Compare commits

..
9 Commits
Author SHA1 Message Date
johanleroy bde5358ea8 release: git-arboretum 3.5.0 (cache SPA, copier/coller terminal, fichiers des groupes), desktop 0.2.1
CI / No em/en dashes (push) Successful in 3s
CI / Build & test (Node 24) (push) Successful in 10m50s
CI / Build & test (Node 22) (push) Successful in 11m2s
Release / Publish to Gitea npm registry (push) Successful in 10m56s
Desktop Release / Build Linux (AppImage + deb) (push) Successful in 13m21s
Desktop Release / Publish floating desktop-latest release (push) Successful in 11s
CI / Pack & boot smoke (Node 22) (push) Successful in 9m53s
Desktop Release / Build Windows (NSIS + portable) (push) Canceled after 0s
Cause racine de l'ecran noir apres mise a jour : l'etag faible de @fastify/static derive de
taille+mtime, et npm pack fige le mtime de tout le tarball a une date constante (1985-10-26). Deux
index.html de versions differentes mais de meme taille partageaient donc le meme etag : le client
recevait un 304, gardait son index perime, et demandait des /assets/<hash> disparus ; le fallback SPA
repondait index.html en text/html pour ces modules, le navigateur refusait le script, rien ne peignait.

- fix(server): index.html et tous les fichiers non haches servis en no-store, validation
  conditionnelle desactivee (etag/lastModified) pour qu'un client bloque sur un index perime se
  repare seul ; /assets/ (noms haches) passent en immutable un an
- feat(web): copier/coller dans le terminal xterm, dont la selection n'est pas une selection DOM :
  Ctrl+Maj+C / Ctrl+Maj+V, Cmd+C / Cmd+V sur macOS, Ctrl+Inser / Maj+Inser, plus interception de
  l'evenement DOM copy pour que le Copier natif fonctionne. Ctrl+C reste SIGINT
- fix(web): script anti-FOUC sorti dans /theme-boot.js, la CSP script-src 'self' du daemon refusait
  de l'executer inline (le theme n'etait donc pose qu'au montage de la SPA)
- feat(web): les worktrees d'un groupe se deplient sur leur arborescence de fichiers dans le panneau
  Groupes (meme composant et meme etat d'expansion que l'Explorateur), et un worktree ainsi deplie
  est desormais surveille en temps reel
- fix: octet nul litteral remplace par \0 dans trois sources (stores/ide.ts, GitPanel.vue,
  vscode/repos-tree.ts) : git et grep les traitaient comme binaires, leurs diffs etaient
  illisibles en revue et la garde CI lint-dashes (git grep -I) les sautait en silence
- test: cacheControlFor et clipboardIntent en tests purs, verify-clipboard.mjs (E2E Chromium CDP :
  copie, collage et SIGINT prouves par le presse-papier reel et par le systeme de fichiers),
  capture groups-dark-desktop ajoutee a verify-ui.mjs
2026-08-04 16:23:33 +02:00
johanleroy 9624270d9b ci: rendre lisible l'échec d'attache de release (401 / 403 distingués)
CI / No em/en dashes (push) Successful in 3s
Deploy site (production) / build-and-deploy (push) Successful in 47s
CI / Build & test (Node 24) (push) Successful in 10m12s
CI / Build & test (Node 22) (push) Successful in 10m23s
CI / Pack & boot smoke (Node 22) (push) Successful in 9m55s
Le parsing JSON du script n'était pas tolérant à une réponse vide : sur un 401, deux
« SyntaxError: Unexpected end of JSON input » de Node s'affichaient AVANT le message d'erreur utile et
noyaient le diagnostic. La lecture de champ est désormais tolérante, et le script nomme la cause selon
le code HTTP : 401 = token invalide ou expiré, 403 = portées insuffisantes.

Testé contre un faux serveur pour les trois cas (401, 403, succès) : messages attendus et codes de
sortie corrects (1 en échec, 0 en succès).
2026-08-04 15:44:12 +02:00
johanleroy c8bf6534e0 fix(site): barre de navigation lisible à toutes les largeurs, et bouton de remontée
Les huit liens de la barre ne tiennent qu'au-delà de ~1180px. En dessous, la barre flex les compressait
au lieu de les masquer : « Start project », « Git services » et « How it works » se cassaient sur deux
ou trois lignes, les libellés recouvraient le logo et le bouton Gitea sortait du cadre. Sous 900px, il
n'y avait par ailleurs AUCUNE navigation : les sections n'étaient atteignables qu'en scrollant.

- Aucun libellé ne peut plus se casser (`whitespace-nowrap` + `shrink-0`), et le logo ne se rogne plus.
- Les liens apparaissent par palier de largeur : 4 dès 900px, 6 à partir de 1024, les 8 à partir de
  1180. Pur CSS, aucun JS, aucune mesure au runtime.
- Sous 900px, un bouton menu ouvre un panneau listant TOUS les liens (plus Gitea), refermé au choix
  d'un lien ou par Échap. Le bouton Gitea quitte la barre à ces largeurs, sinon le bouton menu se
  retrouvait tronqué au bord de l'écran sur un mobile de 390px.
- Le libellé « Gitea » n'apparaît qu'au-delà de 1180px ; en dessous l'icône suffit et l'aria-label reste.

Ajout d'un bouton « remonter en haut » en bas à droite : mêmes tokens que le reste du site, visible
seulement après 600px de défilement, cible de 44px, respecte prefers-reduced-motion.

Vérifié au rendu à 390, 760, 900, 1024, 1180 et 1440px, dans les deux thèmes, menu ouvert compris.
2026-08-04 15:43:59 +02:00
johanleroy c8d30c7b0d fix(desktop): nom d'artefact distinct pour le build Windows portable
CI / No em/en dashes (push) Successful in 3s
CI / Build & test (Node 24) (push) Successful in 10m27s
CI / Build & test (Node 22) (push) Successful in 10m58s
VSCode Release / Package VSIX (push) Successful in 9m57s
Release / Publish to Gitea npm registry (push) Successful in 10m16s
CI / Pack & boot smoke (Node 22) (push) Successful in 10m16s
Desktop Release / Build Linux (AppImage + deb) (push) Failing after 8m31s
Desktop Release / Build Windows (NSIS + portable) (push) Canceled after 0s
Desktop Release / Publish floating desktop-latest release (push) Skipped
`win.artifactName` s'applique aux deux cibles : l'installeur NSIS et le build portable produisaient
tous deux `Arboretum-<version>-x64.exe`, donc une collision où l'un écrase l'autre. Le portable prend
un suffixe explicite. Les liens de la vitrine visent l'installeur NSIS, dont le nom ne change pas.
2026-08-04 15:07:27 +02:00
johanleroy f96b36c548 ci: un token de release refusé doit faire échouer le job, pas passer inaperçu
CI / No em/en dashes (push) Successful in 3s
CI / Build & test (Node 24) (push) Successful in 10m11s
CI / Build & test (Node 22) (push) Successful in 10m26s
CI / Pack & boot smoke (Node 22) (push) Successful in 9m52s
Avec un NPM_TOKEN expiré, les trois workflows de release sont ressortis « réussis » alors qu'aucune
release n'avait été créée et qu'aucun asset n'était attaché : l'attache était en continue-on-error et
le script sortait en 0 quand l'API refusait le token. Diagnostiquer a demandé de comparer les assets
de releases pour comprendre ce que les logs auraient dit tout de suite.

Désormais : token ABSENT (fork, run sans secret) reste un cas légitime qui sort proprement, mais un
token PRÉSENT et refusé, ou un upload d'asset en échec, fait échouer le job avec un message qui nomme
les portées attendues. Les artefacts du run sont uploadés AVANT cette étape, donc un job rouge ne
perd aucun binaire.

L'attache du VSIX passe au même script partagé : elle dupliquait la logique, avec le même angle mort.
2026-08-04 14:29:27 +02:00
johanleroy e4dd64b535 ci: corrige le contrôle d'autonomie du tarball et allège le typecheck desktop
CI / Build & test (Node 22) (push) Successful in 10m7s
CI / Build & test (Node 24) (push) Successful in 9m57s
CI / No em/en dashes (push) Successful in 3s
CI / Pack & boot smoke (Node 22) (push) Successful in 9m50s
Release / Publish to Gitea npm registry (push) Failing after 6m5s
VSCode Release / Package VSIX (push) Successful in 10m27s
Desktop Release / Build Linux (AppImage + deb) (push) Successful in 13m55s
Desktop Release / Publish floating desktop-latest release (push) Successful in 18s
Desktop Release / Build Windows (NSIS + portable) (push) Canceled after 0s
Le contrôle « paquet autonome » cherchait la chaîne `@arboretum/shared` n'importe où dans le JS
publié. Un commentaire de code qui mentionne le paquet (pour dire où vit la règle partagée, cf.
core/session-match.ts) suffisait donc à faire échouer le job, alors que l'inlining était correct.
Le grep vise désormais les vraies formes d'import (from / require( / import(), ce qui est ce que la
garde veut réellement interdire.

L'étape de typecheck desktop téléchargeait ~100 Mo de binaire Electron, sur les deux versions de la
matrice : le job passait de 3 à 12 minutes. ELECTRON_SKIP_BINARY_DOWNLOAD=1 et une seule version de
Node suffisent pour un `tsc --noEmit`.
2026-08-04 13:27:32 +02:00
johanleroy 63f2697745 release: git-arboretum 3.4.0 (visibilité temps réel, historisation), desktop 0.2.0 (Windows, logo), vscode 0.4.1, site 0.4.0
CI / Build & test (Node 22) (push) Successful in 11m12s
CI / Build & test (Node 24) (push) Successful in 10m14s
CI / No em/en dashes (push) Successful in 3s
Deploy site (production) / build-and-deploy (push) Successful in 19s
CI / Pack & boot smoke (Node 22) (push) Has been cancelled
Tout est additif : PROTOCOL_VERSION inchangé, aucune rupture d'API.

Temps réel réellement armé
- `pinSession` n'était appelé nulle part : une session vivante épingle désormais le watcher FS de son
  worktree (`WorktreeManager.syncSessionPin` + `resolveWorktreeForCwd`), donc un worktree où un agent
  écrit se rafraîchit même si personne ne le regarde (mesuré ~350 ms).
- Les abonnements `watch` sortent de `GitPanel`, démonté dès qu'on quitte son onglet, ce qui coupait le
  seul abonnement de toute l'app : `composables/useWatchedWorktrees.ts` (monté dans App.vue) suit le
  worktree actif et les dépôts dépliés, borné à 40.
- Une coupure WS ne laisse plus l'UI sur des listes périmées : rechargement complet au retour.
- `worktree_changes` alimente `worktrees.changeVersion`, consommé par l'arbre de fichiers, le diff
  (son `:version` était câblé à 0) et l'éditeur, qui recharge un tampon propre ou lève la bannière de
  conflit avant la sauvegarde au lieu d'attendre le 409.

Corrélation session ↔ worktree par contenance (`@arboretum/shared/path-match.ts`)
- Un terminal lancé dans un sous-répertoire (« Démarrer le projet ») ou une session de groupe reliée
  par `--add-dir` apparaissent enfin sous leur worktree ; le worktree le plus spécifique gagne.
- Règle unique partagée par le daemon, le web et l'extension.

Historisation
- `commitLog` / `commitDiff` purs, `GET /repos/:id/worktrees/log` et `diff?commit=` (hash strictement
  validé, mêmes bornes que les diffs de fichiers).
- `CommitHistory.vue` sous le panneau Git : commits, marquage des non poussés, diff déplié sur place.

Visibilité
- Compteurs git complets sur chaque worktree de l'arbre et du panneau Groupes (ils n'existaient qu'en
  barre de statut, pour le seul worktree actif), avec upstream et dernier commit en infobulle ;
  `locked`, `prunable` et un dépôt invalide sont désormais visibles.
- Le panneau Groupes montre sa composition réelle (dépôts, worktrees, sessions) et teinte l'explorateur.

Polish visuel
- Les toasts d'erreur, persistants, s'empilaient derrière les modals : téléportés au-dessus.
- Sur mobile, ouvrir un terminal ou changer d'activité n'avait aucun effet visible.
- Tailles de panneaux clampées sur la fenêtre, barres d'onglets sans scrollbar parasite, états de
  chargement et d'erreur dans les trois panneaux, accessibilité des 11 modals centralisée dans
  ModalHost, splitters au clavier, numéros de diff collants, `window.confirm` remplacé.

Windows (daemon et packaging)
- `where.exe`, PowerShell comme shell de lancement, askpass `.cmd` (clone/push HTTPS par PAT),
  `taskkill /T`, `%APPDATA%`, `arboretum install` via tâche planifiée.
- Scripts de build exécutables sur un hôte Windows (`npm.cmd`, extraction sans `unzip` ni `bash`).
- Job CI `windows-latest` conditionné par ENABLE_WINDOWS_BUILD ; procédure runner dans docs/CI_RUNNERS.md.

Logo Debian : cause racine
- Une icône unique de 895×895 atterrissait dans `hicolor/895x895`, répertoire absent d'`index.theme`
  donc ignoré par la spécification freedesktop ; et `executableName` dérivait du nom scopé du paquet
  (`@arboretumdesktop`). Jeu d'icônes standard généré + `executableName: arboretum`, plus
  `deb.synopsis` (description courte vide dans apt) et `Section: devel`.
- Runtime Node embarqué élagué : 205 → 118 Mo.
- Auto-update réparé : la release flottante `desktop-latest` que les binaires interrogent n'existait pas.

Doc et vitrine
- README/README.fr : installation par plateforme, mode serveur web (nginx, LAN), dépannage, variables
  d'environnement, flags manquants.
- Doc in-app réécrite (elle renvoyait aux pages Worktrees et Sessions supprimées).
- Section « Accès distant » dans les Réglages ; le 403 BAD_ORIGIN nomme le flag à ajouter.
- Site : prérequis et registre npm privé (le `npx` affiché renvoyait un 404), téléchargements réels par
  plateforme, section « trois façons de l'utiliser », navigation complétée, 16 clés i18n mortes purgées.

Vérifications : 483 tests unitaires, 14 acceptances E2E vertes (dont p14/p15 nouvelles), captures de
rendu sans erreur console (nouveau `verify-ui.mjs`), .deb reconstruit et contrôlé (icônes aux tailles
standard, entrée .desktop valide).
2026-08-04 13:02:11 +02:00
johanleroy a7e04278fd release: git-arboretum 3.3.0 (« Démarrer le projet » : lancement multi-terminaux), vscode 0.4.0, desktop 0.1.3
CI / Build & test (Node 22) (push) Successful in 10m17s
CI / Build & test (Node 24) (push) Successful in 10m13s
CI / No em/en dashes (push) Successful in 4s
Deploy site (production) / build-and-deploy (push) Successful in 24s
Release / Publish to Gitea npm registry (push) Successful in 10m17s
VSCode Release / Package VSIX (push) Successful in 9m39s
Desktop Release / Build Linux (AppImage + deb) (push) Successful in 15m41s
CI / Pack & boot smoke (Node 22) (push) Successful in 10m3s
« Démarrer le projet » : un repo définit une fois ses commandes de démarrage
(serveur de dev, API, base de données), un clic ouvre un terminal PTY par
commande dans le dock IDE.

Serveur (additif, PROTOCOL_VERSION inchangé) :
- LaunchCommand[] persistées sur repos.launch_commands (migration 13) ; champ additif SessionSummary.launchRunId.
- POST /repos/:id/launch : résolution du worktree côté serveur, cwd de commande borné (anti-traversal), commandIds outrepasse enabled.
- GET /repos/:id/launch/detect : détection package.json / Procfile / docker-compose.
- Shell de login interactif ($SHELL -l -i, charge le PATH nvm/asdf) + auto-type de la commande ; le shell survit à la commande (échec visible).

Web : LaunchProjectModal + actions (ProjectTreeNode, SessionsPanel, CommandPalette), stores sessions/worktrees, i18n EN/FR.

Alignement du reste du projet :
- Extension VS Code 0.4.0 : commande Start Project (repo/worktree), Stop Launch, badge « launch » dans l'arbre, méthode REST startLaunch.
- Site vitrine : 16e feature card (Rocket) + section showcase « Start the project » (mockup fidèle au modal), i18n EN/FR.
- Documentation : README (EN + FR), help-content (EN + FR), CHANGELOGs server + vscode.

