudit(db, { actor: req.authContext?.tokenId ?? 'unknown', action: 'group.update', resourceId: id });
|
||||
return reply.send({ group } satisfies GroupResponse);
|
||||
} catch (err) {
|
||||
return sendManagerError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.delete('/api/v1/groups/:id', async (req, reply) => {
|
||||
const { id } = req.params as { id: string };
|
||||
if (!gm.deleteGroup(id)) {
|
||||
return reply.status(404).send({ error: { code: 'NOT_FOUND', message: 'No group with this id' } });
|
||||
}
|
||||
recordAudit(db, { actor: req.authContext?.tokenId ?? 'unknown', action: 'group.delete', resourceId: id });
|
||||
return reply.send({ ok: true });
|
||||
});
|
||||
|
||||
app.post('/api/v1/groups/:id/repos', async (req, reply) => {
|
||||
const { id } = req.params as { id: string };
|
||||
const body = req.body as Partial<AddRepoRequest> | null;
|
||||
if (!body || typeof body.repoId !== 'string') {
|
||||
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'repoId is required' } });
|
||||
}
|
||||
try {
|
||||
return reply.send({ group: gm.addRepo(id, body.repoId) } satisfies GroupResponse);
|
||||
} catch (err) {
|
||||
return sendManagerError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.delete('/api/v1/groups/:id/repos/:repoId', async (req, reply) => {
|
||||
const { id, repoId } = req.params as { id: string; repoId: string };
|
||||
try {
|
||||
return reply.send({ group: gm.removeRepo(id, repoId) } satisfies GroupResponse);
|
||||
} catch (err) {
|
||||
return sendManagerError(reply, err);
|
||||
}
|
||||
});
|
||||
}
|
||||
@@ -3,8 +3,10 @@
|
||||
import type { FastifyInstance } from 'fastify';
|
||||
import type { PushSubscribeRequest, PushUnsubscribeRequest, VapidKeyResponse } from '@arboretum/shared';
|
||||
import type { PushService } from '../core/push-service.js';
|
||||
import type { Db } from '../db/index.js';
|
||||
import { recordAudit } from '../core/audit-log.js';
|
||||
|
||||
export function registerPushRoutes(app: FastifyInstance, push: PushService): void {
|
||||
export function registerPushRoutes(app: FastifyInstance, push: PushService, db: Db): void {
|
||||
app.get('/api/v1/push/vapid-public-key', async (): Promise<VapidKeyResponse> => ({ key: push.publicKey() }));
|
||||
|
||||
app.post('/api/v1/push/subscribe', async (req, reply) => {
|
||||
@@ -15,6 +17,7 @@ export function registerPushRoutes(app: FastifyInstance, push: PushService): voi
|
||||
// garanti non-null : la route est protégée par le preValidation global.
|
||||
const tokenId = req.authContext!.tokenId;
|
||||
push.subscribe(tokenId, { endpoint: body.endpoint, keys: { p256dh: body.keys.p256dh, auth: body.keys.auth } }, req.headers['user-agent'] ?? null);
|
||||
recordAudit(db, { actor: tokenId, action: 'push.subscribe' });
|
||||
return reply.status(201).send({ ok: true });
|
||||
});
|
||||
|
||||
@@ -24,6 +27,7 @@ export function registerPushRoutes(app: FastifyInstance, push: PushService): voi
|
||||
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'endpoint is required' } });
|
||||
}
|
||||
push.unsubscribe(body.endpoint);
|
||||
recordAudit(db, { actor: req.authContext?.tokenId ?? 'unknown', action: 'push.unsubscribe' });
|
||||
return reply.send({ ok: true });
|
||||
});
|
||||
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
import type { FastifyInstance, FastifyReply } from 'fastify';
|
||||
import type { CreateRepoRequest, RepoResponse, ReposListResponse, UpdateRepoRequest } from '@arboretum/shared';
|
||||
import type { CreateRepoRequest, DiscoverReposResponse, RepoResponse, ReposListResponse, UpdateRepoRequest } from '@arboretum/shared';
|
||||
import type { WorktreeManager } from '../core/worktree-manager.js';
|
||||
import type { Db } from '../db/index.js';
|
||||
import { readScanRoots } from '../core/scan-settings.js';
|
||||
|
||||
/** Mappe une erreur du manager (statusCode + code) vers une réponse REST normalisée. */
|
||||
export function sendManagerError(reply: FastifyReply, err: unknown): FastifyReply {
|
||||
@@ -8,9 +10,19 @@ export function sendManagerError(reply: FastifyReply, err: unknown): FastifyRepl
|
||||
return reply.status(e.statusCode ?? 500).send({ error: { code: e.code ?? 'INTERNAL', message: e.message ?? 'Internal error' } });
|
||||
}
|
||||
|
||||
export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager): void {
|
||||
export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager, db: Db): void {
|
||||
app.get('/api/v1/repos', async (): Promise<ReposListResponse> => ({ repos: await wt.listRepos() }));
|
||||
|
||||
// Scan manuel : découvre et auto-enregistre les repos sous les racines configurées (settings).
|
||||
app.post('/api/v1/repos/discover', async (_req, reply) => {
|
||||
try {
|
||||
const res: DiscoverReposResponse = await wt.discoverRepos({ roots: readScanRoots(db) });
|
||||
return reply.send(res);
|
||||
} catch (err) {
|
||||
return sendManagerError(reply, err);
|
||||
}
|
||||
});
|
||||
|
||||
app.post('/api/v1/repos', async (req, reply) => {
|
||||
const body = req.body as Partial<CreateRepoRequest> | null;
|
||||
if (!body || typeof body.path !== 'string') {
|
||||
@@ -38,6 +50,7 @@ export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager): v
|
||||
...(body.label !== undefined ? { label: body.label } : {}),
|
||||
...(body.postCreateHooks !== undefined ? { postCreateHooks: body.postCreateHooks } : {}),
|
||||
...(body.preTrust !== undefined ? { preTrust: body.preTrust } : {}),
|
||||
...(typeof body.hidden === 'boolean' ? { hidden: body.hidden } : {}),
|
||||
});
|
||||
const res: RepoResponse = { repo };
|
||||
return reply.send(res);
|
||||
|
||||
69
packages/server/src/routes/settings.ts
Normal file
69
packages/server/src/routes/settings.ts
Normal file
@@ -0,0 +1,69 @@
|
||||
// Réglages exposés à l'UI (onglet Réglages). Frontière de sécurité CENTRALE : la table `settings`
|
||||
// contient aussi des SECRETS (server_secret, vapid_private). Ces routes n'exposent QUE des champs
|
||||
// non sensibles et n'écrivent QUE des clés explicitement allow-listées — jamais les secrets.
|
||||
import type { FastifyInstance } from 'fastify';
|
||||
import type { ServerInfo, SettingsResponse, UpdateSettingsRequest } from '@arboretum/shared';
|
||||
import type { Config } from '../config.js';
|
||||
import { type Db, setSetting } from '../db/index.js';
|
||||
import type { PushService } from '../core/push-service.js';
|
||||
import { recordAudit } from '../core/audit-log.js';
|
||||
import {
|
||||
SCAN_INTERVAL_KEY,
|
||||
SCAN_ROOTS_KEY,
|
||||
normalizeScanIntervalMin,
|
||||
normalizeScanRoots,
|
||||
readScanIntervalMin,
|
||||
readScanRoots,
|
||||
} from '../core/scan-settings.js';
|
||||
|
||||
// Réglages modifiables via l'API (allow-list stricte). Les secrets ne figurent JAMAIS ici.
|
||||
export function registerSettingsRoutes(
|
||||
app: FastifyInstance,
|
||||
db: Db,
|
||||
config: Config,
|
||||
serverVersion: string,
|
||||
push: PushService,
|
||||
): void {
|
||||
const serverInfo = (): ServerInfo => ({
|
||||
version: serverVersion,
|
||||
port: config.port,
|
||||
bind: config.bind,
|
||||
allowedOrigins: config.allowedOrigins,
|
||||
dataDir: config.dataDir,
|
||||
vapidPublicKey: push.publicKey() || null,
|
||||
vapidContact: config.vapidContact,
|
||||
});
|
||||
const snapshot = (): SettingsResponse => ({
|
||||
settings: {
|
||||
scanRoots: readScanRoots(db),
|
||||
scanIntervalMin: readScanIntervalMin(db),
|
||||
},
|
||||
server: serverInfo(),
|
||||
});
|
||||
|
||||
app.get('/api/v1/settings', async (): Promise<SettingsResponse> => snapshot());
|
||||
|
||||
app.patch('/api/v1/settings', async (req, reply) => {
|
||||
const body = (req.body as Partial<UpdateSettingsRequest> | null) ?? {};
|
||||
if ('scanRoots' in body) {
|
||||
const roots = normalizeScanRoots(body.scanRoots);
|
||||
if (!roots) {
|
||||
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'scanRoots must be an array of ≤16 absolute, normalized paths (never "/")' } });
|
||||
}
|
||||
setSetting(db, SCAN_ROOTS_KEY, JSON.stringify(roots));
|
||||
}
|
||||
if ('scanIntervalMin' in body) {
|
||||
const interval = normalizeScanIntervalMin(body.scanIntervalMin);
|
||||
if (interval === null) {
|
||||
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'scanIntervalMin must be an integer between 0 and 1440' } });
|
||||
}
|
||||
setSetting(db, SCAN_INTERVAL_KEY, String(interval));
|
||||
}
|
||||
recordAudit(db, {
|
||||
actor: req.authContext?.tokenId ?? 'unknown',
|
||||
action: 'settings.update',
|
||||
details: { keys: Object.keys(body) },
|
||||
});
|
||||
return reply.send(snapshot());
|
||||
});
|
||||
}
|
||||
@@ -5,6 +5,7 @@ import {
|
||||
PROTOCOL_VERSION,
|
||||
encodeBinaryFrame,
|
||||
parseClientMessage,
|
||||
type GroupSummary,
|
||||
type RepoSummary,
|
||||
type ServerMessage,
|
||||
type SessionSummary,
|
||||
@@ -13,6 +14,7 @@ import {
|
||||
import type { ClientBinding, PtyManager } from '../core/pty-manager.js';
|
||||
import type { DiscoveryService } from '../core/discovery-service.js';
|
||||
import type { WorktreeManager } from '../core/worktree-manager.js';
|
||||
import type { GroupManager } from '../core/group-manager.js';
|
||||
|
||||
const HEARTBEAT_MS = 30_000;
|
||||
|
||||
@@ -26,6 +28,7 @@ export function registerWsGateway(
|
||||
manager: PtyManager,
|
||||
discovery: DiscoveryService,
|
||||
worktrees: WorktreeManager,
|
||||
groups: GroupManager,
|
||||
serverVersion: string,
|
||||
): void {
|
||||
app.get('/ws', { websocket: true }, (socket: WebSocket, req) => {
|
||||
@@ -35,6 +38,7 @@ export function registerWsGateway(
|
||||
let helloDone = false;
|
||||
let subscribedSessions = false;
|
||||
let subscribedWorktrees = false;
|
||||
let subscribedGroups = false;
|
||||
let alive = true;
|
||||
|
||||
const send = (msg: ServerMessage): void => {
|
||||
@@ -66,6 +70,12 @@ export function registerWsGateway(
|
||||
const onWorktreeRemoved = (e: { repoId: string; path: string }): void => {
|
||||
if (subscribedWorktrees) send({ type: 'worktree_removed', ...e });
|
||||
};
|
||||
const onGroupUpdate = (group: GroupSummary): void => {
|
||||
if (subscribedGroups) send({ type: 'group_update', group });
|
||||
};
|
||||
const onGroupRemoved = (groupId: string): void => {
|
||||
if (subscribedGroups) send({ type: 'group_removed', groupId });
|
||||
};
|
||||
manager.on('session_update', onSessionUpdate);
|
||||
manager.on('session_exit', onSessionExit);
|
||||
discovery.on('discovery_update', onDiscoveryUpdate);
|
||||
@@ -73,6 +83,8 @@ export function registerWsGateway(
|
||||
worktrees.on('repo_removed', onRepoRemoved);
|
||||
worktrees.on('worktree_update', onWorktreeUpdate);
|
||||
worktrees.on('worktree_removed', onWorktreeRemoved);
|
||||
groups.on('group_update', onGroupUpdate);
|
||||
groups.on('group_removed', onGroupRemoved);
|
||||
|
||||
const heartbeat = setInterval(() => {
|
||||
if (!alive) {
|
||||
@@ -111,6 +123,7 @@ export function registerWsGateway(
|
||||
case 'sub': {
|
||||
subscribedSessions = msg.topics.includes('sessions');
|
||||
subscribedWorktrees = msg.topics.includes('worktrees');
|
||||
subscribedGroups = msg.topics.includes('groups');
|
||||
return;
|
||||
}
|
||||
case 'attach': {
|
||||
@@ -202,6 +215,8 @@ export function registerWsGateway(
|
||||
worktrees.off('repo_removed', onRepoRemoved);
|
||||
worktrees.off('worktree_update', onWorktreeUpdate);
|
||||
worktrees.off('worktree_removed', onWorktreeRemoved);
|
||||
groups.off('group_update', onGroupUpdate);
|
||||
groups.off('group_removed', onGroupRemoved);
|
||||
for (const [, st] of channels) manager.detach(st.sessionId, st.binding);
|
||||
channels.clear();
|
||||
});
|
||||
|
||||
@@ -7,6 +7,7 @@ import { openDb, type Db } from '../src/db/index.js';
|
||||
import { munge } from '../src/core/jsonl-discovery.js';
|
||||
import { readProcStart } from '../src/core/session-registry.js';
|
||||
import type { Config } from '../src/config.js';
|
||||
import type { DiscoverReposResponse, RepoResponse, ReposListResponse } from '@arboretum/shared';
|
||||
|
||||
// resolveClaudeBin() fait `which claude` : on le stub pour ne pas dépendre d'un claude réel en PATH.
|
||||
vi.mock('node:child_process', () => ({ execFileSync: () => '/usr/bin/claude\n' }));
|
||||
@@ -91,9 +92,25 @@ describe('app e2e — auth, origin et sessions', () => {
|
||||
expect(cookie).toBeDefined();
|
||||
expect(cookie?.httpOnly).toBe(true);
|
||||
expect(cookie?.sameSite).toBe('Strict');
|
||||
// Login local (http, pas de x-forwarded-proto) → pas de Secure, sinon le cookie casserait en localhost.
|
||||
expect(cookie?.secure).toBeFalsy();
|
||||
cookieValue = cookie!.value;
|
||||
});
|
||||
|
||||
it('cookie Secure posé derrière un front HTTPS (x-forwarded-proto)', async () => {
|
||||
const res = await t.bundle.app.inject({
|
||||
method: 'POST',
|
||||
url: '/api/v1/auth/login',
|
||||
headers: { 'x-forwarded-proto': 'https' },
|
||||
payload: { token: t.token },
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
const cookie = res.cookies.find((c) => c.name === 'arb_session');
|
||||
expect(cookie?.secure).toBe(true);
|
||||
expect(cookie?.httpOnly).toBe(true);
|
||||
expect(cookie?.sameSite).toBe('Strict');
|
||||
});
|
||||
|
||||
it('routes API sans auth → 401', async () => {
|
||||
for (const url of ['/api/v1/sessions', '/api/v1/auth/me']) {
|
||||
const res = await t.bundle.app.inject({ method: 'GET', url });
|
||||
@@ -111,7 +128,8 @@ describe('app e2e — auth, origin et sessions', () => {
|
||||
cookies: { arb_session: cookieValue },
|
||||
});
|
||||
expect(me.statusCode).toBe(200);
|
||||
expect(me.json()).toEqual({ ok: true, tokenLabel: 'initial', serverVersion: '0.0.0-test' });
|
||||
expect(me.json()).toMatchObject({ ok: true, tokenLabel: 'initial', serverVersion: '0.0.0-test' });
|
||||
expect(typeof (me.json() as { tokenId: string }).tokenId).toBe('string');
|
||||
});
|
||||
|
||||
it('cookie altéré → 401', async () => {
|
||||
@@ -337,3 +355,59 @@ describe('app e2e — découverte, resume & fork (P2)', () => {
|
||||
expect(fork.statusCode).toBe(201);
|
||||
});
|
||||
});
|
||||
|
||||
describe('app e2e — découverte auto des repos & masquage', () => {
|
||||
let t: TestApp;
|
||||
let scanRoot: string;
|
||||
const bearer = (): Record<string, string> => ({ authorization: `Bearer ${t.token}` });
|
||||
|
||||
beforeAll(() => {
|
||||
t = makeApp('repos-discover');
|
||||
// un « repo » côté scanner = un dossier avec .git (le scanner ne lance pas git).
|
||||
scanRoot = join(dir, 'scan-root');
|
||||
mkdirSync(join(scanRoot, 'alpha', '.git'), { recursive: true });
|
||||
mkdirSync(join(scanRoot, 'beta', '.git'), { recursive: true });
|
||||
});
|
||||
|
||||
it('POST /repos/discover enregistre les repos sous les racines configurées', async () => {
|
||||
// configure la racine de scan via l'allow-list settings, désactive le périodique
|
||||
const patch = await t.bundle.app.inject({
|
||||
method: 'PATCH',
|
||||
url: '/api/v1/settings',
|
||||
headers: bearer(),
|
||||
payload: { scanRoots: [scanRoot], scanIntervalMin: 0 },
|
||||
});
|
||||
expect(patch.statusCode).toBe(200);
|
||||
|
||||
const disc = await t.bundle.app.inject({ method: 'POST', url: '/api/v1/repos/discover', headers: bearer() });
|
||||
expect(disc.statusCode).toBe(200);
|
||||
const body = disc.json() as DiscoverReposResponse;
|
||||
expect(body.added).toBe(2);
|
||||
expect(body.scanned).toBe(2);
|
||||
|
||||
const list = await t.bundle.app.inject({ method: 'GET', url: '/api/v1/repos', headers: bearer() });
|
||||
const repos = (list.json() as ReposListResponse).repos;
|
||||
expect(repos.map((r) => r.label).sort()).toEqual(['alpha', 'beta']);
|
||||
expect(repos.every((r) => r.hidden === false)).toBe(true);
|
||||
|
||||
// re-scan : idempotent (aucun nouveau)
|
||||
const disc2 = await t.bundle.app.inject({ method: 'POST', url: '/api/v1/repos/discover', headers: bearer() });
|
||||
expect((disc2.json() as DiscoverReposResponse).added).toBe(0);
|
||||
});
|
||||
|
||||
it('PATCH /repos/:id { hidden } masque le repo', async () => {
|
||||
const list = await t.bundle.app.inject({ method: 'GET', url: '/api/v1/repos', headers: bearer() });
|
||||
const repo = (list.json() as ReposListResponse).repos[0];
|
||||
const patch = await t.bundle.app.inject({
|
||||
method: 'PATCH',
|
||||
url: `/api/v1/repos/${repo.id}`,
|
||||
headers: bearer(),
|
||||
payload: { hidden: true },
|
||||
});
|
||||
expect(patch.statusCode).toBe(200);
|
||||
expect((patch.json() as RepoResponse).repo.hidden).toBe(true);
|
||||
// toujours listé (les masqués restent récupérables) mais avec hidden=true
|
||||
const after = await t.bundle.app.inject({ method: 'GET', url: '/api/v1/repos', headers: bearer() });
|
||||
expect((after.json() as ReposListResponse).repos.find((r) => r.id === repo.id)?.hidden).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
164
packages/server/test/audit-data-routes.test.ts
Normal file
164
packages/server/test/audit-data-routes.test.ts
Normal file
@@ -0,0 +1,164 @@
|
||||
// Lot 5 — sécurité enterprise : en-têtes de sécurité, journal d'audit, RGPD (export/suppression),
|
||||
// garde Content-Type. Vérifie le câblage de bout en bout via buildApp + token bootstrap.
|
||||
import { mkdtempSync, rmSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { afterAll, beforeAll, describe, expect, it, vi } from 'vitest';
|
||||
import { buildApp, type AppBundle } from '../src/app.js';
|
||||
import { openDb, type Db } from '../src/db/index.js';
|
||||
import type { Config } from '../src/config.js';
|
||||
import type { AuditLogsResponse, DataExportResponse, DeleteMyDataResponse } from '@arboretum/shared';
|
||||
|
||||
vi.mock('node:child_process', () => ({ execFileSync: () => '/usr/bin/claude\n' }));
|
||||
vi.mock('@homebridge/node-pty-prebuilt-multiarch', () => {
|
||||
class FakePty {
|
||||
pid = 424242;
|
||||
write = vi.fn();
|
||||
resize = vi.fn();
|
||||
pause = vi.fn();
|
||||
resume = vi.fn();
|
||||
kill = vi.fn();
|
||||
onData(): { dispose: () => void } {
|
||||
return { dispose: () => {} };
|
||||
}
|
||||
onExit(): { dispose: () => void } {
|
||||
return { dispose: () => {} };
|
||||
}
|
||||
}
|
||||
return { default: { spawn: (): FakePty => new FakePty() } };
|
||||
});
|
||||
|
||||
process.env.ARBORETUM_LOG = 'silent';
|
||||
|
||||
let dir: string;
|
||||
let bundle: AppBundle;
|
||||
let db: Db;
|
||||
let token: string;
|
||||
const auth = (): { authorization: string } => ({ authorization: `Bearer ${token}` });
|
||||
|
||||
beforeAll(() => {
|
||||
dir = mkdtempSync(join(tmpdir(), 'arboretum-audit-'));
|
||||
const dbPath = join(dir, 'audit.db');
|
||||
db = openDb(dbPath);
|
||||
const config: Config = {
|
||||
port: 9998,
|
||||
bind: '127.0.0.1',
|
||||
dbPath,
|
||||
dataDir: dir,
|
||||
allowedOrigins: ['https://host.tailnet.ts.net'],
|
||||
printToken: false,
|
||||
claudeProjectsDir: join(dir, 'claude', 'projects'),
|
||||
claudeSessionsDir: join(dir, 'claude', 'sessions'),
|
||||
vapidContact: 'mailto:test@localhost',
|
||||
autoDiscover: false,
|
||||
};
|
||||
bundle = buildApp(config, db, '1.2.3-test');
|
||||
const t = bundle.auth.ensureBootstrapToken();
|
||||
if (!t) throw new Error('bootstrap token attendu');
|
||||
token = t;
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
await bundle.app.close();
|
||||
db.close();
|
||||
rmSync(dir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
describe('En-têtes de sécurité', () => {
|
||||
it('pose les en-têtes durs + no-store sur /api, sans header Server', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/me', headers: auth() });
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.headers['x-content-type-options']).toBe('nosniff');
|
||||
expect(res.headers['x-frame-options']).toBe('DENY');
|
||||
expect(res.headers['referrer-policy']).toBe('no-referrer');
|
||||
expect(res.headers['content-security-policy']).toContain("default-src 'self'");
|
||||
expect(res.headers['content-security-policy']).toContain("frame-ancestors 'none'");
|
||||
expect(String(res.headers['cache-control'])).toContain('no-store');
|
||||
expect(res.headers['server']).toBeUndefined();
|
||||
});
|
||||
|
||||
it('pose HSTS uniquement derrière HTTPS (x-forwarded-proto)', async () => {
|
||||
const http = await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/me', headers: auth() });
|
||||
expect(http.headers['strict-transport-security']).toBeUndefined();
|
||||
const https = await bundle.app.inject({
|
||||
method: 'GET',
|
||||
url: '/api/v1/auth/me',
|
||||
headers: { ...auth(), 'x-forwarded-proto': 'https' },
|
||||
});
|
||||
expect(String(https.headers['strict-transport-security'])).toContain('max-age=');
|
||||
});
|
||||
|
||||
it('rejette une mutation avec corps non-JSON (415)', async () => {
|
||||
const res = await bundle.app.inject({
|
||||
method: 'POST',
|
||||
url: '/api/v1/auth/tokens',
|
||||
headers: { ...auth(), 'content-type': 'text/plain' },
|
||||
payload: 'label=pwned',
|
||||
});
|
||||
expect(res.statusCode).toBe(415);
|
||||
});
|
||||
});
|
||||
|
||||
describe('Journal d’audit', () => {
|
||||
it('journalise la création de token et l’expose via GET /audit-logs', async () => {
|
||||
const create = await bundle.app.inject({
|
||||
method: 'POST',
|
||||
url: '/api/v1/auth/tokens',
|
||||
headers: auth(),
|
||||
payload: { label: 'ci-extra' },
|
||||
});
|
||||
expect(create.statusCode).toBe(201);
|
||||
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/audit-logs', headers: auth() });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json() as AuditLogsResponse;
|
||||
const actions = body.entries.map((e) => e.action);
|
||||
expect(actions).toContain('token.create');
|
||||
expect(actions).toContain('secret.generate'); // généré au bootstrap (system)
|
||||
// aucune VALEUR secrète en clair : pas de chaîne hex de 64 caractères (server_secret / clé).
|
||||
// (les ids sont des UUID avec tirets → non concernés ; 'server_secret' est un nom de ressource.)
|
||||
expect(res.body).not.toMatch(/[a-f0-9]{64}/i);
|
||||
});
|
||||
|
||||
it('journalise les échecs de login (actor anonymous)', async () => {
|
||||
await bundle.app.inject({ method: 'POST', url: '/api/v1/auth/login', payload: { token: 'arb_invalid_xxx' } });
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/audit-logs?limit=200', headers: auth() });
|
||||
const body = res.json() as AuditLogsResponse;
|
||||
expect(body.entries.some((e) => e.action === 'login.failure' && e.actor === 'anonymous')).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
describe('RGPD', () => {
|
||||
it('exporte les données du token authentifié', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/data/export', headers: auth() });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json() as DataExportResponse;
|
||||
expect(Array.isArray(body.tokens)).toBe(true);
|
||||
expect(body.tokens.some((t) => t.current)).toBe(true);
|
||||
expect(Array.isArray(body.pushSubscriptions)).toBe(true);
|
||||
expect(Array.isArray(body.sessions)).toBe(true);
|
||||
expect(body.settings).toHaveProperty('scanRoots');
|
||||
});
|
||||
|
||||
it('supprime en deux temps (pending → confirm → done) et révoque le token', async () => {
|
||||
const pending = await bundle.app.inject({ method: 'POST', url: '/api/v1/data/delete-my-data', headers: auth(), payload: {} });
|
||||
const p = pending.json() as DeleteMyDataResponse;
|
||||
expect(p.status).toBe('pending');
|
||||
expect(p.confirm).toBeTruthy();
|
||||
|
||||
// un 2e token existe (créé plus haut) → révoquer le token courant est autorisé.
|
||||
const done = await bundle.app.inject({
|
||||
method: 'POST',
|
||||
url: '/api/v1/data/delete-my-data',
|
||||
headers: auth(),
|
||||
payload: { confirm: p.confirm },
|
||||
});
|
||||
const d = done.json() as DeleteMyDataResponse;
|
||||
expect(d.status).toBe('done');
|
||||
expect(d.summary.tokenRevoked).toBe(true);
|
||||
|
||||
// le token courant est désormais révoqué → 401.