Vérifié : 430 tests, typecheck, build (web + site + vscode), acceptance-p13 ALL GREEN, VSIX packagé, garde anti-tirets, vérif visuelle du site (thèmes clair et sombre).
2026-07-21 13:54:16 +02:00
johanleroy 7327407193 release: desktop 0.1.2 (embarque le daemon 3.2.0, UI Emerald)
CI / Build & test (Node 22) (push) Successful in 10m19s
CI / Build & test (Node 24) (push) Successful in 10m6s
CI / No em/en dashes (push) Successful in 3s
Desktop Release / Build Linux (AppImage + deb) (push) Successful in 14m47s
CI / Pack & boot smoke (Node 22) (push) Successful in 10m1s
2026-07-21 08:58:55 +02:00
149 changed files with 6262 additions and 656 deletions
+98
View File
@@ -0,0 +1,98 @@
#!/usr/bin/env bash
# Attache des fichiers à une release Gitea, de façon idempotente (re-run friendly).
#
# Usage : attach-release-assets.sh <tag> <release-name> <fichier...>
# Env : RELEASE_TOKEN (token Gitea avec write:repository), GITHUB_SERVER_URL, GITHUB_REPOSITORY.
#
# Partagé par tous les jobs de release desktop et par le VSIX : la logique était dupliquée, et toute
# correction devait être faite trois fois.
set -uo pipefail
tag="${1:?tag manquant}"
release_name="${2:?nom de release manquant}"
shift 2
# Token ABSENT : cas légitime (fork, run sans secret) → on sort proprement.
# Token PRÉSENT mais refusé par l'API : anomalie, on doit ÉCHOUER. Sinon le job reste vert alors
# qu'aucun asset n'est attaché et qu'aucune release n'est créée, ce qui s'est produit avec un token
# expiré : trois workflows « réussis » et zéro fichier publié.
if [ -z "${RELEASE_TOKEN:-}" ]; then
echo "::notice::RELEASE_TOKEN absent, aucun asset attaché (les artefacts du run restent disponibles)."
exit 0
fi
api="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}"
auth="Authorization: token ${RELEASE_TOKEN}"
body=$(mktemp)
trap 'rm -f "$body"' EXIT
# Lecture d'un champ JSON TOLÉRANTE : une réponse vide ou non-JSON (401, 403, 404) doit donner une
# chaîne vide, pas une pile d'appels Node. Sans ça, deux `SyntaxError: Unexpected end of JSON input`
# s'affichaient avant le vrai message d'erreur et noyaient le diagnostic.
json_field() {
node -e "let s='';process.stdin.on('data',(d)=>{s+=d}).on('end',()=>{try{const o=JSON.parse(s);const v=o?.[process.argv[1]];process.stdout.write(v==null?'':String(v))}catch{process.stdout.write('')}})" "$1"
}
# `curl` silencieux qui écrit le corps dans $body et renvoie le code HTTP sur stdout.
http_call() {
curl -sS -o "$body" -w '%{http_code}' "$@"
}
# --- résolution de la release (existante, sinon création) -------------------------------------
code=$(http_call -H "$auth" "${api}/releases/tags/${tag}")
release_id=$(json_field id < "$body")
if [ -z "$release_id" ]; then
# 401/403 sur une simple lecture : inutile de tenter la création, le token est en cause.
case "$code" in
401)
echo "::error::le token de release est refusé (HTTP 401) : il est invalide, révoqué ou expiré."
echo "::error::régénérer un token Gitea et mettre à jour le secret NPM_TOKEN du dépôt."
exit 1
;;
403)
echo "::error::le token de release manque de droits (HTTP 403) sur ${GITHUB_REPOSITORY}."
echo "::error::portées attendues : write:repository (releases et assets) et write:package (publication npm)."
exit 1
;;
esac
create_code=$(http_call -X POST -H "$auth" -H 'Content-Type: application/json' \
-d "{\"tag_name\":\"${tag}\",\"name\":\"${release_name}\"}" "${api}/releases")
release_id=$(json_field id < "$body")
if [ -z "$release_id" ]; then
echo "::error::impossible de créer la release ${tag} (HTTP ${create_code})."
echo "::error::réponse de l'API : $(head -c 300 "$body")"
exit 1
fi
echo "release ${tag} créée (id ${release_id})."
else
echo "release ${tag} trouvée (id ${release_id})."
fi
# --- attache des fichiers ----------------------------------------------------------------------
failed=0
for f in "$@"; do
[ -f "$f" ] || continue
name=$(basename "$f")
# L'API Gitea refuse un asset de même nom : on supprime l'ancien pour que le dernier build gagne.
http_call -H "$auth" "${api}/releases/${release_id}/assets" > /dev/null
existing=$(node -e "let s='';process.stdin.on('data',(d)=>{s+=d}).on('end',()=>{try{const a=JSON.parse(s);const m=Array.isArray(a)?a.find((x)=>x.name===process.argv[1]):null;process.stdout.write(m?String(m.id):'')}catch{process.stdout.write('')}})" "$name" < "$body")
if [ -n "$existing" ]; then
echo "remplacement de $name (asset $existing)"
http_call -X DELETE -H "$auth" "${api}/releases/${release_id}/assets/${existing}" > /dev/null
fi
upload_code=$(http_call -X POST -H "$auth" -F "attachment=@${f}" "${api}/releases/${release_id}/assets?name=${name}")
if [ "$upload_code" -ge 200 ] && [ "$upload_code" -lt 300 ]; then
echo "attaché : $name"
else
echo "::error::échec de l'upload de ${name} (HTTP ${upload_code}) : $(head -c 200 "$body")"
failed=1
fi
done
if [ "$failed" != "0" ]; then
echo "::error::au moins un asset n'a pas pu être attaché à ${tag}."
exit 1
fi
echo "Assets attachés à la release ${tag}."
+19 -5
View File
@@ -29,6 +29,17 @@ jobs:
- run: npm run build - run: npm run build
- run: npm run build:site - run: npm run build:site
- run: npx vitest run - run: npx vitest run
# packages/desktop est HORS des workspaces (CI daemon allégée) : sans cette étape, son code
# n'était JAMAIS typechecké avant un tag de release. Une seule version de Node suffit, et
# ELECTRON_SKIP_BINARY_DOWNLOAD évite de télécharger ~100 Mo de binaire Electron dont un
# typecheck n'a aucun besoin (c'est ce qui rendait le job très long).
- name: Typecheck desktop shell
if: matrix.node == '22'
env:
ELECTRON_SKIP_BINARY_DOWNLOAD: '1'
run: |
npm --prefix packages/desktop ci
npm run typecheck:desktop
pack-smoke: pack-smoke:
name: Pack & boot smoke (Node 22) name: Pack & boot smoke (Node 22)
@@ -57,9 +68,11 @@ jobs:
rm -rf /tmp/inspect && mkdir -p /tmp/inspect && tar -xzf "$tgz" -C /tmp/inspect rm -rf /tmp/inspect && mkdir -p /tmp/inspect && tar -xzf "$tgz" -C /tmp/inspect
test -f /tmp/inspect/package/dist/_shared/index.js \ test -f /tmp/inspect/package/dist/_shared/index.js \
|| { echo "ERREUR: dist/_shared/index.js absent de $tgz : inline-shared n'a pas tourné ?"; exit 1; } || { echo "ERREUR: dist/_shared/index.js absent de $tgz : inline-shared n'a pas tourné ?"; exit 1; }
if grep -rq '@arboretum/shared' /tmp/inspect/package/dist; then # On cherche les vraies formes d'IMPORT, pas la simple chaîne : un commentaire de code qui
# mentionne le paquet (pour dire où vit la règle partagée) est légitime et ne casse rien.
if grep -rqE "(from|require\(|import\()[[:space:]]*['\"]@arboretum/shared" /tmp/inspect/package/dist; then
echo "ERREUR: import bare '@arboretum/shared' encore présent dans le JS publié" echo "ERREUR: import bare '@arboretum/shared' encore présent dans le JS publié"
grep -rn '@arboretum/shared' /tmp/inspect/package/dist; exit 1 grep -rnE "(from|require\(|import\()[[:space:]]*['\"]@arboretum/shared" /tmp/inspect/package/dist; exit 1
fi fi
echo "OK: paquet autonome : shared inliné dans dist/_shared, aucun import externe" echo "OK: paquet autonome : shared inliné dans dist/_shared, aucun import externe"
- name: Install tarball in an empty project - name: Install tarball in an empty project
@@ -86,15 +99,16 @@ jobs:
lint-dashes: lint-dashes:
# Interdit tout tiret cadratin (U+2014) ou demi-cadratin (U+2013) dans les fichiers suivis. # Interdit tout tiret cadratin (U+2014) ou demi-cadratin (U+2013) dans les fichiers suivis.
# Utiliser a la place : point median, deux-points, virgule, ou tiret simple pour les plages. # Utiliser a la place : point median, deux-points, virgule, ou tiret simple pour les plages.
# Exclusions : logo binaire + captures brutes du terminal (fidelite des fixtures de dialogue). # `-I` ignore les fichiers BINAIRES : une icone PNG/ICO peut contenir ces octets par hasard, ce
# qui faisait echouer la garde sans aucun texte fautif. Exclusion restante : les captures brutes
# du terminal (fichiers texte, fidelite des fixtures de dialogue).
name: No em/en dashes name: No em/en dashes
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Fail on U+2014 / U+2013 (outside allow-list) - name: Fail on U+2014 / U+2013 (outside allow-list)
run: | run: |
if git grep -nP '[\x{2014}\x{2013}]' -- . \ if git grep -nPI '[\x{2014}\x{2013}]' -- . \
':(exclude)brand/arboretum-logo-source.png' \
':(exclude)packages/server/test/fixtures/dialogs/*.raw'; then ':(exclude)packages/server/test/fixtures/dialogs/*.raw'; then
echo "::error::Tiret cadratin/demi-cadratin trouve. Utiliser point median, deux-points, virgule ou tiret simple (plages)." echo "::error::Tiret cadratin/demi-cadratin trouve. Utiliser point median, deux-points, virgule ou tiret simple (plages)."
exit 1 exit 1
+142 -30
View File
@@ -1,12 +1,23 @@
# Packaging de l'app de bureau Electron, déclenché UNIQUEMENT par un tag desktop-vX.Y.Z (séparé de # Packaging de l'app de bureau Electron, déclenché par un tag desktop-vX.Y.Z (séparé de la release du
# la release du daemon qui écoute v*, et du VSIX qui écoute vscode-v*). Linux (AppImage + deb) est # daemon qui écoute v*, et du VSIX qui écoute vscode-v*).
# automatisé ici ; Windows et macOS se buildent sur ces OS (voir packages/desktop/README.md) et #
# leurs artefacts sont attachés manuellement à la release. # Linux (AppImage + deb) : toujours automatisé.
# Windows (NSIS + portable) : job dédié, ACTIVÉ par la variable de dépôt ENABLE_WINDOWS_BUILD=true une
# fois qu'un runner labellisé `windows-latest` est enregistré sur le forge. Procédure complète dans
# docs/CI_RUNNERS.md. Tant que la variable est absente, le job est sauté et la release Linux part
# normalement ; le repli reste un build manuel attaché à la release.
# Le cross-build depuis Linux est IMPOSSIBLE : node-pty ne copie conpty.dll / OpenConsole.exe que si
# l'hôte de build est Windows, et son tarball ne contient que les prebuilds linux.
# macOS (dmg + zip) : non automatisé (aucun runner) ; build manuel documenté dans le README desktop.
#
# `workflow_dispatch` permet de tester les jobs sans créer de tag (le garde-fou tag == version est
# alors ignoré, puisqu'il n'y a pas de tag à comparer).
name: Desktop Release name: Desktop Release
on: on:
push: push:
tags: ['desktop-v*'] tags: ['desktop-v*']
workflow_dispatch:
permissions: permissions:
contents: write contents: write
@@ -26,6 +37,7 @@ jobs:
cache: npm cache: npm
# Garde-fou : le tag (sans "desktop-v") doit correspondre à la version du paquet desktop. # Garde-fou : le tag (sans "desktop-v") doit correspondre à la version du paquet desktop.
- name: Verify tag matches desktop version - name: Verify tag matches desktop version
if: github.event_name == 'push'
run: | run: |
pkg=$(node -p "require('./packages/desktop/package.json').version") pkg=$(node -p "require('./packages/desktop/package.json').version")
tag="${GITHUB_REF_NAME#desktop-v}" tag="${GITHUB_REF_NAME#desktop-v}"
@@ -41,6 +53,11 @@ jobs:
# Build complet : shell + daemon empaqueté + Node standalone + AppImage/deb (electron-builder). # Build complet : shell + daemon empaqueté + Node standalone + AppImage/deb (electron-builder).
- name: Build installers - name: Build installers
run: cd packages/desktop && npm run dist:linux run: cd packages/desktop && npm run dist:linux
- name: Compute checksums
run: |
cd packages/desktop/release
sha256sum *.AppImage *.deb > SHA256SUMS-linux.txt
cat SHA256SUMS-linux.txt
# Artefacts du run : canal fiable, indépendant de l'API release. # Artefacts du run : canal fiable, indépendant de l'API release.
- uses: actions/upload-artifact@v3 - uses: actions/upload-artifact@v3
with: with:
@@ -48,40 +65,135 @@ jobs:
path: | path: |
packages/desktop/release/*.AppImage packages/desktop/release/*.AppImage
packages/desktop/release/*.deb packages/desktop/release/*.deb
packages/desktop/release/*.blockmap
packages/desktop/release/latest-linux.yml packages/desktop/release/latest-linux.yml
# Best-effort : attache les installeurs (+ latest-linux.yml pour l'auto-update) à la release packages/desktop/release/SHA256SUMS-linux.txt
# Gitea du tag (crée la release si absente). Réutilise NPM_TOKEN (même token Gitea) : ce token # Attache les installeurs (+ latest-linux.yml pour l'auto-update) à la release du tag. Réutilise
# doit porter la portée write:repository en plus de write:package, sinon l'API release renvoie # NPM_TOKEN (même token Gitea) : il doit porter write:repository en plus de write:package, sinon
# un 403 (l'attache est ignorée, les installeurs restent disponibles en artefact du run). # l'API release renvoie 403. Pas de continue-on-error : les artefacts du run sont déjà uploadés à
- name: Attach installers to Gitea release # l'étape précédente, donc un échec ici ne perd rien et doit être VU (avec un token expiré, la
# release ressortait verte et vide).
- name: Attach installers to the tag release
if: github.event_name == 'push'
env:
RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
version=$(node -p "require('./packages/desktop/package.json').version")
bash .gitea/scripts/attach-release-assets.sh "${GITHUB_REF_NAME}" "Arboretum Desktop ${version}" \
packages/desktop/release/*.AppImage \
packages/desktop/release/*.deb \
packages/desktop/release/*.blockmap \
packages/desktop/release/latest-linux.yml \
packages/desktop/release/SHA256SUMS-linux.txt
windows:
name: Build Windows (NSIS + portable)
# Activé par la variable de dépôt ENABLE_WINDOWS_BUILD (voir docs/CI_RUNNERS.md). Sans runner
# Windows enregistré, un job non conditionné resterait en attente indéfiniment et bloquerait la
# release entière.
if: vars.ENABLE_WINDOWS_BUILD == 'true'
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ env.NODE_VERSION }}
- name: Verify tag matches desktop version
if: github.event_name == 'push'
shell: bash
run: |
pkg=$(node -p "require('./packages/desktop/package.json').version")
tag="${GITHUB_REF_NAME#desktop-v}"
if [ "$pkg" != "$tag" ]; then
echo "ERREUR: tag '$tag' != version desktop '$pkg'"
exit 1
fi
echo "OK: tag $tag == version $pkg"
- run: npm ci
- name: Install desktop deps
shell: bash
run: cd packages/desktop && npm ci
# `dist:win` sur hôte Windows : c'est le SEUL chemin qui produit un node-pty utilisable (ConPTY,
# conpty.dll + OpenConsole.exe copiés par le post-install de node-pty).
- name: Build installers
shell: bash
run: cd packages/desktop && npm run dist:win
- name: Compute checksums
shell: bash
run: |
cd packages/desktop/release
sha256sum *.exe > SHA256SUMS-windows.txt
cat SHA256SUMS-windows.txt
- uses: actions/upload-artifact@v3
with:
name: desktop-windows
path: |
packages/desktop/release/*.exe
packages/desktop/release/*.blockmap
packages/desktop/release/latest.yml
packages/desktop/release/SHA256SUMS-windows.txt
# Pas de continue-on-error : cf. la note du job Linux.
- name: Attach installers to the tag release
if: github.event_name == 'push'
shell: bash
env:
RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
version=$(node -p "require('./packages/desktop/package.json').version")
bash .gitea/scripts/attach-release-assets.sh "${GITHUB_REF_NAME}" "Arboretum Desktop ${version}" \
packages/desktop/release/*.exe \
packages/desktop/release/*.blockmap \
packages/desktop/release/latest.yml \
packages/desktop/release/SHA256SUMS-windows.txt
# Canal d'auto-update : electron-updater interroge une URL FIXE
# (.../releases/download/desktop-latest, cf. electron-builder.yml). Ce tag flottant doit donc exister
# et porter les latest*.yml de la dernière version, sinon l'updater reçoit un 404 · c'était le cas
# jusqu'en 0.1.3, où l'auto-update annoncé ne fonctionnait pour personne.
latest-channel:
name: Publish floating desktop-latest release
if: github.event_name == 'push'
runs-on: ubuntu-latest
needs: [linux]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ env.NODE_VERSION }}
- uses: actions/download-artifact@v3
with:
name: desktop-linux
path: dl
# Les artefacts Windows n'existent que si le job correspondant a tourné : téléchargement toléré
# en échec pour ne jamais bloquer la publication du canal Linux.
- uses: actions/download-artifact@v3
continue-on-error: true continue-on-error: true
with:
name: desktop-windows
path: dl
# On repart d'une release flottante VIERGE : sinon les assets de la version précédente y
# restent (mêmes noms de fichiers uniquement remplacés, un ancien numéro de version subsisterait).
# La recréation est faite par le script suivant, via l'API (Gitea crée le tag au besoin).
- name: Reset the floating release
env: env:
RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }} RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }}
run: | run: |
if [ -z "$RELEASE_TOKEN" ]; then if [ -z "$RELEASE_TOKEN" ]; then
echo "::notice::NPM_TOKEN absent : installeurs disponibles en artefact uniquement." echo "::notice::NPM_TOKEN absent, canal desktop-latest non publié."
exit 0 exit 0
fi fi
api="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}" api="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}"
auth="Authorization: token ${RELEASE_TOKEN}" auth="Authorization: token ${RELEASE_TOKEN}"
old=$(curl -fsSL -H "$auth" "${api}/releases/tags/desktop-latest" | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id || ''" || true)
if [ -n "$old" ]; then
echo "suppression de l'ancienne release flottante (id ${old})"
curl -fsSL -X DELETE -H "$auth" "${api}/releases/${old}" || true
fi
curl -fsSL -X DELETE -H "$auth" "${api}/tags/desktop-latest" || true
- name: Attach installers to the floating release
env:
RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
version=$(node -p "require('./packages/desktop/package.json').version") version=$(node -p "require('./packages/desktop/package.json').version")
rid=$(curl -fsSL -H "$auth" "${api}/releases/tags/${GITHUB_REF_NAME}" | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id || ''" || true) bash .gitea/scripts/attach-release-assets.sh desktop-latest "Arboretum Desktop (latest, ${version})" \
if [ -z "$rid" ]; then dl/*.AppImage dl/*.deb dl/*.exe dl/*.blockmap dl/latest-linux.yml dl/latest.yml dl/SHA256SUMS-*.txt
rid=$(curl -fsSL -X POST -H "$auth" -H 'Content-Type: application/json' \
-d "{\"tag_name\":\"${GITHUB_REF_NAME}\",\"name\":\"Arboretum Desktop ${version}\"}" \
"${api}/releases" | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id || ''")
fi
for f in packages/desktop/release/*.AppImage packages/desktop/release/*.deb packages/desktop/release/latest-linux.yml; do
[ -f "$f" ] || continue
name=$(basename "$f")
# Re-run idempotent : supprimer un asset existant du même nom avant de ré-uploader, pour
# que le dernier build gagne (l'API Gitea refuse sinon un asset déjà présent).
existing=$(curl -fsSL -H "$auth" "${api}/releases/${rid}/assets" | node -e "const a=JSON.parse(require('fs').readFileSync(0,'utf8'));const m=Array.isArray(a)?a.find(x=>x.name===process.argv[1]):null;process.stdout.write(m?String(m.id):'')" "$name" || true)
if [ -n "$existing" ]; then
echo "replacing existing $name (asset $existing)"
curl -fsSL -X DELETE -H "$auth" "${api}/releases/${rid}/assets/${existing}" || true
fi
echo "attaching $name"
curl -fsSL -X POST -H "$auth" -F "attachment=@${f}" "${api}/releases/${rid}/assets?name=${name}"
done
echo "Installeurs Linux attachés à la release ${GITHUB_REF_NAME}."
+7 -23
View File
@@ -45,31 +45,15 @@ jobs:
with: with:
name: vsix name: vsix
path: packages/vscode/*.vsix path: packages/vscode/*.vsix
# Best-effort : attache le VSIX à la release Gitea du tag (crée la release si absente). # Attache le VSIX à la release Gitea du tag (créée si absente), via le script partagé avec la
# Réutilise le secret NPM_TOKEN (même token Gitea que la publication du daemon) : ce token doit # release desktop : la logique était dupliquée, avec le même angle mort. Réutilise le secret
# porter write:repository en plus de write:package, sinon l'API release renvoie un 403. Sans # NPM_TOKEN (même token Gitea que la publication du daemon), qui doit porter write:repository en
# token, l'étape est ignorée sans faire échouer le job (continue-on-error) ; le VSIX reste # plus de write:package. Sans token du tout, le script sort proprement ; avec un token REFUSÉ, il
# disponible en artefact. # échoue, pour que l'anomalie soit visible (le VSIX reste dans les artefacts du run).
- name: Attach VSIX to Gitea release - name: Attach VSIX to Gitea release
continue-on-error: true
env: env:
RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }} RELEASE_TOKEN: ${{ secrets.NPM_TOKEN }}
run: | run: |
if [ -z "$RELEASE_TOKEN" ]; then
echo "::notice::NPM_TOKEN absent : VSIX disponible en artefact uniquement."
exit 0
fi
api="${GITHUB_SERVER_URL}/api/v1/repos/${GITHUB_REPOSITORY}"
auth="Authorization: token ${RELEASE_TOKEN}"
version=$(node -p "require('./packages/vscode/package.json').version") version=$(node -p "require('./packages/vscode/package.json').version")
vsix="packages/vscode/git-arboretum-${version}.vsix" bash .gitea/scripts/attach-release-assets.sh "${GITHUB_REF_NAME}" "Arboretum VSCode ${version}" \
# id de release du tag, sinon création "packages/vscode/git-arboretum-${version}.vsix"
rid=$(curl -fsSL -H "$auth" "${api}/releases/tags/${GITHUB_REF_NAME}" | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id || ''" || true)
if [ -z "$rid" ]; then
rid=$(curl -fsSL -X POST -H "$auth" -H 'Content-Type: application/json' \
-d "{\"tag_name\":\"${GITHUB_REF_NAME}\",\"name\":\"Arboretum VSCode ${version}\"}" \
"${api}/releases" | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).id || ''")
fi
curl -fsSL -X POST -H "$auth" -F "attachment=@${vsix}" \
"${api}/releases/${rid}/assets?name=git-arboretum-${version}.vsix"
echo "VSIX attaché à la release ${GITHUB_REF_NAME}."
+95 -5
View File
@@ -49,6 +49,7 @@ Un unique daemon Node.js que vous lancez sur votre machine de dev (en app de bur
- **Découverte & reprise de sessions** : les sessions lancées dans votre propre terminal apparaissent automatiquement ; reprenez les sessions mortes, observez ou forkez les vivantes. Ne corrompt jamais une session vivante. Masquez les anciennes qui encombrent la liste (un clic efface tout l'historique externe ; elles restent reprenables). - **Découverte & reprise de sessions** : les sessions lancées dans votre propre terminal apparaissent automatiquement ; reprenez les sessions mortes, observez ou forkez les vivantes. Ne corrompt jamais une session vivante. Masquez les anciennes qui encombrent la liste (un clic efface tout l'historique externe ; elles restent reprenables).
- **Terminal web** : terminal xterm.js complet vers chaque session managée, qui survit aux déconnexions du navigateur ; vraiment plein écran, avec l'invite ancrée en bas et tout l'historique défilable au-dessus. - **Terminal web** : terminal xterm.js complet vers chaque session managée, qui survit aux déconnexions du navigateur ; vraiment plein écran, avec l'invite ancrée en bas et tout l'historique défilable au-dessus.
- **IDE multi-projet** : un espace de travail pour tous les projets ouverts à la fois (pas de fenêtre par projet). Un arbre unique (projet, worktrees, sessions Claude), un éditeur Monaco à onglets (plusieurs fichiers de projets différents côte à côte, avec diffs inline par fichier), un dock bas de terminaux de session, et des panneaux Git / Sessions / Groupes. Éditez les fichiers, indexez les changements sélectivement, committez (ou amendez), fetch/pull et push, au même endroit. Un watcher de système de fichiers en temps réel garde la vue à jour au fil des éditions de l'agent. Disponible en app de bureau native et dans le navigateur. - **IDE multi-projet** : un espace de travail pour tous les projets ouverts à la fois (pas de fenêtre par projet). Un arbre unique (projet, worktrees, sessions Claude), un éditeur Monaco à onglets (plusieurs fichiers de projets différents côte à côte, avec diffs inline par fichier), un dock bas de terminaux de session, et des panneaux Git / Sessions / Groupes. Éditez les fichiers, indexez les changements sélectivement, committez (ou amendez), fetch/pull et push, au même endroit. Un watcher de système de fichiers en temps réel garde la vue à jour au fil des éditions de l'agent. Disponible en app de bureau native et dans le navigateur.
- **Démarrez un projet en un clic** : beaucoup de projets exigent plusieurs commandes longue durée pour démarrer (serveur de dev, API, base de données). Définissez-les une fois par projet (libellés, commandes shell, sous-dossier optionnel), auto-détectées depuis les scripts `package.json`, un `Procfile` ou `docker-compose`, puis lancez-les toutes d'un coup, un terminal attaché par commande. Chacune tourne dans votre shell de login (donc `npm`, `docker`, nvm/asdf sont dans le `PATH`) et reste vivante après la fin de la commande, pour que les échecs restent à l'écran ; arrêtez tout le lot en une action.
- **Supervision depuis votre téléphone** : PWA installable avec notifications push quand une session vous attend ; répondez à une demande (ses options, ou refusez) sans ouvrir de terminal. - **Supervision depuis votre téléphone** : PWA installable avec notifications push quand une session vous attend ; répondez à une demande (ses options, ou refusez) sans ouvrir de terminal.
- **Groupes de travail** : regroupez des repos liés (ex. une API, son frontend web et sa doc) dans un groupe nommé, puis lancez **une seule session Claude qui les couvre tous à la fois** (via le flag `--add-dir` du CLI) : une conversation unique avec un contexte partagé travaillant à travers chaque repo, plus une vue unifiée de tous leurs worktrees et une grille multi-terminaux côte à côte. Une session de groupe peut d'abord créer le même worktree de branche dans chaque repo, ou tourner directement sur les checkouts principaux. - **Groupes de travail** : regroupez des repos liés (ex. une API, son frontend web et sa doc) dans un groupe nommé, puis lancez **une seule session Claude qui les couvre tous à la fois** (via le flag `--add-dir` du CLI) : une conversation unique avec un contexte partagé travaillant à travers chaque repo, plus une vue unifiée de tous leurs worktrees et une grille multi-terminaux côte à côte. Une session de groupe peut d'abord créer le même worktree de branche dans chaque repo, ou tourner directement sur les checkouts principaux.
- **Services git distants** : connectez vos comptes GitHub, GitLab ou Gitea (personal access token ou app password), stockés **chiffrés au repos** (AES-256-GCM) ; parcourez vos dépôts distants et clonez-les en HTTPS avec progression en direct, directement depuis le dashboard. - **Services git distants** : connectez vos comptes GitHub, GitLab ou Gitea (personal access token ou app password), stockés **chiffrés au repos** (AES-256-GCM) ; parcourez vos dépôts distants et clonez-les en HTTPS avec progression en direct, directement depuis le dashboard.
@@ -128,6 +129,19 @@ Vous préférez une app native au daemon-dans-un-terminal ? Arboretum fournit un
L'app de bureau n'est qu'une coquille autour du même daemon et de la même interface web : tout ce qui suit (espace de travail, git, sessions) fonctionne à l'identique. L'app de bureau n'est qu'une coquille autour du même daemon et de la même interface web : tout ce qui suit (espace de travail, git, sessions) fonctionne à l'identique.
### Installer selon la plateforme
| Plateforme | Artefact | Notes |
|---|---|---|
| **Debian / Ubuntu** | `Arboretum-<version>-amd64.deb` | `sudo apt install ./Arboretum-*.deb`. Installe la dépendance `git`. À préférer à l'AppImage sous Debian : il pose l'entrée de lanceur et ses icônes. |
| **Autres Linux** | `Arboretum-<version>-x86_64.AppImage` | `chmod +x` puis lancer. Aucune entrée de menu sans un outil d'intégration comme `appimaged`. |
| **Windows** | `Arboretum-<version>-x64.exe` (NSIS) ou le build portable | Non signé : SmartScreen affiche « éditeur inconnu », choisissez **Informations complémentaires → Exécuter quand même**. Nécessite Windows 10 1809+ (ConPTY). |
| **macOS** | `Arboretum-<version>.dmg` | Ni signé ni notarisé : clic droit sur l'app → **Ouvrir**, ou `xattr -dr com.apple.quarantine /Applications/Arboretum.app`. Buildé à la demande, voir `packages/desktop/README.md`. |
Sous Windows aussi, le CLI `claude` doit être dans votre PATH ; si l'app ne le trouve pas, renseignez son
chemin dans **Réglages → CLI Claude**. Le lancement du daemon à l'ouverture de session y est également
géré (`arboretum install` enregistre une tâche planifiée).
## Utiliser Arboretum ## Utiliser Arboretum
1. **Ajoutez un dépôt.** Depuis le dashboard, enregistrez un repo git local par son chemin. Configurez éventuellement des **hooks post-création** (ex. `npm ci`, `cp ../.env .env`) exécutés automatiquement à chaque création d'un nouveau worktree pour ce repo. 1. **Ajoutez un dépôt.** Depuis le dashboard, enregistrez un repo git local par son chemin. Configurez éventuellement des **hooks post-création** (ex. `npm ci`, `cp ../.env .env`) exécutés automatiquement à chaque création d'un nouveau worktree pour ce repo.
@@ -163,10 +177,10 @@ Elle est distribuée en **VSIX privé**. Buildez-la et packagez-la depuis le mon
```bash ```bash
npm run build:vscode npm run build:vscode
cd packages/vscode && npx @vscode/vsce package --no-dependencies # → git-arboretum-0.3.0.vsix cd packages/vscode && npx @vscode/vsce package --no-dependencies # → git-arboretum-<version>.vsix
``` ```
Puis installez-la via **Extensions : Installer à partir d'un VSIX…** (ou `code --install-extension git-arboretum-0.3.0.vsix`), lancez **Arboretum: Sign In** et collez un token. Détails complets dans [`packages/vscode/README.md`](packages/vscode/README.md). Puis installez-la via **Extensions : Installer à partir d'un VSIX…** (ou `code --install-extension git-arboretum-<version>.vsix`), lancez **Arboretum: Sign In** et collez un token. Détails complets dans [`packages/vscode/README.md`](packages/vscode/README.md).
## Accès distant depuis votre téléphone ## Accès distant depuis votre téléphone
@@ -187,6 +201,47 @@ Ouvrez `https://<machine>.<tailnet>.ts.net` depuis n'importe quel appareil de vo
> ⚠️ Un terminal web, c'est de l'exécution de code à distance **par conception**. N'exposez jamais Arboretum directement sur l'internet public. > ⚠️ Un terminal web, c'est de l'exécution de code à distance **par conception**. N'exposez jamais Arboretum directement sur l'internet public.
### Mode serveur web (réseau local, reverse proxy)
Quel que soit le front que vous mettez devant, retenez la règle qui piège tout le monde en premier : **le
daemon rejette toute requête dont il ne connaît pas l'`Origin`**, avec un `403 BAD_ORIGIN`. L'adresse que
vous tapez dans le navigateur doit être passée en `--allow-origin` (répétable). Réglages → **Accès
distant** affiche l'origine courante, la liste autorisée, et la commande exacte pour en ajouter une.
**Derrière un reverse proxy** (nginx, Caddy, Traefik), avec terminaison TLS sur votre domaine :
```nginx
# nginx : l'upgrade WebSocket ET X-Forwarded-Proto sont nécessaires
location / {
proxy_pass http://127.0.0.1:7317;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme; # rend le cookie de session Secure
proxy_read_timeout 3600s; # terminaux longue durée
}
```
```bash
npx @johanleroy/git-arboretum --allow-origin https://arboretum.exemple.com
```
C'est `X-Forwarded-Proto: https` qui indique à Arboretum de marquer son cookie de session `Secure` ; sans
cet en-tête, le cookie reste non-Secure derrière votre front HTTPS. Gardez un timeout de lecture large :
un WebSocket de terminal reste inactif de longs moments.
**Sur le réseau local, sans proxy** (le moins recommandé : HTTP simple, pas de Web Push, pas d'install PWA) :
```bash
npx @johanleroy/git-arboretum \
--bind 0.0.0.0 --i-know-this-exposes-a-terminal \
--allow-origin http://192.168.1.42:7317
```
Le flag d'acquittement est obligatoire et n'est jamais ajouté pour vous : sortir de la boucle locale doit
être un acte délibéré. Restreignez l'accès au niveau réseau (pare-feu, VPN) et préférez Tailscale.
## Le faire tourner en service d'arrière-plan ## Le faire tourner en service d'arrière-plan
Le plus rapide pour faire tourner Arboretum en service qui survit à la déconnexion et redémarre au boot, c'est l'installeur intégré. Installez une version figée globalement, puis lancez `install`. Il détecte votre OS, écrit le fichier de service, le démarre et affiche le token unique : Le plus rapide pour faire tourner Arboretum en service qui survit à la déconnexion et redémarre au boot, c'est l'installeur intégré. Installez une version figée globalement, puis lancez `install`. Il détecte votre OS, écrit le fichier de service, le démarre et affiche le token unique :
@@ -196,7 +251,7 @@ npm i -g @johanleroy/git-arboretum
arboretum install --allow-origin https://MACHINE.TAILNET.ts.net arboretum install --allow-origin https://MACHINE.TAILNET.ts.net
``` ```
Cela met en place un **service systemd utilisateur** sous Linux (`~/.config/systemd/user/arboretum.service`) ou un **LaunchAgent launchd** sous macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`). Tous les flags du daemon (`--port`, `--allow-origin`, `--db`, …) sont propagés au service. Gérez-le avec : Cela met en place un **service systemd utilisateur** sous Linux (`~/.config/systemd/user/arboretum.service`), un **LaunchAgent launchd** sous macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`), ou une **tâche planifiée** sous Windows (`Arboretum`, déclenchée à l'ouverture de session, enregistrée par `schtasks`). Toujours sous votre compte utilisateur, jamais en root ni SYSTEM. Tous les flags du daemon (`--port`, `--allow-origin`, `--db`, …) sont propagés au service. Gérez-le avec :
```bash ```bash
arboretum status # état du service (+ où lire les logs) arboretum status # état du service (+ où lire les logs)
@@ -252,7 +307,9 @@ Les options du daemon sont des flags CLI :
| `--allow-origin <url>` | aucun | Origine `Origin` autorisée supplémentaire (répétable). Nécessaire pour l'accès Tailscale/HTTPS. | | `--allow-origin <url>` | aucun | Origine `Origin` autorisée supplémentaire (répétable). Nécessaire pour l'accès Tailscale/HTTPS. |
| `--db <path>` | `<data>/arboretum.db` | Chemin de la base SQLite. | | `--db <path>` | `<data>/arboretum.db` | Chemin de la base SQLite. |
| `--vapid-contact <mailto/url>` | `mailto:arboretum@localhost` | Sujet de contact VAPID pour le Web Push. | | `--vapid-contact <mailto/url>` | `mailto:arboretum@localhost` | Sujet de contact VAPID pour le Web Push. |
| `--print-token` | `false` | Indication sur le réaffichage du token (les tokens sont hashés et ne peuvent pas être réaffichés). | | `--print-token` | `false` | Affiche le jeton d'accès au démarrage (et le crée si la base n'en a aucun). |
| `--claude-home <chemin>` | `~/.claude` | Surcharge la racine d'installation de Claude (registre de sessions et transcripts). |
| `--no-discover` | `false` | Désactive la découverte auto des dépôts (scan au démarrage et re-scan périodique). |
| `--i-know-this-exposes-a-terminal` | `false` | Reconnaître le bind sur une adresse non-loopback. **À éviter** : préférez Tailscale Serve. | | `--i-know-this-exposes-a-terminal` | `false` | Reconnaître le bind sur une adresse non-loopback. **À éviter** : préférez Tailscale Serve. |
`arboretum install` accepte tous les flags du daemon ci-dessus (propagés tels quels au service), plus : `arboretum install` accepte tous les flags du daemon ci-dessus (propagés tels quels au service), plus :
@@ -264,7 +321,18 @@ Les options du daemon sont des flags CLI :
| `--dry-run` | Affiche le unit/plist et les commandes sans rien appliquer. | | `--dry-run` | Affiche le unit/plist et les commandes sans rien appliquer. |
| `--no-enable` | Écrit le fichier de service sans l'activer/le démarrer. | | `--no-enable` | Écrit le fichier de service sans l'activer/le démarrer. |
L'état (la base SQLite) vit dans `$XDG_DATA_HOME/arboretum` (par défaut `~/.local/share/arboretum`). L'état (la base SQLite) vit dans `$XDG_DATA_HOME/arboretum`, avec pour défaut
`~/.local/share/arboretum` sous Linux et macOS, et `%APPDATA%\arboretum` sous Windows.
Variables d'environnement :
| Variable | Utilisée par | Description |
|---|---|---|
| `ARBORETUM_LOG` | daemon | Niveau de log (`fatal`, `error`, `warn`, `info`, `debug`, `trace`). Défaut `info`. |
| `ARBORETUM_SECRET_KEY` | daemon | Clé de 32 octets (base64 ou hex) chiffrant les identifiants git stockés. Générée et conservée en base si absente. |
| `ARBORETUM_EMIT_TOKEN_FD` | daemon | Écrit le jeton d'accès sur ce descripteur de fichier au démarrage. Utilisé par l'app de bureau pour s'auto-connecter ; pas destiné à un usage manuel. |
| `XDG_DATA_HOME` | daemon | Racine du répertoire de données (voir ci-dessus). |
| `ARBORETUM_SHELL` | daemon (Windows) | Shell utilisé pour les commandes de projet. Défaut `powershell.exe`. |
Les réglages au-delà des flags CLI (les répertoires qu'Arboretum scanne pour trouver des repos et à quelle fréquence, le chemin et le home du binaire `claude`, et les fenêtres de rétention / purge des sessions) vivent dans les **Réglages** de l'UI. Ils sont diffusés via le WebSocket, donc chaque navigateur connecté reflète un changement en temps réel, sans rechargement. Les réglages au-delà des flags CLI (les répertoires qu'Arboretum scanne pour trouver des repos et à quelle fréquence, le chemin et le home du binaire `claude`, et les fenêtres de rétention / purge des sessions) vivent dans les **Réglages** de l'UI. Ils sont diffusés via le WebSocket, donc chaque navigateur connecté reflète un changement en temps réel, sans rechargement.
@@ -290,6 +358,19 @@ Tailscale Serve est **la** façon d'atteindre Arboretum depuis d'autres appareil
Voir [`SECURITY.md`](SECURITY.md) pour le modèle de menace complet et [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md) pour le durcissement en environnement réglementé. Voir [`SECURITY.md`](SECURITY.md) pour le modèle de menace complet et [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md) pour le durcissement en environnement réglementé.
## Dépannage
| Symptôme | Cause & correction |
|---|---|
| `npm error 404 Not Found @johanleroy/git-arboretum` | Le paquet vit sur un registre privé. Déclarez le scope dans votre `~/.npmrc` : `@johanleroy:registry=https://git.lidge.fr/api/packages/johanleroy/npm/` |
| `403 BAD_ORIGIN` dans la console, interface blanche | L'adresse utilisée n'est pas dans la liste autorisée. Redémarrez avec `--allow-origin <cette origine exacte>` (schéma, hôte et port doivent correspondre). |
| `ERR_UNKNOWN_BUILTIN_MODULE node:sqlite` ou plantage au démarrage | Node est antérieur à 22.16. Vérifiez avec `node --version` : `node:sqlite` n'est stable qu'à partir de là. L'app de bureau embarque son runtime et n'est pas concernée. |
| « Claude Code CLI not found in PATH » | Le daemon tourne avec un PATH minimal (cas typique sous systemd/launchd). Renseignez le chemin du binaire dans **Réglages → CLI Claude**, ou réinstallez le service avec `arboretum install`, qui fige votre PATH interactif. |
| Impossible d'activer les notifications | Le Web Push exige HTTPS. Utilisez Tailscale Serve ou un reverse proxy ; sur iOS, installez d'abord la PWA. |
| Le lanceur affiche une icône générique (Linux) | Corrigé en desktop 0.2.0 : les paquets antérieurs installaient une taille d'icône non standard, ignorée par la spécification freedesktop. Mettez le `.deb` à jour ; si l'icône persiste, lancez `gtk-update-icon-cache -f /usr/share/icons/hicolor` ou reconnectez-vous. |
| SmartScreen ou Gatekeeper bloque l'app | Attendu : les binaires ne sont pas signés. Voir le tableau par plateforme plus haut. |
| Un terminal reste vide après « Démarrer le projet » | La commande a été tapée dans un shell de login qui n'a pas démarré. Regardez l'onglet : le shell survit volontairement à l'échec, l'erreur y est donc visible. |
## Ce qui le distingue ## Ce qui le distingue
| | Arboretum | GitKraken Agent Mode / Conductor / Nimbalyst | Happy / CloudCLI | Anthropic Remote Control | | | Arboretum | GitKraken Agent Mode / Conductor / Nimbalyst | Happy / CloudCLI | Anthropic Remote Control |
@@ -333,8 +414,17 @@ node packages/server/scripts/acceptance-p9.mjs # commit/push avancé : staging
node packages/server/scripts/acceptance-p10.mjs # archivage automatique des sessions node packages/server/scripts/acceptance-p10.mjs # archivage automatique des sessions
node packages/server/scripts/acceptance-p11.mjs # synchronisation des réglages en temps réel node packages/server/scripts/acceptance-p11.mjs # synchronisation des réglages en temps réel
node packages/server/scripts/acceptance-p12.mjs # services git distants + clone HTTPS node packages/server/scripts/acceptance-p12.mjs # services git distants + clone HTTPS
node packages/server/scripts/acceptance-p13.mjs # démarrer le projet : commandes de lancement, multi-terminaux
node packages/server/scripts/acceptance-p14.mjs # temps réel armé : watcher épinglé par session, corrélation cwd
node packages/server/scripts/acceptance-p15.mjs # historisation : log de commits & diff par commit
``` ```
Contrôle de rendu (Chromium headless via CDP, sans Playwright) : après `npm run build`, lancez
`node packages/server/scripts/copy-web.mjs` puis
`node packages/server/scripts/verify-ui.mjs [dossier]`. Le script démarre un daemon isolé, crée un dépôt
de démonstration et écrit des captures de l'IDE dans les deux thèmes, en largeurs desktop et mobile, en
échouant sur toute erreur console.
Le protocole s'est enrichi (de façon additive, sans bump de version) pour porter ces nouveautés : messages client `watch` / `unwatch` et signal ciblé `worktree_changes` (P7), plus les broadcasts `session_archived` (P10), `settings_update` (P11) et `clone_update` (P12). Côté serveur, le tout s'appuie sur `core/git.ts` (le moteur git pur), `core/fs-watcher.ts` (chokidar), `core/git-credentials.ts` + `core/clone-manager.ts` (identifiants chiffrés & clone), et les services d'archivage de sessions et de réglages. Le protocole s'est enrichi (de façon additive, sans bump de version) pour porter ces nouveautés : messages client `watch` / `unwatch` et signal ciblé `worktree_changes` (P7), plus les broadcasts `session_archived` (P10), `settings_update` (P11) et `clone_update` (P12). Côté serveur, le tout s'appuie sur `core/git.ts` (le moteur git pur), `core/fs-watcher.ts` (chokidar), `core/git-credentials.ts` + `core/clone-manager.ts` (identifiants chiffrés & clone), et les services d'archivage de sessions et de réglages.
## Soutenir le projet ## Soutenir le projet
+95 -5
View File
@@ -49,6 +49,7 @@ A single Node.js daemon you run on your dev machine (as a native desktop app, or
- **Session discovery & resume**: sessions you launched in your own terminal show up automatically; resume dead ones, observe or fork live ones. Never corrupts a live session. Hide the old ones that clutter the list (one click clears the whole external history; they stay resumable). - **Session discovery & resume**: sessions you launched in your own terminal show up automatically; resume dead ones, observe or fork live ones. Never corrupts a live session. Hide the old ones that clutter the list (one click clears the whole external history; they stay resumable).
- **Web terminal**: full xterm.js terminal to every managed session, surviving browser disconnects; truly fullscreen, with the prompt pinned to the bottom and full scrollback above. - **Web terminal**: full xterm.js terminal to every managed session, surviving browser disconnects; truly fullscreen, with the prompt pinned to the bottom and full scrollback above.
- **Multi-project IDE**: one workspace for every open project at once (no per-project window). A single tree (project, worktrees, Claude sessions), a tabbed Monaco editor (several files from different projects side by side, with inline per-file diffs), a bottom dock of session terminals, and Git / Sessions / Groups panels. Edit files, stage changes selectively, commit (or amend), fetch/pull and push, all in one place. A real-time file-system watcher keeps the view live as the agent edits. Available as a native desktop app and in the browser. - **Multi-project IDE**: one workspace for every open project at once (no per-project window). A single tree (project, worktrees, Claude sessions), a tabbed Monaco editor (several files from different projects side by side, with inline per-file diffs), a bottom dock of session terminals, and Git / Sessions / Groups panels. Edit files, stage changes selectively, commit (or amend), fetch/pull and push, all in one place. A real-time file-system watcher keeps the view live as the agent edits. Available as a native desktop app and in the browser.
- **Start a project in one click**: many projects need several long-running commands to boot (dev server, API, database). Define them once per project (labels, shell commands, optional subdir), auto-detected from `package.json` scripts, a `Procfile` or `docker-compose`, then launch them all at once, one attached terminal per command. Each runs in your login shell (so `npm`, `docker`, nvm/asdf are on `PATH`) and stays live after the command exits, so failures stay on screen; stop the whole set in one action.