|
||||
const after = await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/me', headers: auth() });
|
||||
expect(after.statusCode).toBe(401);
|
||||
});
|
||||
});
|
||||
143
packages/server/test/auth-tokens.test.ts
Normal file
143
packages/server/test/auth-tokens.test.ts
Normal file
@@ -0,0 +1,143 @@
|
||||
// Gestion des tokens d'accès via l'API REST (onglet Réglages) : create → list → revoke,
|
||||
// flag « courant », jamais de hash exposé, garde anti lock-out sur le dernier token.
|
||||
import { mkdtempSync, rmSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { afterAll, beforeAll, describe, expect, it, vi } from 'vitest';
|
||||
import { buildApp, type AppBundle } from '../src/app.js';
|
||||
import { openDb, type Db } from '../src/db/index.js';
|
||||
import type { Config } from '../src/config.js';
|
||||
import type { CreateTokenResponse, MeResponse, TokensListResponse } from '@arboretum/shared';
|
||||
|
||||
// Mêmes stubs que les autres tests de routes : pas de vrai claude ni de vrai PTY.
|
||||
vi.mock('node:child_process', () => ({ execFileSync: () => '/usr/bin/claude\n' }));
|
||||
vi.mock('@homebridge/node-pty-prebuilt-multiarch', () => {
|
||||
class FakePty {
|
||||
pid = 424242;
|
||||
write = vi.fn();
|
||||
resize = vi.fn();
|
||||
pause = vi.fn();
|
||||
resume = vi.fn();
|
||||
kill = vi.fn();
|
||||
onData(): { dispose: () => void } {
|
||||
return { dispose: () => {} };
|
||||
}
|
||||
onExit(): { dispose: () => void } {
|
||||
return { dispose: () => {} };
|
||||
}
|
||||
}
|
||||
return { default: { spawn: (): FakePty => new FakePty() } };
|
||||
});
|
||||
|
||||
process.env.ARBORETUM_LOG = 'silent';
|
||||
|
||||
let dir: string;
|
||||
let bundle: AppBundle;
|
||||
let db: Db;
|
||||
let token: string;
|
||||
|
||||
const auth = (): { authorization: string } => ({ authorization: `Bearer ${token}` });
|
||||
|
||||
beforeAll(() => {
|
||||
dir = mkdtempSync(join(tmpdir(), 'arboretum-tokens-'));
|
||||
const dbPath = join(dir, 'tokens.db');
|
||||
db = openDb(dbPath);
|
||||
const config: Config = {
|
||||
port: 7317,
|
||||
bind: '127.0.0.1',
|
||||
dbPath,
|
||||
dataDir: dir,
|
||||
allowedOrigins: [],
|
||||
printToken: false,
|
||||
claudeProjectsDir: join(dir, 'claude', 'projects'),
|
||||
claudeSessionsDir: join(dir, 'claude', 'sessions'),
|
||||
vapidContact: 'mailto:test@localhost',
|
||||
};
|
||||
bundle = buildApp(config, db, '0.0.0-test');
|
||||
const t = bundle.auth.ensureBootstrapToken();
|
||||
if (!t) throw new Error('bootstrap token attendu sur une base vierge');
|
||||
token = t;
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
await bundle.app.close();
|
||||
db.close();
|
||||
rmSync(dir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
describe('routes de gestion des tokens', () => {
|
||||
it('GET /auth/me expose le tokenId courant', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/me', headers: auth() });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const me = res.json() as MeResponse;
|
||||
expect(typeof me.tokenId).toBe('string');
|
||||
expect(me.tokenId.length).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
it('liste le token initial et le marque « courant », sans jamais exposer de hash', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/tokens', headers: auth() });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json() as TokensListResponse;
|
||||
expect(body.tokens).toHaveLength(1);
|
||||
expect(body.tokens[0]?.label).toBe('initial');
|
||||
expect(body.tokens[0]?.current).toBe(true);
|
||||
// aucune fuite de hash / valeur en clair
|
||||
expect(JSON.stringify(body)).not.toMatch(/token_hash|tokenHash/);
|
||||
});
|
||||
|
||||
it('crée un token (valeur en clair renvoyée une fois), puis utilisable pour s’authentifier', async () => {
|
||||
const res = await bundle.app.inject({
|
||||
method: 'POST',
|
||||
url: '/api/v1/auth/tokens',
|
||||
headers: auth(),
|
||||
payload: { label: 'laptop' },
|
||||
});
|
||||
expect(res.statusCode).toBe(201);
|
||||
const created = res.json() as CreateTokenResponse;
|
||||
expect(created.label).toBe('laptop');
|
||||
expect(created.token).toMatch(/^arb_[0-9a-f]{48}$/);
|
||||
|
||||
// le nouveau token authentifie réellement
|
||||
const me = await bundle.app.inject({
|
||||
method: 'GET',
|
||||
url: '/api/v1/auth/me',
|
||||
headers: { authorization: `Bearer ${created.token}` },
|
||||
});
|
||||
expect((me.json() as MeResponse).tokenLabel).toBe('laptop');
|
||||
});
|
||||
|
||||
it('rejette un label vide ou trop long (400)', async () => {
|
||||
const empty = await bundle.app.inject({ method: 'POST', url: '/api/v1/auth/tokens', headers: auth(), payload: { label: ' ' } });
|
||||
expect(empty.statusCode).toBe(400);
|
||||
const tooLong = await bundle.app.inject({ method: 'POST', url: '/api/v1/auth/tokens', headers: auth(), payload: { label: 'x'.repeat(65) } });
|
||||
expect(tooLong.statusCode).toBe(400);
|
||||
});
|
||||
|
||||
it('révoque un token non courant (204), qui disparaît de la liste et n’authentifie plus', async () => {
|
||||
const before = (await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/tokens', headers: auth() })).json() as TokensListResponse;
|
||||
const victim = before.tokens.find((t) => !t.current);
|
||||
expect(victim).toBeDefined();
|
||||
const del = await bundle.app.inject({ method: 'DELETE', url: `/api/v1/auth/tokens/${victim!.id}`, headers: auth() });
|
||||
expect(del.statusCode).toBe(200);
|
||||
const after = (await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/tokens', headers: auth() })).json() as TokensListResponse;
|
||||
expect(after.tokens.find((t) => t.id === victim!.id)).toBeUndefined();
|
||||
});
|
||||
|
||||
it('404 sur un id inconnu', async () => {
|
||||
const res = await bundle.app.inject({ method: 'DELETE', url: '/api/v1/auth/tokens/nope-xyz', headers: auth() });
|
||||
expect(res.statusCode).toBe(404);
|
||||
});
|
||||
|
||||
it('409 LAST_TOKEN : refuse de révoquer le dernier token actif', async () => {
|
||||
const list = (await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/tokens', headers: auth() })).json() as TokensListResponse;
|
||||
expect(list.tokens).toHaveLength(1); // seul le token courant subsiste
|
||||
const res = await bundle.app.inject({ method: 'DELETE', url: `/api/v1/auth/tokens/${list.tokens[0]!.id}`, headers: auth() });
|
||||
expect(res.statusCode).toBe(409);
|
||||
expect(res.json()).toMatchObject({ error: { code: 'LAST_TOKEN' } });
|
||||
});
|
||||
|
||||
it('sans authentification → 401', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/auth/tokens' });
|
||||
expect(res.statusCode).toBe(401);
|
||||
});
|
||||
});
|
||||
166
packages/server/test/cli-install.test.ts
Normal file
166
packages/server/test/cli-install.test.ts
Normal file
@@ -0,0 +1,166 @@
|
||||
import { afterEach, describe, expect, it } from 'vitest';
|
||||
import { homedir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import {
|
||||
detectPlatform,
|
||||
parseInstallArgs,
|
||||
buildServiceArgs,
|
||||
resolveBin,
|
||||
resolveScriptPath,
|
||||
renderSystemdUnit,
|
||||
renderLaunchAgentPlist,
|
||||
xmlEscape,
|
||||
systemdUnitPath,
|
||||
launchAgentPlistPath,
|
||||
} from '../src/cli/install.js';
|
||||
|
||||
describe('cli install — detectPlatform', () => {
|
||||
it('accepte linux et darwin', () => {
|
||||
expect(detectPlatform('linux')).toBe('linux');
|
||||
expect(detectPlatform('darwin')).toBe('darwin');
|
||||
});
|
||||
|
||||
it('rejette les autres plateformes avec un message clair', () => {
|
||||
expect(() => detectPlatform('win32')).toThrow(/Linux \(systemd\) and macOS \(launchd\)/);
|
||||
expect(() => detectPlatform('freebsd')).toThrow(/freebsd/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('cli install — buildServiceArgs', () => {
|
||||
it('aucun flag → aucun argument (le service garde les défauts loopback)', () => {
|
||||
expect(buildServiceArgs(parseInstallArgs([]))).toEqual([]);
|
||||
});
|
||||
|
||||
it('propage --port et --allow-origin (répétable) dans un ordre stable', () => {
|
||||
const flags = parseInstallArgs(['--port', '8080', '--allow-origin', 'a', '--allow-origin', 'b']);
|
||||
expect(buildServiceArgs(flags)).toEqual(['--port', '8080', '--allow-origin', 'a', '--allow-origin', 'b']);
|
||||
});
|
||||
|
||||
it("n'injecte JAMAIS --i-know-this-exposes-a-terminal (modèle de sécurité)", () => {
|
||||
const flags = parseInstallArgs(['--bind', '0.0.0.0', '--port', '7317']);
|
||||
expect(buildServiceArgs(flags)).not.toContain('--i-know-this-exposes-a-terminal');
|
||||
});
|
||||
|
||||
it("ne propage pas les flags propres à l'install (bin-path, label, dry-run, no-enable)", () => {
|
||||
const flags = parseInstallArgs(['--bin-path', '/usr/local/bin/arboretum', '--label', 'x', '--dry-run', '--no-enable']);
|
||||
expect(buildServiceArgs(flags)).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('cli install — resolveBin', () => {
|
||||
it('par défaut : node (process.execPath) + dist/index.js', () => {
|
||||
const { exec, args } = resolveBin({});
|
||||
expect(exec).toBe(process.execPath);
|
||||
expect(args).toHaveLength(1);
|
||||
expect(args[0]).toBe(resolveScriptPath());
|
||||
expect(args[0]).toMatch(/index\.(js|ts)$/);
|
||||
});
|
||||
|
||||
it('--bin-path force le wrapper, sans argument de script', () => {
|
||||
expect(resolveBin({ binPath: '/usr/local/bin/arboretum' })).toEqual({
|
||||
exec: '/usr/local/bin/arboretum',
|
||||
args: [],
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe('cli install — renderSystemdUnit', () => {
|
||||
it('contient le ExecStart calculé et les directives clés', () => {
|
||||
const unit = renderSystemdUnit({ exec: '/usr/bin/node', scriptArgs: ['/opt/arboretum/index.js', '--port', '7317'] });
|
||||
expect(unit).toContain('ExecStart=/usr/bin/node /opt/arboretum/index.js --port 7317');
|
||||
expect(unit).toContain('Restart=on-failure');
|
||||
expect(unit).toContain('KillSignal=SIGTERM');
|
||||
expect(unit).toContain('TimeoutStopSec=10');
|
||||
expect(unit).toContain('WantedBy=default.target');
|
||||
});
|
||||
|
||||
it('quote les tokens contenant un espace', () => {
|
||||
const unit = renderSystemdUnit({ exec: '/path with space/node', scriptArgs: ['/s.js'] });
|
||||
expect(unit).toContain('ExecStart="/path with space/node" /s.js');
|
||||
});
|
||||
|
||||
it('snapshot du unit pour un jeu de flags fixe', () => {
|
||||
const unit = renderSystemdUnit({
|
||||
exec: '/usr/bin/node',
|
||||
scriptArgs: ['/opt/arboretum/index.js', '--port', '7317', '--allow-origin', 'https://m.ts.net'],
|
||||
});
|
||||
expect(unit).toMatchInlineSnapshot(`
|
||||
"[Unit]
|
||||
Description=Arboretum — git worktree & Claude Code dashboard
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/bin/node /opt/arboretum/index.js --port 7317 --allow-origin https://m.ts.net
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
KillSignal=SIGTERM
|
||||
TimeoutStopSec=10
|
||||
Environment=NODE_ENV=production
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
"
|
||||
`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('cli install — renderLaunchAgentPlist', () => {
|
||||
const base = {
|
||||
label: 'fr.lidge.arboretum',
|
||||
programArguments: ['/usr/bin/node', '/opt/index.js', '--port', '7317'],
|
||||
stdoutPath: '/Users/me/Library/Logs/arboretum/out.log',
|
||||
stderrPath: '/Users/me/Library/Logs/arboretum/err.log',
|
||||
};
|
||||
|
||||
it('contient le label, les ProgramArguments ordonnés et les clés launchd', () => {
|
||||
const plist = renderLaunchAgentPlist(base);
|
||||
expect(plist).toContain('<string>fr.lidge.arboretum</string>');
|
||||
const idxNode = plist.indexOf('<string>/usr/bin/node</string>');
|
||||
const idxScript = plist.indexOf('<string>/opt/index.js</string>');
|
||||
expect(idxNode).toBeGreaterThan(0);
|
||||
expect(idxScript).toBeGreaterThan(idxNode);
|
||||
expect(plist).toContain('<key>RunAtLoad</key>');
|
||||
expect(plist).toContain('<key>KeepAlive</key>');
|
||||
expect(plist).toContain('<key>StandardOutPath</key>');
|
||||
});
|
||||
|
||||
it('échappe les caractères XML dans les arguments (URL avec &)', () => {
|
||||
const plist = renderLaunchAgentPlist({
|
||||
...base,
|
||||
programArguments: ['/usr/bin/node', '/opt/index.js', '--allow-origin', 'https://a?b&c=d'],
|
||||
});
|
||||
expect(plist).toContain('https://a?b&c=d');
|
||||
expect(plist).not.toContain('b&c=d');
|
||||
});
|
||||
});
|
||||
|
||||
describe('cli install — xmlEscape', () => {
|
||||
it('échappe &, < et >', () => {
|
||||
expect(xmlEscape('a & b < c > d')).toBe('a & b < c > d');
|
||||
});
|
||||
});
|
||||
|
||||
describe('cli install — chemins', () => {
|
||||
const savedXdg = process.env.XDG_CONFIG_HOME;
|
||||
afterEach(() => {
|
||||
if (savedXdg === undefined) delete process.env.XDG_CONFIG_HOME;
|
||||
else process.env.XDG_CONFIG_HOME = savedXdg;
|
||||
});
|
||||
|
||||
it('systemdUnitPath respecte XDG_CONFIG_HOME', () => {
|
||||
process.env.XDG_CONFIG_HOME = '/tmp/xdg';
|
||||
expect(systemdUnitPath()).toBe('/tmp/xdg/systemd/user/arboretum.service');
|
||||
});
|
||||
|
||||
it('systemdUnitPath retombe sur ~/.config sans XDG_CONFIG_HOME', () => {
|
||||
delete process.env.XDG_CONFIG_HOME;
|
||||
expect(systemdUnitPath()).toBe(join(homedir(), '.config', 'systemd', 'user', 'arboretum.service'));
|
||||
});
|
||||
|
||||
it('launchAgentPlistPath place le plist dans ~/Library/LaunchAgents', () => {
|
||||
expect(launchAgentPlistPath('fr.lidge.arboretum')).toBe(
|
||||
join(homedir(), 'Library', 'LaunchAgents', 'fr.lidge.arboretum.plist'),
|
||||
);
|
||||
});
|
||||
});
|
||||
14
packages/server/test/fixtures/dialogs/ask2.raw
vendored
14
packages/server/test/fixtures/dialogs/ask2.raw
vendored
@@ -19,7 +19,7 @@
|
||||
[2GClaude[9GCode'll[17Gbe[20Gable[25Gto[28Gread,[34Gedit,[40Gand[44Gexecute[52Gfiles[58Ghere.
|
||||
|
||||
|
||||
|
||||
|
||||
[2G]8;id=zaxmda;https://code.claude.com/docs/en/security[38;2;153;153;153mSecurity guide[39m]8;;
|
||||
|
||||
|
||||
@@ -321,13 +321,13 @@
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[2C[6A[38;2;255;183;101mSim[8G[38;2;255;153;51mrin[14G[38;2;153;153;153m(2s · [38;2;177;177;177mthinking with xhigh effort[38;2;153;153;153m)[39m
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[19C[6A[38;2;173;173;173mthinking with xhigh effort[39m
|
||||
[19C[6A[38;2;173;173;173mthinking with xhigh effort[39m
|
||||
|
||||
|
||||
|
||||
@@ -343,7 +343,7 @@
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[19C[6A[38;2;161;161;161mthinking with xhigh effort[39m
|
||||
[19C[6A[38;2;161;161;161mthinking with xhigh effort[39m
|
||||
|
||||
|
||||
|
||||
@@ -359,7 +359,7 @@
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[21C[6A[38;2;153;153;153m57[34Gthinking with xhigh effort[39m
|
||||
[21C[6A[38;2;153;153;153m57[34Gthinking with xhigh effort[39m
|
||||
|
||||
|
||||
|
||||
@@ -566,7 +566,7 @@
|
||||
|
||||
[3G[38;2;153;153;153mesc[7Gto[10Ginterrupt[21G[38;2;255;204;0mYou've[28Gused[33G96%[37Gof[40Gyour[45Gsession[53Glimit[59G·[61Gresets[68G7pm[72G(America/Lima)[87G·[89G/usage-credits[104Gto[107Grequest[115Gmore[39m
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[4C[6A[38;2;255;153;51mn[8G[38;2;255;183;101mn[39m
|
||||
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
[2GClaude[9GCode'll[17Gbe[20Gable[25Gto[28Gread,[34Gedit,[40Gand[44Gexecute[52Gfiles[58Ghere.
|
||||
|
||||
|
||||
|
||||
|
||||
[2G]8;id=zaxmda;https://code.claude.com/docs/en/security[38;2;153;153;153mSecurity guide[39m]8;;
|
||||
|
||||
|
||||
@@ -475,7 +475,7 @@
|
||||
[14C[6A[38;2;153;153;153m4[35Gthought for 1s)[39m[K
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
[2GClaude[9GCode'll[17Gbe[20Gable[25Gto[28Gread,[34Gedit,[40Gand[44Gexecute[52Gfiles[58Ghere.
|
||||
|
||||
|
||||
|
||||
|
||||
[2G]8;id=zaxmda;https://code.claude.com/docs/en/security[38;2;153;153;153mSecurity guide[39m]8;;
|
||||
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
[2GClaude[9GCode'll[17Gbe[20Gable[25Gto[28Gread,[34Gedit,[40Gand[44Gexecute[52Gfiles[58Ghere.
|
||||
|
||||
|
||||
|
||||
|
||||
[2G]8;id=zaxmda;https://code.claude.com/docs/en/security[38;2;153;153;153mSecurity guide[39m]8;;
|
||||
|
||||
|
||||
@@ -218,13 +218,13 @@
|
||||
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[6A[38;2;255;153;51m✻[39m
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[6A[38;2;255;153;51m✽[39m
|
||||
@@ -242,7 +242,7 @@
|
||||
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[12C[6A[38;2;153;153;153m(1s · thinking with xhigh effort)[39m
|
||||
|
||||
|
||||
@@ -251,7 +251,7 @@
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[5C[6A[38;2;255;183;101mo[9G[38;2;255;153;51mn[14G[38;2;153;153;153m2[19G[38;2;169;169;169mthinking with xhigh effort[39m
|
||||
[5C[6A[38;2;255;183;101mo[9G[38;2;255;153;51mn[14G[38;2;153;153;153m2[19G[38;2;169;169;169mthinking with xhigh effort[39m
|
||||
|
||||
|
||||
|
||||
@@ -416,7 +416,7 @@
|
||||
[2B[38;2;153;153;153m❯ [39m[K
|
||||
|
||||
[38;2;136;136;136m────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────[39m
|
||||
|
||||
|
||||
[3G[38;2;153;153;153mesc[7Gto[10Ginterrupt[21G[38;2;255;204;0mYou've[28Gused[33G91%[37Gof[40Gyour[45Gsession[53Glimit[59G·[61Gresets[68G7pm[72G(America/Lima)[87G·[89G/usage-credits[104Gto[107Grequest[115Gmore[39m
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
@@ -430,16 +430,16 @@
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[6A[38;2;255;153;51m*[10Gng[39m
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
[2C[3A[?25h[?2026l[?2026h[?25l[2D[3B
|
||||
[11C[6A[38;2;255;153;51m…[39m
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -19,7 +19,7 @@
|
||||
[2GClaude[9GCode'll[17Gbe[20Gable[25Gto[28Gread,[34Gedit,[40Gand[44Gexecute[52Gfiles[58Ghere.
|
||||
|
||||
|
||||
|
||||
|
||||
[2G]8;id=zaxmda;https://code.claude.com/docs/en/security[38;2;153;153;153mSecurity guide[39m]8;;
|
||||
|
||||
|
||||
|
||||
100
packages/server/test/group-manager.test.ts
Normal file
100
packages/server/test/group-manager.test.ts
Normal file
@@ -0,0 +1,100 @@
|
||||
import { describe, expect, it, beforeEach, vi } from 'vitest';
|
||||
import { GroupManager } from '../src/core/group-manager.js';
|
||||
import { openDb, type Db } from '../src/db/index.js';
|
||||
|
||||
/** Insère un repo minimal directement (le GroupManager n'a besoin que de repos.id). */
|
||||
function insertRepo(db: Db, id: string, path: string): void {
|
||||
db.prepare(
|
||||
"INSERT INTO repos (id, path, label, default_branch, post_create_hooks, pre_trust, created_at) VALUES (?, ?, ?, NULL, '[]', 0, ?)",
|
||||
).run(id, path, id, new Date().toISOString());
|
||||
}
|
||||
|
||||
describe('GroupManager', () => {
|
||||
let db: Db;
|
||||
let gm: GroupManager;
|
||||
|
||||
beforeEach(() => {
|
||||
db = openDb(':memory:');
|
||||
insertRepo(db, 'repo-a', '/tmp/a');
|
||||
insertRepo(db, 'repo-b', '/tmp/b');
|
||||
gm = new GroupManager(db);
|
||||
});
|
||||
|
||||
it('createGroup : groupe vide, persisté, événement group_update émis', () => {
|
||||
const spy = vi.fn();
|
||||
gm.on('group_update', spy);
|
||||
const g = gm.createGroup({ label: 'Sprint 42' });
|
||||
expect(g).toMatchObject({ label: 'Sprint 42', description: null, color: null, repoIds: [] });
|
||||
expect(gm.listGroups()).toHaveLength(1);
|
||||
expect(spy).toHaveBeenCalledWith(expect.objectContaining({ id: g.id }));
|
||||
});
|
||||
|
||||
it('createGroup : repoIds initiaux ordonnés et dédoublonnés', () => {
|
||||
const g = gm.createGroup({ label: 'Eco', repoIds: ['repo-b', 'repo-a', 'repo-b'] });
|
||||
expect(g.repoIds).toEqual(['repo-b', 'repo-a']);
|
||||
});
|
||||
|
||||
it('createGroup : repoId inexistant → 404', () => {
|
||||
expect(() => gm.createGroup({ label: 'X', repoIds: ['nope'] })).toThrow(
|
||||
expect.objectContaining({ statusCode: 404, code: 'REPO_NOT_FOUND' }),
|
||||
);
|
||||
expect(gm.listGroups()).toHaveLength(0); // rollback de la transaction
|
||||
});
|
||||
|
||||
it('createGroup : validations (label vide / trop long, couleur invalide)', () => {
|
||||
expect(() => gm.createGroup({ label: ' ' })).toThrow(expect.objectContaining({ statusCode: 400 }));
|
||||
expect(() => gm.createGroup({ label: 'x'.repeat(101) })).toThrow(expect.objectContaining({ statusCode: 400 }));
|
||||
expect(() => gm.createGroup({ label: 'X', color: 'red' })).toThrow(expect.objectContaining({ statusCode: 400 }));
|
||||
expect(gm.createGroup({ label: 'X', color: '#4f46e5' }).color).toBe('#4f46e5');
|
||||
});
|
||||
|
||||
it('getGroup : id inconnu → 404', () => {
|
||||
expect(() => gm.getGroup('nope')).toThrow(expect.objectContaining({ statusCode: 404, code: 'NOT_FOUND' }));
|
||||
});
|
||||
|
||||
it('updateGroup : modifie label/description/color et bump updatedAt', () => {
|
||||
const g = gm.createGroup({ label: 'A' });
|
||||
const updated = gm.updateGroup(g.id, { label: 'B', description: 'hello', color: '#000000' });
|
||||
expect(updated).toMatchObject({ label: 'B', description: 'hello', color: '#000000' });
|
||||
expect(gm.updateGroup(g.id, { description: '' }).description).toBeNull(); // '' → null
|
||||
});
|
||||
|
||||
it('addRepo : idempotent (PRIMARY KEY), émet group_update', () => {
|
||||
const g = gm.createGroup({ label: 'A' });
|
||||
const spy = vi.fn();
|
||||
gm.on('group_update', spy);
|
||||
expect(gm.addRepo(g.id, 'repo-a').repoIds).toEqual(['repo-a']);
|
||||
expect(gm.addRepo(g.id, 'repo-a').repoIds).toEqual(['repo-a']); // pas de doublon
|
||||
expect(gm.addRepo(g.id, 'repo-b').repoIds).toEqual(['repo-a', 'repo-b']);
|
||||
expect(spy).toHaveBeenCalledTimes(3);
|
||||
});
|
||||
|
||||
it('addRepo : groupe ou repo inexistant → 404', () => {
|
||||
const g = gm.createGroup({ label: 'A' });
|
||||
expect(() => gm.addRepo('nope', 'repo-a')).toThrow(expect.objectContaining({ statusCode: 404, code: 'NOT_FOUND' }));
|
||||
expect(() => gm.addRepo(g.id, 'nope')).toThrow(expect.objectContaining({ statusCode: 404, code: 'REPO_NOT_FOUND' }));
|
||||
});
|
||||
|
||||
it('removeRepo : idempotent (retrait d’un repo absent = no-op)', () => {
|
||||
const g = gm.createGroup({ label: 'A', repoIds: ['repo-a'] });
|
||||
expect(gm.removeRepo(g.id, 'repo-a').repoIds).toEqual([]);
|
||||
expect(gm.removeRepo(g.id, 'repo-a').repoIds).toEqual([]); // déjà absent → succès
|
||||
});
|
||||
|
||||
it('deleteGroup : true + group_removed ; id inconnu → false', () => {
|
||||
const g = gm.createGroup({ label: 'A' });
|
||||
const spy = vi.fn();
|
||||
gm.on('group_removed', spy);
|
||||
expect(gm.deleteGroup(g.id)).toBe(true);
|
||||
expect(spy).toHaveBeenCalledWith(g.id);
|
||||
expect(gm.deleteGroup(g.id)).toBe(false);
|
||||
expect(gm.listGroups()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it('CASCADE : supprimer un repo purge la membership (PRAGMA foreign_keys = ON)', () => {
|
||||
const g = gm.createGroup({ label: 'A', repoIds: ['repo-a', 'repo-b'] });
|
||||
expect(gm.getGroup(g.id).repoIds).toEqual(['repo-a', 'repo-b']);
|
||||
db.prepare('DELETE FROM repos WHERE id = ?').run('repo-a');
|
||||
expect(gm.getGroup(g.id).repoIds).toEqual(['repo-b']);
|
||||
});
|
||||
});
|
||||
@@ -13,7 +13,7 @@ function writeJsonl(projectsDir: string, cwd: string, sid: string, lines: object
|
||||
describe('munge', () => {
|
||||
it('reproduit le nom de dossier ~/.claude/projects', () => {
|
||||
expect(munge('/home/x/My Project!')).toBe('-home-x-My-Project-');
|
||||
expect(munge('/home/johan/WebstormProjects/arboretum')).toBe('-home-johan-WebstormProjects-arboretum');
|
||||
expect(munge('/home/user/projects/demo')).toBe('-home-user-projects-demo');
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
104
packages/server/test/repo-scanner.test.ts
Normal file
104
packages/server/test/repo-scanner.test.ts
Normal file
@@ -0,0 +1,104 @@
|
||||
import { describe, expect, it, afterEach } from 'vitest';
|
||||
import { mkdtempSync, mkdirSync, rmSync, symlinkSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { scanForRepos } from '../src/core/repo-scanner.js';
|
||||
|
||||
const dirs: string[] = [];
|
||||
afterEach(() => {
|
||||
for (const d of dirs.splice(0)) rmSync(d, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
function tmpRoot(): string {
|
||||
const d = mkdtempSync(join(tmpdir(), 'arb-scan-'));
|
||||
dirs.push(d);
|
||||
return d;
|
||||
}
|
||||
// un « repo » pour le scanner = un dossier contenant `.git` (le scanner ne lance jamais git).