- **Supervision from your phone**: installable PWA with push notifications when a session needs you; answer a prompt (its options, or deny) without opening a terminal. - **Supervision from your phone**: installable PWA with push notifications when a session needs you; answer a prompt (its options, or deny) without opening a terminal.
- **Work groups**: bundle related repos (e.g. an API, its web frontend and its docs) into a named group, then launch **one Claude session that spans all of them at once** (via the CLI's `--add-dir`): a single conversation with one shared context working across every repo, plus a unified view of all their worktrees and a side-by-side multi-terminal grid. Group sessions can either create the same branch worktree in each repo first, or run straight on the main checkouts. - **Work groups**: bundle related repos (e.g. an API, its web frontend and its docs) into a named group, then launch **one Claude session that spans all of them at once** (via the CLI's `--add-dir`): a single conversation with one shared context working across every repo, plus a unified view of all their worktrees and a side-by-side multi-terminal grid. Group sessions can either create the same branch worktree in each repo first, or run straight on the main checkouts.
- **Remote git services**: connect your GitHub, GitLab or Gitea accounts (personal access token or app password), stored **encrypted at rest** (AES-256-GCM); browse your remote repositories and clone them over HTTPS with live progress, straight from the dashboard. - **Remote git services**: connect your GitHub, GitLab or Gitea accounts (personal access token or app password), stored **encrypted at rest** (AES-256-GCM); browse your remote repositories and clone them over HTTPS with live progress, straight from the dashboard.
@@ -128,6 +129,19 @@ Prefer a native app to the daemon-in-a-terminal? Arboretum ships an **Electron d
The desktop app is just a shell around the same daemon and web UI, so everything below (workspace, git, sessions) works identically. The desktop app is just a shell around the same daemon and web UI, so everything below (workspace, git, sessions) works identically.
### Installing per platform
| Platform | Artifact | Notes |
|---|---|---|
| **Debian / Ubuntu** | `Arboretum-<version>-amd64.deb` | `sudo apt install ./Arboretum-*.deb`. Pulls in `git`. Preferred over the AppImage on Debian: it installs the launcher entry and its icons. |
| **Other Linux** | `Arboretum-<version>-x86_64.AppImage` | `chmod +x` then run. No desktop entry unless you use a tool like `appimaged`. |
| **Windows** | `Arboretum-<version>-x64.exe` (NSIS) or the portable build | Not code-signed: SmartScreen shows "unknown publisher", choose **More info → Run anyway**. Needs Windows 10 1809+ (ConPTY). |
| **macOS** | `Arboretum-<version>.dmg` | Not signed or notarized: right-click the app → **Open**, or `xattr -dr com.apple.quarantine /Applications/Arboretum.app`. Built on demand, see `packages/desktop/README.md`. |
Windows also needs the `claude` CLI on your PATH like any other platform; if the app cannot find it,
set its path in **Settings → Claude CLI**. Running the daemon at logon is supported there too
(`arboretum install` registers a scheduled task).
## Using Arboretum ## Using Arboretum
1. **Add a repository.** From the dashboard, register a local git repo by its path. Optionally configure **post-create hooks** (e.g. `npm ci`, `cp ../.env .env`) that run automatically every time you create a new worktree for that repo. 1. **Add a repository.** From the dashboard, register a local git repo by its path. Optionally configure **post-create hooks** (e.g. `npm ci`, `cp ../.env .env`) that run automatically every time you create a new worktree for that repo.
@@ -163,10 +177,10 @@ It is distributed as a **private VSIX**. Build and package it from the monorepo:
```bash ```bash
npm run build:vscode npm run build:vscode
cd packages/vscode && npx @vscode/vsce package --no-dependencies # → git-arboretum-0.3.0.vsix cd packages/vscode && npx @vscode/vsce package --no-dependencies # → git-arboretum-<version>.vsix
``` ```
Then install it via **Extensions: Install from VSIX…** (or `code --install-extension git-arboretum-0.3.0.vsix`), run **Arboretum: Sign In** and paste a token. Full details in [`packages/vscode/README.md`](packages/vscode/README.md). Then install it via **Extensions: Install from VSIX…** (or `code --install-extension git-arboretum-<version>.vsix`), run **Arboretum: Sign In** and paste a token. Full details in [`packages/vscode/README.md`](packages/vscode/README.md).
## Remote access from your phone ## Remote access from your phone
@@ -187,6 +201,47 @@ Open `https://<machine>.<tailnet>.ts.net` from any device on your tailnet. **Web
> ⚠️ A web terminal is remote code execution **by design**. Never expose Arboretum directly to the public internet. > ⚠️ A web terminal is remote code execution **by design**. Never expose Arboretum directly to the public internet.
### Web server mode (LAN, reverse proxy)
Whatever front you put in place, remember the rule that trips everyone up first: **the daemon rejects any
request whose `Origin` it does not know**, with `403 BAD_ORIGIN`. The address you type in the browser must
be passed with `--allow-origin` (repeatable). Settings → **Remote access** shows the current origin, the
allowed list, and the exact command to add one.
**Behind a reverse proxy** (nginx, Caddy, Traefik), terminating TLS on your own domain:
```nginx
# nginx: the WebSocket upgrade and X-Forwarded-Proto are both required
location / {
proxy_pass http://127.0.0.1:7317;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme; # makes the session cookie Secure
proxy_read_timeout 3600s; # long-lived terminals
}
```
```bash
npx @johanleroy/git-arboretum --allow-origin https://arboretum.example.com
```
`X-Forwarded-Proto: https` is what tells Arboretum to mark its session cookie `Secure`; without it the
cookie stays non-Secure behind your HTTPS front. Keep the proxy read timeout generous, a terminal
WebSocket is idle for long stretches.
**On the LAN, without a proxy** (least recommended: plain HTTP, no Web Push, no PWA install):
```bash
npx @johanleroy/git-arboretum \
--bind 0.0.0.0 --i-know-this-exposes-a-terminal \
--allow-origin http://192.168.1.42:7317
```
The acknowledgement flag is mandatory and never added for you: binding beyond loopback must be a
deliberate act. Restrict access at the network level (firewall, VPN) and prefer Tailscale.
## Running it as a background service ## Running it as a background service
The quickest way to run Arboretum as a service that survives logout and restarts on boot is the built-in installer. Install a pinned version globally, then run `install`. It detects your OS, writes the service file, starts it, and prints the one-time token: The quickest way to run Arboretum as a service that survives logout and restarts on boot is the built-in installer. Install a pinned version globally, then run `install`. It detects your OS, writes the service file, starts it, and prints the one-time token:
@@ -196,7 +251,7 @@ npm i -g @johanleroy/git-arboretum
arboretum install --allow-origin https://MACHINE.TAILNET.ts.net arboretum install --allow-origin https://MACHINE.TAILNET.ts.net
``` ```
This sets up a **systemd user service** on Linux (`~/.config/systemd/user/arboretum.service`) or a **launchd LaunchAgent** on macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`). Every daemon flag (`--port`, `--allow-origin`, `--db`, …) is propagated to the service. Manage it with: This sets up a **systemd user service** on Linux (`~/.config/systemd/user/arboretum.service`), a **launchd LaunchAgent** on macOS (`~/Library/LaunchAgents/fr.lidge.arboretum.plist`), or a **scheduled task** on Windows (`Arboretum`, triggered at logon, registered with `schtasks`). Always as your user, never as root or SYSTEM. Every daemon flag (`--port`, `--allow-origin`, `--db`, …) is propagated to the service. Manage it with:
```bash ```bash
arboretum status # service status (+ where to read logs) arboretum status # service status (+ where to read logs)
@@ -252,7 +307,9 @@ Daemon options are CLI flags:
| `--allow-origin <url>` | none | Additional allowed `Origin` (repeatable). Needed for Tailscale/HTTPS access. | | `--allow-origin <url>` | none | Additional allowed `Origin` (repeatable). Needed for Tailscale/HTTPS access. |
| `--db <path>` | `<data>/arboretum.db` | SQLite database path. | | `--db <path>` | `<data>/arboretum.db` | SQLite database path. |
| `--vapid-contact <mailto/url>` | `mailto:arboretum@localhost` | VAPID contact subject for Web Push. | | `--vapid-contact <mailto/url>` | `mailto:arboretum@localhost` | VAPID contact subject for Web Push. |
| `--print-token` | `false` | Hint about token re-printing (tokens are hashed and cannot be re-shown). | | `--print-token` | `false` | Print the access token on start (bootstraps one if the database has none). |
| `--claude-home <path>` | `~/.claude` | Override the Claude install root (session registry and transcripts). |
| `--no-discover` | `false` | Disable repository auto-discovery (start-up scan and periodic re-scan). |
| `--i-know-this-exposes-a-terminal` | `false` | Acknowledge binding to a non-loopback address. **Avoid**: prefer Tailscale Serve. | | `--i-know-this-exposes-a-terminal` | `false` | Acknowledge binding to a non-loopback address. **Avoid**: prefer Tailscale Serve. |
`arboretum install` accepts every daemon flag above (propagated verbatim to the service) plus: `arboretum install` accepts every daemon flag above (propagated verbatim to the service) plus:
@@ -264,7 +321,18 @@ Daemon options are CLI flags:
| `--dry-run` | Print the unit/plist and commands without applying anything. | | `--dry-run` | Print the unit/plist and commands without applying anything. |
| `--no-enable` | Write the service file but do not enable/start it. | | `--no-enable` | Write the service file but do not enable/start it. |
State (the SQLite database) lives in `$XDG_DATA_HOME/arboretum` (default `~/.local/share/arboretum`). State (the SQLite database) lives in `$XDG_DATA_HOME/arboretum`, defaulting to
`~/.local/share/arboretum` on Linux and macOS and `%APPDATA%\arboretum` on Windows.
Environment variables:
| Variable | Used by | Description |
|---|---|---|
| `ARBORETUM_LOG` | daemon | Log level (`fatal`, `error`, `warn`, `info`, `debug`, `trace`). Default `info`. |
| `ARBORETUM_SECRET_KEY` | daemon | 32-byte key (base64 or hex) encrypting stored git credentials. Generated and stored in the database when absent. |
| `ARBORETUM_EMIT_TOKEN_FD` | daemon | Write the access token to this file descriptor at start-up. Used by the desktop app to sign itself in; not meant for manual use. |
| `XDG_DATA_HOME` | daemon | Root of the data directory (see above). |
| `ARBORETUM_SHELL` | daemon (Windows) | Shell used to run project commands. Default `powershell.exe`. |
Settings beyond CLI flags (the directories Arboretum scans for repos and how often, the `claude` binary path and home, and the session retention / purge windows) live in **Settings** in the UI. They are broadcast over the WebSocket, so every connected browser reflects a change in real time, no reload needed. Settings beyond CLI flags (the directories Arboretum scans for repos and how often, the `claude` binary path and home, and the session retention / purge windows) live in **Settings** in the UI. They are broadcast over the WebSocket, so every connected browser reflects a change in real time, no reload needed.
@@ -290,6 +358,19 @@ Tailscale Serve is **the** way to reach Arboretum from other devices, not just a
See [`SECURITY.md`](SECURITY.md) for the full threat model and [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md) for hardening in regulated environments. See [`SECURITY.md`](SECURITY.md) for the full threat model and [`docs/ENTERPRISE_DEPLOYMENT.md`](docs/ENTERPRISE_DEPLOYMENT.md) for hardening in regulated environments.
## Troubleshooting
| Symptom | Cause & fix |
|---|---|
| `npm error 404 Not Found @johanleroy/git-arboretum` | The package lives on a private registry. Add the scope to your `~/.npmrc`: `@johanleroy:registry=https://git.lidge.fr/api/packages/johanleroy/npm/` |
| `403 BAD_ORIGIN` in the browser console, blank UI | The address you are using is not in the allowed list. Restart with `--allow-origin <that exact origin>` (scheme, host and port must match). |
| `ERR_UNKNOWN_BUILTIN_MODULE node:sqlite` or a crash on start | Node is older than 22.16. Check with `node --version`; `node:sqlite` is only stable from there. The desktop app bundles its own runtime and is immune. |
| "Claude Code CLI not found in PATH" | The daemon runs with a minimal PATH (typical under systemd/launchd). Set the binary path in **Settings → Claude CLI**, or reinstall the service with `arboretum install`, which freezes your interactive PATH. |
| Notifications cannot be enabled | Web Push requires HTTPS. Use Tailscale Serve or a reverse proxy; on iOS, install the PWA first. |
| The app launcher shows a generic icon (Linux) | Fixed in desktop 0.2.0: earlier packages installed a single non-standard icon size that the freedesktop spec ignores. Upgrade the `.deb`; if the icon persists, run `gtk-update-icon-cache -f /usr/share/icons/hicolor` or log out and back in. |
| SmartScreen or Gatekeeper blocks the app | Expected: the binaries are not signed. See the per-platform table above. |
| A terminal stays blank after "Start project" | The command was typed into a login shell that failed to start. Check the tab: the shell survives the failure on purpose, so the error is visible in it. |
## What makes it different ## What makes it different
| | Arboretum | GitKraken Agent Mode / Conductor / Nimbalyst | Happy / CloudCLI | Anthropic Remote Control | | | Arboretum | GitKraken Agent Mode / Conductor / Nimbalyst | Happy / CloudCLI | Anthropic Remote Control |
@@ -333,8 +414,17 @@ node packages/server/scripts/acceptance-p9.mjs # advanced commit/push: selecti
node packages/server/scripts/acceptance-p10.mjs # automatic session archival node packages/server/scripts/acceptance-p10.mjs # automatic session archival
node packages/server/scripts/acceptance-p11.mjs # real-time settings sync node packages/server/scripts/acceptance-p11.mjs # real-time settings sync
node packages/server/scripts/acceptance-p12.mjs # remote git services + HTTPS clone node packages/server/scripts/acceptance-p12.mjs # remote git services + HTTPS clone
node packages/server/scripts/acceptance-p13.mjs # start the project: launch commands & multi-terminal
node packages/server/scripts/acceptance-p14.mjs # armed real-time: session-pinned watcher, cwd correlation
node packages/server/scripts/acceptance-p15.mjs # history: commit log & per-commit diff
``` ```
Rendering check (headless Chromium over CDP, no Playwright): after `npm run build`, run
`node packages/server/scripts/copy-web.mjs` then
`node packages/server/scripts/verify-ui.mjs [outdir]`. It starts an isolated daemon, seeds a demo repo,
and writes screenshots of the IDE in both themes at desktop and mobile widths, failing on any console
error.
The protocol grew (additively, no version bump) to carry the new surface: client `watch` / `unwatch` messages and the targeted `worktree_changes` signal (P7), plus `session_archived` (P10), `settings_update` (P11) and `clone_update` (P12) broadcasts. Server-side, the work is backed by `core/git.ts` (the pure git engine), `core/fs-watcher.ts` (chokidar), `core/git-credentials.ts` + `core/clone-manager.ts` (encrypted credentials & clone), and the session-archive and settings services. The protocol grew (additively, no version bump) to carry the new surface: client `watch` / `unwatch` messages and the targeted `worktree_changes` signal (P7), plus `session_archived` (P10), `settings_update` (P11) and `clone_update` (P12) broadcasts. Server-side, the work is backed by `core/git.ts` (the pure git engine), `core/fs-watcher.ts` (chokidar), `core/git-credentials.ts` + `core/clone-manager.ts` (encrypted credentials & clone), and the session-archive and settings services.
## Support ## Support
+42
View File
@@ -16,9 +16,17 @@ Sorties :
packages/web/public/icon-512.png icône PWA maskable (arbre, fond #09090b) packages/web/public/icon-512.png icône PWA maskable (arbre, fond #09090b)
packages/web/public/apple-touch-icon.png icône iOS 180 (arbre, fond #09090b) packages/web/public/apple-touch-icon.png icône iOS 180 (arbre, fond #09090b)
packages/web/public/favicon.ico favicon transparent (arbre, 16/32/48) packages/web/public/favicon.ico favicon transparent (arbre, 16/32/48)
packages/web/public/screenshot-ide-{dark,light}.png captures du manifeste PWA (copiées de brand/)
packages/desktop/resources/icon.png source 1024 (electron-builder : macOS + dérivations)
packages/desktop/resources/icon.ico icône Windows multi-tailles (NSIS + fenêtre)
packages/desktop/resources/icons/NNxNN.png jeu Linux aux TAILLES STANDARD hicolor
packages/desktop/resources/trayTemplate.png (+@2x) icône de barre de menus macOS (monochrome)
packages/vscode/media/icon.png icône du VSIX (128, requise par tout marketplace)
Usage : python3 brand/build-assets.py <source.png> Usage : python3 brand/build-assets.py <source.png>
""" """
import os
import shutil
import sys import sys
import numpy as np import numpy as np
from PIL import Image from PIL import Image
@@ -94,6 +102,40 @@ def main():
fav = square(tree, 0.04) fav = square(tree, 0.04)
fav.save("packages/web/public/favicon.ico", sizes=[(16, 16), (32, 32), (48, 48)]) fav.save("packages/web/public/favicon.ico", sizes=[(16, 16), (32, 32), (48, 48)])
print(" packages/web/public/favicon.ico 16/32/48") print(" packages/web/public/favicon.ico 16/32/48")
# captures utilisées par le manifeste PWA (installation enrichie Chrome/Edge)
for theme in ("dark", "light"):
src = f"brand/screenshot-ide-{theme}.png"
if os.path.exists(src):
shutil.copyfile(src, f"packages/web/public/screenshot-ide-{theme}.png")
print(f" packages/web/public/screenshot-ide-{theme}.png (copié)")
# --- app de bureau -------------------------------------------------------------------
# electron-builder n'invente RIEN pour Linux : sans un dossier d'icônes aux tailles standard
# hicolor, il installe l'unique taille source (ex. 895x895), répertoire que la spécification
# freedesktop ignore → aucun logo au lanceur. D'où la génération explicite ci-dessous.
print("packages/desktop/resources/")
os.makedirs("packages/desktop/resources/icons", exist_ok=True)
desk = square(tree, 0.08)
save(desk, "packages/desktop/resources/icon.png", 1024)
for size in (16, 24, 32, 48, 64, 128, 256, 512):
save(desk, f"packages/desktop/resources/icons/{size}x{size}.png", size)
desk.resize((256, 256), Image.LANCZOS).save(
"packages/desktop/resources/icon.ico", sizes=[(16, 16), (24, 24), (32, 32), (48, 48), (64, 64), (128, 128), (256, 256)]
)
print(" packages/desktop/resources/icon.ico 16→256")
# macOS : la barre de menus exige une image TEMPLATE (monochrome + alpha), sinon l'icône est
# illisible et ne suit pas le thème clair/sombre du système.
tpl = tree.copy()
tpl_alpha = tpl.getchannel("A")
template = Image.new("RGBA", tpl.size, (0, 0, 0, 0))
template.putalpha(tpl_alpha)
save(template, "packages/desktop/resources/trayTemplate.png", 16)
save(template, "packages/desktop/resources/trayTemplate@2x.png", 32)
# --- extension VS Code ---------------------------------------------------------------
print("packages/vscode/media/")
os.makedirs("packages/vscode/media", exist_ok=True)
save(square(tree, 0.10, bg=BG), "packages/vscode/media/icon.png", 128)
if __name__ == "__main__": if __name__ == "__main__":
+134
View File
@@ -0,0 +1,134 @@
# Runners Gitea Actions · ajouter Windows (et macOS)
Ce document explique comment activer le build **Windows** de l'app de bureau dans la CI. Il est écrit
pour être appliqué tel quel sur `git.lidge.fr` (Gitea 1.25).
## Pourquoi un runner Windows est obligatoire
Le cross-build Windows depuis Linux **ne peut pas fonctionner**, pour deux raisons vérifiées dans
`node_modules/@homebridge/node-pty-prebuilt-multiarch` :
1. `scripts/check-prebuild.js` sort en succès dès que le binaire de l'hôte existe, donc
`prebuild-install` n'est jamais appelé et aucun binaire `win32` n'est téléchargé (le tarball publié
ne contient que `prebuilds/linux-*`) ;
2. `scripts/post-install.js` ne copie `conpty.dll` et `OpenConsole.exe` **que si la plateforme de build
est win32**. Sans eux, pas de ConPTY, donc **aucun terminal** dans l'app.
Un build produit sous Wine serait donc installable mais inutilisable. C'est pour cela que
`packages/desktop/README.md` ne propose plus cette voie.
## État actuel
| Plateforme | Runner | Build |
|---|---|---|
| Linux | `ubuntu-latest` (déjà en place) | automatique à chaque tag `desktop-v*` |
| Windows | **à enregistrer** | job `windows`, activé par la variable `ENABLE_WINDOWS_BUILD` |
| macOS | aucun | manuel (`npm run dist:mac` sur un Mac) |
Le job Windows est conditionné par `if: vars.ENABLE_WINDOWS_BUILD == 'true'`. Tant que la variable
n'existe pas, le job est **sauté** : la release Linux part normalement. Sans cette condition, un job
`runs-on: windows-latest` sans runner disponible resterait en attente et bloquerait la release entière.
## 1. Préparer la machine Windows
Prérequis (Windows 10 1809+ ou Windows 11, x64) :
- **Git pour Windows** (fournit aussi `bash`, utilisé par les étapes `shell: bash` du workflow) ;
- **Node.js 22.21.1** (même version que `NODE_VERSION` dans le workflow) ;
- rien d'autre : `node-pty` s'installe via des binaires précompilés, aucun compilateur C++ n'est requis.
Vérification rapide dans PowerShell :
```powershell
node --version # v22.21.1
git --version
bash --version # fourni par Git for Windows
```
## 2. Enregistrer le runner
Récupérer un jeton d'enregistrement dans Gitea : **Site Administration → Actions → Runners → Create new
runner** (jeton d'instance), ou au niveau du dépôt : **Settings → Actions → Runners**.
Puis, dans PowerShell (répertoire dédié, par exemple `C:\actions-runner`) :
```powershell
mkdir C:\actions-runner; cd C:\actions-runner
# Binaire act_runner pour Windows (adapter la version à celle de votre Gitea)
Invoke-WebRequest -Uri "https://gitea.com/gitea/act_runner/releases/download/v0.2.13/act_runner-0.2.13-windows-amd64.exe" -OutFile act_runner.exe
.\act_runner.exe register --no-interactive `
--instance https://git.lidge.fr `
--token <JETON_DENREGISTREMENT> `
--name windows-builder `
--labels windows-latest:host
```
Le label **`windows-latest:host`** est essentiel : `:host` signifie « exécuter directement sur la
machine », sans conteneur (il n'y a pas d'image Docker Windows utilisable ici), et `windows-latest` est
le nom attendu par `runs-on` dans le workflow.
Démarrage manuel pour un premier essai :
```powershell
.\act_runner.exe daemon
```
## 3. Exécuter le runner en service
Pour qu'il survive aux redémarrages, créer une tâche planifiée « à l'ouverture de session » (même
principe que `arboretum install` sur Windows) :
```powershell
schtasks /Create /TN "GiteaActRunner" /TR "C:\actions-runner\act_runner.exe daemon" `
/SC ONLOGON /RL LIMITED /F
schtasks /Run /TN "GiteaActRunner"
```
Alternative : [NSSM](https://nssm.cc/) pour un vrai service Windows, si le runner doit tourner sans
session ouverte. Attention : un service hors session n'a pas accès au profil utilisateur.
## 4. Activer le job dans la CI
Dans Gitea, sur le dépôt `johanleroy/arboretum` : **Settings → Actions → Variables → Add Variable**
| Nom | Valeur |
|---|---|
| `ENABLE_WINDOWS_BUILD` | `true` |
## 5. Vérifier sans créer de tag
Le workflow accepte `workflow_dispatch` : **Actions → Desktop Release → Run workflow**. Dans ce mode, le
garde-fou « tag == version » est ignoré et rien n'est attaché à une release ; les installeurs sont
récupérables dans les artefacts du run (`desktop-windows`).
Contrôles à faire sur l'installeur produit :
1. l'installeur NSIS s'exécute et propose le répertoire d'installation ;
2. l'app démarre et affiche l'IDE **sans écran de connexion** (le token passe par le descripteur 3 ;
c'est le point le plus susceptible de différer sur Windows, cf. `packages/desktop/src/main/daemon.ts`) ;
3. un terminal s'ouvre et répond (ConPTY présent) ;
4. le CLI `claude` est trouvé (sinon renseigner son chemin dans Réglages → Claude CLI) ;
5. « Démarrer le projet » lance bien les commandes sous PowerShell.
## 6. Signature de code
Aucun binaire n'est signé. SmartScreen affichera « éditeur inconnu » au premier lancement : choisir
« Informations complémentaires » puis « Exécuter quand même ». Pour signer plus tard, ajouter les
secrets `CSC_LINK` (certificat .pfx encodé en base64) et `CSC_KEY_PASSWORD` au dépôt : electron-builder
les utilise automatiquement, sans changement de workflow.
## Repli si aucun runner n'est possible
Sur une machine Windows, avec le dépôt cloné :
```powershell
npm ci
cd packages\desktop
npm ci
npm run dist:win
```
Puis attacher `packages\desktop\release\*.exe`, `latest.yml` et les `.blockmap` à la release
`desktop-vX.Y.Z` depuis l'interface Gitea. Le canal d'auto-update (`desktop-latest`) doit recevoir les
mêmes fichiers, sinon les utilisateurs Windows ne verront pas la mise à jour.
+3 -3
View File
@@ -7933,7 +7933,7 @@
}, },
"packages/server": { "packages/server": {
"name": "@johanleroy/git-arboretum", "name": "@johanleroy/git-arboretum",
"version": "3.2.0", "version": "3.5.0",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@fastify/cookie": "^11.0.0", "@fastify/cookie": "^11.0.0",
@@ -7967,7 +7967,7 @@
}, },
"packages/site": { "packages/site": {
"name": "@arboretum/site", "name": "@arboretum/site",
"version": "0.3.0", "version": "0.4.0",
"dependencies": { "dependencies": {
"vue": "^3.5.38", "vue": "^3.5.38",
"vue-i18n": "^11.4.5" "vue-i18n": "^11.4.5"
@@ -8063,7 +8063,7 @@
}, },
"packages/vscode": { "packages/vscode": {
"name": "git-arboretum", "name": "git-arboretum",
"version": "0.3.0", "version": "0.4.1",
"license": "MIT", "license": "MIT",
"devDependencies": { "devDependencies": {
"@arboretum/shared": "0.1.0", "@arboretum/shared": "0.1.0",
+3 -1
View File
@@ -26,7 +26,9 @@
"dev:site": "npm run dev -w @arboretum/site", "dev:site": "npm run dev -w @arboretum/site",
"preview:site": "npm run preview -w @arboretum/site", "preview:site": "npm run preview -w @arboretum/site",
"build:vscode": "npm run build -w @arboretum/shared -w git-arboretum", "build:vscode": "npm run build -w @arboretum/shared -w git-arboretum",
"dev:vscode": "npm run dev -w git-arboretum" "dev:vscode": "npm run dev -w git-arboretum",
"typecheck:desktop": "npm --prefix packages/desktop run typecheck",
"build:desktop": "npm --prefix packages/desktop run build"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^22.10.0", "@types/node": "^22.10.0",
+69
View File
@@ -0,0 +1,69 @@
# Changelog
Notable changes to the Arboretum desktop app (`packages/desktop`). The daemon and the VS Code
extension keep their own changelogs in `packages/server/CHANGELOG.md` and
`packages/vscode/CHANGELOG.md`.
## 0.2.1
Ships the daemon 3.5.0, which fixes the black window seen after updating the app.
- **Black window after an update, fixed.** The window loaded an `index.html` kept from the previous
version (revalidated as `304` because the tarball mtime is constant, so the etag did not change) whose
`/assets/<hash>` files no longer existed. Nothing painted. If you hit it before updating, the app
repairs itself now; clearing `~/.config/Arboretum/Partitions/arboretum/Cache` was the manual fix.
- **Copy & paste in session terminals.** `Ctrl+Shift+C` / `Ctrl+Shift+V` (`Cmd+C` / `Cmd+V` on macOS);
the Edit menu's Copy also works on a terminal selection now. `Ctrl+C` still interrupts.
- Browse the files of a group's worktrees straight from the Groups panel.
The Electron shell itself is unchanged.
## 0.2.0
Distribution release: the Linux launcher icon finally shows up, Windows becomes a first-class target,
and the embedded runtime loses a third of its weight.
- **Launcher icon fixed (Linux).** Earlier packages installed a single 895×895 icon. That size is not
declared in `hicolor/index.theme`, so by the freedesktop spec every desktop environment ignored it and
the launcher fell back to a generic icon. The build now generates the standard set (16 → 512) plus a
proper `.ico` for Windows, and forces `executableName: arboretum` (the scoped package name was
producing `@arboretumdesktop` as binary, `.desktop` file and icon name).
- **Package metadata.** A non-empty short description in `apt show` (`deb.synopsis` was missing),
`Section: devel` instead of `default`, a single-line `Comment` in the desktop entry (it was multi-line,
hence invalid), plus `GenericName` and `Keywords` for search.
- **Windows.** Build scripts run on a Windows host again (`npm`/`npx` are `.cmd` shims that
`execFileSync` cannot resolve; the Node extraction used `unzip` and `bash -c cp/rm`, none of which
exist there). The daemon side gained what it needed to actually work: `where.exe` to find the Claude
CLI, PowerShell as the launch shell, a `.cmd` askpass so HTTPS clone/push with a token works, and
`taskkill /T` so stopping a terminal takes its whole process tree down. CI has a `windows-latest` job,
enabled by the `ENABLE_WINDOWS_BUILD` repository variable, see `docs/CI_RUNNERS.md`.
- **Auto-update repaired.** Shipped binaries point at a `desktop-latest` release that never existed, so
no client could ever see an update. The release workflow now recreates that floating release on every
version and attaches the `latest*.yml` files and installers to it, with `.blockmap`s for differential
updates and `SHA256SUMS`.
- **Smaller download.** The bundled Node runtime is pruned to the binary and its licence (no headers, no
docs, no `npm`/`corepack`): ~205 MB → ~118 MB. Nothing at runtime used them, the daemon's dependencies
being installed at build time.
- **macOS integration.** An application menu (without it ⌘C / ⌘V / ⌘A were not bound anywhere in the
app), `app.on('activate')` so the Dock icon brings back a hidden window, and a monochrome template tray
icon that follows the menu-bar theme.
- **PATH enrichment on Windows.** `%LOCALAPPDATA%\Programs` and `%APPDATA%\npm` are added to the daemon's
PATH, where the Claude CLI and global npm binaries live (this was POSIX-only).
## 0.1.3
Ships the 3.3.0 daemon ("Start the project": launch commands and multi-terminal boot).
## 0.1.2
Ships the 3.2.0 daemon (Emerald visual overhaul, light and dark themes).
## 0.1.1
- Fixed the missing window/launcher logo under Debian and Wayland by pinning the runtime app id
(`app.setName('Arboretum')`) to the `StartupWMClass` written in the desktop entry.
## 0.1.0
First desktop release: an Electron shell that runs the daemon as a child process and opens its UI
already authenticated, with a bundled Node runtime, a tray icon, launch-at-login and auto-update.
+51 -13
View File
@@ -15,7 +15,8 @@ not by the main `npm run build`.
2. The daemon mints a fresh token and writes `{token, url}` on file descriptor 3 (private stdio pipe). 2. The daemon mints a fresh token and writes `{token, url}` on file descriptor 3 (private stdio pipe).
3. The shell posts that token to `/api/v1/auth/login` from the window's session (server to server), 3. The shell posts that token to `/api/v1/auth/login` from the window's session (server to server),
which drops the `arb_session` cookie into the session jar, then loads the SPA on `127.0.0.1`. which drops the `arb_session` cookie into the session jar, then loads the SPA on `127.0.0.1`.
4. On quit, the daemon child gets `SIGTERM` (then `SIGKILL` after a grace delay). 4. On quit, the daemon child is asked to stop (`SIGTERM` on POSIX, `taskkill /T` on Windows, which
Windows requires to take the whole process tree down rather than leaving PTY grandchildren behind).
A standalone Node runtime (pinned, >= 22.16) is bundled instead of reusing Electron's Node, so A standalone Node runtime (pinned, >= 22.16) is bundled instead of reusing Electron's Node, so
`node:sqlite` works without a flag and the `node-pty` prebuild keeps the `node.` ABI prefix. `node:sqlite` works without a flag and the `node-pty` prebuild keeps the `node.` ABI prefix.
@@ -56,24 +57,61 @@ Fully supported. `dist:linux` runs on a Linux host or the Gitea CI runner.
### Windows ### Windows
Build on a Windows host (recommended): the `node-pty` win32 native binary and the installer **Must be built on a Windows host.** Cross-building from Linux (including via Wine) does not work, and
(`makensis`) are most reliable there. Cross-building from Linux via Wine is a best-effort fallback. the option has been removed from this document to stop people losing time on it:
The app uses ConPTY (Windows 10 1809+). The installer is not code-signed yet, so SmartScreen shows
- `node-pty`'s `check-prebuild.js` exits successfully as soon as the *host* binary exists, so
`prebuild-install` never runs and no win32 binary is fetched (its published tarball only ships
`prebuilds/linux-*`);
- its `post-install.js` copies `conpty.dll` and `OpenConsole.exe` **only when the build platform is
win32**. Without them there is no ConPTY, hence no terminal at all.
In CI this is a dedicated job on a `windows-latest` runner, enabled by the `ENABLE_WINDOWS_BUILD`
repository variable. Full procedure to register such a runner: [`docs/CI_RUNNERS.md`](../../docs/CI_RUNNERS.md).
The app requires Windows 10 1809+ (ConPTY). The installer is not code-signed, so SmartScreen shows
"unknown publisher": choose "More info" then "Run anyway". "unknown publisher": choose "More info" then "Run anyway".
### macOS (best-effort) ### macOS (best-effort)
Build on a Mac (`dmg`/`zip` cannot be produced elsewhere). The app is **not** signed or notarized, Build on a Mac (`dmg`/`zip` cannot be produced elsewhere); there is no macOS runner, so it is a manual
so Gatekeeper blocks the first launch: right-click the app then "Open", or run step. The app is **not** signed or notarized, so Gatekeeper blocks the first launch: right-click the app
`xattr -dr com.apple.quarantine /Applications/Arboretum.app`. then "Open", or run `xattr -dr com.apple.quarantine /Applications/Arboretum.app`.
## What the shell adds beyond the window
- **Tray icon** (`src/main/tray.ts`): open the window, toggle launch-at-login, quit. On macOS it uses a
monochrome *template* image so it follows the menu-bar theme.
- **Application menu** (`src/main/app-menu.ts`): required on macOS, where without it ⌘C / ⌘V / ⌘A are not
bound anywhere in the app. Closing the window hides it; `app.on('activate')` brings it back from the Dock.
- **Launch at login** (`src/main/autostart.ts`): a `.desktop` file under `~/.config/autostart` on Linux,
`app.setLoginItemSettings` on Windows/macOS.
- **Auto-update** (`src/main/updater.ts`): see below.
- **PATH enrichment** (`src/main/env.ts`): a GUI app starts with a minimal PATH. On POSIX we add
`/usr/local/bin`, `/opt/homebrew/bin`, `~/.local/bin`; on Windows `%LOCALAPPDATA%\Programs` and
`%APPDATA%\npm`, where the Claude CLI and global npm binaries actually live.
## Auto-update ## Auto-update
electron-builder emits `latest*.yml` next to the artifacts; `electron-updater` (wired in a later electron-builder emits `latest*.yml` next to the artifacts and `electron-updater` reads them from a
change) points at the Gitea release assets. Auto-update works for Windows (NSIS) and Linux **floating `desktop-latest` release** on Gitea, which the release workflow recreates on every version
(AppImage); macOS updates are manual while the app is unsigned. (that URL is baked into shipped binaries, so it must always exist). Auto-update covers Windows (NSIS)
and Linux (AppImage); macOS updates are manual while the app is unsigned.
## Icon ## Bundled Node runtime
`resources/icon.png` (square, >= 512px) is the single source; electron-builder derives every `scripts/fetch-node.mjs` downloads a pinned Node (SHA256 verified) and **prunes it** to the binary and
platform icon from it. its licence: headers, docs and `npm`/`corepack` are removed, since the daemon's dependencies are
installed at build time, never at runtime. That takes the embedded runtime from ~205 MB to ~118 MB.
## Icons
Generated by `python3 brand/build-assets.py` from the source logo, into `resources/`:
- `icons/{16,24,32,48,64,128,256,512}x*.png` : the Linux set, at **standard hicolor sizes**. This is not
cosmetic: with a single non-standard size (the old 895×895), the directory is not declared in
`hicolor/index.theme` and the freedesktop spec makes desktops ignore it, so the launcher showed no
icon at all.
- `icon.png` (1024) : macOS source and generic fallback.
- `icon.ico` : Windows (NSIS installer and window).
- `trayTemplate.png` (+`@2x`) : monochrome macOS menu-bar icon.
+54 -6
View File
@@ -21,27 +21,59 @@ extraResources:
to: node to: node
- from: resources/icon.png - from: resources/icon.png
to: icon.png to: icon.png
- from: resources/trayTemplate.png
to: trayTemplate.png
- from: resources/trayTemplate@2x.png
to: trayTemplate@2x.png
# Icône : electron-builder dérive toutes les tailles/formats par OS depuis resources/icon.png # Icônes : générées par `python3 brand/build-assets.py` depuis le logo source.
# (buildResources), pas besoin de .ico/.icns séparés. # - `resources/icons/` : jeu Linux aux TAILLES STANDARD hicolor (16→512). Indispensable : sans lui,
# electron-builder installe l'unique taille du PNG source (895x895), or `hicolor/index.theme` ne
# déclare pas ce répertoire, donc la spécification freedesktop l'ignore et AUCUN logo n'apparaît
# au lanceur (c'était le bug du .deb 0.1.x).
# - `resources/icon.png` (1024) : source macOS et dérivations.
# - `resources/icon.ico` : Windows (installeur NSIS + fenêtre).
linux: linux:
target: [AppImage, deb] target: [AppImage, deb]
category: Development category: Development
icon: resources/icons
# `executableName` explicite : sinon electron-builder le dérive du `name` SCOPÉ du package
# (@arboretum/desktop → « @arboretumdesktop »), qui se retrouvait dans /usr/bin, le .desktop et son
# `Icon=` · un nom d'icône commençant par « @ » n'est pas résoluble.
executableName: arboretum
artifactName: ${productName}-${version}-${arch}.${ext} artifactName: ${productName}-${version}-${arch}.${ext}
synopsis: Self-hosted multi-project AI IDE for git worktrees
# Entrée .desktop (forme plate, mergée telle quelle par electron-builder 25). StartupWMClass DOIT # Entrée .desktop (forme plate, mergée telle quelle par electron-builder 25). StartupWMClass DOIT
# correspondre à l'app_id runtime (posé par app.setName('Arboretum') dans src/main/main.ts) pour # correspondre à l'app_id runtime (posé par app.setName('Arboretum') dans src/main/main.ts) pour
# que GNOME/Wayland associe la fenêtre au lanceur et affiche le logo. Redondant avec le défaut # que GNOME/Wayland associe la fenêtre au lanceur et affiche le logo. Redondant avec le défaut
# (productName) mais explicite et robuste à un futur changement de productName. # (productName) mais explicite et robuste à un futur changement de productName.
desktop: desktop:
StartupWMClass: Arboretum StartupWMClass: Arboretum
# Note : le .deb installe l'icône et rafraîchit le cache (postinst electron-builder). L'AppImage, GenericName: AI IDE for git worktrees
# lui, n'installe aucun .desktop sans intégration (appimaged) : sur Debian, préférer le .deb. Keywords: git;worktree;claude;ide;terminal;
# Pas de `Comment` ici : electron-builder l'écrase systématiquement après la surcharge
# (LinuxTargetHelper : desktopMeta.Comment = deb.description || package.json description). C'est
# donc la description du package.json qui fait foi, et elle DOIT rester sur une seule ligne : un
# texte multi-lignes produirait une entrée .desktop invalide (lignes suivantes lues comme clés).
# Note : avec des tailles standard, GTK/KDE résolvent l'icône même sans cache d'icônes rafraîchi
# (le postinst d'electron-builder n'appelle pas gtk-update-icon-cache). L'AppImage, lui, n'installe
# aucun .desktop sans intégration (appimaged) : sur Debian, préférer le .deb.
deb: deb:
# git est requis pour les operations de worktree ; claude n'est pas dans les depots (documente). # git est requis pour les operations de worktree ; claude n'est pas dans les depots (documente).
depends: [git] depends: [git]
# Mainteneur .deb explicite (electron-builder l'exige ; sinon derive de author.email du package.json). # Mainteneur .deb explicite (electron-builder l'exige ; sinon derive de author.email du package.json).
maintainer: Johan LEROY <contact@johanleroy.fr> maintainer: Johan LEROY <contact@johanleroy.fr>
# `synopsis` alimente la description COURTE du paquet : sans lui, `apt show` affichait une ligne
# vide (electron-builder concatène `synopsis || ''` puis la description longue).
# `synopsis` = description COURTE du paquet : sans elle, `apt show` affichait une ligne vide
# (electron-builder concatène `synopsis || ''` puis la description longue). La description longue
# reste celle du package.json, volontairement sur une seule ligne (cf. note sur Comment ci-dessus).
synopsis: Self-hosted multi-project AI IDE for git worktrees
# electron-builder nomme ce champ `packageCategory` (et non `section`) : il alimente le champ
# Section: du paquet, qui valait « default » jusqu'ici.
packageCategory: devel
priority: optional
win: win:
target: target:
@@ -49,22 +81,38 @@ win:
arch: [x64] arch: [x64]
- target: portable - target: portable
arch: [x64] arch: [x64]
icon: resources/icon.ico
# Affiché par SmartScreen et dans les métadonnées de l'exécutable. Le binaire n'est PAS signé :
# SmartScreen montrera « éditeur inconnu » (documenté dans le README).
publisherName: Johan LEROY
artifactName: ${productName}-${version}-${arch}.${ext} artifactName: ${productName}-${version}-${arch}.${ext}
# Le build portable produit lui aussi un .exe : sans nom distinct, il entrerait en collision avec
# l'installeur NSIS (les deux cibles héritent de `win.artifactName`) et l'un écraserait l'autre.
portable:
artifactName: ${productName}-${version}-${arch}-portable.${ext}
nsis: nsis:
oneClick: false oneClick: false
perMachine: false perMachine: false
allowToChangeInstallationDirectory: true allowToChangeInstallationDirectory: true
shortcutName: Arboretum
uninstallDisplayName: Arboretum ${version}
createDesktopShortcut: true
license: ../../LICENSE
mac: mac:
target: [dmg, zip] target: [dmg, zip]
icon: resources/icon.png
category: public.app-category.developer-tools category: public.app-category.developer-tools
# macOS best-effort : non signe (documente : clic droit -> Ouvrir, ou xattr -dr com.apple.quarantine) # macOS best-effort : non signe (documente : clic droit -> Ouvrir, ou xattr -dr com.apple.quarantine)
identity: null identity: null
hardenedRuntime: false hardenedRuntime: false
# Auto-update (electron-updater, cable en C5) : provider generic pointant sur les assets de release # Auto-update (electron-updater) : provider generic pointant sur un tag FLOTTANT `desktop-latest`,
# Gitea. Genere latest*.yml a cote des artefacts. # que la CI recrée à chaque release en y attachant les installeurs et les `latest*.yml`. Ce tag doit
# exister, sinon l'updater reçoit un 404 (c'était le cas jusqu'en 0.1.3) : voir
# .gitea/workflows/desktop-release.yml, étape « Publish floating desktop-latest release ».
publish: publish:
provider: generic provider: generic
url: https://git.lidge.fr/johanleroy/arboretum/releases/download/desktop-latest url: https://git.lidge.fr/johanleroy/arboretum/releases/download/desktop-latest
+2 -2
View File
@@ -1,12 +1,12 @@
{ {
"name": "@arboretum/desktop", "name": "@arboretum/desktop",
"version": "0.1.1", "version": "0.2.1",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "@arboretum/desktop", "name": "@arboretum/desktop",
"version": "0.1.1", "version": "0.2.1",
"license": "MIT", "license": "MIT",
"devDependencies": { "devDependencies": {
"@types/node": "^22.10.0", "@types/node": "^22.10.0",
+18 -2
View File
@@ -1,9 +1,25 @@
{ {
"name": "@arboretum/desktop", "name": "@arboretum/desktop",
"private": true, "private": true,
"version": "0.1.1", "version": "0.2.1",
"description": "Arboretum desktop app: Electron shell that runs the daemon and shows its web UI", "description": "Self-hosted multi-project AI IDE for git worktrees and Claude Code sessions",
"homepage": "https://git-arboretum.com", "homepage": "https://git-arboretum.com",
"repository": {
"type": "git",
"url": "git+https://git.lidge.fr/johanleroy/arboretum.git"
},
"bugs": {
"url": "https://git.lidge.fr/johanleroy/arboretum/issues"
},
"keywords": [
"arboretum",
"git",
"worktree",
"claude",
"ide",
"electron",
"desktop"
],
"license": "MIT", "license": "MIT",
"author": { "author": {
"name": "Johan LEROY", "name": "Johan LEROY",
Binary file not shown.