|
||||
function makeRepo(...segs: string[]): void {
|
||||
mkdirSync(join(...segs, '.git'), { recursive: true });
|
||||
}
|
||||
|
||||
const limits = { maxDepth: 6, maxRepos: 2000 };
|
||||
|
||||
describe('scanForRepos', () => {
|
||||
it('trouve un repo simple', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root, 'proj');
|
||||
const { paths, truncated } = await scanForRepos([root], limits);
|
||||
expect(paths).toEqual([join(root, 'proj')]);
|
||||
expect(truncated).toBe(false);
|
||||
});
|
||||
|
||||
it('ne descend pas dans un repo trouvé (sous-repo ignoré)', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root, 'a');
|
||||
makeRepo(root, 'a', 'sub'); // imbriqué : doit être ignoré
|
||||
const { paths } = await scanForRepos([root], limits);
|
||||
expect(paths).toEqual([join(root, 'a')]);
|
||||
});
|
||||
|
||||
it('descend dans une racine qui est elle-même un repo (workspace + sous-repos)', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root); // la racine fournie contient elle-même un .git (cas WebstormProjects)
|
||||
makeRepo(root, 'a');
|
||||
makeRepo(root, 'b');
|
||||
const { paths } = await scanForRepos([root], limits);
|
||||
// la racine ET ses dépôts internes sont découverts (la racine n'arrête pas le scan)
|
||||
expect([...paths].sort()).toEqual([root, join(root, 'a'), join(root, 'b')].sort());
|
||||
});
|
||||
|
||||
it('ignore node_modules et les dotdirs', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root, 'node_modules', 'pkg');
|
||||
makeRepo(root, '.hidden', 'x');
|
||||
makeRepo(root, 'real');
|
||||
const { paths } = await scanForRepos([root], limits);
|
||||
expect(paths).toEqual([join(root, 'real')]);
|
||||
});
|
||||
|
||||
it('respecte maxDepth', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root, 'a', 'b', 'c', 'deep'); // repo à profondeur 4
|
||||
const shallow = await scanForRepos([root], { maxDepth: 2, maxRepos: 2000 });
|
||||
expect(shallow.paths).toEqual([]);
|
||||
const deep = await scanForRepos([root], { maxDepth: 4, maxRepos: 2000 });
|
||||
expect(deep.paths).toEqual([join(root, 'a', 'b', 'c', 'deep')]);
|
||||
});
|
||||
|
||||
it('ne suit pas les symlinks (cycle terminé, pas de doublon)', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root, 'proj');
|
||||
try {
|
||||
symlinkSync(root, join(root, 'loop')); // cycle vers la racine
|
||||
} catch {
|
||||
/* symlink non autorisé sous certains CI : le test reste valide sans le lien */
|
||||
}
|
||||
const { paths } = await scanForRepos([root], limits);
|
||||
expect(paths).toEqual([join(root, 'proj')]);
|
||||
});
|
||||
|
||||
it('tronque à maxRepos', async () => {
|
||||
const root = tmpRoot();
|
||||
makeRepo(root, 'r1');
|
||||
makeRepo(root, 'r2');
|
||||
makeRepo(root, 'r3');
|
||||
const { paths, truncated } = await scanForRepos([root], { maxDepth: 6, maxRepos: 2 });
|
||||
expect(truncated).toBe(true);
|
||||
expect(paths.length).toBeLessThanOrEqual(2);
|
||||
});
|
||||
|
||||
it('ignore une racine inexistante sans lever', async () => {
|
||||
const { paths } = await scanForRepos(['/nope/does/not/exist'], limits);
|
||||
expect(paths).toEqual([]);
|
||||
});
|
||||
|
||||
it('scanne plusieurs racines', async () => {
|
||||
const r1 = tmpRoot();
|
||||
const r2 = tmpRoot();
|
||||
makeRepo(r1, 'one');
|
||||
makeRepo(r2, 'two');
|
||||
const { paths } = await scanForRepos([r1, r2], limits);
|
||||
expect([...paths].sort()).toEqual([join(r1, 'one'), join(r2, 'two')].sort());
|
||||
});
|
||||
});
|
||||
37
packages/server/test/secret-box.test.ts
Normal file
37
packages/server/test/secret-box.test.ts
Normal file
@@ -0,0 +1,37 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
import { randomBytes } from 'node:crypto';
|
||||
import { SecretBox } from '../src/core/secret-box.js';
|
||||
|
||||
const box = (): SecretBox => new SecretBox(randomBytes(32));
|
||||
|
||||
describe('SecretBox', () => {
|
||||
it('chiffre puis déchiffre (round-trip)', () => {
|
||||
const b = box();
|
||||
const secret = 'deadbeef'.repeat(8);
|
||||
const enc = b.encrypt(secret);
|
||||
expect(enc.startsWith('v1:')).toBe(true);
|
||||
expect(enc).not.toContain(secret); // le clair n'apparaît pas
|
||||
expect(b.decrypt(enc)).toBe(secret);
|
||||
});
|
||||
|
||||
it('produit un chiffré différent à chaque fois (IV aléatoire)', () => {
|
||||
const b = box();
|
||||
expect(b.encrypt('x')).not.toBe(b.encrypt('x'));
|
||||
});
|
||||
|
||||
it('retourne tel quel une valeur en clair (legacy) et la détecte', () => {
|
||||
const b = box();
|
||||
expect(b.isEncrypted('plain-secret')).toBe(false);
|
||||
expect(b.decrypt('plain-secret')).toBe('plain-secret');
|
||||
expect(b.isEncrypted(b.encrypt('x'))).toBe(true);
|
||||
});
|
||||
|
||||
it('échoue si la clé ne correspond pas (GCM authentifié)', () => {
|
||||
const enc = box().encrypt('secret');
|
||||
expect(() => box().decrypt(enc)).toThrow();
|
||||
});
|
||||
|
||||
it('échoue sur un format chiffré corrompu', () => {
|
||||
expect(() => box().decrypt('v1:zzz')).toThrow();
|
||||
});
|
||||
});
|
||||
139
packages/server/test/settings-routes.test.ts
Normal file
139
packages/server/test/settings-routes.test.ts
Normal file
@@ -0,0 +1,139 @@
|
||||
// Routes Réglages : GET expose la config non sensible (jamais les secrets), PATCH n'écrit que
|
||||
// l'allow-list (découverte des dépôts) et ignore toute clé hors allow-list.
|
||||
import { mkdtempSync, rmSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { afterAll, beforeAll, describe, expect, it, vi } from 'vitest';
|
||||
import { buildApp, type AppBundle } from '../src/app.js';
|
||||
import { getSetting, openDb, type Db } from '../src/db/index.js';
|
||||
import type { Config } from '../src/config.js';
|
||||
import type { SettingsResponse } from '@arboretum/shared';
|
||||
|
||||
vi.mock('node:child_process', () => ({ execFileSync: () => '/usr/bin/claude\n' }));
|
||||
vi.mock('@homebridge/node-pty-prebuilt-multiarch', () => {
|
||||
class FakePty {
|
||||
pid = 424242;
|
||||
write = vi.fn();
|
||||
resize = vi.fn();
|
||||
pause = vi.fn();
|
||||
resume = vi.fn();
|
||||
kill = vi.fn();
|
||||
onData(): { dispose: () => void } {
|
||||
return { dispose: () => {} };
|
||||
}
|
||||
onExit(): { dispose: () => void } {
|
||||
return { dispose: () => {} };
|
||||
}
|
||||
}
|
||||
return { default: { spawn: (): FakePty => new FakePty() } };
|
||||
});
|
||||
|
||||
process.env.ARBORETUM_LOG = 'silent';
|
||||
|
||||
let dir: string;
|
||||
let bundle: AppBundle;
|
||||
let db: Db;
|
||||
let token: string;
|
||||
|
||||
const auth = (): { authorization: string } => ({ authorization: `Bearer ${token}` });
|
||||
|
||||
beforeAll(() => {
|
||||
dir = mkdtempSync(join(tmpdir(), 'arboretum-settings-'));
|
||||
const dbPath = join(dir, 'settings.db');
|
||||
db = openDb(dbPath);
|
||||
const config: Config = {
|
||||
port: 9999,
|
||||
bind: '127.0.0.1',
|
||||
dbPath,
|
||||
dataDir: dir,
|
||||
allowedOrigins: ['https://host.tailnet.ts.net'],
|
||||
printToken: false,
|
||||
claudeProjectsDir: join(dir, 'claude', 'projects'),
|
||||
claudeSessionsDir: join(dir, 'claude', 'sessions'),
|
||||
vapidContact: 'mailto:test@localhost',
|
||||
};
|
||||
bundle = buildApp(config, db, '1.2.3-test');
|
||||
const t = bundle.auth.ensureBootstrapToken();
|
||||
if (!t) throw new Error('bootstrap token attendu');
|
||||
token = t;
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
await bundle.app.close();
|
||||
db.close();
|
||||
rmSync(dir, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
describe('GET /api/v1/settings', () => {
|
||||
it('renvoie la config serveur non sensible et aucune racine de scan par défaut', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/settings', headers: auth() });
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json() as SettingsResponse;
|
||||
expect(body.server.version).toBe('1.2.3-test');
|
||||
expect(body.server.port).toBe(9999);
|
||||
expect(body.server.bind).toBe('127.0.0.1');
|
||||
expect(body.server.allowedOrigins).toEqual(['https://host.tailnet.ts.net']);
|
||||
expect(body.server.vapidPublicKey).toBeTruthy(); // clé publique = sûre à exposer
|
||||
// défauts de découverte : AUCUNE racine (clean install → pas de scan) + intervalle 5 min
|
||||
expect(body.settings.scanRoots).toEqual([]);
|
||||
expect(body.settings.scanIntervalMin).toBe(5);
|
||||
});
|
||||
|
||||
it('n’expose AUCUN secret (server_secret, clé privée VAPID)', async () => {
|
||||
const res = await bundle.app.inject({ method: 'GET', url: '/api/v1/settings', headers: auth() });
|
||||
const raw = res.body;
|
||||
const secret = getSetting(db, 'server_secret');
|
||||
const vapidPrivate = getSetting(db, 'vapid_private');
|
||||
expect(secret).toBeTruthy();
|
||||
expect(raw).not.toContain(secret as string);
|
||||
expect(raw).not.toContain(vapidPrivate as string);
|
||||
expect(raw).not.toMatch(/server_secret|vapid_private|privateKey/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('PATCH /api/v1/settings — sécurité', () => {
|
||||
it('ignore toute clé hors allow-list (ne touche pas aux secrets)', async () => {
|
||||
const before = getSetting(db, 'server_secret');
|
||||
await bundle.app.inject({ method: 'PATCH', url: '/api/v1/settings', headers: auth(), payload: { server_secret: 'pwned', vapid_private: 'pwned' } });
|
||||
expect(getSetting(db, 'server_secret')).toBe(before); // inchangé
|
||||
expect(getSetting(db, 'vapid_private')).not.toBe('pwned');
|
||||
});
|
||||
|
||||
it('sans authentification → 401', async () => {
|
||||
const res = await bundle.app.inject({ method: 'PATCH', url: '/api/v1/settings', payload: { scanRoots: ['/home/u/work'] } });
|
||||
expect(res.statusCode).toBe(401);
|
||||
});
|
||||
});
|
||||
|
||||
describe('PATCH /api/v1/settings — découverte des dépôts', () => {
|
||||
it('enregistre des scanRoots et un intervalle valides et les renvoie', async () => {
|
||||
const res = await bundle.app.inject({
|
||||
method: 'PATCH',
|
||||
url: '/api/v1/settings',
|
||||
headers: auth(),
|
||||
payload: { scanRoots: ['/home/u/work', '/srv/code'], scanIntervalMin: 10 },
|
||||
});
|
||||
expect(res.statusCode).toBe(200);
|
||||
const body = res.json() as SettingsResponse;
|
||||
expect(body.settings.scanRoots).toEqual(['/home/u/work', '/srv/code']);
|
||||
expect(body.settings.scanIntervalMin).toBe(10);
|
||||
// persisté
|
||||
const get = await bundle.app.inject({ method: 'GET', url: '/api/v1/settings', headers: auth() });
|
||||
expect((get.json() as SettingsResponse).settings.scanRoots).toEqual(['/home/u/work', '/srv/code']);
|
||||
});
|
||||
|
||||
it('rejette des racines non absolues, "/", avec ".." ou en surnombre (400)', async () => {
|
||||
const bads: unknown[] = [['relative/path'], ['/'], ['/a/../b'], Array.from({ length: 17 }, (_, i) => `/r${i}`)];
|
||||
for (const scanRoots of bads) {
|
||||
const res = await bundle.app.inject({ method: 'PATCH', url: '/api/v1/settings', headers: auth(), payload: { scanRoots } });
|
||||
expect(res.statusCode).toBe(400);
|
||||
}
|
||||
});
|
||||
|
||||
it('rejette un intervalle hors borne (400)', async () => {
|
||||
const res = await bundle.app.inject({ method: 'PATCH', url: '/api/v1/settings', headers: auth(), payload: { scanIntervalMin: 5000 } });
|
||||
expect(res.statusCode).toBe(400);
|
||||
const neg = await bundle.app.inject({ method: 'PATCH', url: '/api/v1/settings', headers: auth(), payload: { scanIntervalMin: -1 } });
|
||||
expect(neg.statusCode).toBe(400);
|
||||
});
|
||||
});
|
||||
@@ -1,9 +1,9 @@
|
||||
import { describe, expect, it, beforeEach, afterEach, vi } from 'vitest';
|
||||
import { execFileSync } from 'node:child_process';
|
||||
import { mkdtempSync, writeFileSync, rmSync, existsSync } from 'node:fs';
|
||||
import { mkdtempSync, mkdirSync, writeFileSync, rmSync, existsSync } from 'node:fs';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join, basename, dirname, resolve } from 'node:path';
|
||||
import type { WorktreeSummary } from '@arboretum/shared';
|
||||
import type { RepoSummary, WorktreeSummary } from '@arboretum/shared';
|
||||
import { WorktreeManager } from '../src/core/worktree-manager.js';
|
||||
import { PtyManager } from '../src/core/pty-manager.js';
|
||||
import { DiscoveryService } from '../src/core/discovery-service.js';
|
||||
@@ -34,9 +34,7 @@ afterEach(() => {
|
||||
for (const d of dirs.splice(0)) rmSync(d, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
function makeTmpRepo(): string {
|
||||
const dir = mkdtempSync(join(tmpdir(), 'arb-wtm-'));
|
||||
dirs.push(dir);
|
||||
function gitInit(dir: string): void {
|
||||
const run = (...args: string[]): void => void execFileSync('git', args, { cwd: dir, stdio: 'pipe' });
|
||||
run('init', '-b', 'main');
|
||||
run('config', 'user.email', 'test@arboretum.dev');
|
||||
@@ -44,9 +42,21 @@ function makeTmpRepo(): string {
|
||||
writeFileSync(join(dir, 'README.md'), '# test\n');
|
||||
run('add', '-A');
|
||||
run('commit', '-m', 'init');
|
||||
}
|
||||
|
||||
function makeTmpRepo(): string {
|
||||
const dir = mkdtempSync(join(tmpdir(), 'arb-wtm-'));
|
||||
dirs.push(dir);
|
||||
gitInit(dir);
|
||||
return dir;
|
||||
}
|
||||
|
||||
/** Crée un vrai repo git à un chemin donné (sous une racine de scan contrôlée). */
|
||||
function makeRepoAt(path: string): void {
|
||||
mkdirSync(path, { recursive: true });
|
||||
gitInit(path);
|
||||
}
|
||||
|
||||
describe('WorktreeManager', () => {
|
||||
let db: Db;
|
||||
let pty: PtyManager;
|
||||
@@ -144,4 +154,79 @@ describe('WorktreeManager', () => {
|
||||
pty.spawn({ cwd: wtPath, command: 'bash' });
|
||||
await expect(wt.deleteWorktree(r.id, wtPath, false)).rejects.toMatchObject({ statusCode: 409, code: 'SESSION_LIVE_IN_WORKTREE' });
|
||||
});
|
||||
|
||||
it('addRepo renvoie hidden:false ; updateRepo({hidden}) bascule et émet repo_update', async () => {
|
||||
const repo = makeTmpRepo();
|
||||
const r = await wt.addRepo({ path: repo });
|
||||
expect(r.hidden).toBe(false);
|
||||
const updates: RepoSummary[] = [];
|
||||
wt.on('repo_update', (s) => updates.push(s));
|
||||
const u = await wt.updateRepo(r.id, { hidden: true });
|
||||
expect(u.hidden).toBe(true);
|
||||
expect(updates.some((s) => s.id === r.id && s.hidden)).toBe(true);
|
||||
});
|
||||
|
||||
it('listAllWorktrees exclut les repos masqués', async () => {
|
||||
const repo = makeTmpRepo();
|
||||
const r = await wt.addRepo({ path: repo });
|
||||
expect((await wt.listAllWorktrees()).length).toBeGreaterThan(0); // main worktree présent
|
||||
await wt.updateRepo(r.id, { hidden: true });
|
||||
expect(await wt.listAllWorktrees()).toHaveLength(0);
|
||||
});
|
||||
|
||||
it('discoverRepos : auto-ajoute les nouveaux, idempotent, masqué non ressuscité, supprimé re-découvrable', async () => {
|
||||
const root = mkdtempSync(join(tmpdir(), 'arb-scan-'));
|
||||
dirs.push(root);
|
||||
makeRepoAt(join(root, 'a'));
|
||||
makeRepoAt(join(root, 'b'));
|
||||
|
||||
const updates: RepoSummary[] = [];
|
||||
wt.on('repo_update', (s) => updates.push(s));
|
||||
|
||||
const res = await wt.discoverRepos({ roots: [root], maxDepth: 2 });
|
||||
expect(res.added).toBe(2);
|
||||
expect(res.scanned).toBe(2);
|
||||
expect(await wt.listRepos()).toHaveLength(2);
|
||||
expect(updates).toHaveLength(2); // un repo_update par nouveau
|
||||
|
||||
// re-scan : idempotent (aucun ajout, aucune émission)
|
||||
updates.length = 0;
|
||||
const res2 = await wt.discoverRepos({ roots: [root], maxDepth: 2 });
|
||||
expect(res2.added).toBe(0);
|
||||
expect(updates).toHaveLength(0);
|
||||
expect(await wt.listRepos()).toHaveLength(2);
|
||||
|
||||
// masquer 'a' puis re-scan : reste masqué, jamais ré-ajouté (invariant central)
|
||||
const repoA = (await wt.listRepos()).find((r) => resolve(r.path) === resolve(join(root, 'a')));
|
||||
await wt.updateRepo(repoA!.id, { hidden: true });
|
||||
updates.length = 0;
|
||||
const res3 = await wt.discoverRepos({ roots: [root], maxDepth: 2 });
|
||||
expect(res3.added).toBe(0);
|
||||
expect((await wt.listRepos()).find((r) => r.id === repoA!.id)?.hidden).toBe(true);
|
||||
|
||||
// supprimer 'b' puis re-scan : re-découvert (volontaire)
|
||||
const repoB = (await wt.listRepos()).find((r) => resolve(r.path) === resolve(join(root, 'b')));
|
||||
wt.removeRepo(repoB!.id);
|
||||
expect(await wt.listRepos()).toHaveLength(1);
|
||||
const res4 = await wt.discoverRepos({ roots: [root], maxDepth: 2 });
|
||||
expect(res4.added).toBe(1);
|
||||
expect(await wt.listRepos()).toHaveLength(2);
|
||||
});
|
||||
|
||||
it('discoverRepos : repo disparu du disque conservé en DB (valid=false), non re-trouvé', async () => {
|
||||
const root = mkdtempSync(join(tmpdir(), 'arb-scan-'));
|
||||
dirs.push(root);
|
||||
makeRepoAt(join(root, 'gone'));
|
||||
await wt.discoverRepos({ roots: [root], maxDepth: 2 });
|
||||
expect(await wt.listRepos()).toHaveLength(1);
|
||||
|
||||
rmSync(join(root, 'gone'), { recursive: true, force: true }); // disparaît du disque
|
||||
const res = await wt.discoverRepos({ roots: [root], maxDepth: 2 });
|
||||
expect(res.added).toBe(0); // plus trouvé par le scan
|
||||
const repos = await wt.listRepos();
|
||||
expect(repos).toHaveLength(1); // mais la ligne est conservée (pas de suppression auto)
|
||||
expect(repos[0].valid).toBe(false);
|
||||
// robustesse : un repo dont le chemin a disparu ne fait pas planter /worktrees (git échoue → [])
|
||||
await expect(wt.listAllWorktrees()).resolves.toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
// Types REST partagés (préfixe /api/v1).
|
||||
import type { PostCreateHook, RepoSummary, SessionSummary, WorktreeSummary } from './protocol.js';
|
||||
import type { GroupSummary, PostCreateHook, RepoSummary, SessionSummary, WorktreeSummary } from './protocol.js';
|
||||
|
||||
export interface ApiError {
|
||||
error: { code: string; message: string; details?: unknown };
|
||||
@@ -14,10 +14,34 @@ export interface LoginResponse {
|
||||
}
|
||||
export interface MeResponse {
|
||||
ok: true;
|
||||
/** id du token de la session courante — sert à marquer « courant » dans la liste des tokens. */
|
||||
tokenId: string;
|
||||
tokenLabel: string;
|
||||
serverVersion: string;
|
||||
}
|
||||
|
||||
// ---- Gestion des tokens d'accès (onglet Réglages) ----
|
||||
export interface TokenInfo {
|
||||
id: string;
|
||||
label: string;
|
||||
createdAt: string;
|
||||
lastUsedAt: string | null;
|
||||
/** true pour le token de la session courante. */
|
||||
current: boolean;
|
||||
}
|
||||
export interface TokensListResponse {
|
||||
tokens: TokenInfo[];
|
||||
}
|
||||
export interface CreateTokenRequest {
|
||||
label: string;
|
||||
}
|
||||
export interface CreateTokenResponse {
|
||||
id: string;
|
||||
label: string;
|
||||
/** valeur en clair — affichée une seule fois, jamais re-récupérable. */
|
||||
token: string;
|
||||
}
|
||||
|
||||
export interface CreateSessionRequest {
|
||||
cwd: string;
|
||||
/** binaire à lancer — défaut "claude" ; "bash" sert aux tests d'acceptation sans quota */
|
||||
@@ -52,6 +76,19 @@ export interface UpdateRepoRequest {
|
||||
label?: string;
|
||||
postCreateHooks?: PostCreateHook[];
|
||||
preTrust?: boolean;
|
||||
/** true = masquer le repo (exclu du dashboard, conservé en DB) ; false = ré-afficher. */
|
||||
hidden?: boolean;
|
||||
}
|
||||
|
||||
/** Résultat d'un scan de découverte (POST /api/v1/repos/discover). */
|
||||
export interface DiscoverReposResponse {
|
||||
/** dossiers-repos trouvés sur disque. */
|
||||
scanned: number;
|
||||
/** repos réellement insérés (nouveaux, non déjà enregistrés). */
|
||||
added: number;
|
||||
durationMs: number;
|
||||
/** true si la limite (maxRepos / timeout) a été atteinte avant la fin du scan. */
|
||||
truncated: boolean;
|
||||
}
|
||||
|
||||
export interface WorktreesListResponse {
|
||||
@@ -91,6 +128,30 @@ export interface AdoptWorktreeRequest {
|
||||
preTrust?: boolean;
|
||||
}
|
||||
|
||||
// ---- Groupes de travail (P5) ----
|
||||
export interface GroupsListResponse {
|
||||
groups: GroupSummary[];
|
||||
}
|
||||
export interface GroupResponse {
|
||||
group: GroupSummary;
|
||||
}
|
||||
export interface CreateGroupRequest {
|
||||
label: string;
|
||||
description?: string;
|
||||
color?: string;
|
||||
/** ids de repos initiaux (défaut : []). */
|
||||
repoIds?: string[];
|
||||
}
|
||||
export interface UpdateGroupRequest {
|
||||
label?: string;
|
||||
/** null pour effacer. */
|
||||
description?: string | null;
|
||||
color?: string | null;
|
||||
}
|
||||
export interface AddRepoRequest {
|
||||
repoId: string;
|
||||
}
|
||||
|
||||
// ---- Navigateur de répertoires (sélecteur de dossier côté web) ----
|
||||
export interface FsEntry {
|
||||
name: string;
|
||||
@@ -122,3 +183,72 @@ export interface PushSubscribeRequest {
|
||||
export interface PushUnsubscribeRequest {
|
||||
endpoint: string;
|
||||
}
|
||||
|
||||
// ---- Réglages & info serveur (onglet Réglages) ----
|
||||
/** Config runtime non sensible du daemon — lecture seule (changée via flags CLI + redémarrage). */
|
||||
export interface ServerInfo {
|
||||
version: string;
|
||||
port: number;
|
||||
bind: string;
|
||||
allowedOrigins: string[];
|
||||
dataDir: string;
|
||||
/** clé publique VAPID (sûre à exposer) ; null si push indisponible. */
|
||||
vapidPublicKey: string | null;
|
||||
vapidContact: string;
|
||||
}
|
||||
export interface SettingsResponse {
|
||||
/** réglages modifiables à chaud (allow-list serveur — jamais les secrets). */
|
||||
settings: {
|
||||
/** racines absolues scannées pour la découverte auto des repos (défaut : aucune → pas de scan). */
|
||||
scanRoots: string[];
|
||||
/** intervalle du re-scan périodique en minutes ; 0 = périodique désactivé. */
|
||||
scanIntervalMin: number;
|
||||
};
|
||||
server: ServerInfo;
|
||||
}
|
||||
export interface UpdateSettingsRequest {
|
||||
/** racines absolues à scanner (chemins normalisés, ≤ 16) ; remplace la liste. */
|
||||
scanRoots?: string[];
|
||||
/** intervalle du re-scan périodique en minutes (0–1440 ; 0 désactive). */
|
||||
scanIntervalMin?: number;
|
||||
}
|
||||
|
||||
// ---- Journal d'audit (conformité entreprise) ----
|
||||
export interface AuditLogEntry {
|
||||
id: string;
|
||||
/** horodatage ISO 8601 */
|
||||
ts: string;
|
||||
/** tokenId de l'acteur, 'system' (auto) ou 'anonymous' (avant auth) */
|
||||
actor: string;
|
||||
/** verbe.objet, ex. 'token.create', 'settings.update' */
|
||||
action: string;
|
||||
resourceId: string | null;
|
||||
/** métadonnées non sensibles (jamais de secret) */
|
||||
details: unknown;
|
||||
result: string;
|
||||
}
|
||||
export interface AuditLogsResponse {
|
||||
entries: AuditLogEntry[];
|
||||
/** curseur de pagination (ts à passer en `before`) ; null si fin de liste. */
|
||||
nextBefore: string | null;
|
||||
}
|
||||
|
||||
// ---- RGPD : export / suppression des données liées au token authentifié ----
|
||||
export interface DataExportResponse {
|
||||
exportedAt: string;
|
||||
tokens: Array<{ id: string; label: string; createdAt: string; lastUsedAt: string | null; current: boolean }>;
|
||||
pushSubscriptions: Array<{ endpoint: string; userAgent: string | null; createdAt: string; lastOkAt: string | null }>;
|
||||
sessions: Array<{ id: string; cwd: string; command: string; title: string | null; createdAt: string; endedAt: string | null; exitCode: number | null }>;
|
||||
settings: { scanRoots: string[]; scanIntervalMin: number };
|
||||
}
|
||||
export interface DeleteMyDataRequest {
|
||||
/** code de confirmation renvoyé par un premier appel sans `confirm` ; doit être renvoyé pour exécuter. */
|
||||
confirm?: string;
|
||||
}
|
||||
export interface DeleteMyDataResponse {
|
||||
/** 'pending' = confirmation requise (renvoie `confirm`) ; 'done' = suppression effectuée. */
|
||||
status: 'pending' | 'done';
|
||||
confirm?: string;
|
||||
/** récapitulatif de ce qui sera/a été supprimé. */
|
||||
summary: { pushSubscriptions: number; tokenRevoked: boolean };
|
||||
}
|
||||
|
||||
@@ -136,6 +136,8 @@ export interface RepoSummary {
|
||||
createdAt: string;
|
||||
/** false si le chemin n'est plus un repo git accessible. */
|
||||
valid: boolean;
|
||||
/** true = masqué du dashboard (conservé en DB → non ré-ajouté au re-scan). */
|
||||
hidden: boolean;
|
||||
}
|
||||
|
||||
export interface WorktreeGitStatus {
|
||||
@@ -160,6 +162,22 @@ export interface WorktreeSummary {
|
||||
sessions: SessionSummary[];
|
||||
}
|
||||
|
||||
// ---- Groupes de travail (P5) ----
|
||||
// Un groupe regroupe plusieurs repos pour piloter des sessions Claude en simultané sur
|
||||
// plusieurs worktrees. Membership légère : seule la liste d'ids de repos est persistée ;
|
||||
// les repos/worktrees/sessions du groupe sont dérivés par filtrage sur `repoId` côté client.
|
||||
export interface GroupSummary {
|
||||
id: string;
|
||||
label: string;
|
||||
description: string | null;
|
||||
/** couleur d'accent UI (hex `#rrggbb`) ou null. */
|
||||
color: string | null;
|
||||
/** ids de repos membres, ordonnés par leur position dans le groupe. */
|
||||
repoIds: string[];
|
||||
createdAt: string;
|
||||
updatedAt: string;
|
||||
}
|
||||
|
||||
// ---- Messages client → serveur ----
|
||||
export type ClientMessage =
|
||||
| { type: 'hello'; protocol: number }
|
||||
@@ -172,7 +190,7 @@ export type ClientMessage =
|
||||
| { type: 'answer'; channel: number; action: 'select' | 'confirm' | 'deny'; optionN?: number }
|
||||
| { type: 'resize'; channel: number; cols: number; rows: number }
|
||||
| { type: 'ack'; channel: number; bytes: number }
|
||||
| { type: 'sub'; topics: Array<'sessions' | 'worktrees'> }
|
||||
| { type: 'sub'; topics: Array<'sessions' | 'worktrees' | 'groups'> }
|
||||
| { type: 'ping' };
|
||||
|
||||
// ---- Messages serveur → client ----
|
||||
@@ -187,6 +205,8 @@ export type ServerMessage =
|
||||
| { type: 'repo_removed'; repoId: string }
|
||||
| { type: 'worktree_update'; repoId: string; worktree: WorktreeSummary }
|
||||
| { type: 'worktree_removed'; repoId: string; path: string }
|
||||
| { type: 'group_update'; group: GroupSummary }
|
||||
| { type: 'group_removed'; groupId: string }
|
||||
| { type: 'error'; code: ErrorCode; message: string; channel?: number }
|
||||
| { type: 'pong' };
|
||||
|
||||
@@ -244,8 +264,8 @@ export function parseClientMessage(raw: string): ClientMessage | null {
|
||||
? { type: 'ack', channel: m.channel, bytes: m.bytes }
|
||||
: null;
|
||||
case 'sub':
|
||||
return Array.isArray(m.topics) && m.topics.every((t) => t === 'sessions' || t === 'worktrees')
|
||||
? { type: 'sub', topics: m.topics as Array<'sessions' | 'worktrees'> }
|
||||
return Array.isArray(m.topics) && m.topics.every((t) => t === 'sessions' || t === 'worktrees' || t === 'groups')
|
||||
? { type: 'sub', topics: m.topics as Array<'sessions' | 'worktrees' | 'groups'> }
|
||||
: null;
|
||||
case 'ping':
|
||||
return { type: 'ping' };
|
||||
|
||||
@@ -62,7 +62,7 @@ function assertInvariants(msg: ClientMessage): void {
|
||||
expect(msg.bytes).toBeGreaterThanOrEqual(0);
|
||||
break;
|
||||
case 'sub':
|
||||
expect(msg.topics.every((t) => t === 'sessions')).toBe(true);
|
||||
expect(msg.topics.every((t) => t === 'sessions' || t === 'worktrees' || t === 'groups')).toBe(true);
|
||||
break;
|
||||
case 'ping':
|
||||
break;
|
||||
@@ -117,9 +117,14 @@ describe('parseClientMessage — cas valides', () => {
|
||||
expect(parseClientMessage('{"type":"ack","channel":1,"bytes":0}')).toEqual({ type: 'ack', channel: 1, bytes: 0 });
|
||||
});
|
||||
|
||||
it('sub avec topics sessions/worktrees (et tableau vide accepté)', () => {
|
||||
it('sub avec topics sessions/worktrees/groups (et tableau vide accepté)', () => {
|
||||
expect(parseClientMessage('{"type":"sub","topics":["sessions"]}')).toEqual({ type: 'sub', topics: ['sessions'] });
|
||||
expect(parseClientMessage('{"type":"sub","topics":["sessions","worktrees"]}')).toEqual({ type: 'sub', topics: ['sessions', 'worktrees'] });
|
||||
expect(parseClientMessage('{"type":"sub","topics":["groups"]}')).toEqual({ type: 'sub', topics: ['groups'] });
|
||||
expect(parseClientMessage('{"type":"sub","topics":["sessions","worktrees","groups"]}')).toEqual({
|
||||
type: 'sub',
|
||||
topics: ['sessions', 'worktrees', 'groups'],
|
||||
});
|
||||
expect(parseClientMessage('{"type":"sub","topics":[]}')).toEqual({ type: 'sub', topics: [] });
|
||||
});
|
||||
|
||||
|
||||
53
packages/site/index.html
Normal file
53
packages/site/index.html
Normal file
@@ -0,0 +1,53 @@
|
||||
<!doctype html>
|
||||
<html lang="en" style="background-color: #09090b">
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||
<meta name="color-scheme" content="dark" />
|
||||
<meta name="theme-color" content="#09090b" />
|
||||
|
||||
<title>Arboretum — Mission control for your AI coding agents</title>
|
||||
<meta
|
||||
name="description"
|
||||
content="Arboretum is a local-first daemon you launch with npx that serves a web dashboard to run and supervise many Claude Code sessions across git worktrees — from any device, even your phone."
|
||||
/>
|
||||
<link rel="canonical" href="https://git-arboretum.com/" />
|
||||
|
||||
<!-- Open Graph / Twitter -->
|
||||
<meta property="og:type" content="website" />
|
||||
<meta property="og:url" content="https://git-arboretum.com/" />
|
||||
<meta property="og:title" content="Arboretum — Mission control for your AI coding agents" />
|
||||
<meta
|
||||
property="og:description"
|
||||
content="Run and supervise many Claude Code sessions across every git worktree — from any device, even your phone."
|
||||
/>
|
||||
<meta property="og:site_name" content="Arboretum" />
|
||||
<meta property="og:image" content="https://git-arboretum.com/assets/og-cover.png" />
|
||||
<meta property="og:image:width" content="1200" />
|
||||
<meta property="og:image:height" content="630" />
|
||||
<meta property="og:image:alt" content="Arboretum — mission control for your AI coding agents" />
|
||||
<meta name="twitter:card" content="summary_large_image" />
|
||||
<meta name="twitter:title" content="Arboretum — Mission control for your AI coding agents" />
|
||||
<meta
|
||||
name="twitter:description"
|
||||
content="Run and supervise many Claude Code sessions across every git worktree — from any device, even your phone."
|
||||
/>
|
||||
<meta name="twitter:image" content="https://git-arboretum.com/assets/og-cover.png" />
|
||||
|
||||
<!-- Icons -->
|
||||
<link rel="icon" type="image/svg+xml" href="/icon.svg" />
|
||||
<link rel="icon" type="image/x-icon" href="/favicon.ico" />
|
||||
<link rel="apple-touch-icon" href="/apple-touch-icon.png" />
|
||||
<!-- Polices JetBrains Mono self-host via @fontsource (importées dans src/main.ts). -->
|
||||
</head>
|
||||
<body>
|
||||
<div id="app"></div>
|
||||
<noscript>
|
||||
<div style="padding: 24px; font-family: system-ui, sans-serif; color: #f4f4f5; text-align: center">
|
||||
Arboretum — mission control for your AI coding agents.
|
||||
<a href="https://git.lidge.fr/johanleroy/git-arboretum" style="color: #34d399">View on Gitea</a>.
|
||||
</div>
|
||||
</noscript>
|
||||
<script type="module" src="/src/main.ts"></script>
|
||||
</body>
|
||||
</html>
|
||||
24
packages/site/package.json
Normal file
24
packages/site/package.json
Normal file
@@ -0,0 +1,24 @@
|
||||
{
|
||||
"name": "@arboretum/site",
|
||||
"private": true,
|
||||
"version": "0.1.0",
|
||||
"type": "module",
|
||||
"scripts": {
|
||||
"dev": "vite",
|
||||
"build": "vue-tsc --noEmit && vite build",
|
||||
"preview": "vite preview"
|
||||
},
|
||||
"dependencies": {
|
||||
"vue": "^3.5.38",
|
||||
"vue-i18n": "^11.4.5"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@fontsource/jetbrains-mono": "^5.1.0",
|
||||
"@tailwindcss/vite": "^4.3.0",
|
||||
"@vitejs/plugin-vue": "^6.0.7",
|
||||
"tailwindcss": "^4.3.0",
|
||||
"typescript": "^5.7.0",
|
||||
"vite": "^8.0.16",
|
||||
"vue-tsc": "^3.3.4"
|
||||
}
|
||||
}
|
||||
BIN
packages/site/public/apple-touch-icon.png
Normal file
BIN
packages/site/public/apple-touch-icon.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 15 KiB |
BIN
packages/site/public/assets/arboretum-mark.png
Normal file
BIN
packages/site/public/assets/arboretum-mark.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 28 KiB |
BIN
packages/site/public/assets/og-cover.png
Normal file
BIN
packages/site/public/assets/og-cover.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 75 KiB |
BIN
packages/site/public/favicon.ico
Normal file
BIN
packages/site/public/favicon.ico
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 5.5 KiB |
46
packages/site/public/icon.svg
Normal file
46
packages/site/public/icon.svg
Normal file
@@ -0,0 +1,46 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" width="512" height="512" viewBox="0 0 512 512" role="img" aria-label="Arboretum">
|
||||
<defs>
|
||||
<!-- glow néon : flou doux derrière les traits et les nœuds -->
|
||||
<filter id="glow" x="-30%" y="-30%" width="160%" height="160%">
|
||||
<feGaussianBlur stdDeviation="6" result="b"/>
|
||||
<feMerge><feMergeNode in="b"/><feMergeNode in="SourceGraphic"/></feMerge>
|
||||
</filter>
|
||||
<linearGradient id="branch" x1="256" y1="430" x2="256" y2="90" gradientUnits="userSpaceOnUse">
|
||||
<stop offset="0" stop-color="#10b981"/>
|
||||
<stop offset="1" stop-color="#34d399"/>
|
||||
</linearGradient>
|
||||
</defs>
|
||||
|
||||
<rect width="512" height="512" fill="#09090b"/>
|
||||
|
||||
<!-- branches / circuit (tronc + fourches symétriques), tracées dans la zone sûre maskable -->
|
||||
<g fill="none" stroke="url(#branch)" stroke-width="17" stroke-linecap="round" stroke-linejoin="round" filter="url(#glow)">
|
||||
<!-- tronc : du nœud sommet jusqu'à la base avec le curseur >_ -->
|
||||
<path d="M256 96 V392"/>
|
||||
<!-- paire haute -->
|
||||
<path d="M256 232 L150 232 V150"/>
|
||||
<path d="M256 232 L362 232 V150"/>
|
||||
<!-- paire médiane -->
|
||||
<path d="M256 300 L104 300 V214"/>
|
||||
<path d="M256 300 L408 300 V214"/>
|
||||
<!-- paire basse -->
|
||||
<path d="M256 356 L150 356 V300"/>
|
||||
<path d="M256 356 L362 356 V300"/>
|
||||
<!-- base : invite de commande >_ -->
|
||||
<path d="M232 404 L246 418 L232 432" stroke-width="14"/>
|
||||
<path d="M258 434 H286" stroke-width="14"/>
|
||||
</g>
|
||||
|
||||
<!-- nœuds (sessions) : anneaux cyan lumineux, centre sombre -->
|
||||
<g filter="url(#glow)">
|
||||
<g fill="#09090b" stroke="#22d3ee" stroke-width="9">
|
||||
<circle cx="256" cy="96" r="20"/>
|
||||
<circle cx="150" cy="150" r="16"/>
|
||||
<circle cx="362" cy="150" r="16"/>
|
||||
<circle cx="104" cy="214" r="16"/>
|
||||
<circle cx="408" cy="214" r="16"/>
|
||||
<circle cx="150" cy="300" r="16"/>
|
||||
<circle cx="362" cy="300" r="16"/>
|
||||
</g>
|
||||
</g>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 1.9 KiB |
4
packages/site/public/robots.txt
Normal file
4
packages/site/public/robots.txt
Normal file
@@ -0,0 +1,4 @@
|
||||
User-agent: *
|
||||
Allow: /
|
||||
|
||||
Sitemap: https://git-arboretum.com/sitemap.xml
|
||||
9
packages/site/public/sitemap.xml
Normal file
9
packages/site/public/sitemap.xml
Normal file
@@ -0,0 +1,9 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
|
||||
<url>
|
||||
<loc>https://git-arboretum.com/</loc>
|
||||
<lastmod>2026-06-19</lastmod>
|
||||
<changefreq>monthly</changefreq>
|
||||
<priority>1.0</priority>
|
||||
</url>
|
||||
</urlset>
|
||||
74
packages/site/src/App.vue
Normal file
74
packages/site/src/App.vue
Normal file
@@ -0,0 +1,74 @@
|
||||
<script setup lang="ts">
|
||||
import { watch } from 'vue';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import AppHeader from './components/AppHeader.vue';
|
||||
import HeroSection from './components/HeroSection.vue';
|
||||
import ProblemSection from './components/ProblemSection.vue';
|
||||
import FeaturesSection from './components/FeaturesSection.vue';
|
||||
import ShowcaseSection from './components/ShowcaseSection.vue';
|
||||
import WorkGroupsSection from './components/WorkGroupsSection.vue';
|
||||
import HowItWorksSection from './components/HowItWorksSection.vue';
|
||||
import SecuritySection from './components/SecuritySection.vue';
|
||||
import FaqSection from './components/FaqSection.vue';
|
||||
import FinalCta from './components/FinalCta.vue';
|
||||
import AppFooter from './components/AppFooter.vue';
|
||||
|
||||
const { locale } = useI18n();
|
||||
|
||||
// Tient l'attribut <html lang> synchronisé avec la langue active.
|
||||
watch(
|
||||
locale,
|
||||
(l) => {
|
||||
document.documentElement.lang = l;
|
||||
},
|
||||
{ immediate: true },
|
||||
);
|
||||
|
||||
// Grain de fond + halo emerald (décoratifs) — portés tels quels du design.
|
||||
const grainStyle = {
|
||||
position: 'fixed',
|
||||
inset: '0',
|
||||
zIndex: 0,
|
||||
pointerEvents: 'none',
|
||||
backgroundImage: 'radial-gradient(rgba(255,255,255,.025) 1px,transparent 1.4px)',
|
||||
backgroundSize: '34px 34px',
|
||||
WebkitMaskImage: 'radial-gradient(ellipse 120% 70% at 50% -4%,#000,transparent 70%)',
|
||||
maskImage: 'radial-gradient(ellipse 120% 70% at 50% -4%,#000,transparent 70%)',
|
||||
} as const;
|
||||
|
||||
const glowStyle = {
|
||||
position: 'fixed',
|
||||
top: '-26%',
|
||||
left: '50%',
|
||||
transform: 'translateX(-50%)',
|
||||
width: '1100px',
|
||||
height: '680px',
|
||||
zIndex: 0,
|
||||
pointerEvents: 'none',
|
||||
background: 'radial-gradient(50% 50% at 50% 50%,rgba(16,185,129,.12),transparent 64%)',
|
||||
filter: 'blur(18px)',
|
||||
} as const;
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<div class="relative overflow-x-hidden">
|
||||
<div aria-hidden="true" :style="grainStyle"></div>
|
||||
<div aria-hidden="true" :style="glowStyle"></div>
|
||||
|
||||
<AppHeader />
|
||||
|
||||
<main id="top" class="relative z-[1]">
|
||||
<HeroSection />
|
||||
<ProblemSection />
|
||||
<FeaturesSection />
|
||||
<ShowcaseSection />
|
||||
<WorkGroupsSection />
|
||||
<HowItWorksSection />
|
||||
<SecuritySection />
|
||||
<FaqSection />
|
||||
<FinalCta />
|
||||
</main>
|
||||
|
||||
<AppFooter />
|
||||
</div>
|
||||
</template>
|
||||
47
packages/site/src/components/AppFooter.vue
Normal file
47
packages/site/src/components/AppFooter.vue
Normal file
@@ -0,0 +1,47 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import IconGitea from './icons/IconGitea.vue';
|
||||
|
||||
const { t } = useI18n();
|
||||
const REPO = 'https://git.lidge.fr/johanleroy/git-arboretum';
|
||||
const LICENSE = 'https://git.lidge.fr/johanleroy/git-arboretum/src/branch/main/LICENSE';
|
||||
const COFFEE = 'https://buymeacoffee.com/johanleroy';
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<footer class="relative z-[1] border-t border-[#1c1c1f]">
|
||||
<div class="mx-auto flex max-w-[1200px] flex-wrap items-center justify-between gap-5 px-6 py-[34px]">
|
||||
<div class="flex items-center gap-[11px]">
|
||||
<img
|
||||
src="/assets/arboretum-mark.png"
|
||||
alt=""
|
||||
width="22"
|
||||
height="22"
|
||||
class="h-[22px] w-[22px] object-contain"
|
||||
style="filter: grayscale(1) brightness(1.5); opacity: 0.4"
|
||||
/>
|
||||
<span class="font-mono text-sm text-zinc-300">git-arboretum.com</span>
|
||||
<span class="ml-1 text-[13px] text-zinc-600">— {{ t('footTag') }}</span>
|
||||
</div>
|
||||
<div class="flex items-center gap-[22px] text-sm">
|
||||
<a :href="REPO" target="_blank" rel="noopener" class="inline-flex items-center gap-1.5 text-zinc-400 no-underline transition-colors hover:text-emerald-400">
|
||||
<IconGitea :size="15" />
|
||||
Gitea
|
||||
</a>
|
||||
<a :href="LICENSE" target="_blank" rel="noopener" class="text-zinc-400 no-underline transition-colors hover:text-emerald-400">
|
||||
{{ t('license') }}
|
||||
</a>
|
||||
<a
|
||||
:href="COFFEE"
|
||||
target="_blank"
|
||||
rel="noopener"
|
||||
class="inline-flex items-center gap-1.5 text-zinc-400 no-underline transition-colors hover:text-amber-400 focus-visible:rounded-md focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-amber-400/70"
|
||||
>
|
||||
<svg width="15" height="15" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M10 2v2" /><path d="M14 2v2" /><path d="M5 8h13a1 1 0 0 1 1 1v2a4 4 0 0 1-4 4H8a4 4 0 0 1-4-4V9a1 1 0 0 1 1-1Z" /><path d="M6 15a4 4 0 0 0 4 4h2a4 4 0 0 0 4-4" /><path d="M19 9h1.5a2.5 2.5 0 0 1 0 5H18" /></svg>
|
||||
{{ t('coffee') }}
|
||||
</a>
|
||||
<span class="font-mono text-[12.5px] text-zinc-600">npx @johanleroy/git-arboretum</span>
|
||||
</div>
|
||||
</div>
|
||||
</footer>
|
||||
</template>
|
||||
59
packages/site/src/components/AppHeader.vue
Normal file
59
packages/site/src/components/AppHeader.vue
Normal file
@@ -0,0 +1,59 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import LangToggle from './LangToggle.vue';
|
||||
import IconGitea from './icons/IconGitea.vue';
|
||||
|
||||
const { t } = useI18n();
|
||||
const REPO = 'https://git.lidge.fr/johanleroy/git-arboretum';
|
||||
|
||||
const navLinks = [
|
||||
{ href: '#features', key: 'navFeatures' },
|
||||
{ href: '#how', key: 'navHow' },
|
||||
{ href: '#security', key: 'navSecurity' },
|
||||
{ href: '#faq', key: 'navFaq' },
|
||||
] as const;
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<header
|
||||
class="sticky top-0 z-50 border-b border-[#1c1c1f] bg-[rgba(9,9,11,0.72)] backdrop-blur-[14px]"
|
||||
>
|
||||
<div class="mx-auto flex h-16 max-w-[1200px] items-center justify-between gap-6 px-6">
|
||||
<a href="#top" class="flex items-center gap-2.5 text-zinc-100 no-underline">
|
||||
<img
|
||||
src="/assets/arboretum-mark.png"
|
||||
alt="Arboretum"
|
||||
width="28"
|
||||
height="28"
|
||||
class="block h-7 w-7 object-contain"
|
||||
/>
|
||||
<span class="font-mono text-[17px] font-semibold tracking-[-0.01em]">Arboretum</span>
|
||||
</a>
|
||||
|
||||
<nav class="hidden items-center gap-[30px] min-[900px]:flex">
|
||||
<a
|
||||
v-for="link in navLinks"
|
||||
:key="link.href"
|
||||
:href="link.href"
|
||||
class="text-[14.5px] text-zinc-400 no-underline transition-colors hover:text-zinc-100"
|
||||
>
|
||||
{{ t(link.key) }}
|
||||
</a>
|
||||
</nav>
|
||||
|
||||
<div class="flex items-center gap-3.5">
|
||||
<LangToggle />
|
||||
<a
|
||||
:href="REPO"
|
||||
target="_blank"
|
||||
rel="noopener"
|
||||
aria-label="Gitea"
|
||||
class="inline-flex items-center gap-[7px] rounded-lg border border-zinc-800 px-[13px] py-[7px] text-[13.5px] font-medium text-zinc-300 no-underline transition-colors hover:border-emerald-500/50 hover:text-emerald-400 focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-emerald-500/70"
|
||||
>
|
||||
<IconGitea :size="16" />
|
||||
Gitea
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
</header>
|
||||
</template>
|
||||
52
packages/site/src/components/FaqSection.vue
Normal file
52
packages/site/src/components/FaqSection.vue
Normal file
@@ -0,0 +1,52 @@
|
||||
<script setup lang="ts">
|
||||
import { computed, ref } from 'vue';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { FAQS } from '../i18n/content';
|
||||
import type { AppLocale } from '../i18n';
|
||||
|
||||
const { t, locale } = useI18n();
|
||||
const open = ref(0);
|
||||
const items = computed(() => FAQS[locale.value as AppLocale]);
|
||||
|
||||
function toggle(i: number): void {
|
||||
open.value = open.value === i ? -1 : i;
|
||||
}
|
||||
|
||||
function panelStyle(i: number) {
|
||||
return {
|
||||
maxHeight: open.value === i ? '300px' : '0px',
|
||||
opacity: open.value === i ? 1 : 0,
|
||||
overflow: 'hidden',
|
||||
transition: 'max-height .4s ease, opacity .35s ease',
|
||||
} as const;
|
||||
}
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section id="faq" class="mx-auto max-w-[780px] scroll-mt-[84px] px-6 pb-[100px]">
|
||||
<div v-reveal class="mb-[38px] text-center">
|
||||
<div class="mb-3.5 font-mono text-xs uppercase tracking-[0.14em] text-emerald-400">{{ t('navFaq') }}</div>
|
||||
<h2 class="m-0 text-[clamp(28px,3.4vw,40px)] font-semibold tracking-[-0.025em] text-zinc-50">{{ t('faqTitle') }}</h2>
|
||||
</div>
|
||||
|
||||
<div v-reveal>
|
||||
<div v-for="(f, i) in items" :key="i" class="border-t" :class="open === i ? 'border-emerald-400/40' : 'border-zinc-800'">
|
||||
<button
|
||||
type="button"
|
||||
:aria-expanded="open === i"
|
||||
:aria-controls="`faq-panel-${i}`"
|
||||
class="flex w-full cursor-pointer items-center justify-between gap-4 border-none bg-transparent px-1 py-5 text-left text-[clamp(16px,2vw,18px)] font-medium text-zinc-50 focus-visible:rounded-md focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-emerald-500/70"
|
||||
@click="toggle(i)"
|
||||
>
|
||||
<span>{{ f.q }}</span>
|
||||
<span class="flex flex-none text-emerald-400 transition-transform duration-300" :class="open === i ? 'rotate-180' : ''">
|
||||
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#34d399" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m6 9 6 6 6-6" /></svg>
|
||||
</span>
|
||||
</button>
|
||||
<div :id="`faq-panel-${i}`" :style="panelStyle(i)" :inert="open !== i" :aria-hidden="open !== i">
|
||||
<p class="m-0 max-w-[640px] px-1 pb-5 text-[15.5px] leading-[1.6] text-zinc-400">{{ f.a }}</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
17
packages/site/src/components/FeatureCard.vue
Normal file
17
packages/site/src/components/FeatureCard.vue
Normal file
@@ -0,0 +1,17 @@
|
||||
<script setup lang="ts">
|
||||
defineProps<{ title: string }>();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<div
|
||||
class="rounded-xl border border-zinc-800 bg-zinc-900/50 p-6 transition-[transform,border-color] duration-[180ms] ease-in-out hover:-translate-y-[3px] hover:border-emerald-400/40"
|
||||
>
|
||||
<div
|
||||
class="mb-4 inline-flex h-[42px] w-[42px] items-center justify-center rounded-[10px] bg-emerald-500/10 text-emerald-400"
|
||||
>
|
||||
<slot name="icon" />
|
||||
</div>
|
||||
<h3 class="m-0 mb-[7px] text-lg font-semibold text-zinc-50">{{ title }}</h3>
|
||||
<p class="m-0 text-[14.5px] leading-[1.55] text-zinc-400"><slot /></p>
|
||||
</div>
|
||||
</template>
|
||||
76
packages/site/src/components/FeaturesSection.vue
Normal file
76
packages/site/src/components/FeaturesSection.vue
Normal file
@@ -0,0 +1,76 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import FeatureCard from './FeatureCard.vue';
|
||||
const { t } = useI18n();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section id="features" class="mx-auto max-w-[1200px] scroll-mt-[84px] px-6 pb-[100px]">
|
||||
<div v-reveal class="mb-[46px] text-center">
|
||||