After

Width:  |  Height:  |  Size: 48 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 184 KiB

After

Width:  |  Height:  |  Size: 242 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 9.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 650 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 28 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 81 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.7 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 433 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

+42 -6
View File
@@ -2,7 +2,7 @@
// SHA256. Le daemon tourne SUR ce Node (pas celui d'Electron) pour garantir node:sqlite sans flag // SHA256. Le daemon tourne SUR ce Node (pas celui d'Electron) pour garantir node:sqlite sans flag
// et l'ABI node-pty attendue (prefixe `node.`). Options : --platform / --arch (défaut : hôte). // et l'ABI node-pty attendue (prefixe `node.`). Options : --platform / --arch (défaut : hôte).
import { execFileSync } from 'node:child_process'; import { execFileSync } from 'node:child_process';
import { mkdirSync, rmSync, writeFileSync } from 'node:fs'; import { cpSync, existsSync, mkdirSync, readdirSync, rmSync, statSync, writeFileSync } from 'node:fs';
import { createHash } from 'node:crypto'; import { createHash } from 'node:crypto';
import { join, dirname } from 'node:path'; import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url'; import { fileURLToPath } from 'node:url';
@@ -41,9 +41,45 @@ if (expected !== actual) throw new Error(`SHA256 mismatch pour ${name}.${ext}`);
const archive = join(BUILD, `${name}.${ext}`); const archive = join(BUILD, `${name}.${ext}`);
writeFileSync(archive, tarball); writeFileSync(archive, tarball);
if (ext === 'zip') execFileSync('unzip', ['-q', archive, '-d', BUILD], { stdio: 'inherit' }); // `tar` de Windows 10+ (bsdtar) lit aussi les .zip : une seule commande pour les trois plateformes,
else execFileSync('tar', ['-xJf', archive, '-C', BUILD], { stdio: 'inherit' }); // là où `unzip` n'existe pas sur un Windows standard.
// aplatir node-vX-os-arch/ -> build/node/ execFileSync('tar', [ext === 'zip' ? '-xf' : '-xJf', archive, '-C', BUILD], { stdio: 'inherit' });
execFileSync('bash', ['-c', `cp -R "${join(BUILD, name)}/." "${NODE_DIR}/" && rm -rf "${join(BUILD, name)}" "${archive}"`], { stdio: 'inherit' });
console.log(`fetch-node: Node ${NODE_VERSION} (${OS}-${arch}) -> build/node`); // Aplatir node-vX-os-arch/ -> build/node/ avec l'API Node (l'ancien `bash -c 'cp -R … && rm -rf …'`
// rendait ce script inexécutable sur Windows, où il n'y a ni bash, ni cp, ni rm).
const extracted = join(BUILD, name);
cpSync(extracted, NODE_DIR, { recursive: true });
rmSync(extracted, { recursive: true, force: true });
rmSync(archive, { force: true });
// --- élagage ---------------------------------------------------------------------------------
// On n'embarque QUE de quoi exécuter le daemon. La distribution complète pèse ~205 Mo, dont l'essentiel
// est inutile ici : en-têtes de compilation, docs, et surtout npm/corepack (le `npm install --omit=dev`
// du daemon a lieu au BUILD, jamais au runtime).
const PRUNE = ['include', 'share', 'lib', 'CHANGELOG.md', 'README.md'];
for (const rel of PRUNE) rmSync(join(NODE_DIR, rel), { recursive: true, force: true });
// les shims npm/npx/corepack (POSIX : bin/, Windows : racine)
for (const shim of ['npm', 'npx', 'corepack', 'npm.cmd', 'npx.cmd', 'corepack.cmd', 'npm.ps1', 'npx.ps1', 'corepack.ps1']) {
rmSync(join(NODE_DIR, 'bin', shim), { force: true });
rmSync(join(NODE_DIR, shim), { force: true });
}
// Garde-fou : le binaire doit avoir survécu à l'élagage.
const nodeBin = platform === 'win32' ? join(NODE_DIR, 'node.exe') : join(NODE_DIR, 'bin', 'node');
if (!existsSync(nodeBin)) throw new Error(`binaire Node introuvable apres extraction: ${nodeBin}`);
console.log(`fetch-node: Node ${NODE_VERSION} (${OS}-${arch}) -> build/node (${duMb(NODE_DIR)} Mo)`);
/** Taille approximative d'un dossier, en Mo (diagnostic de l'élagage). */
function duMb(dir) {
let total = 0;
const walk = (d) => {
for (const entry of readdirSync(d, { withFileTypes: true })) {
const p = join(d, entry.name);
if (entry.isDirectory()) walk(p);
else if (entry.isFile()) total += statSync(p).size;
}
};
walk(dir);
return Math.round(total / 1024 / 1024);
}
+5 -1
View File
@@ -20,8 +20,12 @@ const arg = (name) => args.find((a) => a.startsWith(`--${name}=`))?.split('=')[1
const platform = arg('platform'); const platform = arg('platform');
const arch = arg('arch'); const arch = arg('arch');
// Sur Windows, `npm`/`npx` sont des shims `.cmd` : `execFileSync` ne les résout pas (ENOENT), il faut
// leur nom complet. Sans ça, tout le chemin de build documenté échouait sur un hôte Windows.
const winShim = (cmd) => (process.platform === 'win32' && (cmd === 'npm' || cmd === 'npx') ? `${cmd}.cmd` : cmd);
const run = (cmd, cmdArgs, cwd, env) => const run = (cmd, cmdArgs, cwd, env) =>
execFileSync(cmd, cmdArgs, { cwd, stdio: 'inherit', env: { ...process.env, ...env } }); execFileSync(winShim(cmd), cmdArgs, { cwd, stdio: 'inherit', env: { ...process.env, ...env } });
rmSync(SERVER_DIR, { recursive: true, force: true }); rmSync(SERVER_DIR, { recursive: true, force: true });
mkdirSync(SERVER_DIR, { recursive: true }); mkdirSync(SERVER_DIR, { recursive: true });
+82
View File
@@ -0,0 +1,82 @@
import { app, Menu, shell, type MenuItemConstructorOptions } from 'electron';
/**
* Menu applicatif. Sur macOS il n'est PAS optionnel : sans lui, aucun raccourci d'édition n'est
* enregistré et ⌘C / ⌘V / ⌘A / ⌘Z ne fonctionnent nulle part dans l'app (y compris dans les terminaux
* et l'éditeur). Sur Linux/Windows on garde un menu minimal, masqué par défaut (`setMenuBarVisibility`
* côté fenêtre) mais qui enregistre quand même les accélérateurs standard.
*/
export function installAppMenu(opts: { url: string; onQuit: () => void }): void {
const isMac = process.platform === 'darwin';
const macAppMenu: MenuItemConstructorOptions[] = isMac
? [
{
label: app.name,
submenu: [
{ role: 'about' },
{ type: 'separator' },
{ role: 'hide' },
{ role: 'hideOthers' },
{ role: 'unhide' },
{ type: 'separator' },
{ label: 'Quit Arboretum', accelerator: 'Command+Q', click: opts.onQuit },
],
},
]
: [];
const template: MenuItemConstructorOptions[] = [
...macAppMenu,
{
label: 'File',
submenu: isMac ? [{ role: 'close' }] : [{ label: 'Quit', accelerator: 'Ctrl+Q', click: opts.onQuit }],
},
{
label: 'Edit',
submenu: [
{ role: 'undo' },
{ role: 'redo' },
{ type: 'separator' },
{ role: 'cut' },
{ role: 'copy' },
{ role: 'paste' },
{ role: 'selectAll' },
],
},
{
label: 'View',
submenu: [
{ role: 'reload' },
{ role: 'forceReload' },
{ type: 'separator' },
{ role: 'resetZoom' },
{ role: 'zoomIn' },
{ role: 'zoomOut' },
{ type: 'separator' },
{ role: 'togglefullscreen' },
{ role: 'toggleDevTools' },
],
},
{
label: 'Window',
submenu: isMac ? [{ role: 'minimize' }, { role: 'zoom' }, { type: 'separator' }, { role: 'front' }] : [{ role: 'minimize' }],
},
{
role: 'help',
submenu: [
{ label: 'Open in browser', click: () => void shell.openExternal(opts.url) },
{ label: 'Website', click: () => void shell.openExternal('https://git-arboretum.com') },
],
},
];
Menu.setApplicationMenu(Menu.buildFromTemplate(template));
app.setAboutPanelOptions({
applicationName: 'Arboretum',
applicationVersion: app.getVersion(),
copyright: 'Copyright © 2026 Johan Leroy',
website: 'https://git-arboretum.com',
});
}
+22 -2
View File
@@ -6,10 +6,30 @@ import { homedir } from 'node:os';
// `claude`. Le réglage `claude_bin_path` (UI) reste le filet de secours. // `claude`. Le réglage `claude_bin_path` (UI) reste le filet de secours.
export function buildChildEnv(extra: Record<string, string>): NodeJS.ProcessEnv { export function buildChildEnv(extra: Record<string, string>): NodeJS.ProcessEnv {
const env: NodeJS.ProcessEnv = { ...process.env, ...extra }; const env: NodeJS.ProcessEnv = { ...process.env, ...extra };
if (process.platform !== 'win32') { const extras = pathExtras(process.platform, env);
const extras = ['/usr/local/bin', '/opt/homebrew/bin', join(homedir(), '.local', 'bin'), '/usr/bin', '/bin']; if (extras.length > 0) {
const current = env.PATH ? env.PATH.split(delimiter) : []; const current = env.PATH ? env.PATH.split(delimiter) : [];
env.PATH = [...new Set([...extras, ...current])].join(delimiter); env.PATH = [...new Set([...extras, ...current])].join(delimiter);
} }
return env; return env;
} }
/**
* Répertoires à ajouter au PATH du daemon, par plateforme. Windows était entièrement ignoré : or
* l'installeur natif de Claude Code se pose dans %LOCALAPPDATA%\Programs et npm global dans
* %APPDATA%\npm, deux emplacements absents du PATH d'une app lancée depuis le menu Démarrer.
*/
export function pathExtras(platform: NodeJS.Platform, env: NodeJS.ProcessEnv = process.env): string[] {
const home = env.USERPROFILE ?? homedir();
if (platform === 'win32') {
const local = env.LOCALAPPDATA ?? join(home, 'AppData', 'Local');
const roaming = env.APPDATA ?? join(home, 'AppData', 'Roaming');
return [
join(local, 'Programs'),
join(local, 'Programs', 'claude'),
join(roaming, 'npm'),
join(home, '.local', 'bin'),
];
}
return ['/usr/local/bin', '/opt/homebrew/bin', join(home, '.local', 'bin'), '/usr/bin', '/bin'];
}
+6
View File
@@ -4,6 +4,7 @@ import { startDaemon, type DaemonHandle } from './daemon';
import { seedSessionCookie } from './auth'; import { seedSessionCookie } from './auth';
import { loadWindowState, saveWindowState } from './window-state'; import { loadWindowState, saveWindowState } from './window-state';
import { createTray } from './tray'; import { createTray } from './tray';
import { installAppMenu } from './app-menu';
import { initUpdater } from './updater'; import { initUpdater } from './updater';
import { resolveIconPath } from './paths'; import { resolveIconPath } from './paths';
@@ -39,10 +40,15 @@ async function bootstrap(): Promise<void> {
daemon = await startDaemon({ dataDir, port: PORT, onLog: (l) => process.stdout.write(l) }); daemon = await startDaemon({ dataDir, port: PORT, onLog: (l) => process.stdout.write(l) });
await seedSessionCookie(PARTITION, daemon.url, daemon.token); await seedSessionCookie(PARTITION, daemon.url, daemon.token);
createWindow(daemon.url); createWindow(daemon.url);
installAppMenu({ url: daemon.url, onQuit: quitApp });
tray = createTray({ show: showWindow, quit: quitApp }); tray = createTray({ show: showWindow, quit: quitApp });
initUpdater(); initUpdater();
} }
// macOS : la fenêtre est cachée (pas détruite) à la fermeture. Sans ce handler, cliquer l'icône du
// Dock ne la ramenait jamais et l'app paraissait bloquée en arrière-plan.
app.on('activate', showWindow);
function showWindow(): void { function showWindow(): void {
if (!win) return; if (!win) return;
if (win.isMinimized()) win.restore(); if (win.isMinimized()) win.restore();
+14
View File
@@ -1,5 +1,6 @@
import { app } from 'electron'; import { app } from 'electron';
import { join } from 'node:path'; import { join } from 'node:path';
import { existsSync } from 'node:fs';
// Résolution des chemins runtime : dev (depuis le repo) vs packagé (extraResources). // Résolution des chemins runtime : dev (depuis le repo) vs packagé (extraResources).
// __dirname pointe sur dist/ (bundle esbuild) une fois construit. // __dirname pointe sur dist/ (bundle esbuild) une fois construit.
@@ -23,6 +24,19 @@ export function resolveIconPath(): string {
: join(__dirname, '..', 'resources', 'icon.png'); : join(__dirname, '..', 'resources', 'icon.png');
} }
/**
* Icône de barre système. macOS exige une image « template » (monochrome) dans la barre de menus ;
* ailleurs on retombe sur le logo couleur. `null` si l'asset n'est pas présent (build sans
* régénération des icônes) : l'appelant utilise alors resolveIconPath().
*/
export function resolveTrayIconPath(): string | null {
if (process.platform !== 'darwin') return null;
const path = app.isPackaged
? join(process.resourcesPath, 'trayTemplate.png')
: join(__dirname, '..', 'resources', 'trayTemplate.png');
return existsSync(path) ? path : null;
}
/** Binaire Node qui exécute le daemon (>= 22.16 : node:sqlite + ABI node-pty maîtrisé). */ /** Binaire Node qui exécute le daemon (>= 22.16 : node:sqlite + ABI node-pty maîtrisé). */
export function resolveNodeBin(): string { export function resolveNodeBin(): string {
if (app.isPackaged) { if (app.isPackaged) {
+9 -3
View File
@@ -1,11 +1,17 @@
import { Menu, Tray, nativeImage } from 'electron'; import { Menu, Tray, nativeImage } from 'electron';
import { isAutoStartEnabled, setAutoStart } from './autostart'; import { isAutoStartEnabled, setAutoStart } from './autostart';
import { resolveIconPath } from './paths'; import { resolveIconPath, resolveTrayIconPath } from './paths';
/** Icône de barre système : ouvrir la fenêtre, basculer le lancement au login, quitter. */ /** Icône de barre système : ouvrir la fenêtre, basculer le lancement au login, quitter. */
export function createTray(opts: { show: () => void; quit: () => void }): Tray { export function createTray(opts: { show: () => void; quit: () => void }): Tray {
const image = nativeImage.createFromPath(resolveIconPath()); // macOS exige une image TEMPLATE (monochrome + alpha) dans la barre de menus : elle s'inverse
const tray = new Tray(image.isEmpty() ? nativeImage.createEmpty() : image.resize({ width: 18, height: 18 })); // automatiquement selon le thème système. Une icône couleur y est illisible. Windows attend 16px.
const trayPath = resolveTrayIconPath() ?? resolveIconPath();
const raw = nativeImage.createFromPath(trayPath);
const size = process.platform === 'darwin' ? 16 : process.platform === 'win32' ? 16 : 18;
const image = raw.isEmpty() ? nativeImage.createEmpty() : raw.resize({ width: size, height: size });
if (process.platform === 'darwin' && !image.isEmpty()) image.setTemplateImage(true);
const tray = new Tray(image);
tray.setToolTip('Arboretum'); tray.setToolTip('Arboretum');
const buildMenu = (): void => { const buildMenu = (): void => {
+73
View File
@@ -3,6 +3,79 @@
Notable changes to `@johanleroy/git-arboretum` (the Arboretum daemon). The VS Code Notable changes to `@johanleroy/git-arboretum` (the Arboretum daemon). The VS Code
extension keeps its own changelog in `packages/vscode/CHANGELOG.md`. extension keeps its own changelog in `packages/vscode/CHANGELOG.md`.
## 3.5.0
Fixes a black screen after every update, gives the web terminal a working copy & paste, and lets you
browse a group's files without leaving the Groups panel. Fully additive, no protocol version bump.
- **No more black screen after an update.** The embedded SPA is served by `@fastify/static`, whose weak
etag derives from size + mtime, and `npm pack` pins the mtime of every file in the tarball to a
constant (1985-10-26). Two different `index.html` of equal size therefore shared an etag: clients got a
`304 Not Modified` and kept an index referencing `/assets/<hash>` files that no longer existed. The
fallback route then answered those module requests with `index.html` as `text/html`, the browser
refused the script, and nothing painted. `index.html` and every other unhashed file are now served
`no-store` with conditional validation disabled, so a client holding a stale copy repairs itself;
hashed `/assets/` are served `immutable` for a year.
- **Copy & paste in the terminal.** xterm's selection is not a DOM selection, so the native Copy (the
Electron Edit menu, the browser context menu) had nothing to copy and terminal output could not be
retrieved at all. `Ctrl+Shift+C` / `Ctrl+Shift+V` (`Cmd+C` / `Cmd+V` on macOS, plus
`Ctrl+Insert` / `Shift+Insert`) now copy the selection and paste the clipboard, and the DOM `copy`
event is intercepted so the native Copy works too. `Ctrl+C` is deliberately untouched: it stays SIGINT.
- **Theme applied before the first paint again.** The anti-FOUC script was inline in `index.html`, which
the daemon's own CSP (`script-src 'self'`) refused to execute; it moved to `/theme-boot.js`.
- **Browse files from the Groups panel.** A group's worktrees expand into their file tree, the same
component and the same expansion state as the Explorer, and those worktrees are now watched for
real-time changes too.
- **Sources are text again.** Three files embedded a literal NUL byte in a string separator, which made
git and grep treat them as binary: their diffs were unreviewable and the `lint-dashes` CI guard
(`git grep -I`) silently skipped them. Escaped as `\0`, same runtime value.
## 3.4.0
Visibility release: the real-time machinery is now actually armed, worktrees show what they are worth,
and history is served. Fully additive, no protocol version bump.
- **Real-time that no longer depends on which panel is open.** A live session now pins the FS watcher of
its worktree, so a worktree an agent is writing into refreshes on its own even when nobody is looking at
it (`pinSession` existed but was never called). On the client side, `watch` subscriptions moved out of
the Git panel, which was unmounted as soon as you left its tab, taking the app's only subscription with
it; they now follow what you actually look at (active worktree plus expanded repositories).
- **Reconnection no longer loses state.** The protocol replays nothing, so every event missed during a
WebSocket outage was lost for good. The client reloads repos, worktrees, sessions and settings whenever
the connection comes back.
- **Session correlation by containment.** A terminal started in a *subdirectory* of a worktree (which
"Start the project" allows) and a group session covering a worktree through `--add-dir` are now listed
under that worktree, instead of vanishing from the tree. The rule lives in `@arboretum/shared`, shared by
the daemon, the web UI and the VS Code extension; the most specific worktree wins.
- **History API.** `GET /api/v1/repos/:id/worktrees/log` serves the branch commits with the count of
unpushed ones, and `GET .../worktrees/diff?commit=<hash>` the full diff of a commit (hash strictly
validated, same size limits as file diffs). The UI unfolds them in place under the Git panel.
- **Full git counters where they matter.** `ahead`/`behind`, staged, unstaged and conflict counts were
only visible in the status bar, for the active worktree. They are now on every worktree row of the tree
and of the Groups panel, with upstream and last commit in the tooltip. `locked`, `prunable` and an
invalid repository are surfaced too.
- **Groups show their composition.** A group lists its repositories with their worktrees and git state,
its sessions (live and recent) and the directories a group session spans. Its colour tints those repos
in the explorer.
- **Actionable `403 BAD_ORIGIN`.** The error now names the exact `--allow-origin` flag to add, and logs
it. It is the first wall of any LAN or reverse-proxy access.
- **Windows support in the daemon.** `where.exe` for CLI discovery, PowerShell as the project launch
shell, a `.cmd` askpass so token-based HTTPS clone/push works, `taskkill /T` for process-tree
termination, `%APPDATA%` for the data directory, and `arboretum install` registering a scheduled task.
- **UI fixes.** Error toasts were painted behind modals (they are sticky, so they piled up invisible);
on mobile, opening a terminal or switching activity had no visible effect; the dock could push the
status bar out of the viewport; panels showed "nothing here" instead of a loading or error state;
modals had no dialog role, focus trap or focus restore; the splitters are now keyboard operable; diff
line numbers stay pinned while scrolling.
## 3.3.0
"Start the project": boot a project's long-running commands (dev server, API, database) in one click. Fully additive, no protocol or API change.
- **Launch commands per repo.** A repo now carries reusable start commands (label, shell command, optional subdirectory), persisted as JSON and edited from the dashboard. They can be auto-detected from `package.json` scripts, a `Procfile` or a `docker-compose` file.
- **One terminal per command.** `POST /api/v1/repos/:id/launch` resolves the target worktree server-side (the client never passes a raw path) and opens one managed terminal per enabled command, all sharing a launch run id so you can stop the whole set in one action. Each command runs in your interactive login shell (so `npm`, `docker`, nvm/asdf are on `PATH`) and the shell stays live after the command exits, keeping failures on screen.
- **Surfaces.** Start a project from a repo or worktree menu, the sessions panel or the command palette. The VS Code extension exposes it too (see its changelog).
## 3.2.0 ## 3.2.0
Visual overhaul: the web UI adopts the "Emerald" design system and gains a full theme system. No protocol or API change (fully additive, backward compatible). Visual overhaul: the web UI adopts the "Emerald" design system and gains a full theme system. No protocol or API change (fully additive, backward compatible).
+2 -2
View File
@@ -1,7 +1,7 @@
{ {
"name": "@johanleroy/git-arboretum", "name": "@johanleroy/git-arboretum",
"version": "3.2.0", "version": "3.5.0",
"description": "Self-hosted web dashboard for git worktrees and the Claude Code sessions running on them", "description": "Self-hosted multi-project AI IDE for git worktrees and the Claude Code sessions running on them",
"license": "MIT", "license": "MIT",
"type": "module", "type": "module",
"author": "Johan LEROY <contact@johanleroy.fr>", "author": "Johan LEROY <contact@johanleroy.fr>",
+202
View File
@@ -0,0 +1,202 @@
#!/usr/bin/env node
// Acceptation P13 (sans navigateur, sans quota Claude) : « Démarrer le projet » (lancement
// multi-terminaux). Vrai daemon + vrai repo git tmp + vrai client WS. Couvre : exposition/persistance
// de launch_commands (+ broadcast repo_update), auto-détection (package.json/Procfile/compose),
// lancement d'un terminal par commande activée (même launchRunId, command bash, titre = label),
// auto-type réellement exécuté (marqueur dans le ring) dans un shell INTERACTIF (survit à la commande),
// bornage anti-traversal du cwd + sous-dossier valide, sélection par commandIds, filtrage des désactivées,
// et « tout arrêter ».
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, mkdirSync, rmSync, writeFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import { createRequire } from 'node:module';
const require = createRequire(import.meta.url);
const WebSocket = require('ws');
const PORT = 7553;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p13-'));
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
mkdirSync(join(repo, 'sub'), { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
// Fichiers pour l'auto-détection.
writeFileSync(join(repo, 'package.json'), JSON.stringify({ scripts: { dev: 'echo dev', build: 'echo build', test: 'echo test' } }));
writeFileSync(join(repo, 'Procfile'), 'web: echo procweb\n');
writeFileSync(join(repo, 'docker-compose.yml'), 'services: {}\n');
writeFileSync(join(repo, 'README.md'), '# demo\n');
git('add', '-A');
git('commit', '-m', 'init');
const srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
// Client WS multiplexé (contrôle JSON + sortie binaire → ring décodé en latin1).
function wsClient(cookie) {
const ws = new WebSocket(`ws://127.0.0.1:${PORT}/ws`, { headers: { Origin: ORIGIN, Cookie: cookie } });
ws.binaryType = 'arraybuffer';
const state = { msgs: [], outputs: new Map() };
ws.on('message', (data, isBinary) => {
if (!isBinary) {
state.msgs.push(JSON.parse(String(data)));
return;
}
const buf = Buffer.from(data);
const type = buf.readUInt8(0);
const channel = buf.readUInt32LE(1);
const payload = buf.subarray(5);
if (type === 0x02) state.outputs.set(channel, payload.toString('latin1'));
else state.outputs.set(channel, ((state.outputs.get(channel) ?? '') + payload.toString('latin1')).slice(-200000));
});
const waitMsg = async (pred, timeout = 8000) => {
const t0 = Date.now();
while (Date.now() - t0 < timeout) {
const m = state.msgs.find(pred);
if (m) return m;
await sleep(50);
}
return null;
};
return { ws, state, waitMsg, send: (m) => ws.send(JSON.stringify(m)) };
}
const j = (path, method, cookie, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
try {
await sleep(1500);
const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0];
check('boot + token bootstrap', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? '';
check('login → cookie', login.status === 200 && cookie.startsWith('arb_session='));
// Enregistre le repo.
const reg = await j('/api/v1/repos', 'POST', cookie, { path: repo });
const repoId = (await reg.json()).repo?.id;
check('register repo', reg.status === 201 && !!repoId);
// launchCommands vide par défaut.
const list0 = await (await j('/api/v1/repos', 'GET', cookie)).json();
const r0 = list0.repos.find((r) => r.id === repoId);
check('launchCommands défaut = []', Array.isArray(r0?.launchCommands) && r0.launchCommands.length === 0);
// Auto-détection.
const det = await (await j(`/api/v1/repos/${repoId}/launch/detect`, 'GET', cookie)).json();
const runs = (det.suggestions ?? []).map((s) => s.run);
check(
'detect : package.json + Procfile + docker-compose',
runs.includes('npm run dev') && runs.includes('npm run build') && runs.some((r) => r.startsWith('echo procweb')) && runs.includes('docker compose up'),
`${runs.length} suggestions`,
);
check('detect : dev activé, build désactivé (heuristique)', (det.suggestions.find((s) => s.run === 'npm run dev')?.enabled === true) && (det.suggestions.find((s) => s.run === 'npm run build')?.enabled === false));
// Abonnement worktrees pour vérifier le broadcast repo_update.
const c1 = wsClient(cookie);
await new Promise((res, rej) => (c1.ws.on('open', res), c1.ws.on('error', rej)));
c1.send({ type: 'hello', protocol: 1 });
await c1.waitMsg((m) => m.type === 'hello_ok');
c1.send({ type: 'sub', topics: ['worktrees', 'sessions'] });
await sleep(200);
const nonce = String(token).slice(-6);
const commands = [
{ id: 'c-web', label: 'web', run: `echo ARB_LAUNCH_OK_${nonce}; echo ARB_FLAGS_$-; sleep 30`, enabled: true },
{ id: 'c-api', label: 'api', run: 'sleep 30', enabled: true },
{ id: 'c-build', label: 'build', run: 'echo SHOULD_NOT_RUN', enabled: false },
{ id: 'c-sub', label: 'sub', run: 'pwd; sleep 30', cwd: 'sub', enabled: false },
{ id: 'c-esc', label: 'esc', run: 'pwd', cwd: '../../etc', enabled: false },
];
const patch = await j(`/api/v1/repos/${repoId}`, 'PATCH', cookie, { launchCommands: commands });
const patched = (await patch.json()).repo;
check('PATCH launchCommands persiste', patch.status === 200 && patched.launchCommands.length === 5);
const evt = await c1.waitMsg((m) => m.type === 'repo_update' && m.repo?.id === repoId && (m.repo.launchCommands?.length ?? 0) === 5);
check('broadcast repo_update porte launchCommands', !!evt);
// Lancement par défaut (commandes activées : web, api).
const launch = await j(`/api/v1/repos/${repoId}/launch`, 'POST', cookie, {});
const lr = await launch.json();
check('POST /launch → N sessions (activées only)', launch.status === 201 && lr.sessions?.length === 2, `${lr.sessions?.length} sessions`);
const runIds = new Set(lr.sessions.map((s) => s.launchRunId));
check('même launchRunId sur tous les terminaux', runIds.size === 1 && [...runIds][0], [...runIds][0]);
check('command = bash + titre = label', lr.sessions.every((s) => s.command === 'bash') && lr.sessions.map((s) => s.title).sort().join(',') === 'api,web');
const launchRunId = [...runIds][0];
// Attache au terminal « web » → l'auto-type a été exécuté (marqueur) dans un shell INTERACTIF.
const webSid = lr.sessions.find((s) => s.title === 'web').id;
c1.send({ type: 'attach', sessionId: webSid, mode: 'interactive', cols: 120, rows: 32 });
const att = await c1.waitMsg((m) => m.type === 'attached' && m.sessionId === webSid);
await sleep(1200);
const out = c1.state.outputs.get(att.channel) ?? '';
check('auto-type exécuté (marqueur dans le ring)', out.includes(`ARB_LAUNCH_OK_${nonce}`), `${out.length} o`);
check('shell interactif (flags $- contiennent i)', /ARB_FLAGS_[a-zA-Z]*i/.test(out));
// Le shell survit à la commande (sleep encore vivant).
const sess1 = await (await j('/api/v1/sessions', 'GET', cookie)).json();
const apiSid = lr.sessions.find((s) => s.title === 'api').id;
check('shell survivant (session live)', sess1.sessions.find((s) => s.id === apiSid)?.live === true);
// Sélection par commandIds (web seul).
const one = await (await j(`/api/v1/repos/${repoId}/launch`, 'POST', cookie, { commandIds: ['c-web'] })).json();
check('commandIds : sous-ensemble', one.sessions?.length === 1 && one.sessions[0].title === 'web');
// Sous-dossier valide : pwd sous le worktree.
const subRes = await (await j(`/api/v1/repos/${repoId}/launch`, 'POST', cookie, { commandIds: ['c-sub'] })).json();
const subSid = subRes.sessions?.[0]?.id;
c1.send({ type: 'attach', sessionId: subSid, mode: 'interactive', cols: 120, rows: 32 });
const attSub = await c1.waitMsg((m) => m.type === 'attached' && m.sessionId === subSid);
await sleep(800);
check('cwd sous-dossier borné (pwd dans /sub)', (c1.state.outputs.get(attSub.channel) ?? '').includes('/sub'));
// Traversal rejeté : cwd ../../etc.
const esc = await j(`/api/v1/repos/${repoId}/launch`, 'POST', cookie, { commandIds: ['c-esc'] });
check('cwd traversal rejeté (4xx)', esc.status >= 400 && esc.status < 500, `status ${esc.status}`);
// « Tout arrêter » : kill de tous les terminaux du launchRunId initial.
const before = (await (await j('/api/v1/sessions', 'GET', cookie)).json()).sessions.filter((s) => s.launchRunId === launchRunId);
for (const s of before) await j(`/api/v1/sessions/${s.id}`, 'DELETE', cookie);
// Un shell interactif ignore SIGTERM (standard) → mort garantie au SIGKILL après le délai de grâce (~5 s).
await sleep(6500);
const after = (await (await j('/api/v1/sessions', 'GET', cookie)).json()).sessions.filter((s) => s.launchRunId === launchRunId);
check('tout arrêter → terminaux non vivants', before.length === 2 && after.length === 2 && after.every((s) => !s.live));
c1.ws.close();
} catch (err) {
check('exception', false, String(err && err.stack ? err.stack : err));
} finally {
srv.kill('SIGTERM');
await sleep(1500);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? '\nACCEPTANCE P13: ALL GREEN' : `\nACCEPTANCE P13: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
+174
View File
@@ -0,0 +1,174 @@
#!/usr/bin/env node
// Acceptation P14 (sans navigateur, sans quota Claude) : temps réel « armé ». Vrai daemon + vrai repo
// git tmp + vrai client WS. Couvre les trois trous de visibilité corrigés :
// 1. une session vivante épingle le watcher FS de SON worktree → les compteurs git d'un worktree
// secondaire restent temps réel même si AUCUN client ne le regarde (avant : point « modifié » figé
// sur le dernier listing REST) ;
// 2. corrélation par contenance : un terminal lancé dans un SOUS-répertoire du worktree y est
// rattaché (« Démarrer le projet »), et pas au checkout principal ;
// 3. `watch` explicite → `worktree_changes` ciblé sur ce worktree secondaire.
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, rmSync, writeFileSync, mkdirSync, appendFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import { createRequire } from 'node:module';
const require = createRequire(import.meta.url);
const WebSocket = require('ws');
const PORT = 7554;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p14-'));
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
mkdirSync(join(repo, 'packages', 'api'), { recursive: true });
writeFileSync(join(repo, 'README.md'), '# demo\n');
writeFileSync(join(repo, 'packages', 'api', 'index.js'), 'console.log(1)\n');
git('add', '-A');
git('commit', '-m', 'init');
const srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
function wsClient(cookie) {
const ws = new WebSocket(`ws://127.0.0.1:${PORT}/ws`, { headers: { Origin: ORIGIN, Cookie: cookie } });
const state = { msgs: [] };
ws.on('message', (data, isBinary) => {
if (!isBinary) state.msgs.push(JSON.parse(String(data)));
});
const waitMsg = async (pred, timeout = 8000) => {
const t0 = Date.now();
while (Date.now() - t0 < timeout) {
const m = state.msgs.find(pred);
if (m) return m;
await sleep(50);
}
return null;
};
return { ws, state, waitMsg, send: (m) => ws.send(JSON.stringify(m)) };
}
const j = (path, method, cookie, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
try {
await sleep(1500);
const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0];
check('boot + token bootstrap', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? '';