<div class="mb-3.5 font-mono text-xs uppercase tracking-[0.14em] text-emerald-400">{{ t('featKicker') }}</div>
|
||||
<h2 class="m-0 text-[clamp(28px,3.4vw,40px)] font-semibold tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('featTitle') }}
|
||||
</h2>
|
||||
</div>
|
||||
|
||||
<div v-reveal class="grid grid-cols-[repeat(auto-fit,minmax(264px,1fr))] gap-4">
|
||||
<FeatureCard :title="t('feat1Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><line x1="6" y1="3" x2="6" y2="15" /><circle cx="18" cy="6" r="3" /><circle cx="6" cy="18" r="3" /><path d="M18 9a9 9 0 0 1-9 9" /></svg>
|
||||
</template>
|
||||
{{ t('feat1Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat2Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><rect width="7" height="7" x="3" y="3" rx="1" /><rect width="7" height="7" x="14" y="3" rx="1" /><rect width="7" height="7" x="14" y="14" rx="1" /><rect width="7" height="7" x="3" y="14" rx="1" /></svg>
|
||||
</template>
|
||||
{{ t('feat2Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat3Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M22 12h-4l-3 9L9 3l-3 9H2" /></svg>
|
||||
</template>
|
||||
<span class="text-sky-300">{{ t('busy') }}</span> ·
|
||||
<span class="text-amber-300">{{ t('waiting') }}</span> ·
|
||||
<span class="text-emerald-400">{{ t('idle') }}</span> — {{ t('feat3Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat4Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><rect width="14" height="20" x="5" y="2" rx="2.5" /><path d="M12 18h.01" /></svg>
|
||||
</template>
|
||||
{{ t('feat4Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat5Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M10.27 21a1.94 1.94 0 0 0 3.46 0" /><path d="M3.262 15.326A1 1 0 0 0 4 17h16a1 1 0 0 0 .74-1.673C19.41 13.956 18 12.499 18 8A6 6 0 0 0 6 8c0 4.499-1.411 5.956-2.738 7.326" /></svg>
|
||||
</template>
|
||||
{{ t('feat5Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat6Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M21 15a2 2 0 0 1-2 2H7l-4 4V5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2z" /></svg>
|
||||
</template>
|
||||
{{ t('feat6Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat7Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M2.97 12.92A2 2 0 0 0 2 14.63v3.24a2 2 0 0 0 .97 1.71l3 1.8a2 2 0 0 0 2.06 0L12 19v-5.5l-5-3-4.03 2.42Z" /><path d="m7 16.5-4.74-2.85" /><path d="m7 16.5 5-3" /><path d="M7 16.5v5.17" /><path d="M12 13.5V19l3.97 2.38a2 2 0 0 0 2.06 0l3-1.8a2 2 0 0 0 .97-1.71v-3.24a2 2 0 0 0-.97-1.71L17 10.5l-5 3Z" /><path d="m17 16.5 4.74-2.85" /><path d="M7.97 4.42A2 2 0 0 0 7 6.13v4.37l5 3 5-3V6.13a2 2 0 0 0-.97-1.71l-3-1.8a2 2 0 0 0-2.06 0l-3 1.8Z" /></svg>
|
||||
</template>
|
||||
{{ t('feat7Desc') }}
|
||||
</FeatureCard>
|
||||
|
||||
<FeatureCard :title="t('feat8Title')">
|
||||
<template #icon>
|
||||
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z" /></svg>
|
||||
</template>
|
||||
{{ t('feat8Desc') }}
|
||||
</FeatureCard>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
61
packages/site/src/components/FinalCta.vue
Normal file
61
packages/site/src/components/FinalCta.vue
Normal file
@@ -0,0 +1,61 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { useCopy, INSTALL_COMMAND } from '../composables/useCopy';
|
||||
import IconGitea from './icons/IconGitea.vue';
|
||||
import IconCopy from './icons/IconCopy.vue';
|
||||
|
||||
const { t } = useI18n();
|
||||
const { copied, copy } = useCopy();
|
||||
const REPO = 'https://git.lidge.fr/johanleroy/git-arboretum';
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section class="mx-auto max-w-[1200px] px-6 pb-[100px]">
|
||||
<div
|
||||
v-reveal
|
||||
class="rounded-[20px] border border-zinc-800 px-6 py-[clamp(36px,5vw,64px)] text-center"
|
||||
style="background: radial-gradient(120% 140% at 50% 0%, rgba(16, 185, 129, 0.1), transparent 60%), #0c0c0e"
|
||||
>
|
||||
<img
|
||||
src="/assets/arboretum-mark.png"
|
||||
alt=""
|
||||
width="52"
|
||||
height="52"
|
||||
class="mx-auto mb-5 block h-[52px] w-[52px] object-contain"
|
||||
/>
|
||||
<h2 class="m-0 mb-3.5 text-[clamp(30px,4vw,46px)] font-bold leading-[1.08] tracking-[-0.03em] text-zinc-50">
|
||||
{{ t('ctaTitle') }}
|
||||
</h2>
|
||||
<p class="mx-auto mb-7 max-w-[480px] text-[17px] text-zinc-400">{{ t('ctaBody') }}</p>
|
||||
|
||||
<div
|
||||
class="mx-auto flex max-w-[460px] items-stretch overflow-hidden rounded-[10px] border border-zinc-800 bg-zinc-950"
|
||||
>
|
||||
<div class="flex min-w-0 flex-1 items-center gap-2.5 overflow-x-auto whitespace-nowrap px-4 font-mono text-sm">
|
||||
<span class="text-emerald-400">$</span><span class="text-zinc-200">{{ INSTALL_COMMAND }}</span>
|
||||
</div>
|
||||
<button
|
||||
type="button"
|
||||
aria-label="Copy install command"
|
||||
class="inline-flex flex-none items-center gap-[7px] border-l border-zinc-800 bg-zinc-900 px-4 font-mono text-[13px] font-semibold text-zinc-300 transition-colors hover:bg-zinc-800 hover:text-emerald-400 focus-visible:outline-2 focus-visible:-outline-offset-2 focus-visible:outline-emerald-500/70"
|
||||
@click="copy()"
|
||||
>
|
||||
<IconCopy :size="15" />
|
||||
<span aria-live="polite">{{ copied ? t('copied') : t('copy') }}</span>
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<div class="mt-[18px]">
|
||||
<a
|
||||
:href="REPO"
|
||||
target="_blank"
|
||||
rel="noopener"
|
||||
class="inline-flex items-center gap-2 text-[14.5px] text-zinc-400 no-underline transition-colors hover:text-emerald-400"
|
||||
>
|
||||
<IconGitea :size="16" />
|
||||
{{ t('ctaSource') }}
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
212
packages/site/src/components/HeroMockup.vue
Normal file
212
packages/site/src/components/HeroMockup.vue
Normal file
@@ -0,0 +1,212 @@
|
||||
<script setup lang="ts">
|
||||
import { computed } from 'vue';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { useHeroTimeline, type SessionState } from '../composables/useHeroTimeline';
|
||||
import { DLG_OPTS } from '../i18n/content';
|
||||
import type { AppLocale } from '../i18n';
|
||||
|
||||
const { t, locale } = useI18n();
|
||||
const { anim } = useHeroTimeline('hero-stage');
|
||||
|
||||
// Couleurs des lignes de terminal par type (porté de renderVals.C).
|
||||
const LINE_COLORS: Record<string, string> = {
|
||||
cmd: '#52525b',
|
||||
tool: '#a1a1aa',
|
||||
edit: '#34d399',
|
||||
add: '#34d399',
|
||||
del: '#f87171',
|
||||
ok: '#34d399',
|
||||
warn: '#fcd34d',
|
||||
run: '#7dd3fc',
|
||||
};
|
||||
|
||||
const PILL: Record<SessionState, { bg: string; fg: string; dot: string; pulse: string }> = {
|
||||
idle: { bg: 'rgba(2,44,34,.6)', fg: '#34d399', dot: '#34d399', pulse: '' },
|
||||
busy: { bg: 'rgba(8,47,73,.7)', fg: '#7dd3fc', dot: '#7dd3fc', pulse: 'pulseSky 2s ease-in-out infinite' },
|
||||
waiting: { bg: 'rgba(69,26,3,.7)', fg: '#fcd34d', dot: '#fcd34d', pulse: 'pulseAmber 2.2s ease-in-out infinite' },
|
||||
};
|
||||
|
||||
const pill = computed(() => PILL[anim.value.sess]);
|
||||
const sessText = computed(() => t(anim.value.sess));
|
||||
|
||||
const termLines = computed(() =>
|
||||
anim.value.lines.map((l) => ({ text: l.text, color: LINE_COLORS[l.k] ?? '#d4d4d8' })),
|
||||
);
|
||||
|
||||
const dlgOptions = computed(() =>
|
||||
DLG_OPTS[locale.value as AppLocale].map((txt, i) => {
|
||||
const highlighted = anim.value.hl === i;
|
||||
const answered = anim.value.ans === i;
|
||||
const row: Record<string, string> = {
|
||||
display: 'flex',
|
||||
alignItems: 'center',
|
||||
gap: '9px',
|
||||
padding: '7px 9px',
|
||||
borderRadius: '7px',
|
||||
border: '1px solid transparent',
|
||||
background: 'rgba(9,9,11,.4)',
|
||||
transition: 'background .2s, border-color .2s',
|
||||
};
|
||||
if (highlighted) {
|
||||
row.background = 'rgba(69,26,3,.5)';
|
||||
row.border = '1px solid rgba(217,119,6,.6)';
|
||||
}
|
||||
if (answered) {
|
||||
row.background = 'rgba(2,44,34,.45)';
|
||||
row.border = '1px solid rgba(5,150,105,.6)';
|
||||
}
|
||||
return {
|
||||
num: answered ? '✓' : String(i + 1),
|
||||
text: txt,
|
||||
rowStyle: row,
|
||||
numColor: answered ? '#34d399' : '#fbbf24',
|
||||
textColor: answered ? '#a7f3d0' : highlighted ? '#fde68a' : '#d4d4d8',
|
||||
};
|
||||
}),
|
||||
);
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<div id="hero-stage" class="relative min-w-[300px] flex-[1_1_480px]">
|
||||
<div
|
||||
class="relative overflow-hidden rounded-[14px] border border-zinc-800 bg-zinc-950 shadow-hero"
|
||||
>
|
||||
<!-- barre de fenêtre -->
|
||||
<div class="flex items-center gap-2 border-b border-[#1c1c1f] bg-[#0c0c0e] px-[14px] py-[11px]">
|
||||
<span class="h-2.5 w-2.5 rounded-full bg-zinc-700"></span>
|
||||
<span class="h-2.5 w-2.5 rounded-full bg-zinc-700"></span>
|
||||
<span class="h-2.5 w-2.5 rounded-full bg-zinc-700"></span>
|
||||
<span class="ml-2 font-mono text-[11.5px] text-zinc-600">arboretum · localhost:7777</span>
|
||||
</div>
|
||||
|
||||
<div class="flex min-h-[360px]">
|
||||
<!-- sidebar -->
|
||||
<div
|
||||
class="flex w-[168px] flex-none flex-col border-r border-[#1c1c1f] bg-zinc-900/40 px-2.5 py-3"
|
||||
>
|
||||
<div class="flex items-center gap-2 px-1 pb-3">
|
||||
<img
|
||||
src="/assets/arboretum-mark.png"
|
||||
alt=""
|
||||
width="20"
|
||||
height="20"
|
||||
class="h-5 w-5 object-contain"
|
||||
/>
|
||||
<span class="font-mono text-[13px] font-semibold text-zinc-200">Arboretum</span>
|
||||
</div>
|
||||
|
||||
<div
|
||||
class="mb-3 flex items-center gap-2 rounded-lg border border-zinc-800 bg-zinc-950/50 px-[9px] py-[7px]"
|
||||
>
|
||||
<svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="#52525b" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><circle cx="11" cy="11" r="8" /><path d="m21 21-4.3-4.3" /></svg>
|
||||
<span class="flex-1 text-[11.5px] text-zinc-600">{{ t('mSearch') }}</span>
|
||||
<span class="rounded border border-zinc-800 px-[5px] py-px font-mono text-[10px] text-zinc-500">⌘K</span>
|
||||
</div>
|
||||
|
||||
<div class="flex flex-col gap-0.5">
|
||||
<div class="flex items-center gap-[9px] rounded-lg bg-zinc-800 px-[9px] py-[7px] text-zinc-100">
|
||||
<svg width="15" height="15" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><rect width="7" height="9" x="3" y="3" rx="1" /><rect width="7" height="5" x="14" y="3" rx="1" /><rect width="7" height="9" x="14" y="12" rx="1" /><rect width="7" height="5" x="3" y="16" rx="1" /></svg>
|
||||
<span class="text-[12.5px]">{{ t('mDash') }}</span>
|
||||
<span
|
||||
v-show="anim.att > 0"
|
||||
class="ml-auto inline-flex h-[17px] min-w-[17px] items-center justify-center rounded-full px-[5px] font-mono text-[10px] font-bold"
|
||||
style="background: #f59e0b; color: #1c1300"
|
||||
>{{ anim.att }}</span
|
||||
>
|
||||
</div>
|
||||
<div class="flex items-center gap-[9px] rounded-lg px-[9px] py-[7px] text-zinc-400">
|
||||
<svg width="15" height="15" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M2.97 12.92A2 2 0 0 0 2 14.63v3.24a2 2 0 0 0 .97 1.71l3 1.8a2 2 0 0 0 2.06 0L12 19v-5.5l-5-3-4.03 2.42Z" /><path d="M7 16.5 12 13.5" /><path d="M12 13.5V19l3.97 2.38a2 2 0 0 0 2.06 0l3-1.8a2 2 0 0 0 .97-1.71v-3.24a2 2 0 0 0-.97-1.71L17 10.5l-5 3Z" /><path d="m17 16.5 4.74-2.85" /><path d="M7.97 4.42A2 2 0 0 0 7 6.13v4.37l5 3 5-3V6.13a2 2 0 0 0-.97-1.71l-3-1.8a2 2 0 0 0-2.06 0z" /></svg>
|
||||
<span class="text-[12.5px]">{{ t('mGroups') }}</span>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="flex-1"></div>
|
||||
|
||||
<div class="flex flex-col gap-0.5 border-t border-[#1c1c1f] pt-2.5">
|
||||
<div class="flex items-center gap-[9px] rounded-lg px-[9px] py-1.5 text-zinc-400">
|
||||
<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M12.22 2h-.44a2 2 0 0 0-2 2v.18a2 2 0 0 1-1 1.73l-.43.25a2 2 0 0 1-2 0l-.15-.08a2 2 0 0 0-2.73.73l-.22.38a2 2 0 0 0 .73 2.73l.15.1a2 2 0 0 1 1 1.72v.51a2 2 0 0 1-1 1.74l-.15.09a2 2 0 0 0-.73 2.73l.22.38a2 2 0 0 0 2.73.73l.15-.08a2 2 0 0 1 2 0l.43.25a2 2 0 0 1 1 1.73V20a2 2 0 0 0 2 2h.44a2 2 0 0 0 2-2v-.18a2 2 0 0 1 1-1.73l.43-.25a2 2 0 0 1 2 0l.15.08a2 2 0 0 0 2.73-.73l.22-.39a2 2 0 0 0-.73-2.73l-.15-.08a2 2 0 0 1-1-1.74v-.5a2 2 0 0 1 1-1.74l.15-.09a2 2 0 0 0 .73-2.73l-.22-.38a2 2 0 0 0-2.73-.73l-.15.08a2 2 0 0 1-2 0l-.43-.25a2 2 0 0 1-1-1.73V4a2 2 0 0 0-2-2z" /><circle cx="12" cy="12" r="3" /></svg>
|
||||
<span class="text-[12.5px]">{{ t('mSettings') }}</span>
|
||||
</div>
|
||||
<div class="flex items-center gap-[9px] rounded-lg px-[9px] py-1.5 text-zinc-400">
|
||||
<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><circle cx="12" cy="12" r="10" /><path d="M9.09 9a3 3 0 0 1 5.83 1c0 2-3 3-3 3" /><path d="M12 17h.01" /></svg>
|
||||
<span class="text-[12.5px]">{{ t('mHelp') }}</span>
|
||||
</div>
|
||||
<div class="px-[9px] pt-1.5 font-mono text-[10px] text-zinc-700">v0.4.2</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- main -->
|
||||
<div class="flex min-w-0 flex-1 flex-col gap-[11px] p-[13px]">
|
||||
<!-- terminal pane -->
|
||||
<div
|
||||
class="flex min-h-0 flex-1 flex-col overflow-hidden rounded-[10px] border border-zinc-800 bg-zinc-950"
|
||||
>
|
||||
<div class="flex items-center justify-between border-b border-[#1c1c1f] px-[11px] py-2">
|
||||
<span class="font-mono text-[11.5px] text-zinc-400">api · feat/auth</span>
|
||||
<span
|
||||
class="inline-flex items-center gap-1.5 rounded-full px-[9px] py-[3px] font-mono text-[11px]"
|
||||
:style="{ background: pill.bg, color: pill.fg }"
|
||||
>
|
||||
<span
|
||||
class="h-1.5 w-1.5 flex-none rounded-full"
|
||||
:style="{ background: pill.dot, animation: pill.pulse }"
|
||||
></span>
|
||||
{{ sessText }}
|
||||
</span>
|
||||
</div>
|
||||
<div
|
||||
class="flex min-h-[150px] flex-1 flex-col justify-end overflow-hidden p-[11px] font-mono text-xs leading-[1.7] text-zinc-300"
|
||||
>
|
||||
<div v-for="(ln, i) in termLines" :key="i" :style="{ color: ln.color, whiteSpace: 'pre' }">
|
||||
{{ ln.text }}
|
||||
</div>
|
||||
<div v-if="anim.cur">
|
||||
<span class="text-emerald-400">$</span>
|
||||
<span class="ml-1 inline-block h-[13px] w-[7px] animate-blink align-middle bg-zinc-200"></span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- dialogue de permission -->
|
||||
<div
|
||||
v-if="anim.dlg"
|
||||
class="animate-dlg-in rounded-[10px] border border-[rgba(120,53,15,0.6)] bg-[rgba(69,26,3,0.3)] p-[11px]"
|
||||
>
|
||||
<div class="mb-[9px] flex items-center gap-2">
|
||||
<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="#fbbf24" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m21.73 18-8-14a2 2 0 0 0-3.48 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3Z" /><path d="M12 9v4" /><path d="M12 17h.01" /></svg>
|
||||
<span class="text-[12.5px] text-zinc-200">{{ t('dlgQ') }}</span>
|
||||
</div>
|
||||
<div class="flex flex-col gap-[5px]">
|
||||
<div v-for="(op, i) in dlgOptions" :key="i" :style="op.rowStyle">
|
||||
<span
|
||||
class="w-[15px] flex-none text-center font-mono text-[11px] font-bold"
|
||||
:style="{ color: op.numColor }"
|
||||
>{{ op.num }}</span
|
||||
>
|
||||
<span class="text-xs" :style="{ color: op.textColor }">{{ op.text }}</span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- toast push -->
|
||||
<div
|
||||
v-if="anim.toast"
|
||||
class="animate-toast-in absolute bottom-[14px] right-[14px] flex w-[248px] items-start gap-2.5 rounded-[11px] border border-[rgba(120,53,15,0.5)] bg-[#0c0c0e] p-3 shadow-toast"
|
||||
>
|
||||
<span class="inline-flex h-[30px] w-[30px] flex-none items-center justify-center rounded-lg bg-emerald-500/15">
|
||||
<img src="/assets/arboretum-mark.png" alt="" width="18" height="18" class="h-[18px] w-[18px] object-contain" />
|
||||
</span>
|
||||
<div class="min-w-0 flex-1">
|
||||
<div class="flex items-center justify-between">
|
||||
<span class="font-mono text-[11px] text-emerald-400">Arboretum</span>
|
||||
<span class="text-[10px] text-zinc-600">now</span>
|
||||
</div>
|
||||
<div class="mt-[3px] text-[13px] font-semibold text-zinc-100">{{ t('toastTitle') }}</div>
|
||||
<div class="mt-px text-[11.5px] leading-[1.4] text-zinc-400">{{ t('toastBody') }}</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
80
packages/site/src/components/HeroSection.vue
Normal file
80
packages/site/src/components/HeroSection.vue
Normal file
@@ -0,0 +1,80 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { useCopy, INSTALL_COMMAND } from '../composables/useCopy';
|
||||
import HeroMockup from './HeroMockup.vue';
|
||||
import IconGitea from './icons/IconGitea.vue';
|
||||
import IconCopy from './icons/IconCopy.vue';
|
||||
|
||||
const { t } = useI18n();
|
||||
const { copied, copy } = useCopy();
|
||||
const REPO = 'https://git.lidge.fr/johanleroy/git-arboretum';
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section class="mx-auto flex max-w-[1200px] flex-wrap items-center gap-12 px-6 pb-16 pt-[72px]">
|
||||
<div class="min-w-[300px] flex-[1_1_430px]">
|
||||
<div class="mb-[22px] flex items-center gap-[13px]">
|
||||
<img
|
||||
src="/assets/arboretum-mark.png"
|
||||
alt=""
|
||||
width="46"
|
||||
height="46"
|
||||
class="block h-[46px] w-[46px] object-contain"
|
||||
/>
|
||||
<span
|
||||
class="inline-flex items-center gap-2 rounded-full border border-emerald-500/30 bg-emerald-500/[0.07] px-[11px] py-[5px] font-mono text-[11.5px] uppercase tracking-[0.1em] text-emerald-400"
|
||||
>
|
||||
<span class="h-1.5 w-1.5 rounded-full bg-emerald-400 shadow-[0_0_8px_#34d399]"></span>
|
||||
{{ t('heroBadge') }}
|
||||
</span>
|
||||
</div>
|
||||
|
||||
<h1 class="m-0 text-[clamp(40px,5.6vw,64px)] font-bold leading-[1.04] tracking-[-0.035em] text-zinc-50">
|
||||
{{ t('heroTitle') }}
|
||||
</h1>
|
||||
<p class="mt-[22px] max-w-[520px] text-[clamp(17px,1.7vw,20px)] leading-[1.55] text-zinc-400">
|
||||
{{ t('heroSub') }}
|
||||
</p>
|
||||
|
||||
<div
|
||||
class="mt-[30px] flex max-w-[480px] items-stretch overflow-hidden rounded-[10px] border border-zinc-800 bg-zinc-950/60"
|
||||
>
|
||||
<div
|
||||
class="flex min-w-0 flex-1 items-center gap-2.5 overflow-x-auto whitespace-nowrap px-[15px] font-mono text-sm"
|
||||
>
|
||||
<span class="text-emerald-400">$</span><span class="text-zinc-200">{{ INSTALL_COMMAND }}</span>
|
||||
</div>
|
||||
<button
|
||||
type="button"
|
||||
aria-label="Copy install command"
|
||||
class="inline-flex flex-none items-center gap-[7px] border-l border-zinc-800 bg-zinc-900 px-[15px] font-mono text-[13px] font-semibold text-zinc-300 transition-colors hover:bg-zinc-800 hover:text-emerald-400 focus-visible:outline-2 focus-visible:-outline-offset-2 focus-visible:outline-emerald-500/70"
|
||||
@click="copy()"
|
||||
>
|
||||
<IconCopy :size="15" />
|
||||
<span aria-live="polite">{{ copied ? t('copied') : t('copy') }}</span>
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<div class="mt-6 flex flex-wrap gap-[13px]">
|
||||
<a
|
||||
href="#how"
|
||||
class="inline-flex items-center gap-[9px] rounded-[9px] bg-emerald-600 px-6 py-[13px] text-[15.5px] font-semibold text-white no-underline transition-[background,transform] duration-150 ease-in-out hover:-translate-y-px hover:bg-emerald-500 focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-emerald-500/70"
|
||||
>
|
||||
{{ t('getStarted') }}
|
||||
<svg width="17" height="17" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M5 12h14" /><path d="m12 5 7 7-7 7" /></svg>
|
||||
</a>
|
||||
<a
|
||||
:href="REPO"
|
||||
target="_blank"
|
||||
rel="noopener"
|
||||
class="inline-flex items-center gap-[9px] rounded-[9px] border border-zinc-800 px-[22px] py-[13px] text-[15.5px] font-medium text-zinc-100 no-underline transition-colors hover:border-emerald-500/45 hover:text-emerald-400 focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-emerald-500/70"
|
||||
>
|
||||
<IconGitea :size="17" />
|
||||
{{ t('gitea') }}
|
||||
</a>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<HeroMockup />
|
||||
</section>
|
||||
</template>
|
||||
42
packages/site/src/components/HowItWorksSection.vue
Normal file
42
packages/site/src/components/HowItWorksSection.vue
Normal file
@@ -0,0 +1,42 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
const { t } = useI18n();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section id="how" class="mx-auto max-w-[1200px] scroll-mt-[84px] px-6 pb-[100px]">
|
||||
<div v-reveal class="mb-[46px] text-center">
|
||||
<div class="mb-3.5 font-mono text-xs uppercase tracking-[0.14em] text-emerald-400">{{ t('howKicker') }}</div>
|
||||
<h2 class="m-0 text-[clamp(28px,3.4vw,40px)] font-semibold tracking-[-0.025em] text-zinc-50">{{ t('howTitle') }}</h2>
|
||||
</div>
|
||||
|
||||
<div v-reveal class="grid grid-cols-[repeat(auto-fit,minmax(280px,1fr))] gap-4">
|
||||
<div class="rounded-xl border border-zinc-800 bg-zinc-900/50 p-[26px]">
|
||||
<div class="mb-[18px] font-mono text-[13px] text-emerald-400">01</div>
|
||||
<h3 class="m-0 mb-2.5 text-lg font-semibold text-zinc-50">{{ t('step1Title') }}</h3>
|
||||
<p class="m-0 mb-4 text-[14.5px] leading-[1.55] text-zinc-400">{{ t('step1Desc') }}</p>
|
||||
<div class="overflow-x-auto whitespace-nowrap rounded-lg border border-zinc-800 bg-zinc-950 p-[11px] font-mono text-[12.5px] text-zinc-200">
|
||||
<span class="text-emerald-400">$ </span>npx @johanleroy/git-arboretum
|
||||
</div>
|
||||
</div>
|
||||
<div class="rounded-xl border border-zinc-800 bg-zinc-900/50 p-[26px]">
|
||||
<div class="mb-[18px] font-mono text-[13px] text-emerald-400">02</div>
|
||||
<h3 class="m-0 mb-2.5 text-lg font-semibold text-zinc-50">{{ t('step2Title') }}</h3>
|
||||
<p class="m-0 mb-4 text-[14.5px] leading-[1.55] text-zinc-400">{{ t('step2Desc') }}</p>
|
||||
<div class="overflow-x-auto whitespace-nowrap rounded-lg border border-zinc-800 bg-zinc-950 p-[11px] font-mono text-[12.5px] text-sky-300">