check('login → cookie', login.status === 200);
const c = wsClient(cookie);
await new Promise((res, rej) => (c.ws.on('open', res), c.ws.on('error', rej)));
c.send({ type: 'hello', protocol: 1 });
await c.waitMsg((m) => m.type === 'hello_ok');
c.send({ type: 'sub', topics: ['worktrees', 'sessions'] });
const addRepo = await j('/api/v1/repos', 'POST', cookie, { path: repo });
const repoId = (await addRepo.json()).repo.id;
check('POST /repos → 201', addRepo.status === 201 && !!repoId);
// ---- worktree secondaire (feature) avec un sous-répertoire ----
const created = await j(`/api/v1/repos/${repoId}/worktrees`, 'POST', cookie, { branch: 'feature/live', runHooks: false });
const wtPath = (await created.json()).worktree?.path;
check('POST /worktrees → worktree secondaire créé', created.status === 201 && !!wtPath);
const subDir = join(wtPath, 'packages', 'api');
// ---- 2. corrélation par contenance : session lancée DANS un sous-répertoire ----
const sess = await j('/api/v1/sessions', 'POST', cookie, { cwd: subDir, command: 'bash' });
const session = (await sess.json()).session;
check('POST /sessions (cwd = sous-répertoire) → 201', sess.status === 201 && !!session?.id);
await sleep(600);
const list = await (await j('/api/v1/worktrees', 'GET', cookie)).json();
const secondary = (list.worktrees ?? []).find((w) => w.path === wtPath);
const main = (list.worktrees ?? []).find((w) => w.isMain);
check(
'la session du sous-répertoire est rattachée au worktree secondaire',
(secondary?.sessions ?? []).some((s) => s.id === session.id),
`sessions=${(secondary?.sessions ?? []).length}`,
);
check(
'elle n’est PAS rattachée au checkout principal (désambiguïsation)',
!(main?.sessions ?? []).some((s) => s.id === session.id),
);
// ---- 1. session vivante → watcher épinglé SANS aucun watch client ----
// Aucun `watch` n'a été envoyé : seul `pinSession` peut produire cet événement.
await sleep(900); // laisse chokidar finir son scan initial
c.state.msgs.length = 0;
const t0 = Date.now();
appendFileSync(join(wtPath, 'README.md'), 'edited by the agent\n');
const upd = await c.waitMsg((m) => m.type === 'worktree_update' && m.worktree?.path === wtPath && m.worktree?.git?.dirtyCount > 0, 6000);
check('worktree secondaire non regardé : worktree_update reçu (pinSession)', !!upd, upd ? `${Date.now() - t0}ms` : 'timeout');
check('les compteurs git du worktree secondaire sont frais', (upd?.worktree?.git?.unstagedCount ?? 0) >= 1);
// ---- pas de worktree_changes sans watch (le détail reste ciblé) ----
const changesWithoutWatch = c.state.msgs.find((m) => m.type === 'worktree_changes');
check('sans watch : aucun worktree_changes (push ciblé préservé)', !changesWithoutWatch);
// ---- 3. watch explicite → worktree_changes ciblé ----
c.send({ type: 'watch', repoId, path: wtPath });
await sleep(900);
c.state.msgs.length = 0;
writeFileSync(join(wtPath, 'live.txt'), 'live\n');
const changesMsg = await c.waitMsg((m) => m.type === 'worktree_changes' && m.path === wtPath, 6000);
check('watch → worktree_changes ciblé sur le worktree secondaire', !!changesMsg);
c.send({ type: 'unwatch', repoId, path: wtPath });
await j(`/api/v1/sessions/${session.id}`, 'DELETE', cookie);
await sleep(500);
// ---- contraposée : le temps réel reste PILOTÉ (ni session, ni watch → pas de surveillance) ----
// Un watcher déjà ouvert est volontairement conservé en cache (évincé par la LRU) : on vérifie donc
// sur un worktree neuf, jamais épinglé ni regardé, qu'aucun événement n'est émis.
const idle = await j(`/api/v1/repos/${repoId}/worktrees`, 'POST', cookie, { branch: 'feature/idle', runHooks: false });
const idlePath = (await idle.json()).worktree?.path;
check('POST /worktrees → second worktree (sans session)', idle.status === 201 && !!idlePath);
await sleep(700);
c.state.msgs.length = 0;
writeFileSync(join(idlePath, 'unwatched.txt'), 'x\n');
const idleMsg = await c.waitMsg((m) => m.type === 'worktree_update' && m.worktree?.path === idlePath, 2500);
check('worktree sans session ni watch → aucune surveillance (coût piloté par l’attention)', !idleMsg);
c.ws.close();
} catch (err) {
check('exception', false, String(err));
} finally {
srv.kill('SIGTERM');
await sleep(1500);
check('arrêt propre du daemon (SIGTERM)', srv.exitCode === 0 || srv.signalCode === null || srv.exitCode === null);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? '\nACCEPTANCE P14: ALL GREEN' : `\nACCEPTANCE P14: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
+117
View File
@@ -0,0 +1,117 @@
#!/usr/bin/env node
// Acceptation P15 (sans navigateur, sans quota Claude) : historisation. Vrai daemon + vrai repo git
// tmp. Couvre GET /worktrees/log (ordre, champs, limit/skip, marquage non poussé) et la forme
// `diff?commit=` (diff unifié complet d'un commit, hash invalide et inconnu rejetés).
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, rmSync, writeFileSync, appendFileSync, mkdirSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
const PORT = 7555;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p15-'));
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
writeFileSync(join(repo, 'README.md'), '# demo\n');
git('add', '-A');
git('commit', '-m', 'init');
// un sujet contenant un guillemet et un caractère accentué : piège classique de parsing
appendFileSync(join(repo, 'README.md'), 'deuxième ligne\n');
git('commit', '-am', 'ajoute la « deuxième » ligne');
writeFileSync(join(repo, 'feature.txt'), 'contenu de la feature\n');
git('add', '-A');
git('commit', '-m', 'ajoute feature.txt');
const srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
const j = (path, method, cookie, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
try {
await sleep(1500);
const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0];
check('boot + token bootstrap', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? '';
check('login → cookie', login.status === 200);
const addRepo = await j('/api/v1/repos', 'POST', cookie, { path: repo });
const repoId = (await addRepo.json()).repo.id;
check('POST /repos → 201', addRepo.status === 201 && !!repoId);
const enc = encodeURIComponent(repo);
// ---- GET /log : ordre, champs, sujet non trivial ----
const log = await (await j(`/api/v1/repos/${repoId}/worktrees/log?path=${enc}`, 'GET', cookie)).json();
const subjects = (log.commits ?? []).map((c) => c.subject);
check('GET /log : 3 commits, du plus récent au plus ancien', subjects.length === 3 && subjects[0] === 'ajoute feature.txt' && subjects[2] === 'init');
check('GET /log : sujet accentué et guillemets préservés', subjects[1] === 'ajoute la « deuxième » ligne');
const head = log.commits?.[0];
check('GET /log : champs hash/shortHash/auteur/date remplis', /^[0-9a-f]{40}$/.test(head?.hash ?? '') && (head?.shortHash?.length ?? 0) >= 7 && head?.author === 'Test' && !Number.isNaN(Date.parse(head?.date ?? '')));
check('GET /log : branche locale sans remote → hasUpstream=false', log.hasUpstream === false && log.unpushedCount === 0);
// ---- limit / skip ----
const page = await (await j(`/api/v1/repos/${repoId}/worktrees/log?path=${enc}&limit=1&skip=1`, 'GET', cookie)).json();
check('GET /log : limit + skip bornent la fenêtre', page.commits?.length === 1 && page.commits[0].subject === 'ajoute la « deuxième » ligne');
const bad = await j(`/api/v1/repos/${repoId}/worktrees/log?path=${enc}&limit=abc`, 'GET', cookie);
check('GET /log : limit non numérique → 400', bad.status === 400);
const noPath = await j(`/api/v1/repos/${repoId}/worktrees/log`, 'GET', cookie);
check('GET /log : path manquant → 400', noPath.status === 400);
// ---- diff d'un commit ----
const cd = await (await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=${head.hash}`, 'GET', cookie)).json();
check('GET /diff?commit= : diff unifié du commit', typeof cd.diff === 'string' && cd.diff.includes('feature.txt') && cd.diff.includes('+contenu de la feature'));
check('GET /diff?commit= : ni binaire ni tronqué', cd.binary === false && cd.tooLarge === false);
const shortHash = await (await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=${head.shortHash}`, 'GET', cookie)).json();
check('GET /diff?commit= : hash court accepté', typeof shortHash.diff === 'string' && shortHash.diff.includes('feature.txt'));
const invalid = await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=${encodeURIComponent('--upload-pack=x')}`, 'GET', cookie);
check('GET /diff?commit= : révision non hexadécimale refusée', invalid.status === 400);
const unknown = await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=deadbeef`, 'GET', cookie);
check('GET /diff?commit= : commit inconnu → 404', unknown.status === 404);
const neither = await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}`, 'GET', cookie);
check('GET /diff : ni file ni commit → 400', neither.status === 400);
// ---- la forme fichier reste intacte (non-régression P7/P9) ----
appendFileSync(join(repo, 'README.md'), 'travail en cours\n');
const fileDiff = await (await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&file=README.md`, 'GET', cookie)).json();
check('GET /diff?file= : toujours fonctionnel', typeof fileDiff.diff === 'string' && fileDiff.diff.includes('+travail en cours'));
} catch (err) {
check('exception', false, String(err));
} finally {
srv.kill('SIGTERM');
await sleep(1500);
check('arrêt propre du daemon (SIGTERM)', srv.exitCode === 0 || srv.signalCode === null || srv.exitCode === null);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? '\nACCEPTANCE P15: ALL GREEN' : `\nACCEPTANCE P15: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
@@ -0,0 +1,235 @@
#!/usr/bin/env node
// Vérification E2E du copier / coller dans le terminal web (régression : la sélection d'xterm n'est
// pas une sélection DOM, le « Copier » natif ne voyait donc rien). Daemon temporaire isolé + session
// `bash` (pas `claude` : pas de quota consommé) + Chromium piloté en CDP : on tape un marqueur, on le
// sélectionne à la souris, Ctrl+Shift+C, et on relit le presse-papier réel du navigateur. Puis
// l'inverse : on remplit le presse-papier, Ctrl+Shift+V, et on vérifie que le PTY l'a reçu.
import { spawn } from 'node:child_process';
import { mkdtempSync, rmSync, existsSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import { WebSocket } from 'ws';
const PORT = 7411;
const CDP_PORT = 9334;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
let failures = 0;
function check(label, ok, detail = '') {
console.log(`${ok ? '✅' : '❌'} ${label}${detail ? ` : ${detail}` : ''}`);
if (!ok) failures++;
}
function findChromium() {
for (const bin of ['/usr/bin/chromium', '/usr/bin/chromium-browser', '/usr/bin/google-chrome']) {
if (existsSync(bin)) return bin;
}
return null;
}
/** Client CDP minimal : un socket, corrélation par id. */
function cdp(url) {
const ws = new WebSocket(url, { perMessageDeflate: false });
const pending = new Map();
let seq = 0;
const ready = new Promise((resolve, reject) => {
ws.once('open', resolve);
ws.once('error', reject);
});
ws.on('message', (raw) => {
const msg = JSON.parse(raw.toString());
const entry = pending.get(msg.id);
if (!entry) return;
pending.delete(msg.id);
msg.error ? entry.reject(new Error(msg.error.message)) : entry.resolve(msg.result);
});
return {
ready,
close: () => ws.close(),
send(method, params = {}, sessionId) {
const id = ++seq;
return new Promise((resolve, reject) => {
pending.set(id, { resolve, reject });
ws.send(JSON.stringify({ id, method, params, ...(sessionId ? { sessionId } : {}) }));
setTimeout(() => pending.has(id) && (pending.delete(id), reject(new Error(`CDP timeout: ${method}`))), 30_000);
});
},
};
}
let srv, browser, tmp;
try {
tmp = mkdtempSync(join(tmpdir(), 'arb-clip-'));
srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 't.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, XDG_DATA_HOME: join(tmp, 'xdg'), ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
for (let i = 0; i < 60 && !/arb_[0-9a-f]{16,}/.test(srvOut); i++) await sleep(150);
const token = /arb_[0-9a-f]{16,}/.exec(srvOut)?.[0];
check('daemon temporaire démarré', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const cookie = (login.headers.getSetCookie?.() ?? []).map((c) => c.split(';')[0]).find((c) => c.startsWith('arb_session='));
const cookieValue = cookie?.slice('arb_session='.length) ?? '';
check('login → cookie de session', !!cookie);
const sess = await (
await fetch(`${ORIGIN}/api/v1/sessions`, {
method: 'POST',
headers: { Origin: ORIGIN, Cookie: cookie, 'Content-Type': 'application/json' },
body: JSON.stringify({ cwd: tmp, command: 'bash' }),
})
).json();
const sessionId = sess.session?.id;
check('session bash lancée', !!sessionId);
const chromeBin = findChromium();
check('Chromium disponible', !!chromeBin, chromeBin ?? 'introuvable');
if (!chromeBin || !sessionId) throw new Error('prérequis manquants');
browser = spawn(
chromeBin,
[
'--headless=new',
`--remote-debugging-port=${CDP_PORT}`,
`--user-data-dir=${join(tmp, 'chrome')}`,
'--no-first-run',
'--no-default-browser-check',
'--disable-gpu',
'--hide-scrollbars',
],
{ stdio: ['ignore', 'pipe', 'pipe'] },
);
let wsUrl = null;
for (let i = 0; i < 80 && !wsUrl; i++) {
await sleep(200);
try {
wsUrl = (await (await fetch(`http://127.0.0.1:${CDP_PORT}/json/version`)).json()).webSocketDebuggerUrl;
} catch {
/* pas encore prêt */
}
}
check('Chromium en écoute CDP', !!wsUrl);
const client = cdp(wsUrl);
await client.ready;
// Presse-papier lisible/écrivable sans geste utilisateur (sinon readText() rejette en headless).
await client.send('Browser.grantPermissions', {
origin: ORIGIN,
permissions: ['clipboardReadWrite', 'clipboardSanitizedWrite'],
});
const { targetId } = await client.send('Target.createTarget', { url: 'about:blank' });
const { sessionId: sid } = await client.send('Target.attachToTarget', { targetId, flatten: true });
await client.send('Page.enable', {}, sid);
await client.send('Runtime.enable', {}, sid);
await client.send('Network.enable', {}, sid);
await client.send('Network.setCookie', { name: 'arb_session', value: cookieValue, domain: '127.0.0.1', path: '/', httpOnly: true }, sid);
await client.send('Emulation.setDeviceMetricsOverride', { width: 1440, height: 900, deviceScaleFactor: 1, mobile: false }, sid);
const evaluate = async (expression, awaitPromise = false) =>
(await client.send('Runtime.evaluate', { expression, returnByValue: true, awaitPromise }, sid)).result?.value;
await client.send('Page.navigate', { url: `${ORIGIN}/sessions/${sessionId}` }, sid);
// attend que xterm soit monté ET que bash ait rendu son invite
let screen = null;
for (let i = 0; i < 80 && !screen; i++) {
await sleep(250);
screen = await evaluate(`(() => { const el = document.querySelector('.xterm-screen'); if (!el) return null; const r = el.getBoundingClientRect(); return r.width > 50 ? JSON.stringify(r) : null; })()`);
}
check('terminal xterm monté', !!screen);
const rect = screen ? JSON.parse(screen) : null;
// Le renderer WebGL peint dans un canvas : `.xterm-rows` est vide, on ne peut RIEN vérifier via le
// DOM. Les preuves passent donc par le système de fichiers (le cwd de la session est `tmp`) et par
// le presse-papier réel du navigateur.
const focusTerm = () => client.send('Runtime.evaluate', { expression: `document.querySelector('.xterm-helper-textarea')?.focus()` }, sid);
const pressEnter = async () => {
await client.send('Input.dispatchKeyEvent', { type: 'keyDown', key: 'Enter', code: 'Enter', windowsVirtualKeyCode: 13, nativeVirtualKeyCode: 13, text: '\r' }, sid);
await client.send('Input.dispatchKeyEvent', { type: 'keyUp', key: 'Enter', code: 'Enter', windowsVirtualKeyCode: 13, nativeVirtualKeyCode: 13 }, sid);
};
const waitForFile = async (name, tries = 40) => {
for (let i = 0; i < tries; i++) {
if (existsSync(join(tmp, name))) return true;
await sleep(200);
}
return false;
};
// --- Frappe dans le PTY (Input.insertText → textarea xterm → stdin) ---
await focusTerm();
await client.send('Input.insertText', { text: 'touch typed-ok' }, sid);
await pressEnter();
check('le PTY exécute une commande tapée au clavier', await waitForFile('typed-ok'));
// Marqueur affiché à l'écran, cible de la copie
const MARKER = 'COPIE_MOI_4242';
await client.send('Input.insertText', { text: `echo ${MARKER}` }, sid);
await pressEnter();
await sleep(600);
// --- Sélection à la souris sur la zone du terminal, puis Ctrl+Shift+C ---
if (rect) {
const y = rect.y + 8;
await client.send('Input.dispatchMouseEvent', { type: 'mousePressed', x: rect.x + 2, y, button: 'left', clickCount: 1, buttons: 1 }, sid);
await client.send('Input.dispatchMouseEvent', { type: 'mouseMoved', x: rect.x + rect.width - 4, y: y + 40, button: 'left', buttons: 1 }, sid);
await client.send('Input.dispatchMouseEvent', { type: 'mouseReleased', x: rect.x + rect.width - 4, y: y + 40, button: 'left', clickCount: 1, buttons: 0 }, sid);
}
await sleep(300);
const selection = await evaluate(`(() => { const s = document.querySelector('.xterm')?.classList; return document.getSelection()?.toString() ?? ''; })()`);
// ctrl(2) + shift(8) = 10
const keyOpts = { modifiers: 10, windowsVirtualKeyCode: 67, nativeVirtualKeyCode: 67, key: 'C', code: 'KeyC' };
await client.send('Input.dispatchKeyEvent', { type: 'keyDown', ...keyOpts }, sid);
await client.send('Input.dispatchKeyEvent', { type: 'keyUp', ...keyOpts }, sid);
await sleep(500);
const copied = (await evaluate('navigator.clipboard.readText()', true)) ?? '';
check('Ctrl+Shift+C copie la sélection du terminal', copied.includes(MARKER), JSON.stringify(copied.slice(0, 60)));
// --- Collage : presse-papier → Ctrl+Shift+V → la commande collée doit atteindre le PTY ---
await evaluate(`navigator.clipboard.writeText('touch paste-ok')`, true);
await focusTerm();
const vOpts = { modifiers: 10, windowsVirtualKeyCode: 86, nativeVirtualKeyCode: 86, key: 'V', code: 'KeyV' };
await client.send('Input.dispatchKeyEvent', { type: 'keyDown', ...vOpts }, sid);
await client.send('Input.dispatchKeyEvent', { type: 'keyUp', ...vOpts }, sid);
await sleep(400);
await pressEnter();
check('Ctrl+Shift+V colle le presse-papier dans le terminal', await waitForFile('paste-ok'));
// --- Ctrl+C ne doit PAS être détourné : il reste SIGINT ---
// `sleep 25` bloque le shell ; si le ^C passe, le shell reprend et exécute la commande suivante.
await focusTerm();
await client.send('Input.insertText', { text: 'sleep 25' }, sid);
await pressEnter();
await sleep(700);
const cOpts = { modifiers: 2, windowsVirtualKeyCode: 67, nativeVirtualKeyCode: 67, key: 'c', code: 'KeyC' };
await client.send('Input.dispatchKeyEvent', { type: 'keyDown', ...cOpts }, sid);
await client.send('Input.dispatchKeyEvent', { type: 'keyUp', ...cOpts }, sid);
await sleep(500);
await client.send('Input.insertText', { text: 'touch interrupt-ok' }, sid);
await pressEnter();
check('Ctrl+C reste transmis au PTY (SIGINT, pas une copie)', await waitForFile('interrupt-ok', 30));
client.close();
} catch (err) {
check('exécution du scénario', false, err?.message ?? String(err));
} finally {
browser?.kill('SIGKILL');
srv?.kill('SIGKILL');
await sleep(300);
if (tmp) rmSync(tmp, { recursive: true, force: true });
}
console.log(failures === 0 ? '\nVERIFY CLIPBOARD: ALL GREEN' : `\nVERIFY CLIPBOARD: ${failures} ÉCHEC(S)`);
process.exit(failures === 0 ? 0 : 1);
+239
View File
@@ -0,0 +1,239 @@
#!/usr/bin/env node
// Vérification VISUELLE de la SPA authentifiée, sans Playwright : daemon temporaire isolé + Chromium
// headless piloté en CDP + cookie de session injecté. Produit des captures PNG (thème sombre et clair,
// largeurs desktop et mobile) et échoue si une erreur console / exception Vue survient.
//
// Usage : node packages/server/scripts/verify-ui.mjs [dossier-de-sortie]
// Prérequis : `npm run build` puis `node packages/server/scripts/copy-web.mjs` (le daemon sert la SPA
// depuis packages/server/public, que le build NE rafraîchit PAS).
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, mkdirSync, rmSync, writeFileSync, existsSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname, resolve as resolvePath } from 'node:path';
import { fileURLToPath } from 'node:url';
import { createRequire } from 'node:module';
const require = createRequire(import.meta.url);
const WebSocket = require('ws');
const PORT = 7998;
const CDP_PORT = 9333;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const outDir = resolvePath(process.argv[2] ?? join(serverDir, '..', '..', '.ui-shots'));
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
function findChromium() {
for (const bin of ['chromium', 'chromium-browser', 'google-chrome', 'google-chrome-stable']) {
try {
return execFileSync('which', [bin]).toString().trim();
} catch {
/* essai suivant */
}
}
return null;
}
/** Client CDP minimal : un seul socket, corrélation par id, sessionId pour la cible attachée. */
function cdp(url) {
const ws = new WebSocket(url, { perMessageDeflate: false, maxPayload: 256 * 1024 * 1024 });
let nextId = 1;
const pending = new Map();
const events = [];
ws.on('message', (raw) => {
const msg = JSON.parse(String(raw));
if (msg.id && pending.has(msg.id)) {
const { resolve, reject } = pending.get(msg.id);
pending.delete(msg.id);
msg.error ? reject(new Error(JSON.stringify(msg.error))) : resolve(msg.result);
return;
}
if (msg.method) events.push(msg);
});
const ready = new Promise((res, rej) => (ws.on('open', res), ws.on('error', rej)));
const send = (method, params = {}, sessionId) =>
new Promise((resolve, reject) => {
const id = nextId++;
pending.set(id, { resolve, reject });
ws.send(JSON.stringify({ id, method, params, ...(sessionId ? { sessionId } : {}) }));
setTimeout(() => pending.has(id) && (pending.delete(id), reject(new Error(`CDP timeout: ${method}`))), 30_000);
});
return { ws, ready, send, events };
}
const tmp = mkdtempSync(join(tmpdir(), 'arb-verify-ui-'));
mkdirSync(outDir, { recursive: true });
let srv = null;
let browser = null;
try {
// La SPA servie vient de packages/server/public : garde-fou contre la vérification d'un ancien build.
const publicIndex = join(serverDir, 'public', 'index.html');
check('SPA copiée dans packages/server/public', existsSync(publicIndex), publicIndex);
// --- dépôt de démonstration : un checkout principal, un worktree de feature, du travail en cours ---
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
writeFileSync(join(repo, 'README.md'), '# demo\n');
mkdirSync(join(repo, 'src'), { recursive: true });
writeFileSync(join(repo, 'src', 'app.ts'), 'export const version = 1\n');
git('add', '-A');
git('commit', '-m', 'commit initial');
writeFileSync(join(repo, 'src', 'app.ts'), 'export const version = 2\n');
srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 't.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, XDG_DATA_HOME: join(tmp, 'xdg'), ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
for (let i = 0; i < 60 && !/arb_[0-9a-f]{16,}/.test(srvOut); i++) await sleep(150);
const token = /arb_[0-9a-f]{16,}/.exec(srvOut)?.[0];
check('daemon temporaire démarré + token', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const setCookie = login.headers.getSetCookie?.() ?? [];
const sessionCookie = setCookie.map((c) => c.split(';')[0]).find((c) => c.startsWith('arb_session='));
check('login → cookie de session', !!sessionCookie);
const cookieValue = sessionCookie?.slice('arb_session='.length) ?? '';
const j = (path, method, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: sessionCookie ?? '', ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
const repoId = (await (await j('/api/v1/repos', 'POST', { path: repo })).json()).repo?.id;
check('dépôt de démonstration enregistré', !!repoId);
const wtRes = await (await j(`/api/v1/repos/${repoId}/worktrees`, 'POST', { branch: 'feature/demo', runHooks: false })).json();
check('worktree de feature créé', !!wtRes.worktree?.path);
// du travail non commité dans le worktree de feature, pour peupler les compteurs git de l'arbre
if (wtRes.worktree?.path) writeFileSync(join(wtRes.worktree.path, 'wip.txt'), 'travail en cours\n');
const groupRes = await (await j('/api/v1/groups', 'POST', { label: 'Démo', color: '#34d399', repoIds: [repoId] })).json();
check('groupe de démonstration créé', !!groupRes.group?.id);
const sess = await (await j('/api/v1/sessions', 'POST', { cwd: repo, command: 'bash' })).json();
check('session bash de démonstration', !!sess.session?.id);
// --- Chromium headless en CDP ---
const chromeBin = findChromium();
check('Chromium disponible', !!chromeBin, chromeBin ?? 'introuvable');
if (!chromeBin) throw new Error('Chromium introuvable : impossible de vérifier le rendu');
browser = spawn(
chromeBin,
[
'--headless=new',
`--remote-debugging-port=${CDP_PORT}`,
`--user-data-dir=${join(tmp, 'chrome')}`,
'--no-first-run',
'--no-default-browser-check',
'--disable-gpu',
'--hide-scrollbars',
],
{ stdio: ['ignore', 'pipe', 'pipe'] },
);
let wsUrl = null;
for (let i = 0; i < 80 && !wsUrl; i++) {
await sleep(200);
try {
wsUrl = (await (await fetch(`http://127.0.0.1:${CDP_PORT}/json/version`)).json()).webSocketDebuggerUrl;
} catch {
/* pas encore prêt */
}
}
check('Chromium en écoute CDP', !!wsUrl);
const client = cdp(wsUrl);
await client.ready;
// État de vue injecté avant le premier paint : on veut des captures qui MONTRENT le contenu
// (arbre déplié, worktree actif), pas un IDE vide.
const expanded = JSON.stringify(JSON.stringify([repoId]));
const context = JSON.stringify(JSON.stringify({ repoId, wtPath: repo }));
const seedExplorer = `localStorage.setItem('arb.ide.expandedRepos', ${expanded});localStorage.setItem('arb.ide.context', ${context});`;
const seedGit = `${seedExplorer}localStorage.setItem('arb.ide.activity', '"git"');localStorage.setItem('arb.history.open', 'true');`;
// Panneau Groupes avec le groupe ET le worktree dépliés : c'est la vue qui porte l'arborescence de
// fichiers des membres du groupe, sinon jamais capturée.
const seedGroups =
`${seedExplorer}localStorage.setItem('arb.ide.activity', '"groups"');` +
`localStorage.setItem('arb.ide.expandedGroups', ${JSON.stringify(JSON.stringify([groupRes.group?.id]))});` +
`localStorage.setItem('arb.ide.expandedWts', ${JSON.stringify(JSON.stringify([repo]))});`;
const shots = [
{ name: 'ide-dark-desktop', theme: 'dark', width: 1440, height: 900, seed: seedExplorer },
{ name: 'ide-light-desktop', theme: 'light', width: 1440, height: 900, seed: seedExplorer },
{ name: 'git-dark-desktop', theme: 'dark', width: 1440, height: 900, seed: seedGit },
{ name: 'git-light-desktop', theme: 'light', width: 1440, height: 900, seed: seedGit },
{ name: 'groups-dark-desktop', theme: 'dark', width: 1440, height: 900, seed: seedGroups },
{ name: 'ide-dark-mobile', theme: 'dark', width: 390, height: 844, seed: seedExplorer },
{ name: 'ide-light-mobile', theme: 'light', width: 390, height: 844, seed: seedExplorer },
{ name: 'dashboard-dark-mobile', theme: 'dark', width: 390, height: 844, path: '/dashboard' },
];
for (const shot of shots) {
const { targetId } = await client.send('Target.createTarget', { url: 'about:blank' });
const { sessionId } = await client.send('Target.attachToTarget', { targetId, flatten: true });
await client.send('Runtime.enable', {}, sessionId);
await client.send('Log.enable', {}, sessionId);
await client.send('Network.enable', {}, sessionId);
await client.send('Emulation.setDeviceMetricsOverride', { width: shot.width, height: shot.height, deviceScaleFactor: 1, mobile: shot.width < 500 }, sessionId);
await client.send('Network.setCookie', { name: 'arb_session', value: cookieValue, domain: '127.0.0.1', path: '/', httpOnly: true }, sessionId);
// Thème : la SPA lit `arb.theme` avant le premier paint (script anti-FOUC).
await client.send('Page.enable', {}, sessionId);
await client.send(
'Page.addScriptToEvaluateOnNewDocument',
{ source: `localStorage.setItem('arb.theme', ${JSON.stringify(JSON.stringify(shot.theme))});${shot.seed ?? ''}` },
sessionId,
);
const before = client.events.length;
await client.send('Page.navigate', { url: `${ORIGIN}${shot.path ?? '/ide'}` }, sessionId);
await sleep(3500); // laisse le temps au bootstrap REST + WS et au rendu
const text = await client.send('Runtime.evaluate', { expression: 'document.body.innerText', returnByValue: true }, sessionId);
const rendered = String(text.result?.value ?? '');
check(`${shot.name} : page rendue`, rendered.length > 20, `${rendered.length} caractères`);
const errs = client.events
.slice(before)
.filter((e) => e.sessionId === sessionId)
.filter((e) => (e.method === 'Runtime.consoleAPICalled' && e.params?.type === 'error') || e.method === 'Runtime.exceptionThrown')
.map((e) => e.params?.exceptionDetails?.text ?? (e.params?.args ?? []).map((a) => a.value ?? a.description).join(' '))
// Les erreurs réseau des favicons/manifest en headless ne concernent pas l'app.
.filter((m) => m && !/favicon|manifest\.webmanifest/i.test(m));
check(`${shot.name} : aucune erreur console`, errs.length === 0, errs.slice(0, 3).join(' | '));
const { data } = await client.send('Page.captureScreenshot', { format: 'png', captureBeyondViewport: false }, sessionId);
const file = join(outDir, `${shot.name}.png`);
writeFileSync(file, Buffer.from(data, 'base64'));
check(`${shot.name} : capture écrite`, true, file);
await client.send('Target.closeTarget', { targetId });
}
client.ws.close();
} catch (err) {
check('exception', false, String(err));
} finally {
browser?.kill('SIGTERM');
srv?.kill('SIGTERM');
await sleep(1200);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? `\nVERIFY UI: ALL GREEN (captures dans ${outDir})` : `\nVERIFY UI: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
+42 -3
View File
@@ -64,6 +64,22 @@ const SECURITY_HEADERS: Record<string, string> = {
].join('; '), ].join('; '),
}; };
// Politique de cache du statique. Piège à connaître : `npm pack` normalise le mtime de TOUS les
// fichiers du tarball à une date constante (1985-10-26). L'etag faible de @fastify/static étant
// dérivé de taille+mtime, deux versions différentes d'un même fichier non haché produisent le
// MÊME etag dès que leur taille coïncide : le client reçoit un 304 et garde indéfiniment
// l'ancienne copie. Vécu en production sur index.html à la mise à jour de l'app desktop : l'index
// obsolète référençait des `/assets/<hash>.js` disparus, le fallback SPA répondait du text/html
// pour ces modules, et la page restait noire.
// Conséquence : seuls les fichiers dont le NOM porte un hash de contenu (/assets/) sont
// cachables ; tout le reste (index.html, sw.js, theme-boot.js, manifest, icônes) part en
// no-store, la revalidation par etag n'étant pas fiable ici.
export function cacheControlFor(pathname: string): string {
return pathname.startsWith('/assets/')
? 'public, max-age=31536000, immutable'
: 'no-store';
}
declare module 'fastify' { declare module 'fastify' {
interface FastifyRequest { interface FastifyRequest {
authContext: AuthContext | null; authContext: AuthContext | null;
@@ -183,7 +199,12 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
if (!isApi && !isWs) return; // statique : public (la SPA gère son écran de login) if (!isApi && !isWs) return; // statique : public (la SPA gère son écran de login)
const origin = req.headers.origin; const origin = req.headers.origin;
if (origin && !allowedOrigins.has(origin)) { if (origin && !allowedOrigins.has(origin)) {
return reply.status(403).send({ error: { code: 'BAD_ORIGIN', message: `Origin not allowed: ${origin}` } }); // Message ACTIONNABLE : c'est le premier mur de tout accès non-loopback (LAN, reverse proxy,
// Tailscale). Un « Origin not allowed » sec laissait chercher pendant des heures, alors que la
// correction tient en un flag. Le log serveur porte la même consigne.
const hint = `Origin not allowed: ${origin}. Restart the daemon with --allow-origin ${origin} (repeatable) to permit it.`;
req.log.warn({ origin, allowed: [...allowedOrigins] }, hint);
return reply.status(403).send({ error: { code: 'BAD_ORIGIN', message: hint } });
} }
req.authContext = authenticate(req); req.authContext = authenticate(req);
if (req.routeOptions.config.public) return; if (req.routeOptions.config.public) return;
@@ -195,7 +216,7 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
registerAuthRoutes(app, auth, limiter, serverVersion, db); registerAuthRoutes(app, auth, limiter, serverVersion, db);
registerSessionRoutes(app, manager, discovery, sessionArchive, db); registerSessionRoutes(app, manager, discovery, sessionArchive, db);
registerProjectRoutes(app, manager, db); registerProjectRoutes(app, manager, db);
registerRepoRoutes(app, worktrees, db); registerRepoRoutes(app, worktrees, db, manager);
registerGroupRoutes(app, groups, db, worktrees, manager); registerGroupRoutes(app, groups, db, worktrees, manager);
registerWorktreeRoutes(app, worktrees, db); registerWorktreeRoutes(app, worktrees, db);
registerGitRoutes(app, worktrees, db); registerGitRoutes(app, worktrees, db);
@@ -215,7 +236,25 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
// SPA buildée embarquée dans le paquet npm (public/) : absente en dev (vite dev sert le front) // SPA buildée embarquée dans le paquet npm (public/) : absente en dev (vite dev sert le front)
const publicDir = join(dirname(fileURLToPath(import.meta.url)), '..', 'public'); const publicDir = join(dirname(fileURLToPath(import.meta.url)), '..', 'public');
if (existsSync(publicDir)) { if (existsSync(publicDir)) {
void app.register(fastifyStatic, { root: publicDir, wildcard: false }); void app.register(fastifyStatic, {
root: publicDir,
wildcard: false,
// Validation conditionnelle désactivée : l'etag faible et le Last-Modified dérivent du mtime,
// que `npm pack` fige (cf. cacheControlFor). Les laisser actifs ferait répondre 304 aux
// clients qui détiennent encore un index.html périmé d'une version antérieure : ils y
// resteraient bloqués. Sans etag, ils reçoivent un 200 et se réparent d'eux-mêmes. Le coût
// est nul pour /assets (noms hachés, servis immutable) et négligeable ailleurs.
etag: false,
lastModified: false,
// Indispensable : sinon le plugin écrit son propre `cache-control: public, max-age=0`
// APRÈS setHeaders et écrase le no-store ci-dessous.
cacheControl: false,
// `setHeaders` s'applique aussi aux `reply.sendFile` du fallback SPA ci-dessous.
setHeaders(res, path) {
const rel = path.slice(publicDir.length).replace(/\\/g, '/');
res.setHeader('Cache-Control', cacheControlFor(rel));
},
});
app.setNotFoundHandler((req, reply) => { app.setNotFoundHandler((req, reply) => {
if (req.url.startsWith('/api/') || req.url.startsWith('/ws')) { if (req.url.startsWith('/api/') || req.url.startsWith('/ws')) {
return reply.status(404).send({ error: { code: 'NOT_FOUND', message: 'Route not found' } }); return reply.status(404).send({ error: { code: 'NOT_FOUND', message: 'Route not found' } });
+53 -6
View File
@@ -12,7 +12,7 @@ import { AuthService } from '../auth/service.js';
const SERVICE_NAME = 'arboretum'; const SERVICE_NAME = 'arboretum';
const LAUNCHD_LABEL = 'fr.lidge.arboretum'; const LAUNCHD_LABEL = 'fr.lidge.arboretum';
export type SupportedPlatform = 'linux' | 'darwin'; export type SupportedPlatform = 'linux' | 'darwin' | 'win32';
export interface InstallFlags { export interface InstallFlags {
port?: string | undefined; port?: string | undefined;
@@ -29,15 +29,31 @@ export interface InstallFlags {
// ─── Fonctions pures (génération de contenu / chemins) ──────────────────────────────── // ─── Fonctions pures (génération de contenu / chemins) ────────────────────────────────
/** macOS (launchd) et Linux (systemd) uniquement ; sinon throw avec un message pédagogique. */ /**
* Superviseur par plateforme : systemd (Linux), launchd (macOS), Planificateur de tâches (Windows).
* Toujours en tant qu'utilisateur, jamais en root/SYSTEM.
*/
export function detectPlatform(platform: NodeJS.Platform = process.platform): SupportedPlatform { export function detectPlatform(platform: NodeJS.Platform = process.platform): SupportedPlatform {
if (platform === 'linux' || platform === 'darwin') return platform; if (platform === 'linux' || platform === 'darwin' || platform === 'win32') return platform;
throw new Error( throw new Error(
`Automatic service installation is supported on Linux (systemd) and macOS (launchd) only.\n` + `Automatic service installation is supported on Linux (systemd), macOS (launchd) and Windows ` +
`On ${platform}, run \`arboretum\` manually or set up your own supervisor.`, `(Task Scheduler) only.\nOn ${platform}, run \`arboretum\` manually or set up your own supervisor.`,
); );
} }
/** Nom de la tâche planifiée Windows (visible dans taskschd.msc). */
export const WINDOWS_TASK_NAME = 'Arboretum';
/**
* Arguments `schtasks /Create` d'une tâche « au démarrage de session utilisateur ». `/RL LIMITED`
* garde les privilèges de l'utilisateur (jamais d'élévation), `/F` rend la commande idempotente.
* `/TR` attend UNE chaîne de commande : chaque token à espaces est donc quoté.
*/
export function windowsCreateArgs(input: { taskName: string; exec: string; scriptArgs: string[] }): string[] {
const command = [input.exec, ...input.scriptArgs].map(quoteIfNeeded).join(' ');
return ['/Create', '/TN', input.taskName, '/TR', command, '/SC', 'ONLOGON', '/RL', 'LIMITED', '/F'];
}
export function parseInstallArgs(argv: string[]): InstallFlags { export function parseInstallArgs(argv: string[]): InstallFlags {
const { values } = parseArgs({ const { values } = parseArgs({
args: argv, args: argv,
@@ -207,7 +223,8 @@ export function printUsage(version: string): void {
Usage: Usage:
arboretum [flags] Start the daemon (default) arboretum [flags] Start the daemon (default)
arboretum serve [flags] Start the daemon (explicit alias) arboretum serve [flags] Start the daemon (explicit alias)
arboretum install [flags] Install & start a user service (systemd on Linux, launchd on macOS) arboretum install [flags] Install & start a user service (systemd on Linux, launchd on macOS,
Task Scheduler on Windows)
arboretum uninstall Stop & remove the user service arboretum uninstall Stop & remove the user service
arboretum status Show the service status arboretum status Show the service status
arboretum help Show this help arboretum help Show this help
@@ -218,6 +235,9 @@ Daemon flags:
--allow-origin <url> Additional allowed Origin (repeatable) --allow-origin <url> Additional allowed Origin (repeatable)
--db <path> SQLite database path --db <path> SQLite database path
--vapid-contact <mailto|url> VAPID contact subject for Web Push --vapid-contact <mailto|url> VAPID contact subject for Web Push
--claude-home <path> Override the Claude install root (default ~/.claude)
--print-token Print the access token on start (bootstrap it if missing)
--no-discover Disable repository auto-discovery (startup + periodic scan)
--i-know-this-exposes-a-terminal Acknowledge a non-loopback bind (avoid, prefer Tailscale Serve) --i-know-this-exposes-a-terminal Acknowledge a non-loopback bind (avoid, prefer Tailscale Serve)
Install flags (daemon flags above are propagated to the service): Install flags (daemon flags above are propagated to the service):
@@ -301,6 +321,23 @@ export async function runInstall(argv: string[]): Promise<void> {
return; return;
} }
if (platform === 'win32') {
// Windows : Planificateur de tâches, déclenchement à l'ouverture de session. Pas de service NT
// (il tournerait hors session utilisateur, donc sans accès au profil ni au CLI `claude`).
const createArgs = windowsCreateArgs({ taskName: WINDOWS_TASK_NAME, exec, scriptArgs });
if (flags.dryRun) {
console.log(`# commands:\nschtasks ${createArgs.join(' ')}`);
if (!flags.noEnable) console.log(`schtasks /Run /TN ${WINDOWS_TASK_NAME}`);
return;
}
bootstrapToken(serviceArgs);
run('schtasks.exe', createArgs, { check: true });
console.log(`Registered scheduled task "${WINDOWS_TASK_NAME}" (runs at logon).`);
if (!flags.noEnable) run('schtasks.exe', ['/Run', '/TN', WINDOWS_TASK_NAME], { check: true });
console.log(`\nArboretum task installed. Manage it with: schtasks /Query /TN ${WINDOWS_TASK_NAME}`);
return;
}
// macOS (launchd) // macOS (launchd)
const logs = launchdLogPaths(); const logs = launchdLogPaths();
const programArguments = [exec, ...scriptArgs]; const programArguments = [exec, ...scriptArgs];
@@ -352,6 +389,12 @@ export async function runUninstall(argv: string[]): Promise<void> {
console.log('Arboretum service removed.'); console.log('Arboretum service removed.');
return; return;
} }
if (platform === 'win32') {
run('schtasks.exe', ['/End', '/TN', WINDOWS_TASK_NAME]); // best-effort : arrête l'instance courante
run('schtasks.exe', ['/Delete', '/TN', WINDOWS_TASK_NAME, '/F']);
console.log('Arboretum scheduled task removed.');
return;
}
const plistPath = launchAgentPlistPath(flags.label); const plistPath = launchAgentPlistPath(flags.label);
const uid = process.getuid?.() ?? 0; const uid = process.getuid?.() ?? 0;
run('launchctl', ['bootout', `gui/${uid}/${flags.label}`]); // best-effort run('launchctl', ['bootout', `gui/${uid}/${flags.label}`]); // best-effort
@@ -371,6 +414,10 @@ export async function runStatus(argv: string[]): Promise<void> {
process.exitCode = code; process.exitCode = code;
return; return;
} }
if (platform === 'win32') {
process.exitCode = run('schtasks.exe', ['/Query', '/TN', WINDOWS_TASK_NAME, '/V', '/FO', 'LIST']);
return;
}
const uid = process.getuid?.() ?? 0; const uid = process.getuid?.() ?? 0;
const code = run('launchctl', ['print', `gui/${uid}/${flags.label}`]); const code = run('launchctl', ['print', `gui/${uid}/${flags.label}`]);
console.log(`\nLogs: ${launchdLogPaths().out}`); console.log(`\nLogs: ${launchdLogPaths().out}`);
+16 -1
View File
@@ -25,6 +25,21 @@ export interface Config {
autoDiscover: boolean; autoDiscover: boolean;
} }
/**
* Racine des données applicatives, par plateforme. `XDG_DATA_HOME` reste prioritaire partout (l'app de
* bureau s'en sert pour isoler ses données). Sinon : `%APPDATA%` sur Windows (`~/.local/share` n'y a
* aucun sens et n'est ni sauvegardé ni migré par l'OS), `~/.local/share` ailleurs.
*/
export function defaultDataRoot(
platform: NodeJS.Platform = process.platform,
env: NodeJS.ProcessEnv = process.env,
home: string = homedir(),
): string {
if (env.XDG_DATA_HOME) return env.XDG_DATA_HOME;
if (platform === 'win32') return env.APPDATA ?? join(home, 'AppData', 'Roaming');
return join(home, '.local', 'share');
}
export function loadConfig(argv = process.argv.slice(2)): Config { export function loadConfig(argv = process.argv.slice(2)): Config {
const { values } = parseArgs({ const { values } = parseArgs({
args: argv, args: argv,
@@ -55,7 +70,7 @@ export function loadConfig(argv = process.argv.slice(2)): Config {
); );
} }
const dataDir = join(process.env.XDG_DATA_HOME ?? join(homedir(), '.local', 'share'), 'arboretum'); const dataDir = join(defaultDataRoot(), 'arboretum');
mkdirSync(dataDir, { recursive: true }); mkdirSync(dataDir, { recursive: true });
// La DB contient des secrets (server_secret, clé privée VAPID, hashs de tokens) : le dossier de // La DB contient des secrets (server_secret, clé privée VAPID, hashs de tokens) : le dossier de
// données ne doit jamais être lisible par d'autres utilisateurs du système. chmod best-effort // données ne doit jamais être lisible par d'autres utilisateurs du système. chmod best-effort
+71 -9
View File
@@ -1,5 +1,5 @@
import { execFileSync } from 'node:child_process'; import { execFileSync } from 'node:child_process';
import { accessSync, constants } from 'node:fs'; import { accessSync, constants, existsSync } from 'node:fs';
export interface SpawnSpec { export interface SpawnSpec {
file: string; file: string;
@@ -13,8 +13,17 @@ export interface SpawnOptions {
resume?: { claudeSessionId: string; fork?: boolean }; resume?: { claudeSessionId: string; fork?: boolean };
/** répertoires supplémentaires à relier dans une seule session (P6) : `--add-dir <path>` répété. */ /** répertoires supplémentaires à relier dans une seule session (P6) : `--add-dir <path>` répété. */
addDirs?: string[]; addDirs?: string[];
/** chemin explicite du binaire `claude` (réglage UI) ; sinon résolution via PATH (`which`). */ /** chemin explicite du binaire `claude` (réglage UI) ; sinon résolution via le PATH. */
claudeBinPath?: string | null; claudeBinPath?: string | null;
/**
* Lancement de projet (« Démarrer le projet ») : au lieu de `bash --norc`, lance le shell de
* login interactif de l'utilisateur (`$SHELL -l -i`) pour charger son environnement complet
* (PATH nvm/asdf/~/.local/bin). Indispensable quand le daemon tourne en service systemd/launchd
* (PATH minimal, cf. resolveClaudeBin) : sinon `npm`/`docker` seraient introuvables. Ignoré pour claude.
*/
login?: boolean;
/** plateforme cible (injectable pour les tests) ; défaut `process.platform`. */
platform?: NodeJS.Platform;
} }
/** Diagnostic de résolution du binaire `claude` (exposé en lecture dans Réglages). */ /** Diagnostic de résolution du binaire `claude` (exposé en lecture dans Réglages). */
@@ -29,16 +38,32 @@ export interface ClaudeBinDiagnostic {
let cachedClaudeBin: string | null = null; let cachedClaudeBin: string | null = null;
/**
* Commande de recherche dans le PATH selon la plateforme : `which` n'existe PAS sur Windows, c'est
* `where.exe` (qui peut renvoyer plusieurs lignes, la première étant la retenue).
*/
export function whichCommand(platform: NodeJS.Platform = process.platform): { file: string; args: string[] } {
return platform === 'win32' ? { file: 'where.exe', args: ['claude'] } : { file: 'which', args: ['claude'] };
}
/** Recherche `claude` dans le PATH (sans throw). null si absent. */ /** Recherche `claude` dans le PATH (sans throw). null si absent. */
function findClaudeOnPath(): string | null { function findClaudeOnPath(platform: NodeJS.Platform = process.platform): string | null {
const { file, args } = whichCommand(platform);
try { try {
return execFileSync('which', ['claude'], { encoding: 'utf8' }).trim() || null; const out = execFileSync(file, args, { encoding: 'utf8' });
// `where.exe` liste toutes les correspondances : on garde la première.
return out.split(/\r?\n/).map((l) => l.trim()).find((l) => l.length > 0) ?? null;
} catch { } catch {
return null; return null;
} }
} }
function isExecutable(path: string): boolean { /**
* « Est-ce lançable ? ». Sur Windows, le bit d'exécution POSIX n'a aucun sens (NTFS n'en a pas) et
* `accessSync(X_OK)` y répond au hasard : on se contente donc de l'existence du fichier.
*/
function isExecutable(path: string, platform: NodeJS.Platform = process.platform): boolean {
if (platform === 'win32') return existsSync(path);
try { try {
accessSync(path, constants.X_OK); accessSync(path, constants.X_OK);
return true; return true;
@@ -50,9 +75,9 @@ function isExecutable(path: string): boolean {
/** /**
* Résout le binaire `claude`. Si `configuredPath` est fourni (réglage UI), il est utilisé tel quel * Résout le binaire `claude`. Si `configuredPath` est fourni (réglage UI), il est utilisé tel quel
* (validé exécutable, message clair sinon) et JAMAIS mis en cache (modifiable à chaud). Sinon : * (validé exécutable, message clair sinon) et JAMAIS mis en cache (modifiable à chaud). Sinon :
* `which claude`, mis en cache. Un service systemd/launchd démarre avec un PATH minimal sans * recherche dans le PATH (`which` / `where.exe`), mise en cache. Un service systemd/launchd démarre
* ~/.local/bin → `which claude` y échoue ; d'où le réglage de chemin explicite (et le PATH figé par * avec un PATH minimal sans ~/.local/bin → la recherche y échoue ; d'où le réglage de chemin explicite
* `arboretum install`). * (et le PATH figé par `arboretum install`).
*/ */
export function resolveClaudeBin(configuredPath?: string | null): string { export function resolveClaudeBin(configuredPath?: string | null): string {
if (configuredPath) { if (configuredPath) {
@@ -81,15 +106,52 @@ export function diagnoseClaudeBin(configuredPath?: string | null): ClaudeBinDiag
return found ? { path: found, source: 'path', ok: true } : { path: null, source: null, ok: false }; return found ? { path: found, source: 'path', ok: true } : { path: null, source: null, ok: false };
} }
/** Shells interactifs connus supportant `-l -i` (login + interactif). */
const KNOWN_LOGIN_SHELLS = new Set(['bash', 'zsh', 'fish']);
/**
* Shell interactif pour « Démarrer le projet ».
*
* POSIX : `$SHELL -l -i` s'il fait partie des shells connus supportant ces options (bash/zsh/fish),
* sinon `bash` (un `$SHELL=dash` sortirait aussitôt avec `-l -i`, laissant un terminal vide).
*
* Windows : PowerShell, en restant attaché après la commande auto-tapée (`-NoExit`), avec repli sur
* `cmd.exe /K`. `%COMSPEC%` n'est PAS utilisé comme shell de lancement : il pointe cmd.exe, qui ne
* charge aucun profil utilisateur. La commande est ensuite auto-tapée par le PtyManager, exactement
* comme sous POSIX · le mécanisme est indépendant du shell.
*/
export function resolveInteractiveShell(
platform: NodeJS.Platform = process.platform,
env: NodeJS.ProcessEnv = process.env,
): { file: string; args: string[] } {
if (platform === 'win32') {
const pwsh = env.ARBORETUM_SHELL ?? 'powershell.exe';
return { file: pwsh, args: ['-NoLogo', '-NoExit'] };
}
const shell = env.SHELL;
const file = shell && KNOWN_LOGIN_SHELLS.has(shell.split('/').pop() ?? '') ? shell : 'bash';
return { file, args: ['-l', '-i'] };
}
/** Shell non interactif « neutre » (terminal simple, hors lancement de projet). */
export function resolvePlainShell(platform: NodeJS.Platform = process.platform): { file: string; args: string[] } {
if (platform === 'win32') return { file: 'powershell.exe', args: ['-NoLogo', '-NoExit'] };
return { file: 'bash', args: ['--norc'] };
}
/** Module volontairement abstrait : le plan B « BYO API key / Agent SDK » se brancherait ici. */ /** Module volontairement abstrait : le plan B « BYO API key / Agent SDK » se brancherait ici. */
export function buildSpawnSpec(opts: SpawnOptions): SpawnSpec { export function buildSpawnSpec(opts: SpawnOptions): SpawnSpec {
const platform = opts.platform ?? process.platform;
const env: NodeJS.ProcessEnv = { const env: NodeJS.ProcessEnv = {
...process.env, ...process.env,
TERM: 'xterm-256color', TERM: 'xterm-256color',
COLORTERM: 'truecolor', COLORTERM: 'truecolor',
}; };
if (opts.command === 'bash') { if (opts.command === 'bash') {
return { file: 'bash', args: ['--norc'], env }; // `'bash'` désigne « le shell de la machine », pas littéralement bash : le contrat d'API reste
// stable (claude|bash) et c'est ici qu'on choisit le shell réel par plateforme.
const { file, args } = opts.login ? resolveInteractiveShell(platform) : resolvePlainShell(platform);
return { file, args, env };
} }
const args: string[] = []; const args: string[] = [];
if (opts.resume) { if (opts.resume) {
+31 -4
View File
@@ -7,9 +7,33 @@ import { resolve, sep, join } from 'node:path';
import chokidar, { type FSWatcher } from 'chokidar'; import chokidar, { type FSWatcher } from 'chokidar';
import { resolveGitDir } from './git.js'; import { resolveGitDir } from './git.js';
const DEFAULT_MAX_WATCHERS = 32; // Plafond du pool : l'arbre de projets peut désormais « regarder » tous les worktrees des dépôts
// dépliés (et non plus le seul worktree du panneau Git), il faut donc de la marge. Les entrées
// épinglées (session vivante, checkout principal) ne sont jamais évincées, cf. evictIfNeeded.
const DEFAULT_MAX_WATCHERS = 64;
const DEBOUNCE_MS = 200; const DEBOUNCE_MS = 200;
/**
* Répertoires lourds ignorés en plus de `.git` : ils concentrent l'essentiel des descripteurs inotify
* sans jamais rien apprendre sur le statut git. Liste volontairement CONSERVATRICE (pas de `dist`,
* `build`, `out` ni `vendor`, qui sont versionnés dans certains projets : les ignorer ferait manquer
* un vrai changement).
*/
const IGNORED_DIRS = [
'node_modules',
'.venv',
'venv',
'__pycache__',
'.turbo',
'.cache',
'.pnpm-store',
'coverage',
'.next',
'.nuxt',
'.output',
'target',
];
export interface FsWatcherEvents { export interface FsWatcherEvents {
/** le contenu d'un worktree surveillé a changé (édition, staging, checkout externe…). */ /** le contenu d'un worktree surveillé a changé (édition, staging, checkout externe…). */
worktree_fs_change: [{ repoId: string; path: string }]; worktree_fs_change: [{ repoId: string; path: string }];
@@ -33,11 +57,14 @@ interface WatchEntry {
/** /**
* Ignore tout sous `.git/` SAUF `HEAD` et `index` (⇒ on détecte le `git checkout` externe et le * Ignore tout sous `.git/` SAUF `HEAD` et `index` (⇒ on détecte le `git checkout` externe et le
* staging) ainsi que `node_modules`. chokidar n'ignore pas le dossier `.git` lui-même afin de * staging) ainsi que les répertoires de `IGNORED_DIRS`. chokidar n'ignore pas le dossier `.git`
* pouvoir descendre jusqu'à `HEAD`/`index`, mais saute ses sous-dossiers volumineux (objects…). * lui-même afin de pouvoir descendre jusqu'à `HEAD`/`index`, mais saute ses sous-dossiers
* volumineux (objects…).
*/ */
export function isIgnoredPath(p: string): boolean { export function isIgnoredPath(p: string): boolean {
if (p.includes(`${sep}node_modules${sep}`) || p.endsWith(`${sep}node_modules`)) return true; for (const dir of IGNORED_DIRS) {
if (p.includes(`${sep}${dir}${sep}`) || p.endsWith(`${sep}${dir}`)) return true;
}
if (p.includes(`${sep}.git${sep}`)) { if (p.includes(`${sep}.git${sep}`)) {
return !(p.endsWith(`${sep}HEAD`) || p.endsWith(`${sep}index`)); return !(p.endsWith(`${sep}HEAD`) || p.endsWith(`${sep}index`));
} }
+30 -10
View File
@@ -1,7 +1,7 @@
// Préparation d'un environnement d'authentification git ÉPHÉMÈRE (P12). HTTPS (pat/app_password) : // Préparation d'un environnement d'authentification git ÉPHÉMÈRE (P12). HTTPS (pat/app_password) :
// les identifiants sont fournis via GIT_ASKPASS (script 0o700 lisant deux variables d'env), JAMAIS // les identifiants sont fournis via GIT_ASKPASS (script à permissions restreintes lisant deux variables
// dans l'URL ni dans `.git/config`. GIT_TERMINAL_PROMPT=0 (pas d'invite bloquante). Le script est // d'env), JAMAIS dans l'URL ni dans `.git/config`. GIT_TERMINAL_PROMPT=0 (pas d'invite bloquante). Le
// supprimé en `finally` ; le secret ne transite que par l'env du process enfant (jamais loggé). // script est supprimé en `finally` ; le secret ne transite que par l'env du process enfant (jamais loggé).
import { mkdtemp, writeFile, rm, chmod } from 'node:fs/promises'; import { mkdtemp, writeFile, rm, chmod } from 'node:fs/promises';
import { tmpdir } from 'node:os'; import { tmpdir } from 'node:os';
import { join } from 'node:path'; import { join } from 'node:path';
@@ -11,20 +11,40 @@ import type { GitAuth } from './git-clients/index.js';
// Identité HTTPS par défaut quand l'utilisateur n'a pas fourni de username (token-as-password). // Identité HTTPS par défaut quand l'utilisateur n'a pas fourni de username (token-as-password).
const SERVICE_DEFAULT_USER: Record<GitService, string> = { github: 'x-access-token', gitlab: 'oauth2', gitea: 'oauth2' }; const SERVICE_DEFAULT_USER: Record<GitService, string> = { github: 'x-access-token', gitlab: 'oauth2', gitea: 'oauth2' };
const ASKPASS_SH = "#!/bin/sh\ncase \"$1\" in\n Username*) printf '%s' \"$ARB_GIT_USER\" ;;\n *) printf '%s' \"$ARB_GIT_PASS\" ;;\nesac\n";
// Équivalent Windows : git appelle GIT_ASKPASS avec l'invite en argument. `echo` de cmd.exe ajoute un
// saut de ligne que git tolère (il trime la réponse). `~1` = premier argument sans les guillemets.
const ASKPASS_CMD = [
'@echo off',
'echo %~1 | findstr /b /i "Username" >nul',
'if %errorlevel%==0 (echo %ARB_GIT_USER%) else (echo %ARB_GIT_PASS%)',
'',
].join('\r\n');
/**
* Nom et contenu du script askpass selon la plateforme. Un `.sh` avec shebang n'est PAS exécutable sur
* Windows : sans cette variante `.cmd`, tout clone/push HTTPS par jeton y échouait silencieusement
* (git n'obtenait aucun identifiant et abandonnait, GIT_TERMINAL_PROMPT étant à 0).
*/
export function askpassScript(platform: NodeJS.Platform = process.platform): { name: string; content: string; mode: number } {
return platform === 'win32'
? { name: 'askpass.cmd', content: ASKPASS_CMD, mode: 0o700 }
: { name: 'askpass.sh', content: ASKPASS_SH, mode: 0o700 };
}
export async function withGitAuth<T>( export async function withGitAuth<T>(
service: GitService, service: GitService,
auth: GitAuth, auth: GitAuth,
fn: (env: NodeJS.ProcessEnv) => Promise<T>, fn: (env: NodeJS.ProcessEnv) => Promise<T>,
): Promise<T> { ): Promise<T> {
const dir = await mkdtemp(join(tmpdir(), 'arb-gitauth-')); const dir = await mkdtemp(join(tmpdir(), 'arb-gitauth-'));
const askpass = join(dir, 'askpass.sh'); const script = askpassScript();
const askpass = join(dir, script.name);
const user = auth.username || SERVICE_DEFAULT_USER[service]; const user = auth.username || SERVICE_DEFAULT_USER[service];
await writeFile( await writeFile(askpass, script.content, { mode: script.mode });
askpass, // chmod best-effort : sans effet sur NTFS (comme ailleurs dans le code, cf. config.ts).
"#!/bin/sh\ncase \"$1\" in\n Username*) printf '%s' \"$ARB_GIT_USER\" ;;\n *) printf '%s' \"$ARB_GIT_PASS\" ;;\nesac\n", await chmod(askpass, script.mode).catch(() => {});
{ mode: 0o700 },
);
await chmod(askpass, 0o700);
const env: NodeJS.ProcessEnv = { const env: NodeJS.ProcessEnv = {
...process.env, ...process.env,
GIT_ASKPASS: askpass, GIT_ASKPASS: askpass,
+76 -1
View File
@@ -2,7 +2,7 @@
// les chemins/refs utilisateur. Fonctions pures sans état, prenant un cwd déjà validé par l'appelant. // les chemins/refs utilisateur. Fonctions pures sans état, prenant un cwd déjà validé par l'appelant.
import { execFile, spawn } from 'node:child_process'; import { execFile, spawn } from 'node:child_process';
import { resolve, sep } from 'node:path'; import { resolve, sep } from 'node:path';
import type { WorktreeGitStatus, WorktreeBranchAction, WorktreeBranchMode, FileChange } from '@arboretum/shared'; import type { WorktreeGitStatus, WorktreeBranchAction, WorktreeBranchMode, FileChange, CommitEntry } from '@arboretum/shared';
const GIT_TIMEOUT_MS = 10_000; const GIT_TIMEOUT_MS = 10_000;
// `push` peut dialoguer avec un remote (réseau) : on lui laisse une marge bien plus large. // `push` peut dialoguer avec un remote (réseau) : on lui laisse une marge bien plus large.
@@ -502,6 +502,81 @@ export async function lastCommit(worktreePath: string): Promise<{ hash: string;
return { hash: r.stdout.slice(0, idx), subject: r.stdout.slice(idx + 1).replace(/\n$/, '') }; return { hash: r.stdout.slice(0, idx), subject: r.stdout.slice(idx + 1).replace(/\n$/, '') };
} }
const MAX_LOG_LIMIT = 200;
/**
* Hash de commit : hexadécimal, 4 à 64 caractères. Bornage strict AVANT de le passer à git · un
* identifiant libre ouvrirait la porte à des révisions arbitraires ou à des options déguisées (`-…`).
*/
export function isValidCommitish(hash: string): boolean {
return /^[0-9a-f]{4,64}$/i.test(hash);
}
/**
* Découpe la sortie de `git log -z --format=<n champs séparés par NUL>` en enregistrements. Isolée et
* pure pour être testable sans dépôt : c'est le point délicat (avec `-z`, les séparateurs de champs et
* d'enregistrements sont tous des NUL, il faut donc compter les champs).
*/
export function parseLogZ(stdout: string, fieldsPerCommit: number): string[][] {
const fields = stdout.split('\0');
const out: string[][] = [];
for (let i = 0; i + fieldsPerCommit - 1 < fields.length; i += fieldsPerCommit) {
const rec = fields.slice(i, i + fieldsPerCommit);
if ((rec[0] ?? '').trim() === '') continue;
out.push(rec);
}
return out;
}
/**
* Historique de la branche du worktree. `-z` + champs séparés par NUL : un sujet contenant un saut de
* ligne ne peut pas casser le parsing. `unpushedCount` = commits de tête pas encore poussés
* (`@{u}..HEAD`) ; `hasUpstream: false` signifie qu'AUCUN commit n'est publié (branche purement locale),
* ce que l'UI marque en bloc plutôt que de compter tout l'historique.
*/
export async function commitLog(
worktreePath: string,
opts: { limit?: number; skip?: number } = {},
): Promise<{ commits: CommitEntry[]; unpushedCount: number; hasUpstream: boolean }> {
const limit = Math.min(Math.max(1, Math.trunc(opts.limit ?? 30)), MAX_LOG_LIMIT);
const skip = Math.max(0, Math.trunc(opts.skip ?? 0));
const r = await gitRaw(worktreePath, [
'log',
`--max-count=${limit}`,
`--skip=${skip}`,
'-z',
'--format=%H%x00%h%x00%an%x00%aI%x00%s',
]);
if (r.code !== 0) return { commits: [], unpushedCount: 0, hasUpstream: false }; // dépôt sans commit
const commits: CommitEntry[] = parseLogZ(r.stdout, 5).map((f) => ({
hash: (f[0] ?? '').trim(),
shortHash: f[1] ?? '',
author: f[2] ?? '',
date: f[3] ?? '',
subject: (f[4] ?? '').replace(/\n$/, ''),
}));
const upstream = await gitRaw(worktreePath, ['rev-parse', '--abbrev-ref', '--symbolic-full-name', '@{u}']);
if (upstream.code !== 0) return { commits, unpushedCount: 0, hasUpstream: false };
const count = await gitRaw(worktreePath, ['rev-list', '--count', '@{u}..HEAD']);
return { commits, unpushedCount: count.code === 0 ? Number(count.stdout.trim()) || 0 : 0, hasUpstream: true };
}
/**
* Diff complet d'un commit (`git show`), borné exactement comme `fileDiff` : refus des binaires,
* troncature au-delà de MAX_DIFF_BYTES. Le résultat étant un diff unifié, il passe dans le même
* parseur et la même vue que les diffs de fichiers.
*/
export async function commitDiff(worktreePath: string, hash: string): Promise<{ diff: string; binary: boolean; tooLarge: boolean }> {
if (!isValidCommitish(hash)) throw new Error(`Invalid commit hash: ${hash}`);
const out = await gitRaw(worktreePath, ['show', '--no-color', '--format=', hash]);
if (out.code !== 0) throw new Error(`Unknown commit: ${hash}`);
const raw = out.stdout;
const binary = /^Binary files .* differ$/m.test(raw) || raw.includes('GIT binary patch');
if (binary) return { diff: '', binary: true, tooLarge: false };
if (raw.length > MAX_DIFF_BYTES) return { diff: raw.slice(0, MAX_DIFF_BYTES), binary: false, tooLarge: true };
return { diff: raw, binary: false, tooLarge: false };
}
/** true si le HEAD courant n'est pas encore poussé (amend autorisé). Sans upstream → true. */ /** true si le HEAD courant n'est pas encore poussé (amend autorisé). Sans upstream → true. */
export async function isUnpushed(worktreePath: string): Promise<boolean> { export async function isUnpushed(worktreePath: string): Promise<boolean> {
try { try {
+83
View File
@@ -0,0 +1,83 @@
// Auto-détection des commandes de démarrage d'un projet (« Démarrer le projet »).
// Fonctions PURES et sans effet de bord notable : lecture bornée de quelques fichiers connus dans
// UN répertoire (jamais de récursion, jamais d'exécution). Tolérant : tout fichier absent/illisible
// est simplement ignoré. Les suggestions sont proposées à l'utilisateur, qui coche/ajuste.
import { existsSync, readFileSync } from 'node:fs';
import { randomUUID } from 'node:crypto';
import { join } from 'node:path';
import type { LaunchCommand } from '@arboretum/shared';
/** Taille max lue par fichier (garde-fou anti-fichier géant). */
const MAX_FILE_BYTES = 256 * 1024;
/** Noms de scripts npm activés par défaut (serveurs de dev longue durée) ; les autres sont proposés décochés. */
const DEFAULT_ENABLED_SCRIPT = /(^|:)(dev|start|serve|watch)(:|$)/i;
function readTextSafe(file: string): string | null {
try {
if (!existsSync(file)) return null;
// Lecture bornée : on tronque au-delà de MAX_FILE_BYTES (suffisant pour scripts / Procfile).
return readFileSync(file, 'utf8').slice(0, MAX_FILE_BYTES);
} catch {
return null;
}
}
/** Détecte le gestionnaire de paquets d'après le lockfile présent (défaut : npm). */
function detectRunner(dir: string): { cmd: string } {
if (existsSync(join(dir, 'pnpm-lock.yaml'))) return { cmd: 'pnpm run' };
if (existsSync(join(dir, 'yarn.lock'))) return { cmd: 'yarn' };
if (existsSync(join(dir, 'bun.lockb'))) return { cmd: 'bun run' };
return { cmd: 'npm run' };
}
function mk(label: string, run: string, enabled: boolean): LaunchCommand {
return { id: randomUUID(), label, run, enabled };
}
/** Scripts npm depuis package.json → `<runner> <script>`. */
function fromPackageJson(dir: string): LaunchCommand[] {
const raw = readTextSafe(join(dir, 'package.json'));
if (!raw) return [];
let scripts: Record<string, unknown> | undefined;
try {
const pkg = JSON.parse(raw) as { scripts?: Record<string, unknown> };
scripts = pkg.scripts;
} catch {
return [];
}
if (!scripts || typeof scripts !== 'object') return [];
const runner = detectRunner(dir);
return Object.keys(scripts)
.filter((name) => typeof scripts![name] === 'string')
.map((name) => mk(name, `${runner.cmd} ${name}`, DEFAULT_ENABLED_SCRIPT.test(name)));
}
/** Procfile (heroku/foreman) : lignes `name: command`. Toutes activées (ce sont des cibles d'exécution). */
function fromProcfile(dir: string): LaunchCommand[] {
const raw = readTextSafe(join(dir, 'Procfile'));
if (!raw) return [];
const out: LaunchCommand[] = [];
for (const line of raw.split(/\r?\n/)) {
const m = /^([A-Za-z0-9_-]+):\s*(.+)$/.exec(line.trim());
const name = m?.[1];
const cmd = m?.[2]?.trim();