|
||||
→ http://localhost:7777
|
||||
</div>
|
||||
</div>
|
||||
<div class="rounded-xl border border-zinc-800 bg-zinc-900/50 p-[26px]">
|
||||
<div class="mb-[18px] font-mono text-[13px] text-emerald-400">03</div>
|
||||
<h3 class="m-0 mb-2.5 text-lg font-semibold text-zinc-50">{{ t('step3Title') }}</h3>
|
||||
<p class="m-0 mb-4 text-[14.5px] leading-[1.55] text-zinc-400">{{ t('step3Desc') }}</p>
|
||||
<div class="flex flex-wrap gap-1.5">
|
||||
<span class="rounded-md bg-emerald-500/10 px-[9px] py-1 font-mono text-[11px] text-emerald-400">{{ t('idle') }}</span>
|
||||
<span class="rounded-md bg-[rgba(8,47,73,0.7)] px-[9px] py-1 font-mono text-[11px] text-sky-300">{{ t('busy') }}</span>
|
||||
<span class="rounded-md bg-[rgba(69,26,3,0.6)] px-[9px] py-1 font-mono text-[11px] text-amber-300">{{ t('waiting') }}</span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
37
packages/site/src/components/LangToggle.vue
Normal file
37
packages/site/src/components/LangToggle.vue
Normal file
@@ -0,0 +1,37 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { setLocale, type AppLocale } from '../i18n';
|
||||
|
||||
const { locale } = useI18n();
|
||||
|
||||
function set(l: AppLocale): void {
|
||||
setLocale(l);
|
||||
}
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<div
|
||||
role="group"
|
||||
aria-label="Language"
|
||||
class="flex items-center overflow-hidden rounded-lg border border-zinc-800 bg-zinc-950/40"
|
||||
>
|
||||
<button
|
||||
type="button"
|
||||
:aria-pressed="locale === 'en'"
|
||||
class="cursor-pointer border-none px-[11px] py-1.5 font-mono text-xs font-semibold focus-visible:outline-2 focus-visible:outline-offset-1 focus-visible:outline-emerald-500/70"
|
||||
:class="locale === 'en' ? 'bg-zinc-800 text-emerald-400' : 'bg-transparent text-zinc-500'"
|
||||
@click="set('en')"
|
||||
>
|
||||
EN
|
||||
</button>
|
||||
<button
|
||||
type="button"
|
||||
:aria-pressed="locale === 'fr'"
|
||||
class="cursor-pointer border-none px-[11px] py-1.5 font-mono text-xs font-semibold focus-visible:outline-2 focus-visible:outline-offset-1 focus-visible:outline-emerald-500/70"
|
||||
:class="locale === 'fr' ? 'bg-zinc-800 text-emerald-400' : 'bg-transparent text-zinc-500'"
|
||||
@click="set('fr')"
|
||||
>
|
||||
FR
|
||||
</button>
|
||||
</div>
|
||||
</template>
|
||||
14
packages/site/src/components/ProblemSection.vue
Normal file
14
packages/site/src/components/ProblemSection.vue
Normal file
@@ -0,0 +1,14 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
const { t } = useI18n();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section v-reveal class="mx-auto max-w-[920px] px-6 pb-[92px] pt-12 text-center">
|
||||
<div class="mb-4 font-mono text-xs uppercase tracking-[0.14em] text-emerald-400">{{ t('probKicker') }}</div>
|
||||
<h2 class="m-0 text-[clamp(28px,3.6vw,42px)] font-semibold leading-[1.18] tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('probTitle') }}
|
||||
</h2>
|
||||
<p class="mx-auto mt-[22px] max-w-[640px] text-[clamp(17px,1.6vw,19px)] text-zinc-400">{{ t('probBody') }}</p>
|
||||
</section>
|
||||
</template>
|
||||
47
packages/site/src/components/SecuritySection.vue
Normal file
47
packages/site/src/components/SecuritySection.vue
Normal file
@@ -0,0 +1,47 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
const { t } = useI18n();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section id="security" class="mx-auto max-w-[1200px] scroll-mt-[84px] px-6 pb-[100px]">
|
||||
<div
|
||||
v-reveal
|
||||
class="rounded-[18px] border border-emerald-500/[0.18] p-[clamp(28px,4vw,48px)]"
|
||||
style="background: linear-gradient(180deg, rgba(16, 185, 129, 0.05), rgba(16, 185, 129, 0))"
|
||||
>
|
||||
<div class="mb-[30px] flex flex-wrap items-end justify-between gap-3.5">
|
||||
<div>
|
||||
<div class="mb-3 font-mono text-xs uppercase tracking-[0.14em] text-emerald-400">{{ t('secKicker') }}</div>
|
||||
<h2 class="m-0 text-[clamp(26px,3.2vw,38px)] font-semibold leading-[1.12] tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('secTitle') }}
|
||||
</h2>
|
||||
</div>
|
||||
<p class="m-0 max-w-[380px] text-[15.5px] leading-[1.55] text-zinc-400">{{ t('secIntro') }}</p>
|
||||
</div>
|
||||
|
||||
<div class="grid grid-cols-[repeat(auto-fit,minmax(200px,1fr))] gap-3.5">
|
||||
<div class="flex flex-col gap-2.5 rounded-[11px] border border-zinc-800 bg-[#0c0c0e] p-[18px]">
|
||||
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#34d399" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><rect width="18" height="11" x="3" y="11" rx="2" /><path d="M7 11V7a5 5 0 0 1 10 0v4" /></svg>
|
||||
<div class="text-[15px] font-semibold text-zinc-50">{{ t('sec1Title') }}</div>
|
||||
<div class="text-[13.5px] leading-[1.5] text-zinc-400">{{ t('sec1Desc') }}</div>
|
||||
</div>
|
||||
<div class="flex flex-col gap-2.5 rounded-[11px] border border-zinc-800 bg-[#0c0c0e] p-[18px]">
|
||||
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#34d399" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m15.5 7.5 2.3 2.3a1 1 0 0 0 1.4 0l2.1-2.1a1 1 0 0 0 0-1.4L19 4" /><path d="m21 2-9.6 9.6" /><circle cx="7.5" cy="15.5" r="5.5" /></svg>
|
||||
<div class="text-[15px] font-semibold text-zinc-50">{{ t('sec2Title') }}</div>
|
||||
<div class="text-[13.5px] leading-[1.5] text-zinc-400">{{ t('sec2Desc') }}</div>
|
||||
</div>
|
||||
<div class="flex flex-col gap-2.5 rounded-[11px] border border-zinc-800 bg-[#0c0c0e] p-[18px]">
|
||||
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#34d399" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z" /><path d="m9 12 2 2 4-4" /></svg>
|
||||
<div class="text-[15px] font-semibold text-zinc-50">{{ t('sec3Title') }}</div>
|
||||
<div class="text-[13.5px] leading-[1.5] text-zinc-400">{{ t('sec3Desc') }}</div>
|
||||
</div>
|
||||
<div class="flex flex-col gap-2.5 rounded-[11px] border border-zinc-800 bg-[#0c0c0e] p-[18px]">
|
||||
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#34d399" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M5 12.55a11 11 0 0 1 14.08 0" /><path d="M1.42 9a16 16 0 0 1 21.16 0" /><path d="M8.53 16.11a6 6 0 0 1 6.95 0" /><path d="M12 20h.01" /></svg>
|
||||
<div class="text-[15px] font-semibold text-zinc-50">{{ t('sec4Title') }}</div>
|
||||
<div class="text-[13.5px] leading-[1.5] text-zinc-400">{{ t('sec4Desc') }}</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
170
packages/site/src/components/ShowcaseSection.vue
Normal file
170
packages/site/src/components/ShowcaseSection.vue
Normal file
@@ -0,0 +1,170 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
const { t } = useI18n();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section id="showcase" class="mx-auto flex max-w-[1200px] scroll-mt-[84px] flex-col gap-[92px] px-6">
|
||||
<!-- a) dashboard + needs attention -->
|
||||
<div v-reveal class="flex flex-wrap items-center gap-12">
|
||||
<div class="min-w-[280px] flex-[1_1_380px]">
|
||||
<div class="mb-3 font-mono text-xs uppercase tracking-[0.12em] text-emerald-400">{{ t('scAKicker') }}</div>
|
||||
<h2 class="m-0 mb-4 text-[clamp(26px,3vw,34px)] font-semibold leading-[1.15] tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('scATitle') }}
|
||||
</h2>
|
||||
<p class="m-0 text-[16.5px] leading-[1.6] text-zinc-400">{{ t('scABody') }}</p>
|
||||
</div>
|
||||
<div class="min-w-[280px] flex-[1_1_420px]">
|
||||
<div class="overflow-hidden rounded-xl border border-zinc-800 bg-[#0c0c0e] shadow-card">
|
||||
<div class="flex items-center gap-[9px] border-b border-[#1c1c1f] bg-[rgba(69,26,3,0.18)] px-[15px] py-3">
|
||||
<svg width="15" height="15" viewBox="0 0 24 24" fill="none" stroke="#fcd34d" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m21.73 18-8-14a2 2 0 0 0-3.48 0l-8 14A2 2 0 0 0 4 21h16a2 2 0 0 0 1.73-3Z" /><path d="M12 9v4" /><path d="M12 17h.01" /></svg>
|
||||
<span class="text-sm font-semibold text-zinc-50">{{ t('mAttn') }}</span>
|
||||
<span class="ml-auto rounded-full bg-amber-300/[0.12] px-[9px] py-0.5 font-mono text-[11px] text-amber-300">2</span>
|
||||
</div>
|
||||
<div class="flex flex-col gap-2 p-2.5">
|
||||
<div class="flex items-center gap-3 rounded-[9px] border border-[rgba(120,53,15,0.55)] bg-[rgba(69,26,3,0.3)] px-[13px] py-[11px]">
|
||||
<span class="h-2 w-2 flex-none animate-pulse-amber rounded-full bg-amber-300"></span>
|
||||
<div class="min-w-0 flex-1">
|
||||
<div class="font-mono text-[13px] text-zinc-200">api · feat/auth</div>
|
||||
<div class="text-xs text-[#d4a55a]">Approve change to login.ts?</div>
|
||||
</div>
|
||||
<button type="button" class="flex-none rounded-[7px] border border-amber-300/30 bg-amber-300/[0.12] px-3 py-[5px] text-xs font-semibold text-amber-300">Answer</button>
|
||||
</div>
|
||||
<div class="flex items-center gap-3 rounded-[9px] border border-[rgba(120,53,15,0.55)] bg-[rgba(69,26,3,0.3)] px-[13px] py-[11px]">
|
||||
<span class="h-2 w-2 flex-none animate-pulse-amber rounded-full bg-amber-300"></span>
|
||||
<div class="min-w-0 flex-1">
|
||||
<div class="font-mono text-[13px] text-zinc-200">web · checkout</div>
|
||||
<div class="text-xs text-[#d4a55a]">Run the failing test again?</div>
|
||||
</div>
|
||||
<button type="button" class="flex-none rounded-[7px] border border-amber-300/30 bg-amber-300/[0.12] px-3 py-[5px] text-xs font-semibold text-amber-300">Answer</button>
|
||||
</div>
|
||||
<div class="mx-0.5 my-[3px] h-px bg-[#1c1c1f]"></div>
|
||||
<div class="flex items-center gap-3 rounded-[9px] px-[13px] py-[9px]">
|
||||
<span class="h-2 w-2 flex-none animate-pulse-sky rounded-full bg-sky-300"></span>
|
||||
<div class="min-w-0 flex-1 font-mono text-[13px] text-zinc-400">db · refactor</div>
|
||||
<span class="flex-none font-mono text-[11px] text-sky-300">{{ t('busy') }}</span>
|
||||
</div>
|
||||
<div class="flex items-center gap-3 rounded-[9px] px-[13px] py-[9px]">
|
||||
<span class="h-2 w-2 flex-none rounded-full bg-emerald-400"></span>
|
||||
<div class="min-w-0 flex-1 font-mono text-[13px] text-zinc-400">docs · main</div>
|
||||
<span class="flex-none font-mono text-[11px] text-emerald-400">{{ t('idle') }}</span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- b) multi-terminal grid -->
|
||||
<div v-reveal class="flex flex-wrap-reverse items-center gap-12">
|
||||
<div class="min-w-[280px] flex-[1_1_420px]">
|
||||
<div class="grid grid-cols-2 gap-2.5 overflow-hidden rounded-xl border border-zinc-800 bg-[#0c0c0e] p-3 shadow-card">
|
||||
<div class="overflow-hidden rounded-[9px] border border-zinc-800 bg-zinc-950">
|
||||
<div class="flex items-center justify-between border-b border-[#1c1c1f] px-[11px] py-2">
|
||||
<span class="font-mono text-[11px] text-zinc-400">api · feat/auth</span>
|
||||
<span class="h-1.5 w-1.5 animate-pulse-sky rounded-full bg-sky-300"></span>
|
||||
</div>
|
||||
<div class="p-[11px] font-mono text-[11px] leading-[1.75] text-zinc-300">
|
||||
<div class="text-emerald-400">● Edit session.ts</div>
|
||||
<div class="text-emerald-400">+ const token = sign(...)</div>
|
||||
<div class="text-red-400">- legacy cookie auth</div>
|
||||
<div class="text-zinc-500">refactoring guards…</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="overflow-hidden rounded-[9px] border border-zinc-800 bg-zinc-950">
|
||||
<div class="flex items-center justify-between border-b border-[#1c1c1f] px-[11px] py-2">
|
||||
<span class="font-mono text-[11px] text-zinc-400">web · fix/cart</span>
|
||||
<span class="h-1.5 w-1.5 rounded-full bg-emerald-400"></span>
|
||||
</div>
|
||||
<div class="p-[11px] font-mono text-[11px] leading-[1.75] text-zinc-300">
|
||||
<div class="text-emerald-400">✓ all tests passing</div>
|
||||
<div class="text-zinc-500">24 passed, 0 failed</div>
|
||||
<div>
|
||||
<span class="text-emerald-400">$</span>
|
||||
<span class="ml-1 inline-block h-[11px] w-1.5 animate-blink align-middle bg-zinc-200"></span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="overflow-hidden rounded-[9px] border border-zinc-800 bg-zinc-950">
|
||||
<div class="flex items-center justify-between border-b border-[#1c1c1f] px-[11px] py-2">
|
||||
<span class="font-mono text-[11px] text-zinc-400">db · refactor</span>
|
||||
<span class="h-1.5 w-1.5 animate-pulse-sky rounded-full bg-sky-300"></span>
|
||||
</div>
|
||||
<div class="p-[11px] font-mono text-[11px] leading-[1.75] text-zinc-300">
|
||||
<div class="text-emerald-400">● Write migration</div>
|
||||
<div class="text-zinc-500">0003_add_index.sql</div>
|
||||
<div class="text-zinc-500">applying to schema…</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="overflow-hidden rounded-[9px] border border-zinc-800 bg-zinc-950">
|
||||
<div class="flex items-center justify-between border-b border-[#1c1c1f] px-[11px] py-2">
|
||||
<span class="font-mono text-[11px] text-zinc-400">docs · api</span>
|
||||
<span class="h-1.5 w-1.5 animate-pulse-sky rounded-full bg-sky-300"></span>
|
||||
</div>
|
||||
<div class="p-[11px] font-mono text-[11px] leading-[1.75] text-zinc-300">
|
||||
<div class="text-emerald-400">● Read README.md</div>
|
||||
<div class="text-zinc-500">## Quick start</div>
|
||||
<div class="text-zinc-500">writing examples…</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="min-w-[280px] flex-[1_1_380px]">
|
||||
<div class="mb-3 font-mono text-xs uppercase tracking-[0.12em] text-emerald-400">{{ t('scBKicker') }}</div>
|
||||
<h2 class="m-0 mb-4 text-[clamp(26px,3vw,34px)] font-semibold leading-[1.15] tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('scBTitle') }}
|
||||
</h2>
|
||||
<p class="m-0 text-[16.5px] leading-[1.6] text-zinc-400">{{ t('scBBody') }}</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- c) mobile -->
|
||||
<div v-reveal class="flex flex-wrap items-center gap-12">
|
||||
<div class="min-w-[280px] flex-[1_1_380px]">
|
||||
<div class="mb-3 font-mono text-xs uppercase tracking-[0.12em] text-emerald-400">{{ t('scCKicker') }}</div>
|
||||
<h2 class="m-0 mb-4 text-[clamp(26px,3vw,34px)] font-semibold leading-[1.15] tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('scCTitle') }}
|
||||
</h2>
|
||||
<p class="m-0 text-[16.5px] leading-[1.6] text-zinc-400">{{ t('scCBody') }}</p>
|
||||
</div>
|
||||
<div class="flex min-w-[280px] flex-[1_1_320px] justify-center">
|
||||
<div class="relative w-[288px] overflow-hidden rounded-[40px] border-[9px] border-zinc-900 bg-zinc-950 shadow-phone">
|
||||
<div class="flex h-[30px] items-center justify-center">
|
||||
<div class="h-1.5 w-[90px] rounded-full bg-zinc-800"></div>
|
||||
</div>
|
||||
<div class="px-[13px] pb-[22px]">
|
||||
<div class="flex items-start gap-[11px] rounded-[15px] border border-[rgba(120,53,15,0.5)] bg-[#0c0c0e] p-[13px] shadow-toast-sm">
|
||||
<span class="inline-flex h-[30px] w-[30px] flex-none items-center justify-center rounded-lg bg-emerald-500/[0.14]">
|
||||
<img src="/assets/arboretum-mark.png" alt="" width="18" height="18" class="h-[18px] w-[18px] object-contain" />
|
||||
</span>
|
||||
<div class="min-w-0 flex-1">
|
||||
<div class="flex items-center justify-between">
|
||||
<span class="font-mono text-[11px] text-emerald-400">Arboretum</span>
|
||||
<span class="text-[10px] text-zinc-600">now</span>
|
||||
</div>
|
||||
<div class="mt-[3px] text-[13.5px] font-semibold text-zinc-50">{{ t('toastTitle') }}</div>
|
||||
<div class="text-xs leading-[1.45] text-zinc-400">{{ t('toastBody') }}</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="mt-[14px] overflow-hidden rounded-[15px] border border-zinc-800 bg-zinc-950">
|
||||
<div class="flex items-center gap-2 border-b border-[#1c1c1f] px-[13px] py-[11px]">
|
||||
<span class="h-[7px] w-[7px] animate-pulse-amber rounded-full bg-amber-300"></span>
|
||||
<span class="font-mono text-[11px] text-zinc-300">feat/auth</span>
|
||||
</div>
|
||||
<div class="p-[13px]">
|
||||
<div class="text-[13px] leading-[1.5] text-zinc-300">{{ t('dlgQ') }}</div>
|
||||
<div class="mt-2 rounded-lg border border-[#1c1c1f] bg-[#0c0c0e] p-[9px] font-mono text-[11px] leading-[1.6] text-zinc-500">
|
||||
<div class="text-emerald-400">+ verifyToken(req)</div>
|
||||
<div class="text-red-400">- skipAuth()</div>
|
||||
</div>
|
||||
<div class="mt-[13px] flex gap-2">
|
||||
<button type="button" class="flex-1 rounded-lg bg-emerald-600 py-2.5 text-[13px] font-semibold text-white">{{ t('approve') }}</button>
|
||||
<button type="button" class="flex-1 rounded-lg border border-zinc-800 bg-transparent py-2.5 text-[13px] font-medium text-zinc-300">{{ t('reject') }}</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
55
packages/site/src/components/WorkGroupsSection.vue
Normal file
55
packages/site/src/components/WorkGroupsSection.vue
Normal file
@@ -0,0 +1,55 @@
|
||||
<script setup lang="ts">
|
||||
import { useI18n } from 'vue-i18n';
|
||||
const { t } = useI18n();
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section class="mx-auto max-w-[1200px] scroll-mt-[84px] px-6 py-[92px]">
|
||||
<div
|
||||
v-reveal
|
||||
class="flex flex-wrap items-center gap-12 rounded-[18px] border border-zinc-800 p-[clamp(28px,4vw,52px)]"
|
||||
style="background: linear-gradient(180deg, rgba(24, 24, 27, 0.55), rgba(12, 12, 14, 0.55))"
|
||||
>
|
||||
<div class="min-w-[280px] flex-[1_1_360px]">
|
||||
<div class="mb-3 font-mono text-xs uppercase tracking-[0.12em] text-emerald-400">{{ t('grpKicker') }}</div>
|
||||
<h2 class="m-0 mb-4 text-[clamp(26px,3vw,36px)] font-semibold leading-[1.15] tracking-[-0.025em] text-zinc-50">
|
||||
{{ t('grpTitle') }}
|
||||
</h2>
|
||||
<p class="m-0 text-[16.5px] leading-[1.6] text-zinc-400">{{ t('grpBody') }}</p>
|
||||
</div>
|
||||
<div class="flex min-w-[280px] flex-[1_1_360px] justify-center">
|
||||
<div class="flex w-full max-w-[380px] items-center">
|
||||
<div class="flex flex-none flex-col items-center gap-2">
|
||||
<div
|
||||
class="inline-flex h-[62px] w-[62px] items-center justify-center rounded-[15px] border border-emerald-500/35 bg-emerald-500/[0.12] text-emerald-400"
|
||||
>
|
||||
<svg width="26" height="26" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M2.97 12.92A2 2 0 0 0 2 14.63v3.24a2 2 0 0 0 .97 1.71l3 1.8a2 2 0 0 0 2.06 0L12 19v-5.5l-5-3-4.03 2.42Z" /><path d="M7 16.5 12 13.5" /><path d="M12 13.5V19l3.97 2.38a2 2 0 0 0 2.06 0l3-1.8a2 2 0 0 0 .97-1.71v-3.24a2 2 0 0 0-.97-1.71L17 10.5l-5 3Z" /><path d="m17 16.5 4.74-2.85" /><path d="M7.97 4.42A2 2 0 0 0 7 6.13v4.37l5 3 5-3V6.13a2 2 0 0 0-.97-1.71l-3-1.8a2 2 0 0 0-2.06 0z" /></svg>
|
||||
</div>
|
||||
<span class="font-mono text-[11px] text-zinc-300">payments</span>
|
||||
</div>
|
||||
<div class="relative h-[96px] flex-1">
|
||||
<svg width="100%" height="100%" viewBox="0 0 100 96" preserveAspectRatio="none" class="absolute inset-0" aria-hidden="true">
|
||||
<path d="M0 48 H40 V14 H100" fill="none" stroke="rgba(16,185,129,.45)" stroke-width="1.4" />
|
||||
<path d="M0 48 H40 V48 H100" fill="none" stroke="rgba(16,185,129,.45)" stroke-width="1.4" />
|
||||
<path d="M0 48 H40 V82 H100" fill="none" stroke="rgba(16,185,129,.45)" stroke-width="1.4" />
|
||||
</svg>
|
||||
</div>
|
||||
<div class="flex flex-none flex-col gap-2.5">
|
||||
<div class="flex items-center gap-2 rounded-lg border border-zinc-800 bg-[#0c0c0e] px-3 py-2">
|
||||
<span class="h-1.5 w-1.5 rounded-full bg-sky-300"></span>
|
||||
<span class="font-mono text-[11px] text-zinc-300">api</span>
|
||||
</div>
|
||||
<div class="flex items-center gap-2 rounded-lg border border-zinc-800 bg-[#0c0c0e] px-3 py-2">
|
||||
<span class="h-1.5 w-1.5 rounded-full bg-sky-300"></span>
|
||||
<span class="font-mono text-[11px] text-zinc-300">web</span>
|
||||
</div>
|
||||
<div class="flex items-center gap-2 rounded-lg border border-zinc-800 bg-[#0c0c0e] px-3 py-2">
|
||||
<span class="h-1.5 w-1.5 rounded-full bg-sky-300"></span>
|
||||
<span class="font-mono text-[11px] text-zinc-300">sdk</span>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
20
packages/site/src/components/icons/IconCopy.vue
Normal file
20
packages/site/src/components/icons/IconCopy.vue
Normal file
@@ -0,0 +1,20 @@
|
||||
<script setup lang="ts">
|
||||
withDefaults(defineProps<{ size?: number }>(), { size: 15 });
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<svg
|
||||
:width="size"
|
||||
:height="size"
|
||||
viewBox="0 0 24 24"
|
||||
fill="none"
|
||||
stroke="currentColor"
|
||||
stroke-width="1.9"
|
||||
stroke-linecap="round"
|
||||
stroke-linejoin="round"
|
||||
aria-hidden="true"
|
||||
>
|
||||
<rect width="13" height="13" x="9" y="9" rx="2" />
|
||||
<path d="M5 15c-1.1 0-2-.9-2-2V5c0-1.1.9-2 2-2h8c1.1 0 2 .9 2 2" />
|
||||
</svg>
|
||||
</template>
|
||||
22
packages/site/src/components/icons/IconGitea.vue
Normal file
22
packages/site/src/components/icons/IconGitea.vue
Normal file
@@ -0,0 +1,22 @@
|
||||
<script setup lang="ts">
|
||||
withDefaults(defineProps<{ size?: number }>(), { size: 16 });
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<svg
|
||||
:width="size"
|
||||
:height="size"
|
||||
viewBox="0 0 24 24"
|
||||
fill="none"
|
||||
stroke="currentColor"
|
||||
stroke-width="1.7"
|
||||
stroke-linecap="round"
|
||||
stroke-linejoin="round"
|
||||
aria-hidden="true"
|
||||
>
|
||||
<path d="M4 10h12v4a4 4 0 0 1-4 4H8a4 4 0 0 1-4-4z" />
|
||||
<path d="M16 11h2.5a2.5 2.5 0 0 1 0 5H16" />
|
||||
<path d="M7 3c-.5.8.5 1.6 0 2.5" />
|
||||
<path d="M11 3c-.5.8.5 1.6 0 2.5" />
|
||||
</svg>
|
||||
</template>
|
||||
24
packages/site/src/composables/useCopy.ts
Normal file
24
packages/site/src/composables/useCopy.ts
Normal file
@@ -0,0 +1,24 @@
|
||||
import { ref } from 'vue';
|
||||
|
||||
export const INSTALL_COMMAND = 'npx @johanleroy/git-arboretum';
|
||||
|
||||
// Bouton « copier la commande » : copie + bascule le label 1800 ms (fidèle au design).