if (name && cmd) out.push(mk(name, cmd, true));
}
return out;
}
/** docker-compose présent → suggestion `docker compose up` (énumération des services : évolution future). */
function fromDockerCompose(dir: string): LaunchCommand[] {
const names = ['docker-compose.yml', 'docker-compose.yaml', 'compose.yml', 'compose.yaml'];
const present = names.some((n) => existsSync(join(dir, n)));
return present ? [mk('docker', 'docker compose up', true)] : [];
}
/**
* Détecte des commandes de démarrage candidates dans `dir` (package.json, Procfile, docker-compose).
* Ne récurse pas et n'exécute rien. Renvoie [] si rien n'est détecté ou si `dir` est inaccessible.
*/
export function detectLaunchCommands(dir: string): LaunchCommand[] {
return [...fromPackageJson(dir), ...fromProcfile(dir), ...fromDockerCompose(dir)];
}
+59 -7
View File
@@ -1,4 +1,5 @@
import { EventEmitter } from 'node:events'; import { EventEmitter } from 'node:events';
import { execFile } from 'node:child_process';
import { existsSync, statSync } from 'node:fs'; import { existsSync, statSync } from 'node:fs';
import { randomUUID } from 'node:crypto'; import { randomUUID } from 'node:crypto';
import { homedir } from 'node:os'; import { homedir } from 'node:os';
@@ -40,8 +41,29 @@ type HistoricalRow = {
added_dirs: string | null; added_dirs: string | null;
group_id: string | null; group_id: string | null;
archived_at: string | null; archived_at: string | null;
launch_run_id: string | null;
}; };
/** Longueur max d'une commande auto-tapée (garde-fou ; une ligne shell raisonnable). */
const MAX_INITIAL_INPUT_LEN = 4096;
/**
* Assainit une commande de lancement avant de l'écrire dans le PTY : trim, borne de longueur,
* retrait de tous les caractères de contrôle (dont retours chariot/ligne : le `\r` de soumission
* est ajouté par l'appelant). Empêche l'injection de plusieurs lignes / séquences de contrôle par
* le champ de commande ; le modèle de menace reste inchangé (terminal = RCE par conception).
*/
function sanitizeInitialInput(raw: string): string {
let out = '';
for (const ch of raw.slice(0, MAX_INITIAL_INPUT_LEN)) {
const code = ch.codePointAt(0) ?? 0;
// saute les caractères de contrôle C0 (0x00-0x1F) et DEL (0x7F) : ni multi-lignes ni séquences ANSI.
if (code < 0x20 || code === 0x7f) continue;
out += ch;
}
return out.trim();
}
/** Parse la colonne `added_dirs` (JSON array de chemins) de façon défensive ; [] si NULL/invalide. */ /** Parse la colonne `added_dirs` (JSON array de chemins) de façon défensive ; [] si NULL/invalide. */
function parseAddedDirs(raw: string | null): string[] { function parseAddedDirs(raw: string | null): string[] {
if (!raw) return []; if (!raw) return [];
@@ -85,6 +107,8 @@ interface ManagedSession {
addedDirs: string[]; addedDirs: string[];
/** groupe propriétaire d'une session de groupe multi-repo ; null sinon (P6). */ /** groupe propriétaire d'une session de groupe multi-repo ; null sinon (P6). */
groupId: string | null; groupId: string | null;
/** identifiant partagé par les terminaux d'un même « Démarrer le projet » ; null sinon. */
launchRunId: string | null;
/** détection d'état fin (busy/waiting/idle + dialogue) ; null pour bash (P3-B). */ /** détection d'état fin (busy/waiting/idle + dialogue) ; null pour bash (P3-B). */
tracker: SessionActivityTracker | null; tracker: SessionActivityTracker | null;
/** dernière activité notifiée (détection du front montant vers `waiting` pour le push P4-B). */ /** dernière activité notifiée (détection du front montant vers `waiting` pour le push P4-B). */
@@ -117,6 +141,14 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
addDirs?: string[]; addDirs?: string[];
/** groupe propriétaire (session de groupe, P6). */ /** groupe propriétaire (session de groupe, P6). */
groupId?: string; groupId?: string;
/** shell de login interactif (charge le PATH utilisateur) : lancement de projet uniquement. */
login?: boolean;
/** commande auto-tapée dans le PTY juste après le spawn (« Démarrer le projet »). */
initialInput?: string;
/** titre initial de la session (libellé de l'onglet ; ex. label de commande de lancement). */
title?: string;
/** identifiant partagé par tous les terminaux d'un même lancement de projet. */
launchRunId?: string;
}): SessionSummary { }): SessionSummary {
const cwd = opts.cwd; const cwd = opts.cwd;
if (!existsSync(cwd) || !statSync(cwd).isDirectory()) { if (!existsSync(cwd) || !statSync(cwd).isDirectory()) {
@@ -138,6 +170,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
...(claudeBinPath ? { claudeBinPath } : {}), ...(claudeBinPath ? { claudeBinPath } : {}),
...(opts.resume ? { resume: opts.resume } : {}), ...(opts.resume ? { resume: opts.resume } : {}),
...(addedDirs.length ? { addDirs: addedDirs } : {}), ...(addedDirs.length ? { addDirs: addedDirs } : {}),
...(opts.login ? { login: true } : {}),
}); });
const id = randomUUID(); const id = randomUUID();
const proc = pty.spawn(spec.file, spec.args, { const proc = pty.spawn(spec.file, spec.args, {
@@ -151,7 +184,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
id, id,
cwd, cwd,
command, command,
title: null, title: opts.title ?? null,
createdAt: new Date().toISOString(), createdAt: new Date().toISOString(),
proc, proc,
ring: new RingBuffer(RING_CAPACITY), ring: new RingBuffer(RING_CAPACITY),
@@ -162,6 +195,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
claudeSessionId: null, claudeSessionId: null,
addedDirs, addedDirs,
groupId: opts.groupId ?? null, groupId: opts.groupId ?? null,
launchRunId: opts.launchRunId ?? null,
tracker: null, tracker: null,
prevActivity: null, prevActivity: null,
notifyTimer: null, notifyTimer: null,
@@ -177,19 +211,28 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
} }
this.live.set(id, session); this.live.set(id, session);
this.db this.db
.prepare('INSERT INTO sessions (id, cwd, command, created_at, resumed_from, added_dirs, group_id) VALUES (?, ?, ?, ?, ?, ?, ?)') .prepare('INSERT INTO sessions (id, cwd, command, title, created_at, resumed_from, added_dirs, group_id, launch_run_id) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)')
.run( .run(
id, id,
cwd, cwd,
command, command,
session.title,
session.createdAt, session.createdAt,
opts.resume?.claudeSessionId ?? null, opts.resume?.claudeSessionId ?? null,
addedDirs.length ? JSON.stringify(addedDirs) : null, addedDirs.length ? JSON.stringify(addedDirs) : null,
session.groupId, session.groupId,
session.launchRunId,
); );
proc.onData((data) => this.handleOutput(session, Buffer.from(data, 'utf8'))); proc.onData((data) => this.handleOutput(session, Buffer.from(data, 'utf8')));
proc.onExit(({ exitCode, signal }) => this.handleExit(session, exitCode, signal ?? null)); proc.onExit(({ exitCode, signal }) => this.handleExit(session, exitCode, signal ?? null));
// Auto-type de la commande de lancement APRÈS onData : la commande et sa sortie entrent dans le
// ring et sont rejouées à l'attach. Les octets sont mis en file par le tty tant que le shell
// n'a pas commencé à lire → pas de course. Un seul `\r` final (aligné sur answer()).
if (opts.initialInput) {
const line = sanitizeInitialInput(opts.initialInput);
if (line) proc.write(`${line}\r`);
}
if (command === 'claude') this.captureClaudeSessionId(session); if (command === 'claude') this.captureClaudeSessionId(session);
const summary = this.summarize(session); const summary = this.summarize(session);
@@ -269,7 +312,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
const liveSummaries = [...this.live.values()].map((s) => this.summarize(s)); const liveSummaries = [...this.live.values()].map((s) => this.summarize(s));
const liveIds = new Set(this.live.keys()); const liveIds = new Set(this.live.keys());
const rows = this.db const rows = this.db
.prepare('SELECT id, cwd, command, title, created_at, ended_at, exit_code, claude_session_id, added_dirs, group_id, archived_at FROM sessions ORDER BY created_at DESC LIMIT 100') .prepare('SELECT id, cwd, command, title, created_at, ended_at, exit_code, claude_session_id, added_dirs, group_id, archived_at, launch_run_id FROM sessions ORDER BY created_at DESC LIMIT 100')
.all() as HistoricalRow[]; .all() as HistoricalRow[];
const historical: SessionSummary[] = rows const historical: SessionSummary[] = rows
.filter((r) => !liveIds.has(r.id)) .filter((r) => !liveIds.has(r.id))
@@ -302,6 +345,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
registryStatus: null, registryStatus: null,
...(addedDirs.length ? { addedDirs } : {}), ...(addedDirs.length ? { addedDirs } : {}),
groupId: r.group_id, groupId: r.group_id,
launchRunId: r.launch_run_id,
archived: r.archived_at != null, archived: r.archived_at != null,
}; };
} }
@@ -314,7 +358,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
emitHistoricalUpdate(id: string): void { emitHistoricalUpdate(id: string): void {
if (this.live.has(id)) return; if (this.live.has(id)) return;
const r = this.db const r = this.db
.prepare('SELECT id, cwd, command, title, created_at, ended_at, exit_code, claude_session_id, added_dirs, group_id, archived_at FROM sessions WHERE id = ?') .prepare('SELECT id, cwd, command, title, created_at, ended_at, exit_code, claude_session_id, added_dirs, group_id, archived_at, launch_run_id FROM sessions WHERE id = ?')
.get(id) as HistoricalRow | undefined; .get(id) as HistoricalRow | undefined;
if (!r) return; if (!r) return;
this.emit('session_update', this.historicalSummary(r)); this.emit('session_update', this.historicalSummary(r));
@@ -329,18 +373,25 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
const s = this.live.get(id); const s = this.live.get(id);
if (!s || s.exited) return false; if (!s || s.exited) return false;
try { try {
process.kill(s.proc.pid, 'SIGTERM'); // Windows n'a pas de signaux : node-pty traduit `kill()` en fermeture de la pseudo-console, ce
// qui laisse échapper les petits-enfants (un `npm run dev` lancé dans le shell). Le SIGKILL
// différé est donc remplacé par un `taskkill /T` qui tue l'ARBRE complet.
if (process.platform === 'win32') s.proc.kill();
else process.kill(s.proc.pid, 'SIGTERM');
} catch { } catch {
return false; return false;
} }
s.killTimer ??= setTimeout(() => { s.killTimer ??= setTimeout(() => {
if (!s.exited) { if (s.exited) return;
try { try {
if (process.platform === 'win32') {
execFile('taskkill.exe', ['/PID', String(s.proc.pid), '/T', '/F'], () => {});
} else {
process.kill(s.proc.pid, 'SIGKILL'); process.kill(s.proc.pid, 'SIGKILL');
}
} catch { } catch {
/* déjà mort */ /* déjà mort */
} }
}
}, KILL_GRACE_MS); }, KILL_GRACE_MS);
return true; return true;
} }
@@ -558,6 +609,7 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
dialog: act?.dialog ?? null, dialog: act?.dialog ?? null,
...(s.addedDirs.length ? { addedDirs: s.addedDirs } : {}), ...(s.addedDirs.length ? { addedDirs: s.addedDirs } : {}),
groupId: s.groupId, groupId: s.groupId,
launchRunId: s.launchRunId,
}; };
} }
} }
+33
View File
@@ -0,0 +1,33 @@
// Adaptateur serveur de la corrélation session ↔ worktree : la RÈGLE vit dans `@arboretum/shared`
// (`path-match.ts`, partagée avec le front et l'extension) ; ici on se contente de normaliser les
// chemins avec `resolve()` avant de la lui passer, puisque le serveur manipule des chemins venant de
// git, de la base et de requêtes (fins de slash, `..`, chemins relatifs au cwd du process).
import { resolve } from 'node:path';
import {
containsPath as sharedContains,
findWorktreeForCwd as sharedFind,
sessionBelongsToWorktree as sharedBelongs,
} from '@arboretum/shared';
export function containsPath(parent: string, child: string): boolean {
return sharedContains(resolve(parent), resolve(child));
}
export function sessionBelongsToWorktree(
session: { cwd: string; addedDirs?: string[] },
worktreePath: string,
others: string[] = [],
): boolean {
return sharedBelongs(
{ cwd: resolve(session.cwd), ...(session.addedDirs ? { addedDirs: session.addedDirs.map((d) => resolve(d)) } : {}) },
resolve(worktreePath),
others.map((p) => resolve(p)),
);
}
export function findWorktreeForCwd<T extends { path: string }>(cwd: string, worktrees: T[]): T | null {
// On résout une copie pour la comparaison, puis on renvoie l'objet d'origine (le chemin brut est ce
// que le reste du code attend, notamment les clés du watcher FS).
const normalized = worktrees.map((w) => ({ w, path: resolve(w.path) }));
return sharedFind(resolve(cwd), normalized)?.w ?? null;
}
+189 -19
View File
@@ -9,6 +9,7 @@ import { existsSync, realpathSync } from 'node:fs';
import type { import type {
DiscoverReposResponse, DiscoverReposResponse,
HookRunResult, HookRunResult,
LaunchCommand,
PostCreateHook, PostCreateHook,
RepoSummary, RepoSummary,
SessionSummary, SessionSummary,
@@ -27,6 +28,8 @@ import {
amendCommit, amendCommit,
cleanFiles, cleanFiles,
commitAll, commitAll,
commitDiff,
commitLog,
commitStaged, commitStaged,
defaultBranch, defaultBranch,
fetchRemote, fetchRemote,
@@ -37,6 +40,7 @@ import {
isSafeRelativePath, isSafeRelativePath,
isUnpushed, isUnpushed,
isValidBranchName, isValidBranchName,
isValidCommitish,
listBranches, listBranches,
listChanges, listChanges,
listWorktrees, listWorktrees,
@@ -52,7 +56,8 @@ import {
type ParsedWorktree, type ParsedWorktree,
} from './git.js'; } from './git.js';
import type { FsWatcherService } from './fs-watcher.js'; import type { FsWatcherService } from './fs-watcher.js';
import type { FileChange, FileDiffResponse } from '@arboretum/shared'; import { findWorktreeForCwd, sessionBelongsToWorktree } from './session-match.js';
import type { CommitDiffResponse, FileChange, FileDiffResponse, WorktreeLogResponse } from '@arboretum/shared';
const FACTS_TTL_MS = 2500; const FACTS_TTL_MS = 2500;
const HOOK_TIMEOUT_MS = 5 * 60_000; const HOOK_TIMEOUT_MS = 5 * 60_000;
@@ -71,6 +76,8 @@ interface RepoRow {
pre_trust: number; pre_trust: number;
created_at: string; created_at: string;
hidden: number; hidden: number;
/** commandes de démarrage du projet (JSON array de LaunchCommand) ; '[]' par défaut. */
launch_commands: string;
} }
export interface WorktreeManagerEvents { export interface WorktreeManagerEvents {
@@ -101,6 +108,28 @@ function parseHooks(json: string): PostCreateHook[] {
} }
} }
/** Parse la colonne `launch_commands` (JSON array de LaunchCommand) de façon défensive ; [] si invalide. */
function parseLaunchCommands(json: string): LaunchCommand[] {
try {
const arr = JSON.parse(json) as unknown;
if (!Array.isArray(arr)) return [];
return arr
.filter(
(c): c is LaunchCommand =>
!!c && typeof c.id === 'string' && typeof c.label === 'string' && typeof c.run === 'string' && typeof c.enabled === 'boolean',
)
.map((c) => ({
id: c.id,
label: c.label,
run: c.run,
enabled: c.enabled,
...(typeof c.cwd === 'string' && c.cwd.trim() !== '' ? { cwd: c.cwd } : {}),
}));
} catch {
return [];
}
}
function runHook(cwd: string, hook: PostCreateHook): Promise<HookRunResult> { function runHook(cwd: string, hook: PostCreateHook): Promise<HookRunResult> {
return new Promise((resolveP) => { return new Promise((resolveP) => {
const t0 = Date.now(); const t0 = Date.now();
@@ -128,6 +157,8 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
private readonly locks = new Map<string, Promise<unknown>>(); private readonly locks = new Map<string, Promise<unknown>>();
/** Scan de découverte en cours : coalesce boot + bouton + périodique sur un seul scan. */ /** Scan de découverte en cours : coalesce boot + bouton + périodique sur un seul scan. */
private scanInFlight: Promise<DiscoverReposResponse> | null = null; private scanInFlight: Promise<DiscoverReposResponse> | null = null;
/** Worktree épinglé au watcher FS pour chaque session vivante (clé = id de session). */
private readonly pinnedSessions = new Map<string, { repoId: string; path: string }>();
constructor( constructor(
private readonly db: Db, private readonly db: Db,
@@ -145,6 +176,46 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
if (row) void this.emitWorktree(row, path).catch(() => {}); if (row) void this.emitWorktree(row, path).catch(() => {});
this.emit('worktree_changes', { repoId, path }); this.emit('worktree_changes', { repoId, path });
}); });
// Une session vivante rend son worktree « actif » : on épingle son watcher FS pour que les
// compteurs git restent temps réel même si aucun client ne regarde ce worktree. C'est le cas
// nominal du travail en CLI : l'agent écrit dans un worktree de feature pendant qu'on regarde
// ailleurs. Sans cette épingle, le point « modifié » de l'arbre restait figé sur le dernier
// listing REST.
this.ptyManager.on('session_update', (s) => {
void this.syncSessionPin(s).catch(() => {});
});
}
/** Épingle (session vivante) ou libère (session terminée) le watcher FS du worktree d'une session. */
private async syncSessionPin(s: SessionSummary): Promise<void> {
if (!this.fsWatcher) return;
const pinned = this.pinnedSessions.get(s.id);
if (!s.live) {
if (!pinned) return;
this.pinnedSessions.delete(s.id);
this.fsWatcher.unpinSession(pinned.repoId, pinned.path);
return;
}
if (pinned) return; // déjà épinglé : `session_update` bat au rythme de l'activité
const target = await this.resolveWorktreeForCwd(s.cwd);
if (!target) return; // session hors de tout repo enregistré
this.pinnedSessions.set(s.id, target);
this.fsWatcher.pinSession(target.repoId, target.path);
}
/**
* Worktree connu (tous repos non masqués) contenant ce cwd, le plus spécifique. Un worktree lié vit
* souvent HORS de l'arborescence de son repo : on ne peut donc pas écarter un repo sur son seul
* chemin, il faut ses worktrees réels (servis par le cache court partagé avec les listings).
*/
private async resolveWorktreeForCwd(cwd: string): Promise<{ repoId: string; path: string } | null> {
const rows = this.db.prepare('SELECT id, path FROM repos WHERE hidden = 0').all() as unknown as Array<{ id: string; path: string }>;
const candidates: Array<{ repoId: string; path: string }> = [];
for (const row of rows) {
const facts = await this.repoFacts(row).catch(() => []);
for (const f of facts) candidates.push({ repoId: row.id, path: f.w.path });
}
return findWorktreeForCwd(cwd, candidates);
} }
// ---- repos ---- // ---- repos ----
@@ -160,6 +231,7 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
label: row.label, label: row.label,
defaultBranch: row.default_branch, defaultBranch: row.default_branch,
postCreateHooks: parseHooks(row.post_create_hooks), postCreateHooks: parseHooks(row.post_create_hooks),
launchCommands: parseLaunchCommands(row.launch_commands),
preTrust: row.pre_trust === 1, preTrust: row.pre_trust === 1,
createdAt: row.created_at, createdAt: row.created_at,
valid: await isRepo(row.path), valid: await isRepo(row.path),
@@ -167,12 +239,18 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
}; };
} }
/** Résumé d'un repo par id (null si inconnu). Sert notamment au lancement de projet. */
async getRepo(id: string): Promise<RepoSummary | null> {
const row = this.getRepoRow(id);
return row ? this.rowToSummary(row) : null;
}
async listRepos(): Promise<RepoSummary[]> { async listRepos(): Promise<RepoSummary[]> {
const rows = this.db.prepare('SELECT * FROM repos ORDER BY created_at ASC').all() as unknown as RepoRow[]; const rows = this.db.prepare('SELECT * FROM repos ORDER BY created_at ASC').all() as unknown as RepoRow[];
return Promise.all(rows.map((r) => this.rowToSummary(r))); return Promise.all(rows.map((r) => this.rowToSummary(r)));
} }
async addRepo(opts: { path: string; label?: string; postCreateHooks?: PostCreateHook[]; preTrust?: boolean }): Promise<RepoSummary> { async addRepo(opts: { path: string; label?: string; postCreateHooks?: PostCreateHook[]; preTrust?: boolean; launchCommands?: LaunchCommand[] }): Promise<RepoSummary> {
const path = opts.path; const path = opts.path;
if (!isSafeAbsolutePath(path)) throw httpError(400, 'BAD_REQUEST', 'path must be an absolute, normalized path'); if (!isSafeAbsolutePath(path)) throw httpError(400, 'BAD_REQUEST', 'path must be an absolute, normalized path');
if (!(await isRepo(path))) throw httpError(400, 'NOT_A_REPO', `Not a git repository root: ${path}`); if (!(await isRepo(path))) throw httpError(400, 'NOT_A_REPO', `Not a git repository root: ${path}`);
@@ -187,11 +265,12 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
pre_trust: opts.preTrust ? 1 : 0, pre_trust: opts.preTrust ? 1 : 0,
created_at: new Date().toISOString(), created_at: new Date().toISOString(),
hidden: 0, hidden: 0,
launch_commands: JSON.stringify(opts.launchCommands ?? []),
}; };
try { try {
this.db this.db
.prepare('INSERT INTO repos (id, path, label, default_branch, post_create_hooks, pre_trust, created_at, hidden) VALUES (?, ?, ?, ?, ?, ?, ?, ?)') .prepare('INSERT INTO repos (id, path, label, default_branch, post_create_hooks, pre_trust, created_at, hidden, launch_commands) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)')
.run(row.id, row.path, row.label, row.default_branch, row.post_create_hooks, row.pre_trust, row.created_at, row.hidden); .run(row.id, row.path, row.label, row.default_branch, row.post_create_hooks, row.pre_trust, row.created_at, row.hidden, row.launch_commands);
} catch (err) { } catch (err) {
// Course possible avec un scan concurrent qui aurait inséré le même path entre le SELECT // Course possible avec un scan concurrent qui aurait inséré le même path entre le SELECT
// d'unicité et cet INSERT (contrainte UNIQUE sur path) → on rend le même 409 explicite. // d'unicité et cet INSERT (contrainte UNIQUE sur path) → on rend le même 409 explicite.
@@ -220,16 +299,17 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
this.fsWatcher?.pinRepo(row.id, resolve(row.path)); this.fsWatcher?.pinRepo(row.id, resolve(row.path));
} }
async updateRepo(id: string, patch: { label?: string; postCreateHooks?: PostCreateHook[]; preTrust?: boolean; hidden?: boolean }): Promise<RepoSummary> { async updateRepo(id: string, patch: { label?: string; postCreateHooks?: PostCreateHook[]; preTrust?: boolean; hidden?: boolean; launchCommands?: LaunchCommand[] }): Promise<RepoSummary> {
const row = this.getRepoRow(id); const row = this.getRepoRow(id);
if (!row) throw httpError(404, 'NOT_FOUND', 'No repo with this id'); if (!row) throw httpError(404, 'NOT_FOUND', 'No repo with this id');
if (patch.label !== undefined) row.label = patch.label.trim() || row.label; if (patch.label !== undefined) row.label = patch.label.trim() || row.label;
if (patch.postCreateHooks !== undefined) row.post_create_hooks = JSON.stringify(patch.postCreateHooks); if (patch.postCreateHooks !== undefined) row.post_create_hooks = JSON.stringify(patch.postCreateHooks);
if (patch.preTrust !== undefined) row.pre_trust = patch.preTrust ? 1 : 0; if (patch.preTrust !== undefined) row.pre_trust = patch.preTrust ? 1 : 0;
if (patch.hidden !== undefined) row.hidden = patch.hidden ? 1 : 0; if (patch.hidden !== undefined) row.hidden = patch.hidden ? 1 : 0;
if (patch.launchCommands !== undefined) row.launch_commands = JSON.stringify(patch.launchCommands);
this.db this.db
.prepare('UPDATE repos SET label = ?, post_create_hooks = ?, pre_trust = ?, hidden = ? WHERE id = ?') .prepare('UPDATE repos SET label = ?, post_create_hooks = ?, pre_trust = ?, hidden = ?, launch_commands = ? WHERE id = ?')
.run(row.label, row.post_create_hooks, row.pre_trust, row.hidden, id); .run(row.label, row.post_create_hooks, row.pre_trust, row.hidden, row.launch_commands, id);
const summary = await this.rowToSummary(row); const summary = await this.rowToSummary(row);
this.emit('repo_update', summary); this.emit('repo_update', summary);
// P11 : masqué → on libère le watcher permanent du principal ; ré-affiché → on le réarme. // P11 : masqué → on libère le watcher permanent du principal ; ré-affiché → on le réarme.
@@ -287,6 +367,7 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
pre_trust: 0, pre_trust: 0,
created_at: new Date().toISOString(), created_at: new Date().toISOString(),
hidden: 0, hidden: 0,
launch_commands: '[]',
}; };
const res = insert.run(row.id, row.path, row.label, row.created_at); const res = insert.run(row.id, row.path, row.label, row.created_at);
if (res.changes === 1) { if (res.changes === 1) {
@@ -301,20 +382,28 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
// ---- worktrees ---- // ---- worktrees ----
/** /**
* Sessions (managées + découvertes) dont le cwd correspond à ce chemin de worktree. * Sessions (managées + découvertes) rattachées à ce worktree : cwd dans le worktree (y compris un
* sous-répertoire de « Démarrer le projet ») ou worktree relié en `--add-dir` par une session de
* groupe · voir `sessionBelongsToWorktree`. `siblings` = les autres worktrees du repo, indispensables
* pour qu'un worktree imbriqué ne voie pas ses sessions attribuées aussi au checkout principal.
* Les sessions explicitement masquées (`hidden`) sont exclues, cohérent avec `/api/v1/sessions` * Les sessions explicitement masquées (`hidden`) sont exclues, cohérent avec `/api/v1/sessions`
* (sans quoi le masquage était ignoré dans les fiches worktree). Le tri managées/externes est laissé * (sans quoi le masquage était ignoré dans les fiches worktree). Le tri managées/externes est laissé
* au client (interrupteur « afficher les externes »), qui dispose du champ `source`. La garde de * au client (interrupteur « afficher les externes »), qui dispose du champ `source`. La garde de
* suppression réclame en revanche TOUTES les sessions vivantes (`includeHidden`) pour rester sûre. * suppression réclame en revanche TOUTES les sessions vivantes (`includeHidden`) pour rester sûre.
*/ */
private sessionsForCwd(path: string, opts?: { includeHidden?: boolean }): SessionSummary[] { private sessionsForCwd(path: string, opts?: { includeHidden?: boolean; siblings?: string[] }): SessionSummary[] {
const rp = resolve(path);
return mergeSessions(this.ptyManager.list(), this.discovery.list()) return mergeSessions(this.ptyManager.list(), this.discovery.list())
.filter((s) => resolve(s.cwd) === rp) .filter((s) => sessionBelongsToWorktree(s, path, opts?.siblings ?? []))
.filter((s) => opts?.includeHidden || !s.hidden); .filter((s) => opts?.includeHidden || !s.hidden);
} }
private toSummary(repoId: string, repoPath: string, w: ParsedWorktree, status: WorktreeGitStatus): WorktreeSummary { private toSummary(
repoId: string,
repoPath: string,
w: ParsedWorktree,
status: WorktreeGitStatus,
siblings: string[] = [],
): WorktreeSummary {
return { return {
repoId, repoId,
path: w.path, path: w.path,
@@ -325,11 +414,11 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
prunable: w.prunable, prunable: w.prunable,
isMain: resolve(w.path) === resolve(repoPath), isMain: resolve(w.path) === resolve(repoPath),
git: status, git: status,
sessions: this.sessionsForCwd(w.path), sessions: this.sessionsForCwd(w.path, { siblings }),
}; };
} }
private async repoFacts(row: RepoRow, noCache = false): Promise<Array<{ w: ParsedWorktree; status: WorktreeGitStatus }>> { private async repoFacts(row: { id: string; path: string }, noCache = false): Promise<Array<{ w: ParsedWorktree; status: WorktreeGitStatus }>> {
const cached = this.factsCache.get(row.id); const cached = this.factsCache.get(row.id);
if (!noCache && cached && Date.now() - cached.at < FACTS_TTL_MS) return cached.facts; if (!noCache && cached && Date.now() - cached.at < FACTS_TTL_MS) return cached.facts;
const parsed = (await listWorktrees(row.path)).filter((w) => !w.bare); const parsed = (await listWorktrees(row.path)).filter((w) => !w.bare);
@@ -342,7 +431,8 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
const row = this.getRepoRow(repoId); const row = this.getRepoRow(repoId);
if (!row) return []; if (!row) return [];
const facts = await this.repoFacts(row, noCache); const facts = await this.repoFacts(row, noCache);
return facts.map(({ w, status }) => this.toSummary(row.id, row.path, w, status)); const paths = facts.map(({ w }) => w.path);
return facts.map(({ w, status }) => this.toSummary(row.id, row.path, w, status, paths));
} }
async listAllWorktrees(): Promise<WorktreeSummary[]> { async listAllWorktrees(): Promise<WorktreeSummary[]> {
@@ -376,9 +466,19 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
} }
private async emitWorktree(row: RepoRow, path: string): Promise<WorktreeSummary | null> { private async emitWorktree(row: RepoRow, path: string): Promise<WorktreeSummary | null> {
const w = await this.findWorktree(row, path); // On liste tous les worktrees du repo (et pas seulement celui visé) pour désambiguïser la
// corrélation des sessions entre worktrees imbriqués (cf. sessionsForCwd).
const all = (await listWorktrees(row.path)).filter((w) => !w.bare);
const rp = resolve(path);
const w = all.find((x) => resolve(x.path) === rp);
if (!w) return null; if (!w) return null;
const summary = this.toSummary(row.id, row.path, w, await worktreeStatus(w.path)); const summary = this.toSummary(
row.id,
row.path,
w,
await worktreeStatus(w.path),
all.map((x) => x.path),
);
this.emit('worktree_update', { repoId: row.id, worktree: summary }); this.emit('worktree_update', { repoId: row.id, worktree: summary });
return summary; return summary;
} }
@@ -485,6 +585,25 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
return listChanges(w.path); return listChanges(w.path);
} }
/** Historique de la branche du worktree (lecture, hors lock) : « ce qui a déjà été acté ». */
async getWorktreeLog(repoId: string, path: string, opts: { limit?: number; skip?: number }): Promise<WorktreeLogResponse> {
const { w } = await this.requireWorktree(repoId, path);
const { commits, unpushedCount, hasUpstream } = await commitLog(w.path, opts);
return { repoId, path: w.path, commits, unpushedCount, hasUpstream };
}
/** Diff unifié complet d'un commit (lecture, hors lock). Le hash est validé par la couche git. */
async getCommitDiff(repoId: string, path: string, hash: string): Promise<CommitDiffResponse> {
const { w } = await this.requireWorktree(repoId, path);
if (!isValidCommitish(hash)) throw httpError(400, 'BAD_COMMIT', 'Invalid commit hash');
try {
const d = await commitDiff(w.path, hash);
return { path: w.path, commit: hash, binary: d.binary, tooLarge: d.tooLarge, diff: d.diff };
} catch (err) {
throw httpError(404, 'NOT_FOUND', (err as Error).message);
}
}
/** Diff unifié d'un fichier (détecte untracked → `git diff --no-index`). Lecture, hors lock. */ /** Diff unifié d'un fichier (détecte untracked → `git diff --no-index`). Lecture, hors lock. */
async getFileDiff(repoId: string, path: string, file: string, staged: boolean): Promise<FileDiffResponse> { async getFileDiff(repoId: string, path: string, file: string, staged: boolean): Promise<FileDiffResponse> {
const { w } = await this.requireWorktree(repoId, path); const { w } = await this.requireWorktree(repoId, path);
@@ -601,6 +720,55 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
return abs; return abs;
} }
/**
* « Démarrer le projet » : résout le répertoire de base du lancement. Priorité au worktree
* `worktreePath` (validé comme worktree connu du repo), sinon worktree portant `branch`, sinon
* checkout principal. Le client ne passe JAMAIS un chemin brut non validé (défense en profondeur).
*/
async resolveLaunchBase(repoId: string, opts: { worktreePath?: string; branch?: string }): Promise<string> {
const row = this.getRepoRow(repoId);
if (!row) throw httpError(404, 'NOT_FOUND', 'No repo with this id');
const wp = opts.worktreePath?.trim();
if (wp) {
if (!isSafeAbsolutePath(wp)) throw httpError(400, 'BAD_PATH', 'Worktree path must be absolute and normalized');
const w = await this.findWorktree(row, wp);
if (!w) throw httpError(404, 'NO_RESOLVABLE_WORKTREE', 'No such worktree under this repo');
return resolve(w.path);
}
const branch = opts.branch?.trim();
if (branch) {
const wts = await this.listRepoWorktrees(repoId);
const match = wts.find((w) => w.branch === branch);
if (!match) throw httpError(404, 'NO_RESOLVABLE_WORKTREE', `No worktree on branch ${branch}`);
return resolve(match.path);
}
return resolve(row.path); // checkout principal
}
/**
* Résout le sous-répertoire relatif d'une commande de lancement, borné au répertoire de base
* (anti `..`, anti symlink sortant), calqué sur assertPathInWorktree. Renvoie `base` si vide.
*/
resolveLaunchSubdir(baseDir: string, relCwd?: string): string {
const base = resolve(baseDir);
const rel = relCwd?.trim();
if (!rel) return base;
if (!isSafeRelativePath(rel)) throw httpError(400, 'BAD_PATH', 'Invalid launch cwd');
const abs = resolve(join(base, rel));
if (abs !== base && !abs.startsWith(base + sep)) throw httpError(403, 'PATH_OUTSIDE_WORKTREE', 'Launch cwd escapes the worktree');