|
||||
export function useCopy() {
|
||||
const copied = ref(false);
|
||||
let timer: ReturnType<typeof setTimeout> | undefined;
|
||||
|
||||
async function copy(text: string = INSTALL_COMMAND): Promise<void> {
|
||||
try {
|
||||
if (navigator.clipboard) await navigator.clipboard.writeText(text);
|
||||
} catch {
|
||||
/* clipboard indisponible (contexte non sécurisé) */
|
||||
}
|
||||
copied.value = true;
|
||||
clearTimeout(timer);
|
||||
timer = setTimeout(() => {
|
||||
copied.value = false;
|
||||
}, 1800);
|
||||
}
|
||||
|
||||
return { copied, copy };
|
||||
}
|
||||
113
packages/site/src/composables/useHeroTimeline.ts
Normal file
113
packages/site/src/composables/useHeroTimeline.ts
Normal file
@@ -0,0 +1,113 @@
|
||||
import { onMounted, onUnmounted, ref } from 'vue';
|
||||
|
||||
// Portage 1:1 de la timeline animée du mockup hero (Arboretum.dc.html).
|
||||
export type SessionState = 'idle' | 'busy' | 'waiting';
|
||||
|
||||
export interface AnimLine {
|
||||
text: string;
|
||||
k: string;
|
||||
}
|
||||
|
||||
export interface HeroAnim {
|
||||
sess: SessionState;
|
||||
lines: AnimLine[];
|
||||
att: number;
|
||||
toast: boolean;
|
||||
dlg: boolean;
|
||||
hl: number;
|
||||
ans: number;
|
||||
cur: boolean;
|
||||
}
|
||||
|
||||
const TOTAL = 13000;
|
||||
const TICK = 80;
|
||||
|
||||
interface ScriptEntry {
|
||||
at: number;
|
||||
text: string;
|
||||
k: string;
|
||||
}
|
||||
|
||||
function script(): ScriptEntry[] {
|
||||
return [
|
||||
{ at: 850, text: '$ claude --resume feat/auth', k: 'cmd' },
|
||||
{ at: 1400, text: '> Reading src/auth/login.ts', k: 'tool' },
|
||||
{ at: 1950, text: '● Edit login.ts', k: 'edit' },
|
||||
{ at: 2400, text: " + import { verifyToken } from './jwt'", k: 'add' },
|
||||
{ at: 2850, text: ' + const user = await verifyToken(req)', k: 'add' },
|
||||
{ at: 3350, text: '● Bash npm test -- auth', k: 'edit' },
|
||||
{ at: 3850, text: ' ✓ 14 passed (1.24s)', k: 'ok' },
|
||||
{ at: 4300, text: '● Permission required to edit login.ts', k: 'warn' },
|
||||
{ at: 7950, text: '✓ approved · applying change', k: 'ok' },
|
||||
{ at: 8500, text: '● Edit login.ts', k: 'edit' },
|
||||
{ at: 9050, text: '● Running…', k: 'run' },
|
||||
];
|
||||
}
|
||||
|
||||
export function deriveAnim(clock: number): HeroAnim {
|
||||
const sess: SessionState = clock < 700 ? 'idle' : clock < 4500 ? 'busy' : clock < 7700 ? 'waiting' : 'busy';
|
||||
const sc = script();
|
||||
const lines: AnimLine[] = [];
|
||||
for (const entry of sc) {
|
||||
if (clock >= entry.at) lines.push({ text: entry.text, k: entry.k });
|
||||
}
|
||||
const att = clock >= 4500 && clock < 7700 ? 1 : 0;
|
||||
const toast = clock >= 4650 && clock < 7700;
|
||||
const dlg = clock >= 4600 && clock < 7700;
|
||||
const hl = clock >= 6000 && clock < 7050 ? 0 : -1;
|
||||
const ans = clock >= 7050 && clock < 7700 ? 0 : -1;
|
||||
const cur = sess !== 'waiting';
|
||||
return { sess, lines, att, toast, dlg, hl, ans, cur };
|
||||
}
|
||||
|
||||
export function useHeroTimeline(stageId = 'hero-stage') {
|
||||
const anim = ref<HeroAnim>(deriveAnim(0));
|
||||
let clock = 0;
|
||||
let visible = true;
|
||||
let everVisible = false;
|
||||
let timer: ReturnType<typeof setInterval> | undefined;
|
||||
let io: IntersectionObserver | undefined;
|
||||
|
||||
onMounted(() => {
|
||||
let reduced = false;
|
||||
try {
|
||||
reduced = window.matchMedia('(prefers-reduced-motion: reduce)').matches;
|
||||
} catch {
|
||||
/* ignore */
|
||||
}
|
||||
if (reduced) {
|
||||
anim.value = deriveAnim(5200);
|
||||
return;
|
||||
}
|
||||
const stage = document.getElementById(stageId);
|
||||
if (stage && 'IntersectionObserver' in window) {
|
||||
io = new IntersectionObserver(
|
||||
(entries) => {
|
||||
const e = entries[0];
|
||||
if (!e) return;
|
||||
if (e.isIntersecting) {
|
||||
visible = true;
|
||||
everVisible = true;
|
||||
} else if (everVisible) {
|
||||
visible = false;
|
||||
}
|
||||
},
|
||||
{ threshold: 0, rootMargin: '200px 0px 200px 0px' },
|
||||
);
|
||||
io.observe(stage);
|
||||
}
|
||||
timer = setInterval(() => {
|
||||
if (!visible) return;
|
||||
clock += TICK;
|
||||
if (clock >= TOTAL) clock = 0;
|
||||
anim.value = deriveAnim(clock);
|
||||
}, TICK);
|
||||
});
|
||||
|
||||
onUnmounted(() => {
|
||||
if (timer) clearInterval(timer);
|
||||
if (io) io.disconnect();
|
||||
});
|
||||
|
||||
return { anim };
|
||||
}
|
||||
52
packages/site/src/composables/useScrollReveal.ts
Normal file
52
packages/site/src/composables/useScrollReveal.ts
Normal file
@@ -0,0 +1,52 @@
|
||||
import type { Directive } from 'vue';
|
||||
|
||||
// Directive `v-reveal` : révèle un bloc quand il entre dans le viewport.
|
||||
// Reprend l'intention du setupReveal() du design (seuil ~92% de la hauteur),
|
||||
// via un IntersectionObserver partagé. Respecte prefers-reduced-motion.
|
||||
let reducedMotion = false;
|
||||
try {
|
||||
reducedMotion = window.matchMedia('(prefers-reduced-motion: reduce)').matches;
|
||||
} catch {
|
||||
/* matchMedia indisponible */
|
||||
}
|
||||
|
||||
let observer: IntersectionObserver | null = null;
|
||||
|
||||
function getObserver(): IntersectionObserver | null {
|
||||
if (typeof IntersectionObserver === 'undefined') return null;
|
||||
if (!observer) {
|
||||
observer = new IntersectionObserver(
|
||||
(entries) => {
|
||||
for (const entry of entries) {
|
||||
if (entry.isIntersecting) {
|
||||
entry.target.classList.add('is-visible');
|
||||
observer?.unobserve(entry.target);
|
||||
}
|
||||
}
|
||||
},
|
||||
// -8% en bas ≈ déclenche quand le haut du bloc franchit ~92% du viewport.
|
||||
{ threshold: 0, rootMargin: '0px 0px -8% 0px' },
|
||||
);
|
||||
}
|
||||
return observer;
|
||||
}
|
||||
|
||||
export const reveal: Directive<HTMLElement> = {
|
||||
mounted(el) {
|
||||
el.classList.add('reveal');
|
||||
if (reducedMotion) {
|
||||
el.classList.add('is-visible');
|
||||
return;
|
||||
}
|
||||
const io = getObserver();
|
||||
if (!io) {
|
||||
// Pas d'IntersectionObserver : on révèle immédiatement (pas de contenu caché).
|
||||
el.classList.add('is-visible');
|
||||
return;
|
||||
}
|
||||
io.observe(el);
|
||||
},
|
||||
unmounted(el) {
|
||||
observer?.unobserve(el);
|
||||
},
|
||||
};
|
||||
7
packages/site/src/env.d.ts
vendored
Normal file
7
packages/site/src/env.d.ts
vendored
Normal file
@@ -0,0 +1,7 @@
|
||||
/// <reference types="vite/client" />
|
||||
|
||||
declare module '*.vue' {
|
||||
import type { DefineComponent } from 'vue';
|
||||
const component: DefineComponent<Record<string, unknown>, Record<string, unknown>, unknown>;
|
||||
export default component;
|
||||
}
|
||||
60
packages/site/src/i18n/content.ts
Normal file
60
packages/site/src/i18n/content.ts
Normal file
@@ -0,0 +1,60 @@
|
||||
// Listes structurées (FAQ, options de dialogue) — gardées hors des messages
|
||||
// vue-i18n et indexées par locale, pour rester du texte pur typé (pas d'innerHTML).
|
||||
import type { AppLocale } from './index';
|
||||
|
||||
export interface FaqItem {
|
||||
q: string;
|
||||
a: string;
|
||||
}
|
||||
|
||||
export const FAQS: Record<AppLocale, FaqItem[]> = {
|
||||
en: [
|
||||
{
|
||||
q: 'Is Arboretum an IDE?',
|
||||
a: "No — it's a command center. It doesn't replace your editor; it supervises the AI coding agents working across your repos: spawning sessions, surfacing their state, and letting you answer them.",
|
||||
},
|
||||
{
|
||||
q: 'Does it need the cloud?',
|
||||
a: 'No. Arboretum is local-first. The daemon runs on your own machine and binds to 127.0.0.1 by default. Your code and sessions never leave your network unless you choose to expose the dashboard.',
|
||||
},
|
||||
{
|
||||
q: 'How do I access it remotely?',
|
||||
a: 'Through Tailscale Serve. Expose the dashboard to your tailnet and reach it securely from any device — no port forwarding, no public endpoint.',
|
||||
},
|
||||
{
|
||||
q: 'Does it work on mobile?',
|
||||
a: 'Yes. The dashboard is an installable PWA. Add it to your home screen, get Web Push the moment a session needs you, and approve or reject a prompt with a single tap.',
|
||||
},
|
||||
{
|
||||
q: 'Is my code safe?',
|
||||
a: 'Arboretum binds to localhost, hashes access tokens at rest, and enforces strict origin checks on every request. Remote access runs through Tailscale rather than an open port.',
|
||||
},
|
||||
],
|
||||
fr: [
|
||||
{
|
||||
q: 'Arboretum est-il un IDE ?',
|
||||
a: "Non — c'est un poste de commandement. Il ne remplace pas votre éditeur ; il supervise les agents de code IA qui travaillent sur vos repos : lancement des sessions, affichage de leur état, et réponse à leurs questions.",
|
||||
},
|
||||
{
|
||||
q: 'A-t-il besoin du cloud ?',
|
||||
a: 'Non. Arboretum est local-first. Le daemon tourne sur votre propre machine et se lie à 127.0.0.1 par défaut. Votre code et vos sessions ne quittent jamais votre réseau sauf si vous exposez le dashboard.',
|
||||
},
|
||||
{
|
||||
q: 'Comment y accéder à distance ?',
|
||||
a: "Via Tailscale Serve. Exposez le dashboard à votre tailnet et accédez-y en sécurité depuis n'importe quel appareil — sans redirection de port ni endpoint public.",
|
||||
},
|
||||
{
|
||||
q: 'Fonctionne-t-il sur mobile ?',
|
||||
a: "Oui. Le dashboard est une PWA installable. Ajoutez-le à l'écran d'accueil, recevez un Web Push dès qu'une session a besoin de vous, et approuvez ou refusez une question d'un toucher.",
|
||||
},
|
||||
{
|
||||
q: 'Mon code est-il en sécurité ?',
|
||||
a: "Arboretum se lie à localhost, hashe les tokens au repos, et applique une vérification d'origine stricte sur chaque requête. L'accès distant passe par Tailscale plutôt qu'un port ouvert.",
|
||||
},
|
||||
],
|
||||
};
|
||||
|
||||
export const DLG_OPTS: Record<AppLocale, string[]> = {
|
||||
en: ['Yes, apply the change', "Yes, and don't ask again", 'No, keep current version'],
|
||||
fr: ['Oui, appliquer le changement', 'Oui, et ne plus demander', 'Non, garder la version actuelle'],
|
||||
};
|
||||
93
packages/site/src/i18n/en.ts
Normal file
93
packages/site/src/i18n/en.ts
Normal file
@@ -0,0 +1,93 @@
|
||||
// Messages EN — copie fidèle du dict() du design Arboretum.dc.html.
|
||||
export default {
|
||||
navFeatures: 'Features',
|
||||
navHow: 'How it works',
|
||||
navSecurity: 'Security',
|
||||
navFaq: 'FAQ',
|
||||
gitea: 'View on Gitea',
|
||||
heroBadge: 'Mission control for AI coding agents',
|
||||
heroTitle: 'Mission control for your AI coding agents',
|
||||
heroSub:
|
||||
'Run many Claude Code sessions across every git worktree — and supervise them from any device, even your phone.',
|
||||
getStarted: 'Get started',
|
||||
probKicker: 'The problem',
|
||||
probTitle: "Many agents across worktrees is chaos — and you're chained to one terminal.",
|
||||
probBody:
|
||||
'Sessions scattered across tabs. No idea which agent is waiting on you. Step away from the desk and everything stalls. Arboretum is the single pane of glass.',
|
||||
featKicker: 'Everything in one view',
|
||||
featTitle: 'Built to supervise agents — not to be an IDE',
|
||||
feat1Title: 'Worktree-first',
|
||||
feat1Desc: 'Every session is pinned to a git worktree. You see branches, not chaos.',
|
||||
feat2Title: 'Many sessions, one view',
|
||||
feat2Desc: 'Run parallel Claude Code agents side by side in a single live grid.',
|
||||
feat3Title: 'Fine-grained states',
|
||||
feat3Desc: 'tell at a glance what each agent is doing.',
|
||||
feat4Title: 'Supervise anywhere',
|
||||
feat4Desc: 'Installable PWA. Check in from your laptop, tablet, or phone.',
|
||||
feat5Title: 'Web Push alerts',
|
||||
feat5Desc: 'Get pinged the moment a session needs a decision from you.',
|
||||
feat6Title: 'Answer without a terminal',
|
||||
feat6Desc: 'Respond to agent prompts and dialogs right from the dashboard.',
|
||||
feat7Title: 'Work groups',
|
||||
feat7Desc: 'Group repos and launch the same feature across all of them at once.',
|
||||
feat8Title: 'Local-first & secure',
|
||||
feat8Desc: 'Binds to localhost, hashes tokens, remote access via Tailscale.',
|
||||
scAKicker: 'Worktree-first dashboard',
|
||||
scATitle: 'See what needs you — before anything stalls',
|
||||
scABody:
|
||||
'A live list of every worktree and its session state. The Needs attention rail floats the agents waiting on a decision to the top, so nothing sits blocked while you are heads-down elsewhere.',
|
||||
scBKicker: 'Multi-terminal grid',
|
||||
scBTitle: "Every agent's output, streaming live",
|
||||
scBBody:
|
||||
'Watch all your sessions at once — real terminal output, color-coded by state, updating in real time. Click any pane to take over, answer a prompt, or stop a run.',
|
||||
scCKicker: 'On your phone',
|
||||
scCTitle: 'Unblock an agent from the kitchen',
|
||||
scCBody:
|
||||
'Install the PWA and get a Web Push the second a session needs you. Tap the notification, read the prompt, answer the dialog — your agent keeps moving while you are away.',
|
||||
grpKicker: 'Work groups · cross-repo',
|
||||
grpTitle: 'Ship one feature across every repo at once',
|
||||
grpBody:
|
||||
'Group the repos that move together — a service, its client, its docs. Launch the same task to all of them and Arboretum spins up a worktree and an agent in each, then tracks them as one unit.',
|
||||
howKicker: 'How it works',
|
||||
howTitle: 'Zero install. Three steps.',
|
||||
step1Title: 'Launch the daemon',
|
||||
step1Desc: 'One command. No install, no config, no account.',
|
||||
step2Title: 'Open the dashboard',
|
||||
step2Desc: 'It serves a web dashboard on localhost. Install it as a PWA on any device.',
|
||||
step3Title: 'Spawn & supervise',
|
||||
step3Desc: 'Start Claude Code sessions on any worktree and watch them from anywhere.',
|
||||
secKicker: 'Security',
|
||||
secTitle: 'A web terminal you can actually trust',
|
||||
secIntro: 'Built local-first. Nothing is exposed unless you choose to — and even then, on your terms.',
|
||||
sec1Title: 'Localhost by default',
|
||||
sec1Desc: 'Binds to 127.0.0.1. Nothing leaves your machine unless you say so.',
|
||||
sec2Title: 'Hashed tokens',
|
||||
sec2Desc: 'Access tokens are hashed (sha256) at rest. No plaintext secrets on disk.',
|
||||
sec3Title: 'Strict origin checks',
|
||||
sec3Desc: 'Every request is origin-validated. No cross-site surprises.',
|
||||
sec4Title: 'Remote via Tailscale',
|
||||
sec4Desc: 'Reach it over Tailscale Serve — no public port, no port forwarding.',
|
||||
faqTitle: 'Questions, answered',
|
||||
ctaTitle: 'Take command of your agents',
|
||||
ctaBody: 'One command to launch. Supervise everything from one place.',
|
||||
ctaSource: 'View the source on Gitea',
|
||||
footTag: 'a garden of branches, one pane of glass.',
|
||||
license: 'MIT License',
|
||||
coffee: 'Buy me a coffee',
|
||||
mDash: 'Dashboard',
|
||||
mGroups: 'Groups',
|
||||
mSettings: 'Settings',
|
||||
mHelp: 'Help',
|
||||
mSearch: 'Search',
|
||||
mAttn: 'Needs attention',
|
||||
waiting: 'waiting',
|
||||
busy: 'busy',
|
||||
idle: 'idle',
|
||||
approve: 'Approve',
|
||||
reject: 'Reject',
|
||||
toastTitle: 'Session waiting for you',
|
||||
toastBody: 'api · feat/auth needs a decision',
|
||||
dlgQ: 'Apply this change to login.ts?',
|
||||
copy: 'Copy',
|
||||
copied: 'Copied',
|
||||
};
|
||||
93
packages/site/src/i18n/fr.ts
Normal file
93
packages/site/src/i18n/fr.ts
Normal file
@@ -0,0 +1,93 @@
|
||||
// Messages FR — copie fidèle du dict() du design Arboretum.dc.html.
|
||||
export default {
|
||||
navFeatures: 'Fonctionnalités',
|
||||
navHow: 'Comment ça marche',
|
||||
navSecurity: 'Sécurité',
|
||||
navFaq: 'FAQ',
|
||||
gitea: 'Voir sur Gitea',
|
||||
heroBadge: 'Poste de commandement pour agents de code IA',
|
||||
heroTitle: 'Le poste de commandement de vos agents de code IA',
|
||||
heroSub:
|
||||
"Lancez plusieurs sessions Claude Code à travers chaque worktree git — et supervisez-les depuis n'importe quel appareil, même votre téléphone.",
|
||||
getStarted: 'Commencer',
|
||||
probKicker: 'Le problème',
|
||||
probTitle: "Plein d'agents à travers les worktrees, c'est le chaos — et vous êtes cloué à un seul terminal.",
|
||||
probBody:
|
||||
"Des sessions éparpillées dans des onglets. Aucune idée de quel agent vous attend. Vous quittez le bureau et tout se fige. Arboretum, c'est la vitre unique.",
|
||||
featKicker: 'Tout dans une seule vue',
|
||||
featTitle: 'Conçu pour superviser les agents — pas pour être un IDE',
|
||||
feat1Title: "Worktree d'abord",
|
||||
feat1Desc: 'Chaque session est rattachée à un worktree git. Vous voyez des branches, pas du chaos.',
|
||||
feat2Title: 'Plusieurs sessions, une vue',
|
||||
feat2Desc: 'Lancez des agents Claude Code en parallèle, côte à côte dans une seule grille en direct.',
|
||||
feat3Title: 'États fins',
|
||||
feat3Desc: "sachez d'un coup d'œil ce que fait chaque agent.",
|
||||
feat4Title: 'Supervisez partout',
|
||||
feat4Desc: "PWA installable. Surveillez depuis l'ordinateur, la tablette ou le téléphone.",
|
||||
feat5Title: 'Alertes Web Push',
|
||||
feat5Desc: "Soyez prévenu dès qu'une session attend une décision.",
|
||||
feat6Title: 'Répondre sans terminal',
|
||||
feat6Desc: 'Répondez aux questions et dialogues des agents directement depuis le dashboard.',
|
||||
feat7Title: 'Work groups',
|
||||
feat7Desc: 'Regroupez des repos et lancez la même feature dans tous à la fois.',
|
||||
feat8Title: 'Local-first & sécurisé',
|
||||
feat8Desc: 'Se lie à localhost, hashe les tokens, accès distant via Tailscale.',
|
||||
scAKicker: 'Dashboard worktree-first',
|
||||
scATitle: 'Voyez ce qui vous attend — avant que ça ne bloque',
|
||||
scABody:
|
||||
"Une liste en direct de chaque worktree et de l'état de sa session. Le bandeau À traiter fait remonter les agents en attente d'une décision, pour que rien ne reste bloqué pendant que vous êtes concentré ailleurs.",
|
||||
scBKicker: 'Grille multi-terminaux',
|
||||
scBTitle: 'La sortie de chaque agent, en direct',
|
||||
scBBody:
|
||||
"Surveillez toutes vos sessions en même temps — vraie sortie terminal, couleur selon l'état, mise à jour en temps réel. Cliquez sur un panneau pour reprendre la main, répondre, ou arrêter une exécution.",
|
||||
scCKicker: 'Sur votre téléphone',
|
||||
scCTitle: 'Débloquez un agent depuis la cuisine',
|
||||
scCBody:
|
||||
"Installez la PWA et recevez un Web Push dès qu'une session a besoin de vous. Touchez la notification, lisez la question, répondez au dialogue — votre agent continue pendant que vous êtes loin du bureau.",
|
||||
grpKicker: 'Work groups · cross-repo',
|
||||
grpTitle: "Livrez une feature dans tous les repos d'un coup",
|
||||
grpBody:
|
||||
'Regroupez les repos qui avancent ensemble — un service, son client, sa doc. Lancez la même tâche à tous ; Arboretum crée un worktree et un agent dans chacun, puis les suit comme un seul ensemble.',
|
||||
howKicker: 'Comment ça marche',
|
||||
howTitle: 'Zéro install. Trois étapes.',
|
||||
step1Title: 'Lancez le daemon',
|
||||
step1Desc: "Une commande. Pas d'install, pas de config, pas de compte.",
|
||||
step2Title: 'Ouvrez le dashboard',
|
||||
step2Desc: "Il sert un dashboard web sur localhost. Installez-le en PWA sur n'importe quel appareil.",
|
||||
step3Title: 'Lancez & supervisez',
|
||||
step3Desc: "Démarrez des sessions Claude Code sur n'importe quel worktree et surveillez-les de partout.",
|
||||
secKicker: 'Sécurité',
|
||||
secTitle: 'Un terminal web en qui vous pouvez avoir confiance',
|
||||
secIntro: "Conçu local-first. Rien n'est exposé sauf si vous le décidez — et toujours selon vos règles.",
|
||||
sec1Title: 'Localhost par défaut',
|
||||
sec1Desc: 'Se lie à 127.0.0.1. Rien ne quitte votre machine sans votre accord.',
|
||||
sec2Title: 'Tokens hashés',
|
||||
sec2Desc: 'Les tokens sont hashés (sha256) au repos. Aucun secret en clair sur le disque.',
|
||||
sec3Title: "Vérification d'origine stricte",
|
||||
sec3Desc: 'Chaque requête est validée par origine. Pas de surprise cross-site.',
|
||||
sec4Title: 'Distant via Tailscale',
|
||||
sec4Desc: 'Accédez-y via Tailscale Serve — aucun port public, aucune redirection de port.',
|
||||
faqTitle: 'Vos questions, nos réponses',
|
||||
ctaTitle: 'Prenez le commandement de vos agents',
|
||||
ctaBody: 'Une commande pour lancer. Tout superviser depuis un seul endroit.',
|
||||
ctaSource: 'Voir le code sur Gitea',
|
||||
footTag: 'un jardin de branches, une seule vitre.',
|
||||
license: 'Licence MIT',
|
||||
coffee: 'Paye-moi un café',
|
||||
mDash: 'Tableau de bord',
|
||||
mGroups: 'Groupes',
|
||||
mSettings: 'Réglages',
|
||||
mHelp: 'Aide',
|
||||
mSearch: 'Rechercher',
|
||||
mAttn: 'À traiter',
|
||||
waiting: 'en attente',
|
||||
busy: 'occupé',
|
||||
idle: 'au repos',
|
||||
approve: 'Approuver',
|
||||
reject: 'Refuser',
|
||||
toastTitle: 'Une session vous attend',
|
||||
toastBody: 'api · feat/auth attend une décision',
|
||||
dlgQ: 'Appliquer ce changement à login.ts ?',
|
||||
copy: 'Copier',
|
||||
copied: 'Copié',
|
||||
};
|
||||
37
packages/site/src/i18n/index.ts
Normal file
37
packages/site/src/i18n/index.ts
Normal file
@@ -0,0 +1,37 @@
|
||||
import { createI18n } from 'vue-i18n';
|
||||
import en from './en';
|
||||
import fr from './fr';
|
||||
|
||||
export type AppLocale = 'en' | 'fr';
|
||||
|
||||
const STORAGE_KEY = 'arb-lang';
|
||||
|
||||
// Détection fidèle au design : localStorage prioritaire, sinon langue navigateur
|
||||
// (fr → FR, sinon EN).
|
||||
function initialLocale(): AppLocale {
|
||||
let saved: string | null = null;
|
||||
try {
|
||||
saved = localStorage.getItem(STORAGE_KEY);
|
||||
} catch {
|
||||
/* localStorage indisponible (mode privé, etc.) */
|
||||
}
|
||||
if (saved === 'fr' || saved === 'en') return saved;
|
||||
const nav = (typeof navigator !== 'undefined' && navigator.language ? navigator.language : '').toLowerCase();
|
||||
return nav.indexOf('fr') === 0 ? 'fr' : 'en';
|
||||
}
|
||||
|
||||
export const i18n = createI18n({
|
||||
legacy: false,
|
||||
locale: initialLocale(),
|
||||
fallbackLocale: 'en',
|
||||
messages: { en, fr },
|
||||
});
|
||||
|
||||
export function setLocale(locale: AppLocale): void {
|
||||
i18n.global.locale.value = locale;
|
||||
try {
|
||||
localStorage.setItem(STORAGE_KEY, locale);
|
||||
} catch {
|
||||
/* ignore */
|
||||
}
|
||||
}
|
||||
12
packages/site/src/main.ts
Normal file
12
packages/site/src/main.ts
Normal file
@@ -0,0 +1,12 @@
|
||||
import { createApp } from 'vue';
|
||||
// Polices self-host (subset latin) — bundlées par Vite, aucune requête Google Fonts.
|
||||
import '@fontsource/jetbrains-mono/latin-400.css';
|
||||
import '@fontsource/jetbrains-mono/latin-500.css';
|
||||
import '@fontsource/jetbrains-mono/latin-600.css';
|
||||
import '@fontsource/jetbrains-mono/latin-700.css';
|
||||
import App from './App.vue';
|
||||
import { i18n } from './i18n';
|
||||
import { reveal } from './composables/useScrollReveal';
|
||||
import './style.css';
|
||||
|
||||
createApp(App).use(i18n).directive('reveal', reveal).mount('#app');
|
||||
120
packages/site/src/style.css
Normal file
120
packages/site/src/style.css
Normal file
@@ -0,0 +1,120 @@
|
||||
@import 'tailwindcss';
|
||||
|
||||
/* La palette du design correspond à zinc/emerald/amber/sky/red de Tailwind.
|
||||
On ajoute seulement les tokens hors échelle : ombres, police mono, animations. */
|
||||
@theme {
|
||||
--font-mono: 'JetBrains Mono', ui-monospace, monospace;
|
||||
|
||||
--shadow-hero: 0 30px 80px -30px rgb(0 0 0 / 0.85);
|
||||
--shadow-card: 0 24px 60px -30px rgb(0 0 0 / 0.8);
|
||||
--shadow-phone: 0 30px 70px -28px rgb(0 0 0 / 0.9);
|
||||
--shadow-toast: 0 12px 32px -12px rgb(0 0 0 / 0.7);
|
||||
--shadow-toast-sm: 0 10px 24px -12px rgb(0 0 0 / 0.6);
|
||||
|
||||
--animate-blink: blink 1.05s steps(1) infinite;
|
||||
--animate-pulse-sky: pulseSky 2s ease-in-out infinite;
|
||||
--animate-pulse-amber: pulseAmber 2.2s ease-in-out infinite;
|
||||
--animate-toast-in: toastIn 0.4s cubic-bezier(0.2, 0.8, 0.2, 1) both;
|
||||
--animate-dlg-in: dlgIn 0.35s ease both;
|
||||
}
|
||||
|
||||
/* JetBrains Mono (Open Font License) : @font-face fournis par @fontsource,
|
||||
importés dans main.ts et bundlés par Vite (self-host, pas de CDN Google). */
|
||||
|
||||
html {
|
||||
scroll-behavior: smooth;
|
||||
}
|
||||
body {
|
||||
margin: 0;
|
||||
background-color: #09090b;
|
||||
color: #f4f4f5;
|
||||
font-family: ui-sans-serif, system-ui, -apple-system, 'Segoe UI', sans-serif;
|
||||
font-size: 16px;
|
||||
line-height: 1.6;
|
||||
-webkit-font-smoothing: antialiased;
|
||||
overflow-x: hidden;
|
||||
}
|
||||
::selection {
|
||||
background: rgba(16, 185, 129, 0.3);
|
||||
color: #fff;
|
||||
}
|
||||
|
||||
@keyframes blink {
|
||||
0%,
|
||||
48% {
|
||||
opacity: 1;
|
||||
}
|
||||
49%,
|
||||
100% {
|
||||
opacity: 0;
|
||||
}
|
||||
}
|
||||
@keyframes pulseSky {
|
||||
0% {
|
||||
box-shadow: 0 0 0 0 rgba(125, 211, 252, 0.55);
|
||||
}
|
||||
70%,
|
||||
100% {
|
||||
box-shadow: 0 0 0 6px rgba(125, 211, 252, 0);
|
||||
}
|
||||
}
|
||||
@keyframes pulseAmber {
|
||||
0% {
|
||||
box-shadow: 0 0 0 0 rgba(252, 211, 77, 0.55);
|
||||
}
|
||||
70%,
|
||||
100% {
|
||||
box-shadow: 0 0 0 6px rgba(252, 211, 77, 0);
|
||||
}
|
||||
}
|
||||
@keyframes toastIn {
|
||||
from {
|
||||
opacity: 0;
|
||||
transform: translateY(16px) scale(0.96);
|
||||
}
|
||||
to {
|
||||
opacity: 1;
|
||||
transform: none;
|
||||
}
|
||||
}
|
||||
@keyframes dlgIn {
|
||||
from {
|
||||
opacity: 0;
|
||||
transform: translateY(10px);
|
||||
}
|
||||
to {
|
||||
opacity: 1;
|
||||
transform: none;
|
||||
}
|
||||
}
|
||||
|
||||
@layer base {
|
||||
/* Tailwind v4 ne met plus cursor:pointer sur les boutons → on le rétablit. */
|
||||
button:not(:disabled),
|
||||
[role='button']:not([aria-disabled='true']) {
|
||||
cursor: pointer;
|
||||
}
|
||||
}
|
||||
|
||||
/* Révélation au scroll (directive v-reveal) */
|
||||
.reveal {
|
||||
opacity: 0;
|
||||
transform: translateY(22px);
|
||||
transition:
|
||||
opacity 0.7s ease,
|
||||
transform 0.7s ease;
|
||||
}
|
||||
.reveal.is-visible {
|
||||
opacity: 1;
|
||||
transform: none;
|
||||
}
|
||||
|
||||
@media (prefers-reduced-motion: reduce) {
|
||||
* {
|
||||
animation: none !important;
|
||||
}
|
||||
.reveal {
|
||||
opacity: 1;
|
||||
transform: none;
|
||||
}
|
||||
}
|
||||
16
packages/site/tsconfig.json
Normal file
16
packages/site/tsconfig.json
Normal file
@@ -0,0 +1,16 @@
|
||||
{
|
||||
"extends": "../../tsconfig.base.json",
|
||||
"compilerOptions": {
|
||||
"composite": false,
|
||||
"noEmit": true,
|
||||
"declaration": false,
|
||||
"declarationMap": false,
|
||||
"sourceMap": false,
|
||||
"module": "ESNext",
|
||||
"moduleResolution": "Bundler",
|
||||
"lib": ["ES2023", "DOM", "DOM.Iterable"],
|
||||
"types": ["vite/client"],
|
||||
"useDefineForClassFields": true
|
||||
},
|
||||
"include": ["src/**/*.ts", "src/**/*.vue", "vite.config.ts"]
|
||||
}
|
||||
15
packages/site/vite.config.ts
Normal file
15
packages/site/vite.config.ts
Normal file
@@ -0,0 +1,15 @@
|
||||
import { defineConfig } from 'vite';
|
||||
import vue from '@vitejs/plugin-vue';
|
||||
import tailwindcss from '@tailwindcss/vite';
|
||||
|
||||
// Site vitrine statique (git-arboretum.com) : aucune dépendance au daemon, donc
|
||||
// pas de proxy /api /ws (contrairement à packages/web). `base: '/'` car servi
|
||||
// à la racine d'un domaine dédié.
|
||||
export default defineConfig({
|
||||
plugins: [vue(), tailwindcss()],
|
||||
base: '/',
|
||||
build: {
|
||||
outDir: 'dist',
|
||||
target: 'es2020',
|
||||
},
|
||||
});
|
||||
@@ -10,6 +10,7 @@
|
||||
},
|
||||
"dependencies": {
|
||||
"@arboretum/shared": "*",
|
||||
"@lucide/vue": "^1.21.0",
|
||||
"@xterm/addon-fit": "^0.11.0",
|
||||
"@xterm/addon-webgl": "^0.19.0",
|
||||
"@xterm/xterm": "^6.0.0",
|
||||
|
||||
@@ -1,20 +1,25 @@
|
||||
<template>
|
||||
<div class="flex h-full flex-col">
|
||||
<div
|
||||
v-if="wsReconnecting"
|
||||
class="border-b border-amber-900/50 bg-amber-950/80 px-4 py-1.5 text-center text-xs text-amber-300"
|
||||
>
|
||||
{{ t('ws.reconnecting') }}
|
||||
</div>
|
||||
<RouterView class="min-h-0 flex-1" />
|
||||
<div class="flex h-dvh flex-col">
|
||||
<WsBanner v-if="wsReconnecting" />
|
||||
<AppShell v-if="layout !== 'bare'" :fullbleed="layout === 'fullbleed'">
|
||||
<RouterView />
|
||||
</AppShell>
|
||||
<RouterView v-else class="min-h-0 flex-1" />
|
||||
<ToastContainer />
|
||||
<CommandPalette />
|
||||
</div>
|
||||
</template>
|
||||
|
||||
<script setup lang="ts">
|
||||
import { computed } from 'vue';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { useRoute } from 'vue-router';
|
||||
import { wsClient } from './lib/ws-client';
|
||||
import WsBanner from './components/layout/WsBanner.vue';
|
||||
import AppShell from './components/layout/AppShell.vue';
|
||||
import ToastContainer from './components/ToastContainer.vue';
|
||||
import CommandPalette from './components/CommandPalette.vue';
|
||||
|
||||
const { t } = useI18n();
|
||||
const route = useRoute();
|
||||
const layout = computed(() => route.meta.layout ?? 'shell');
|
||||
const wsReconnecting = computed(() => wsClient.status.value === 'reconnecting');
|
||||
</script>
|
||||
|
||||
37
packages/web/src/components/AttentionSection.vue
Normal file
37
packages/web/src/components/AttentionSection.vue
Normal file
@@ -0,0 +1,37 @@
|
||||
<template>
|
||||
<section v-if="waiting.length" class="flex flex-col gap-2 rounded-xl border border-amber-900/50 bg-amber-950/20 p-3">
|
||||
<div class="flex items-center gap-2">
|
||||
<AlertTriangle :size="16" class="text-amber-400" />
|
||||
<h2 class="text-sm font-semibold text-amber-200">{{ t('attention.title') }}</h2>
|
||||
<BaseBadge tone="amber">{{ t('attention.count', waiting.length) }}</BaseBadge>
|
||||
</div>
|
||||
<div v-for="s in waiting" :key="s.id" class="flex flex-col gap-1">
|
||||
<RouterLink
|
||||
:to="{ name: 'session', params: { id: s.id } }"
|
||||
class="truncate font-mono text-xs text-amber-300/80 transition-colors hover:text-amber-200"
|
||||
:title="s.cwd"
|
||||
>
|
||||
{{ s.cwd }}
|
||||
</RouterLink>
|
||||
<DialogPrompt :session="s" />
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
|
||||
<script setup lang="ts">
|
||||
// Vue « À traiter » : regroupe en tête les sessions bloquées sur un dialogue (cœur de la
|
||||
// supervision mobile). Réutilise DialogPrompt pour répondre sans ouvrir le terminal.
|
||||
import { computed } from 'vue';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { AlertTriangle } from '@lucide/vue';
|
||||
import { useSessionsStore } from '../stores/sessions';
|
||||
import DialogPrompt from './DialogPrompt.vue';
|
||||
import BaseBadge from './ui/BaseBadge.vue';
|
||||
|
||||
const { t } = useI18n();
|
||||
const sessions = useSessionsStore();
|
||||
|
||||
const waiting = computed(() =>
|
||||
sessions.sessions.filter((s) => s.live && s.activity === 'waiting' && s.dialog),
|
||||
);
|
||||
</script>
|
||||
169
packages/web/src/components/CommandPalette.vue
Normal file
169
packages/web/src/components/CommandPalette.vue
Normal file
@@ -0,0 +1,169 @@
|
||||
<template>
|
||||
<Teleport to="body">
|
||||
<div v-if="open" class="fixed inset-0 z-[60] flex items-start justify-center p-4 pt-[10vh]" role="dialog" aria-modal="true">
|
||||
<div class="absolute inset-0 bg-black/60" @click="close" />
|
||||
<div class="relative flex max-h-[70vh] w-full max-w-lg flex-col overflow-hidden rounded-xl border border-zinc-700 bg-zinc-900 shadow-pop">
|
||||
<div class="flex items-center gap-2 border-b border-zinc-800 px-3">
|
||||
<Search :size="16" class="text-zinc-500" />
|
||||
<input
|
||||
ref="inputEl"
|
||||
v-model="query"
|
||||
type="text"
|
||||
class="w-full bg-transparent py-3 text-sm text-zinc-100 outline-none placeholder:text-zinc-600"
|
||||
:placeholder="t('palette.placeholder')"
|
||||
:aria-activedescendant="activeId ? `cmd-${activeId}` : undefined"
|
||||
role="combobox"
|
||||
aria-controls="cmd-listbox"
|
||||
aria-expanded="true"
|
||||
@keydown.down.prevent="move(1)"
|
||||
@keydown.up.prevent="move(-1)"
|
||||
@keydown.enter.prevent="run(results[activeIndex])"
|
||||
@keydown.esc.prevent="close"
|
||||
/>
|
||||
</div>
|
||||
|
||||
<ul v-if="results.length" id="cmd-listbox" role="listbox" class="min-h-0 flex-1 overflow-y-auto p-1.5">
|
||||
<li
|
||||
v-for="(item, i) in results"
|
||||
:id="`cmd-${item.id}`"
|
||||
:key="item.id"
|
||||
role="option"
|
||||
:aria-selected="i === activeIndex"
|
||||
class="flex cursor-pointer items-center gap-2 rounded-lg px-2.5 py-2"
|
||||
:class="i === activeIndex ? 'bg-zinc-800' : 'hover:bg-zinc-800/50'"
|
||||
@mousemove="activeIndex = i"
|
||||
@click="run(item)"
|
||||
>
|
||||
<component :is="item.icon" :size="15" class="shrink-0 text-zinc-500" />
|
||||
<span class="min-w-0 flex-1">
|
||||
<span class="block truncate text-sm text-zinc-100">{{ item.label }}</span>
|
||||
<span v-if="item.sublabel" class="block truncate font-mono text-[11px] text-zinc-500">{{ item.sublabel }}</span>
|
||||
</span>
|
||||
<span class="shrink-0 text-[10px] uppercase tracking-wide text-zinc-600">{{ t(`palette.types.${item.type}`) }}</span>
|
||||
</li>
|
||||
</ul>
|
||||
<p v-else class="px-3 py-6 text-center text-sm text-zinc-500">{{ t('palette.empty') }}</p>
|
||||
|
||||
<div class="border-t border-zinc-800 px-3 py-1.5 text-[11px] text-zinc-600">{{ t('palette.hint') }}</div>
|
||||
</div>
|
||||
</div>
|
||||
</Teleport>
|
||||
</template>
|
||||
|
||||
<script setup lang="ts">
|
||||
import { computed, nextTick, onMounted, onUnmounted, ref, watch, type Component } from 'vue';
|
||||
import { useRouter, type RouteLocationRaw } from 'vue-router';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import { Search, GitBranch, TerminalSquare, Boxes, Plus, FolderPlus } from '@lucide/vue';
|
||||
import { useSessionsStore } from '../stores/sessions';
|
||||
import { useWorktreesStore } from '../stores/worktrees';
|
||||
import { useGroupsStore } from '../stores/groups';
|
||||
import { useCommandPalette } from '../composables/useCommandPalette';
|
||||
|
||||
interface PaletteItem {
|
||||
id: string;
|
||||
type: 'repo' | 'worktree' | 'session' | 'group' | 'action';
|
||||
label: string;
|
||||
sublabel?: string;
|
||||
icon: Component;
|
||||
keywords: string;
|
||||
to?: RouteLocationRaw;
|
||||
run?: () => void;
|
||||
}
|
||||
|
||||
const { t } = useI18n();
|
||||
const router = useRouter();
|
||||
const { open, close, toggle } = useCommandPalette();
|
||||
const sessions = useSessionsStore();
|
||||
const worktrees = useWorktreesStore();
|
||||
const groups = useGroupsStore();
|
||||
|
||||
const query = ref('');
|
||||
const activeIndex = ref(0);
|
||||
const inputEl = ref<HTMLInputElement | null>(null);
|
||||
|
||||
const basename = (p: string): string => p.split('/').filter(Boolean).pop() ?? p;
|
||||
|
||||
const items = computed<PaletteItem[]>(() => {
|
||||
const out: PaletteItem[] = [];
|
||||
for (const r of worktrees.repos) {
|
||||
out.push({ id: `repo-${r.id}`, type: 'repo', label: r.label, sublabel: r.path, icon: GitBranch as Component, keywords: `${r.label} ${r.path}`.toLowerCase(), to: { name: 'dashboard' } });
|
||||
}
|
||||
for (const w of worktrees.worktrees) {
|
||||
const target: RouteLocationRaw = w.sessions[0]
|
||||
? { name: 'session', params: { id: w.sessions[0].id } }
|
||||
: { name: 'dashboard' };
|
||||
out.push({ id: `wt-${w.path}`, type: 'worktree', label: w.branch ?? basename(w.path), sublabel: w.path, icon: GitBranch as Component, keywords: `${w.branch ?? ''} ${w.path}`.toLowerCase(), to: target });
|
||||
}
|
||||
for (const s of sessions.sessions) {
|
||||
out.push({ id: `ses-${s.id}`, type: 'session', label: s.title ?? basename(s.cwd), sublabel: s.cwd, icon: TerminalSquare as Component, keywords: `${s.title ?? ''} ${s.cwd} ${s.command}`.toLowerCase(), to: { name: 'session', params: { id: s.id } } });
|
||||
}
|
||||
for (const g of groups.groups) {
|
||||
out.push({ id: `grp-${g.id}`, type: 'group', label: g.label, ...(g.description ? { sublabel: g.description } : {}), icon: Boxes as Component, keywords: `${g.label} ${g.description ?? ''}`.toLowerCase(), to: { name: 'group', params: { id: g.id } } });
|
||||
}
|
||||
// actions globales
|
||||
out.push({ id: 'act-newSession', type: 'action', label: t('palette.actions.newSession'), icon: Plus as Component, keywords: t('palette.actions.newSession').toLowerCase(), to: { name: 'sessions' } });
|
||||
out.push({ id: 'act-addRepo', type: 'action', label: t('palette.actions.addRepo'), icon: FolderPlus as Component, keywords: t('palette.actions.addRepo').toLowerCase(), to: { name: 'dashboard' } });
|
||||
out.push({ id: 'act-newGroup', type: 'action', label: t('palette.actions.newGroup'), icon: Boxes as Component, keywords: t('palette.actions.newGroup').toLowerCase(), to: { name: 'groups' } });
|
||||
return out;
|
||||
});
|
||||
|
||||
// fuzzy minimal : tous les tokens présents (AND), score = somme des positions (plus tôt = mieux).
|
||||
const results = computed<PaletteItem[]>(() => {
|
||||
const tokens = query.value.trim().toLowerCase().split(/\s+/).filter(Boolean);
|
||||
if (tokens.length === 0) return items.value.slice(0, 30);
|
||||
const scored: { item: PaletteItem; score: number }[] = [];
|
||||
for (const item of items.value) {
|
||||
let score = 0;
|
||||
let ok = true;
|
||||
for (const tok of tokens) {
|
||||
const idx = item.keywords.indexOf(tok);
|
||||
if (idx < 0) {
|
||||
ok = false;
|
||||
break;
|
||||
}
|
||||
score += idx;
|
||||
}
|
||||
if (ok) scored.push({ item, score });
|
||||
}
|
||||
return scored.sort((a, b) => a.score - b.score).slice(0, 30).map((s) => s.item);
|
||||
});
|
||||
|
||||
watch(results, () => {
|
||||
if (activeIndex.value >= results.value.length) activeIndex.value = 0;
|
||||
});
|
||||
|
||||
const activeId = computed(() => results.value[activeIndex.value]?.id);
|
||||
|
||||
function move(delta: number): void {
|
||||
const n = results.value.length;
|
||||
if (n === 0) return;
|
||||
activeIndex.value = (activeIndex.value + delta + n) % n;
|
||||
}
|
||||
|
||||
function run(item: PaletteItem | undefined): void {
|
||||
if (!item) return;
|
||||
close();
|
||||
if (item.run) item.run();
|
||||
else if (item.to) void router.push(item.to);
|
||||
}
|
||||
|
||||
watch(open, async (v) => {
|
||||
if (v) {
|
||||
query.value = '';
|
||||
activeIndex.value = 0;
|
||||
await nextTick();
|
||||
inputEl.value?.focus();
|
||||
}
|
||||
});
|
||||
|
||||
// raccourci global ⌘K / Ctrl+K — en phase de capture pour passer devant xterm (SessionView).
|
||||
function onKey(e: KeyboardEvent): void {
|
||||
if ((e.metaKey || e.ctrlKey) && e.key.toLowerCase() === 'k') {
|
||||
e.preventDefault();
|
||||
toggle();
|
||||
}
|
||||
}
|
||||
onMounted(() => window.addEventListener('keydown', onKey, { capture: true }));
|
||||
onUnmounted(() => window.removeEventListener('keydown', onKey, { capture: true }));
|
||||
</script>
|
||||
122
packages/web/src/components/CrossRepoFeatureModal.vue
Normal file
122
packages/web/src/components/CrossRepoFeatureModal.vue
Normal file
@@ -0,0 +1,122 @@
|
||||
<template>
|
||||
<div class="fixed inset-0 z-50 flex items-center justify-center bg-black/60 p-4" @click.self="emit('close')">
|
||||
<div class="flex max-h-[90vh] w-full max-w-lg flex-col gap-3 overflow-y-auto rounded-lg border border-zinc-800 bg-zinc-900 p-4">
|
||||
<header class="flex items-center gap-2">
|
||||
<h2 class="font-semibold text-zinc-100">{{ t('crossRepo.title') }}</h2>
|
||||
<button class="btn ml-auto text-xs" @click="emit('close')">{{ t('crossRepo.close') }}</button>
|
||||
</header>
|
||||
<p class="text-xs text-zinc-500">{{ t('crossRepo.intro') }}</p>
|
||||
|
||||
<form class="flex flex-col gap-3" @submit.prevent="onSubmit">
|
||||
<label class="flex flex-col gap-1 text-xs text-zinc-400">
|
||||
{{ t('crossRepo.branchLabel') }}
|
||||
<input v-model="branch" class="input font-mono" :placeholder="t('crossRepo.branchPlaceholder')" required />
|
||||
</label>
|
||||
<div class="flex flex-wrap items-end gap-3">
|
||||
<label class="flex items-center gap-1.5 text-xs text-zinc-400">
|
||||
<input v-model="newBranch" type="checkbox" /> {{ t('crossRepo.newBranch') }}
|
||||
</label>
|
||||
<label class="flex flex-col gap-1 text-xs text-zinc-400">
|
||||
{{ t('crossRepo.baseRefLabel') }}
|
||||
<input v-model="baseRef" class="input font-mono" placeholder="HEAD" />
|
||||
</label>
|
||||
<label class="flex flex-col gap-1 text-xs text-zinc-400">
|
||||
{{ t('crossRepo.startLabel') }}
|
||||
<select v-model="startSession" class="input">
|
||||
<option :value="null">{{ t('crossRepo.startNone') }}</option>
|
||||
<option value="claude">claude</option>
|
||||
<option value="bash">bash</option>
|
||||
</select>
|
||||
</label>
|
||||
</div>
|
||||
|
||||
<div class="flex flex-col gap-1 text-xs text-zinc-400">
|
||||
{{ t('crossRepo.reposLabel') }}
|
||||
<div class="flex flex-col gap-1">
|
||||
<label
|
||||
v-for="repo in repos"
|
||||
:key="repo.id"
|
||||
class="flex items-center gap-2 rounded border border-zinc-800 bg-zinc-950/40 px-2 py-1"
|
||||
>
|
||||
<input v-model="selectedRepoIds" type="checkbox" :value="repo.id" :disabled="running" />
|
||||
<span class="flex-1 text-zinc-300">{{ repo.label }}</span>
|
||||
<span v-if="results[repo.id]" class="text-[11px]" :class="statusClass(repo.id)">
|
||||
{{ statusText(repo.id) }}
|
||||
</span>
|
||||
</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="flex items-center gap-2">
|
||||
<button type="submit" class="btn-primary" :disabled="running || branch.trim() === '' || selectedRepoIds.length === 0">
|
||||
{{ running ? t('crossRepo.creating') : t('crossRepo.create', { n: selectedRepoIds.length }) }}
|
||||
</button>
|
||||
<button v-if="hasFailures && !running" type="button" class="btn text-xs" @click="retryFailed">
|
||||
{{ t('crossRepo.retryFailed') }}
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
|
||||
<script setup lang="ts">
|
||||
import { computed, ref } from 'vue';
|
||||
import { useI18n } from 'vue-i18n';
|
||||
import type { RepoSummary } from '@arboretum/shared';
|
||||
import { useGroupsStore, type CrossRepoResult } from '../stores/groups';
|
||||
|
||||
const props = defineProps<{ repos: RepoSummary[] }>();
|
||||
const emit = defineEmits<{ close: [] }>();
|
||||
|
||||
const { t } = useI18n();
|
||||
const groups = useGroupsStore();
|
||||
|
||||
const branch = ref('');
|
||||
const newBranch = ref(true);
|
||||
const baseRef = ref('');
|
||||
const startSession = ref<'claude' | 'bash' | null>(null);
|
||||
const selectedRepoIds = ref<string[]>(props.repos.map((r) => r.id));
|
||||
const results = ref<Record<string, CrossRepoResult>>({});
|
||||
const running = ref(false);
|
||||
|
||||
const hasFailures = computed(() => Object.values(results.value).some((r) => r.status === 'error'));
|
||||
|
||||
function statusClass(repoId: string): string {
|
||||
return results.value[repoId]?.status === 'ok' ? 'text-emerald-400' : 'text-red-400';
|
||||
}
|
||||
function statusText(repoId: string): string {
|
||||
const r = results.value[repoId];
|
||||
if (!r) return '';
|
||||
return r.status === 'ok' ? t('crossRepo.ok') : `${t('crossRepo.error')}: ${r.message ?? ''}`;
|
||||
}
|
||||
|
||||
async function run(repoIds: string[]): Promise<void> {
|
||||
if (repoIds.length === 0) return;
|
||||
running.value = true;
|
||||
for (const id of repoIds) delete results.value[id];
|
||||
try {
|
||||
await groups.createCrossRepoFeature(
|
||||
repoIds,
|
||||
{
|
||||
branch: branch.value.trim(),
|
||||
newBranch: newBranch.value,
|
||||
...(baseRef.value.trim() ? { baseRef: baseRef.value.trim() } : {}),
|
||||
startSession: startSession.value,
|
||||
},
|
||||
(result) => {
|
||||
results.value = { ...results.value, [result.repoId]: result };
|
||||
},
|
||||
);
|
||||
} finally {
|
||||
running.value = false;
|
||||
}
|
||||
}
|
||||
|
||||
function onSubmit(): void {
|
||||
void run([...selectedRepoIds.value]);
|
||||
}
|
||||
function retryFailed(): void {
|
||||
void run(Object.values(results.value).filter((r) => r.status === 'error').map((r) => r.repoId));
|
||||
}
|
||||
</script>
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user