if (existsSync(abs)) {
let real: string;
try {
real = realpathSync(abs);
} catch {
throw httpError(400, 'BAD_PATH', 'Cannot resolve launch cwd');
}
const realBase = realpathSync(base);
if (real !== realBase && !real.startsWith(realBase + sep)) throw httpError(403, 'PATH_OUTSIDE_WORKTREE', 'Launch cwd escapes the worktree (symlink)');
}
return abs;
}
/** Arme le watcher FS sur un worktree (validé) pour le push temps réel du détail. */ /** Arme le watcher FS sur un worktree (validé) pour le push temps réel du détail. */
async watch(repoId: string, path: string): Promise<void> { async watch(repoId: string, path: string): Promise<void> {
if (!this.fsWatcher) return; if (!this.fsWatcher) return;
@@ -729,8 +897,10 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
const w = await this.findWorktree(row, path); const w = await this.findWorktree(row, path);
if (!w) throw httpError(404, 'NOT_FOUND', 'No such worktree under this repo'); if (!w) throw httpError(404, 'NOT_FOUND', 'No such worktree under this repo');
if (resolve(w.path) === resolve(row.path)) throw httpError(400, 'IS_MAIN_WORKTREE', 'Cannot remove the main worktree'); if (resolve(w.path) === resolve(row.path)) throw httpError(400, 'IS_MAIN_WORKTREE', 'Cannot remove the main worktree');
// garde-fou : une session vivante tourne dans ce worktree → exiger une confirmation explicite. // garde-fou : une session vivante tourne dans ce worktree (ou dans un de ses sous-répertoires, ou
if (!force && this.sessionsForCwd(w.path, { includeHidden: true }).some((s) => s.live)) { // le relie en `--add-dir`) → exiger une confirmation explicite.
const siblings = (await listWorktrees(row.path)).map((x) => x.path);
if (!force && this.sessionsForCwd(w.path, { includeHidden: true, siblings }).some((s) => s.live)) {
throw httpError(409, 'SESSION_LIVE_IN_WORKTREE', 'A live session runs in this worktree: pass force to delete anyway'); throw httpError(409, 'SESSION_LIVE_IN_WORKTREE', 'A live session runs in this worktree: pass force to delete anyway');
} }
return this.withLock(repoId, async () => { return this.withLock(repoId, async () => {
+10
View File
@@ -191,6 +191,16 @@ const MIGRATIONS: Array<{ id: number; sql: string }> = [
ALTER TABLE repos ADD COLUMN credential_id TEXT; ALTER TABLE repos ADD COLUMN credential_id TEXT;
`, `,
}, },
{
// « Démarrer le projet » : commandes de démarrage multi-terminaux, stockées en JSON sur le
// repo (miroir de post_create_hooks). Chaque terminal lancé porte un launch_run_id partagé
// (regroupement UI + « tout arrêter ») ; pas de FK (cohérent avec sessions.group_id #8).
id: 13,
sql: `
ALTER TABLE repos ADD COLUMN launch_commands TEXT NOT NULL DEFAULT '[]';
ALTER TABLE sessions ADD COLUMN launch_run_id TEXT;
`,
},
]; ];
export type Db = DatabaseSync; export type Db = DatabaseSync;
+42 -4
View File
@@ -5,7 +5,9 @@
import type { FastifyInstance } from 'fastify'; import type { FastifyInstance } from 'fastify';
import type { import type {
WorktreeChangesResponse, WorktreeChangesResponse,
CommitDiffResponse,
FileDiffResponse, FileDiffResponse,
WorktreeLogResponse,
WorktreeFilesRequest, WorktreeFilesRequest,
DiscardFilesRequest, DiscardFilesRequest,
FetchWorktreeRequest, FetchWorktreeRequest,
@@ -33,12 +35,48 @@ export function registerGitRoutes(app: FastifyInstance, wt: WorktreeManager, db:
} }
}); });
// Diff unifié d'un fichier (staged ou non ; untracked détecté côté manager). // Historique de la branche du worktree (« ce qui a déjà été acté », + ce qui n'est pas poussé).
app.get('/api/v1/repos/:id/worktrees/log', async (req, reply) => {
const { id } = req.params as { id: string };
const q = req.query as { path?: string; limit?: string; skip?: string };
if (typeof q.path !== 'string' || q.path === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'path is required' } });
}
// Bornes appliquées côté couche git (limite dure) : ici on se contente de convertir.
const limit = q.limit !== undefined ? Number(q.limit) : undefined;
const skip = q.skip !== undefined ? Number(q.skip) : undefined;
if ((limit !== undefined && !Number.isFinite(limit)) || (skip !== undefined && !Number.isFinite(skip))) {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'limit and skip must be numbers' } });
}
try {
const res = await wt.getWorktreeLog(id, q.path, {
...(limit !== undefined ? { limit } : {}),
...(skip !== undefined ? { skip } : {}),
});
return reply.send(res satisfies WorktreeLogResponse);
} catch (err) {
return sendManagerError(reply, err);
}
});
// Diff unifié : d'un fichier (`file`), ou d'un commit entier (`commit`). Les deux formes renvoient un
// diff unifié, donc le même parseur et la même vue côté client.
app.get('/api/v1/repos/:id/worktrees/diff', async (req, reply) => { app.get('/api/v1/repos/:id/worktrees/diff', async (req, reply) => {
const { id } = req.params as { id: string }; const { id } = req.params as { id: string };
const q = req.query as { path?: string; file?: string; staged?: string }; const q = req.query as { path?: string; file?: string; staged?: string; commit?: string };
if (typeof q.path !== 'string' || q.path === '' || typeof q.file !== 'string' || q.file === '') { if (typeof q.path !== 'string' || q.path === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'path and file are required' } }); return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'path is required' } });
}
if (typeof q.commit === 'string' && q.commit !== '') {
try {
const res = await wt.getCommitDiff(id, q.path, q.commit);
return reply.send(res satisfies CommitDiffResponse);
} catch (err) {
return sendManagerError(reply, err);
}
}
if (typeof q.file !== 'string' || q.file === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'file or commit is required' } });
} }
const staged = q.staged === '1' || q.staged === 'true'; const staged = q.staged === '1' || q.staged === 'true';
try { try {
+93 -2
View File
@@ -1,8 +1,22 @@
import type { FastifyInstance, FastifyReply } from 'fastify'; import type { FastifyInstance, FastifyReply } from 'fastify';
import type { CreateRepoRequest, DiscoverReposResponse, RepoResponse, ReposListResponse, UpdateRepoRequest } from '@arboretum/shared'; import { randomUUID } from 'node:crypto';
import type {
CreateRepoRequest,
DetectLaunchResponse,
DiscoverReposResponse,
RepoResponse,
ReposListResponse,
SessionSummary,
StartLaunchRequest,
StartLaunchResponse,
UpdateRepoRequest,
} from '@arboretum/shared';
import type { WorktreeManager } from '../core/worktree-manager.js'; import type { WorktreeManager } from '../core/worktree-manager.js';
import type { PtyManager } from '../core/pty-manager.js';
import type { Db } from '../db/index.js'; import type { Db } from '../db/index.js';
import { readScanRoots } from '../core/scan-settings.js'; import { readScanRoots } from '../core/scan-settings.js';
import { recordAudit } from '../core/audit-log.js';
import { detectLaunchCommands } from '../core/launch-detect.js';
/** Mappe une erreur du manager (statusCode + code) vers une réponse REST normalisée. */ /** Mappe une erreur du manager (statusCode + code) vers une réponse REST normalisée. */
export function sendManagerError(reply: FastifyReply, err: unknown): FastifyReply { export function sendManagerError(reply: FastifyReply, err: unknown): FastifyReply {
@@ -10,7 +24,7 @@ export function sendManagerError(reply: FastifyReply, err: unknown): FastifyRepl
return reply.status(e.statusCode ?? 500).send({ error: { code: e.code ?? 'INTERNAL', message: e.message ?? 'Internal error' } }); return reply.status(e.statusCode ?? 500).send({ error: { code: e.code ?? 'INTERNAL', message: e.message ?? 'Internal error' } });
} }
export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager, db: Db): void { export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager, db: Db, manager: PtyManager): void {
app.get('/api/v1/repos', async (): Promise<ReposListResponse> => ({ repos: await wt.listRepos() })); app.get('/api/v1/repos', async (): Promise<ReposListResponse> => ({ repos: await wt.listRepos() }));
// Scan manuel : découvre et auto-enregistre les repos sous les racines configurées (settings). // Scan manuel : découvre et auto-enregistre les repos sous les racines configurées (settings).
@@ -34,6 +48,7 @@ export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager, db
...(body.label !== undefined ? { label: body.label } : {}), ...(body.label !== undefined ? { label: body.label } : {}),
...(body.postCreateHooks !== undefined ? { postCreateHooks: body.postCreateHooks } : {}), ...(body.postCreateHooks !== undefined ? { postCreateHooks: body.postCreateHooks } : {}),
...(body.preTrust !== undefined ? { preTrust: body.preTrust } : {}), ...(body.preTrust !== undefined ? { preTrust: body.preTrust } : {}),
...(body.launchCommands !== undefined ? { launchCommands: body.launchCommands } : {}),
}); });
const res: RepoResponse = { repo }; const res: RepoResponse = { repo };
return reply.status(201).send(res); return reply.status(201).send(res);
@@ -51,6 +66,7 @@ export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager, db
...(body.postCreateHooks !== undefined ? { postCreateHooks: body.postCreateHooks } : {}), ...(body.postCreateHooks !== undefined ? { postCreateHooks: body.postCreateHooks } : {}),
...(body.preTrust !== undefined ? { preTrust: body.preTrust } : {}), ...(body.preTrust !== undefined ? { preTrust: body.preTrust } : {}),
...(typeof body.hidden === 'boolean' ? { hidden: body.hidden } : {}), ...(typeof body.hidden === 'boolean' ? { hidden: body.hidden } : {}),
...(body.launchCommands !== undefined ? { launchCommands: body.launchCommands } : {}),
}); });
const res: RepoResponse = { repo }; const res: RepoResponse = { repo };
return reply.send(res); return reply.send(res);
@@ -66,4 +82,79 @@ export function registerRepoRoutes(app: FastifyInstance, wt: WorktreeManager, db
} }
return reply.send({ ok: true }); return reply.send({ ok: true });
}); });
// « Démarrer le projet » : suggestions de commandes détectées dans le répertoire cible
// (package.json/Procfile/docker-compose). Le worktree cible est résolu côté serveur.
app.get('/api/v1/repos/:id/launch/detect', async (req, reply) => {
const { id } = req.params as { id: string };
const query = (req.query as { worktreePath?: string }) ?? {};
try {
const base = await wt.resolveLaunchBase(id, {
...(typeof query.worktreePath === 'string' ? { worktreePath: query.worktreePath } : {}),
});
return reply.send({ suggestions: detectLaunchCommands(base) } satisfies DetectLaunchResponse);
} catch (err) {
return sendManagerError(reply, err);
}
});
// « Démarrer le projet » : lance un terminal (session managée) par commande activée, tous reliés
// par un même launchRunId. Le cwd de chaque terminal est borné au worktree cible (anti-traversal).
app.post('/api/v1/repos/:id/launch', async (req, reply) => {
const { id } = req.params as { id: string };
const body = (req.body as Partial<StartLaunchRequest> | null) ?? {};
let repo;
try {
repo = await wt.getRepo(id);
} catch (err) {
return sendManagerError(reply, err);
}
if (!repo) return reply.status(404).send({ error: { code: 'NOT_FOUND', message: 'No repo with this id' } });
// Sélection explicite par `commandIds` (outrepasse `enabled`) ; sinon toutes les commandes activées.
const wanted = Array.isArray(body.commandIds) ? new Set(body.commandIds) : null;
const commands = wanted ? repo.launchCommands.filter((c) => wanted.has(c.id)) : repo.launchCommands.filter((c) => c.enabled);
if (commands.length === 0) {
return reply.status(400).send({ error: { code: 'NO_LAUNCH_COMMANDS', message: 'No launch command to start (define or enable commands first)' } });
}
let base: string;
try {
base = await wt.resolveLaunchBase(id, {
...(typeof body.worktreePath === 'string' ? { worktreePath: body.worktreePath } : {}),
...(typeof body.branch === 'string' ? { branch: body.branch } : {}),
});
} catch (err) {
return sendManagerError(reply, err);
}
const launchRunId = randomUUID();
const sessions: SessionSummary[] = [];
const skipped: Array<{ id: string; reason: string }> = [];
for (const cmd of commands) {
if (cmd.run.trim() === '') {
skipped.push({ id: cmd.id, reason: 'empty command' });
continue;
}
try {
const cwd = wt.resolveLaunchSubdir(base, cmd.cwd);
sessions.push(
manager.spawn({ cwd, command: 'bash', login: true, initialInput: cmd.run, title: cmd.label, launchRunId }),
);
} catch (err) {
skipped.push({ id: cmd.id, reason: err instanceof Error ? err.message : String(err) });
}
}
if (sessions.length === 0) {
return reply.status(400).send({ error: { code: 'LAUNCH_FAILED', message: 'No launch command could be started', details: skipped } });
}
recordAudit(db, {
actor: req.authContext?.tokenId ?? 'unknown',
action: 'repo.launch',
resourceId: id,
details: { launchRunId, started: sessions.length, skipped: skipped.length },
});
return reply.status(201).send({ sessions, skipped } satisfies StartLaunchResponse);
});
} }
+31 -2
View File
@@ -12,6 +12,7 @@ import {
xmlEscape, xmlEscape,
systemdUnitPath, systemdUnitPath,
launchAgentPlistPath, launchAgentPlistPath,
windowsCreateArgs,
} from '../src/cli/install.js'; } from '../src/cli/install.js';
describe('cli install · detectPlatform', () => { describe('cli install · detectPlatform', () => {
@@ -20,9 +21,10 @@ describe('cli install · detectPlatform', () => {
expect(detectPlatform('darwin')).toBe('darwin'); expect(detectPlatform('darwin')).toBe('darwin');
}); });
it('rejette les autres plateformes avec un message clair', () => { it('rejette les plateformes sans superviseur connu, avec un message clair', () => {
expect(() => detectPlatform('win32')).toThrow(/Linux \(systemd\) and macOS \(launchd\)/); // win32 est désormais SUPPORTÉ (Planificateur de tâches) : cf. la suite dédiée plus bas.
expect(() => detectPlatform('freebsd')).toThrow(/freebsd/); expect(() => detectPlatform('freebsd')).toThrow(/freebsd/);
expect(() => detectPlatform('aix')).toThrow(/Task Scheduler/);
}); });
}); });
@@ -192,3 +194,30 @@ describe('cli install · chemins', () => {
); );
}); });
}); });
describe('P14 · Windows (Planificateur de tâches)', () => {
it('detectPlatform accepte win32', () => {
expect(detectPlatform('win32')).toBe('win32');
expect(() => detectPlatform('freebsd')).toThrow(/Task Scheduler/);
});
it('windowsCreateArgs : tâche à l’ouverture de session, sans élévation, idempotente', () => {
const args = windowsCreateArgs({
taskName: 'Arboretum',
exec: 'C:\\Program Files\\nodejs\\node.exe',
scriptArgs: ['C:\\app\\dist\\index.js', '--port', '7317'],
});
expect(args).toEqual([
'/Create',
'/TN',
'Arboretum',
'/TR',
'"C:\\Program Files\\nodejs\\node.exe" C:\\app\\dist\\index.js --port 7317',
'/SC',
'ONLOGON',
'/RL',
'LIMITED',
'/F',
]);
});
});
+80
View File
@@ -32,6 +32,10 @@ import {
amendCommit, amendCommit,
lastCommit, lastCommit,
isUnpushed, isUnpushed,
commitLog,
commitDiff,
isValidCommitish,
parseLogZ,
} from '../src/core/git.js'; } from '../src/core/git.js';
import { appendFileSync } from 'node:fs'; import { appendFileSync } from 'node:fs';
@@ -318,3 +322,79 @@ describe('addWorktree : résolution auto (créer / réutiliser)', () => {
await expect(addWorktree(repo, { path: wt, branch: 'dup', mode: 'create' })).rejects.toBeDefined(); await expect(addWorktree(repo, { path: wt, branch: 'dup', mode: 'create' })).rejects.toBeDefined();
}); });
}); });
describe('P14 · historique (commitLog / commitDiff)', () => {
it('parseLogZ : découpe par paquets de champs et tolère un sujet multi-lignes', () => {
const stdout = ['h1', 's1', 'auteur', '2026-01-01T00:00:00Z', 'sujet\navec saut', 'h2', 's2', 'a2', 'd2', 'sujet 2'].join('\0');
const recs = parseLogZ(stdout, 5);
expect(recs).toHaveLength(2);
expect(recs[0]?.[4]).toBe('sujet\navec saut');
expect(recs[1]?.[0]).toBe('h2');
});
it('parseLogZ : ignore un enregistrement final vide (NUL de fin)', () => {
expect(parseLogZ(['h', 's', 'a', 'd', 'sub', ''].join('\0'), 5)).toHaveLength(1);
});
it('isValidCommitish : hex 4-64 uniquement (refuse une option déguisée)', () => {
expect(isValidCommitish('abc1234')).toBe(true);
expect(isValidCommitish('ABCDEF12')).toBe(true);
expect(isValidCommitish('abc')).toBe(false);
expect(isValidCommitish('--upload-pack=x')).toBe(false);
expect(isValidCommitish('HEAD')).toBe(false);
expect(isValidCommitish('main..HEAD')).toBe(false);
});
it('commitLog : ordre récent → ancien, champs remplis, sans upstream tout est local', async () => {
const repo = makeTmpRepo();
appendFileSync(join(repo, 'README.md'), 'second\n');
await commitAll(repo, 'deuxième commit');
const { commits, hasUpstream, unpushedCount } = await commitLog(repo);
expect(commits).toHaveLength(2);
expect(commits[0]?.subject).toBe('deuxième commit');
expect(commits[1]?.subject).toBe('init');
expect(commits[0]?.hash).toMatch(/^[0-9a-f]{40}$/);
expect(commits[0]?.shortHash.length).toBeGreaterThanOrEqual(7);
expect(commits[0]?.author).toBe('Test');
expect(Number.isNaN(Date.parse(commits[0]?.date ?? ''))).toBe(false);
// branche locale sans remote : aucun commit n'est publié
expect(hasUpstream).toBe(false);
expect(unpushedCount).toBe(0);
});
it('commitLog : limit et skip bornent la fenêtre', async () => {
const repo = makeTmpRepo();
for (const n of [1, 2, 3]) {
appendFileSync(join(repo, 'README.md'), `line ${n}\n`);
await commitAll(repo, `commit ${n}`);
}
expect((await commitLog(repo, { limit: 2 })).commits.map((c) => c.subject)).toEqual(['commit 3', 'commit 2']);
expect((await commitLog(repo, { limit: 1, skip: 2 })).commits.map((c) => c.subject)).toEqual(['commit 1']);
});
it('commitLog : dépôt sans aucun commit → liste vide, pas d’exception', async () => {
const dir = mkdtempSync(join(tmpdir(), 'arb-git-empty-'));
dirs.push(dir);
execFileSync('git', ['init', '-b', 'main'], { cwd: dir, stdio: 'pipe' });
const res = await commitLog(dir);
expect(res.commits).toEqual([]);
expect(res.hasUpstream).toBe(false);
});
it('commitDiff : diff unifié du commit demandé, hash invalide et inconnu rejetés', async () => {
const repo = makeTmpRepo();
writeFileSync(join(repo, 'nouveau.txt'), 'contenu\n');
await commitAll(repo, 'ajout fichier');
const [head] = (await commitLog(repo)).commits;
const d = await commitDiff(repo, head?.hash ?? '');
expect(d.binary).toBe(false);
expect(d.tooLarge).toBe(false);
expect(d.diff).toContain('nouveau.txt');
expect(d.diff).toContain('+contenu');
await expect(commitDiff(repo, 'HEAD')).rejects.toThrow(/Invalid commit hash/);
await expect(commitDiff(repo, 'deadbeef')).rejects.toThrow(/Unknown commit/);
});
});
@@ -0,0 +1,55 @@
import { afterAll, describe, expect, it } from 'vitest';
import { mkdtempSync, mkdirSync, rmSync, writeFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { detectLaunchCommands } from '../src/core/launch-detect.js';
const tmp = mkdtempSync(join(tmpdir(), 'launch-detect-'));
afterAll(() => rmSync(tmp, { recursive: true, force: true }));
function fixture(name: string, files: Record<string, string>): string {
const dir = join(tmp, name);
mkdirSync(dir, { recursive: true });
for (const [f, content] of Object.entries(files)) writeFileSync(join(dir, f), content);
return dir;
}
describe('detectLaunchCommands', () => {
it('extrait les scripts npm (par défaut : npm run), active les scripts de dev', () => {
const dir = fixture('npm', {
'package.json': JSON.stringify({ scripts: { dev: 'vite', build: 'vite build', 'test:unit': 'vitest' } }),
});
const cmds = detectLaunchCommands(dir);
const dev = cmds.find((c) => c.run === 'npm run dev');
const build = cmds.find((c) => c.run === 'npm run build');
expect(dev?.enabled).toBe(true); // heuristique : dev/start/serve/watch activés
expect(build?.enabled).toBe(false);
expect(cmds.some((c) => c.run === 'npm run test:unit')).toBe(true);
});
it('utilise pnpm/yarn selon le lockfile présent', () => {
const pnpm = fixture('pnpm', { 'package.json': JSON.stringify({ scripts: { dev: 'x' } }), 'pnpm-lock.yaml': '' });
expect(detectLaunchCommands(pnpm).find((c) => c.label === 'dev')?.run).toBe('pnpm run dev');
const yarn = fixture('yarn', { 'package.json': JSON.stringify({ scripts: { dev: 'x' } }), 'yarn.lock': '' });
expect(detectLaunchCommands(yarn).find((c) => c.label === 'dev')?.run).toBe('yarn dev');
});
it('lit le Procfile (name: command), toutes activées', () => {
const dir = fixture('proc', { Procfile: 'web: bundle exec puma\nworker: rake jobs:work\n# comment\n' });
const cmds = detectLaunchCommands(dir);
expect(cmds.find((c) => c.label === 'web')?.run).toBe('bundle exec puma');
expect(cmds.find((c) => c.label === 'worker')?.enabled).toBe(true);
expect(cmds).toHaveLength(2); // la ligne de commentaire est ignorée
});
it('suggère docker compose up si un fichier compose est présent', () => {
const dir = fixture('compose', { 'compose.yaml': 'services: {}' });
expect(detectLaunchCommands(dir).some((c) => c.run === 'docker compose up')).toBe(true);
});
it('tolère un répertoire vide ou un package.json invalide', () => {
expect(detectLaunchCommands(join(tmp, 'inexistant'))).toEqual([]);
const bad = fixture('bad', { 'package.json': '{ not json' });
expect(detectLaunchCommands(bad)).toEqual([]);
});
});
@@ -0,0 +1,79 @@
import { describe, expect, it } from 'vitest';
import { containsPath, findWorktreeForCwd, sessionBelongsToWorktree } from '../src/core/session-match.js';
describe('containsPath', () => {
it('vrai pour le répertoire lui-même', () => {
expect(containsPath('/p/repo', '/p/repo')).toBe(true);
});
it('vrai pour un descendant', () => {
expect(containsPath('/p/repo', '/p/repo/packages/api')).toBe(true);
});
it('compare par segment, pas par préfixe de chaîne', () => {
// /p/repo ne contient PAS /p/repo-wt-feature (piège du startsWith nu)
expect(containsPath('/p/repo', '/p/repo-wt-feature')).toBe(false);
});
it('faux pour un ancêtre', () => {
expect(containsPath('/p/repo/api', '/p/repo')).toBe(false);
});
it('normalise les chemins non résolus', () => {
expect(containsPath('/p/repo', '/p/repo/./api/../api')).toBe(true);
});
});
describe('sessionBelongsToWorktree', () => {
it('rattache une session lancée à la racine du worktree', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/repo' }, '/p/repo')).toBe(true);
});
it('rattache une session lancée dans un sous-répertoire (« Démarrer le projet »)', () => {
// LaunchCommand.cwd autorise un sous-dossier : le terminal doit rester visible sous son worktree.
expect(sessionBelongsToWorktree({ cwd: '/p/repo/packages/api' }, '/p/repo')).toBe(true);
});
it('ne rattache pas une session d’un worktree frère', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/repo-wt-feat' }, '/p/repo')).toBe(false);
});
it('donne un worktree imbriqué au plus spécifique, pas au principal', () => {
const session = { cwd: '/p/repo/.worktrees/feat/src' };
const all = ['/p/repo', '/p/repo/.worktrees/feat'];
expect(sessionBelongsToWorktree(session, '/p/repo/.worktrees/feat', all)).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/repo', all)).toBe(false);
});
it('rattache une session de groupe via ses répertoires reliés', () => {
// cwd = parent commun (hors des repos), les worktrees couverts vivent dans addedDirs.
const session = { cwd: '/p', addedDirs: ['/p/api', '/p/web'] };
expect(sessionBelongsToWorktree(session, '/p/api')).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/web')).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/docs')).toBe(false);
});
it('ignore un addedDirs absent', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/api' }, '/p/api', [])).toBe(true);
});
});
describe('findWorktreeForCwd', () => {
const worktrees = [
{ repoId: 'r1', path: '/p/api' },
{ repoId: 'r1', path: '/p/api-wt-feat' },
{ repoId: 'r2', path: '/p/api/vendor/web' },
];
it('choisit le worktree le plus spécifique', () => {
expect(findWorktreeForCwd('/p/api/vendor/web/src', worktrees)?.repoId).toBe('r2');
});
it('choisit le worktree frère exact et non le préfixe de chaîne', () => {
expect(findWorktreeForCwd('/p/api-wt-feat/src', worktrees)?.path).toBe('/p/api-wt-feat');
});
it('renvoie null hors de tout worktree connu', () => {
expect(findWorktreeForCwd('/tmp/ailleurs', worktrees)).toBeNull();
});
});
+25
View File
@@ -0,0 +1,25 @@
import { describe, it, expect } from 'vitest';
import { cacheControlFor } from '../src/app.js';
// Régression : à la mise à jour de l'app desktop, l'index.html mis en cache par le client était
// revalidé en 304 (etag = taille+mtime, mtime figé à 1985 par npm pack dans le tarball) et
// continuait donc de référencer des /assets/<hash> disparus → modules servis en text/html par le
// fallback SPA → page noire. Seuls les noms hachés sont cachables.
describe('cacheControlFor', () => {
it('rend les assets hachés cachables indéfiniment', () => {
expect(cacheControlFor('/assets/index-94trXkeo.js')).toBe('public, max-age=31536000, immutable');
expect(cacheControlFor('/assets/inter-latin-wght-normal-Dx4kXJAl.woff2')).toBe(
'public, max-age=31536000, immutable',
);
});
it("interdit la mise en cache de l'index.html", () => {
expect(cacheControlFor('/index.html')).toBe('no-store');
});
it('interdit la mise en cache des fichiers racine non hachés', () => {
for (const p of ['/sw.js', '/theme-boot.js', '/manifest.webmanifest', '/favicon.ico', '/icon-512.png']) {
expect(cacheControlFor(p)).toBe('no-store');
}
});
});
@@ -0,0 +1,94 @@
// Support Windows du daemon : helpers purs, testés avec la plateforme INJECTÉE (ils doivent donc être
// vérifiables depuis Linux). Chacun corrige un point qui rendait le daemon inutilisable sur Windows.
import { describe, expect, it } from 'vitest';
import { buildSpawnSpec, resolveInteractiveShell, resolvePlainShell, whichCommand } from '../src/core/claude-launcher.js';
import { askpassScript } from '../src/core/git-auth.js';
import { defaultDataRoot } from '../src/config.js';
describe('recherche du binaire claude dans le PATH', () => {
it('utilise where.exe sur Windows, which ailleurs', () => {
expect(whichCommand('win32')).toEqual({ file: 'where.exe', args: ['claude'] });
expect(whichCommand('linux')).toEqual({ file: 'which', args: ['claude'] });
expect(whichCommand('darwin').file).toBe('which');
});
});
describe('shell de lancement', () => {
it('POSIX : $SHELL connu en login interactif, sinon bash', () => {
expect(resolveInteractiveShell('linux', { SHELL: '/usr/bin/zsh' })).toEqual({ file: '/usr/bin/zsh', args: ['-l', '-i'] });
expect(resolveInteractiveShell('linux', { SHELL: '/bin/dash' })).toEqual({ file: 'bash', args: ['-l', '-i'] });
expect(resolveInteractiveShell('linux', {})).toEqual({ file: 'bash', args: ['-l', '-i'] });
});
it('Windows : PowerShell qui reste attaché après la commande auto-tapée', () => {
const shell = resolveInteractiveShell('win32', {});
expect(shell.file).toBe('powershell.exe');
expect(shell.args).toContain('-NoExit');
});
it('Windows : le shell est surchargeable par ARBORETUM_SHELL', () => {
expect(resolveInteractiveShell('win32', { ARBORETUM_SHELL: 'pwsh.exe' }).file).toBe('pwsh.exe');
});
it('terminal simple : bash --norc sur POSIX, PowerShell sur Windows', () => {
expect(resolvePlainShell('linux')).toEqual({ file: 'bash', args: ['--norc'] });
expect(resolvePlainShell('win32').file).toBe('powershell.exe');
});
});
describe('buildSpawnSpec · plateforme injectée', () => {
it('command=bash sur Windows lance PowerShell (le contrat d’API reste claude|bash)', () => {
const spec = buildSpawnSpec({ command: 'bash', platform: 'win32' });
expect(spec.file).toBe('powershell.exe');
expect(spec.env.TERM).toBe('xterm-256color');
});
it('command=bash avec login sur Windows reste attaché', () => {
expect(buildSpawnSpec({ command: 'bash', login: true, platform: 'win32' }).args).toContain('-NoExit');
});
it('command=bash sur Linux inchangé', () => {
expect(buildSpawnSpec({ command: 'bash', platform: 'linux' })).toMatchObject({ file: 'bash', args: ['--norc'] });
});
});
describe('script askpass git', () => {
it('Windows : .cmd (un .sh à shebang n’y est pas exécutable)', () => {
const s = askpassScript('win32');
expect(s.name).toBe('askpass.cmd');
expect(s.content).toContain('@echo off');
expect(s.content).toContain('ARB_GIT_USER');
expect(s.content).toContain('ARB_GIT_PASS');
});
it('POSIX : .sh avec shebang', () => {
const s = askpassScript('linux');
expect(s.name).toBe('askpass.sh');
expect(s.content.startsWith('#!/bin/sh')).toBe(true);
expect(s.mode).toBe(0o700);
});
it('les deux variantes distinguent Username du mot de passe', () => {
for (const p of ['win32', 'linux'] as const) {
const c = askpassScript(p).content;
expect(c).toMatch(/Username/i);
}
});
});
describe('racine des données', () => {
it('XDG_DATA_HOME est prioritaire partout (l’app de bureau s’en sert pour isoler)', () => {
expect(defaultDataRoot('win32', { XDG_DATA_HOME: '/iso' }, '/home/u')).toBe('/iso');
expect(defaultDataRoot('linux', { XDG_DATA_HOME: '/iso' }, '/home/u')).toBe('/iso');
});
it('Windows : %APPDATA%, avec repli sur AppData/Roaming', () => {
expect(defaultDataRoot('win32', { APPDATA: 'C:\\Users\\u\\AppData\\Roaming' }, 'C:\\Users\\u')).toBe('C:\\Users\\u\\AppData\\Roaming');
expect(defaultDataRoot('win32', {}, '/home/u')).toBe('/home/u/AppData/Roaming');
});
it('POSIX : ~/.local/share', () => {
expect(defaultDataRoot('linux', {}, '/home/u')).toBe('/home/u/.local/share');
expect(defaultDataRoot('darwin', {}, '/Users/u')).toBe('/Users/u/.local/share');
});
});
+61 -1
View File
@@ -1,5 +1,5 @@
// Types REST partagés (préfixe /api/v1). // Types REST partagés (préfixe /api/v1).
import type { CloneOperation, GroupSummary, PostCreateHook, RepoSummary, SessionSummary, SettingsBroadcast, WorktreeSummary } from './protocol.js'; import type { CloneOperation, GroupSummary, LaunchCommand, PostCreateHook, RepoSummary, SessionSummary, SettingsBroadcast, WorktreeSummary } from './protocol.js';
export interface ApiError { export interface ApiError {
error: { code: string; message: string; details?: unknown }; error: { code: string; message: string; details?: unknown };
@@ -99,6 +99,8 @@ export interface CreateRepoRequest {
label?: string; label?: string;
postCreateHooks?: PostCreateHook[]; postCreateHooks?: PostCreateHook[];
preTrust?: boolean; preTrust?: boolean;
/** commandes de démarrage du projet (« Démarrer le projet »). */
launchCommands?: LaunchCommand[];
} }
export interface UpdateRepoRequest { export interface UpdateRepoRequest {
label?: string; label?: string;
@@ -106,6 +108,8 @@ export interface UpdateRepoRequest {
preTrust?: boolean; preTrust?: boolean;
/** true = masquer le repo (exclu du dashboard, conservé en DB) ; false = ré-afficher. */ /** true = masquer le repo (exclu du dashboard, conservé en DB) ; false = ré-afficher. */
hidden?: boolean; hidden?: boolean;
/** commandes de démarrage du projet (« Démarrer le projet »). */
launchCommands?: LaunchCommand[];
} }
/** Résultat d'un scan de découverte (POST /api/v1/repos/discover). */ /** Résultat d'un scan de découverte (POST /api/v1/repos/discover). */
@@ -233,6 +237,37 @@ export interface FileDiffResponse {
/** texte du diff unifié git (vide si binaire ou tooLarge). */ /** texte du diff unifié git (vide si binaire ou tooLarge). */
diff: string; diff: string;
} }
/** Un commit de l'historique d'un worktree (GET .../worktrees/log). */
export interface CommitEntry {
/** hash complet (clé stable, utilisée pour demander le diff du commit). */
hash: string;
/** hash court tel que git l'abrège (affichage). */
shortHash: string;
author: string;
/** date d'auteur ISO 8601 (%aI). */
date: string;
subject: string;
}
/**
* GET /api/v1/repos/:id/worktrees/log?path=&limit=&skip= : historique de la branche du worktree.
* `unpushedCount` compte les commits de tête pas encore poussés ; `hasUpstream: false` signifie qu'aucun
* commit n'est publié (branche purement locale) et que TOUS sont donc à considérer comme non poussés.
*/
export interface WorktreeLogResponse {
repoId: string;
path: string;
commits: CommitEntry[];
unpushedCount: number;
hasUpstream: boolean;
}
/** GET /api/v1/repos/:id/worktrees/diff?path=&commit= : diff unifié complet d'un commit. */
export interface CommitDiffResponse {
path: string;
commit: string;
binary: boolean;
tooLarge: boolean;
diff: string;
}
/** GET /api/v1/repos/:id/files/content?wt=&path= : contenu d'un fichier (pour l'éditeur Monaco). */ /** GET /api/v1/repos/:id/files/content?wt=&path= : contenu d'un fichier (pour l'éditeur Monaco). */
export interface FileContentResponse { export interface FileContentResponse {
/** chemin relatif au worktree (POSIX). */ /** chemin relatif au worktree (POSIX). */
@@ -313,6 +348,31 @@ export interface StartRepoSessionRequest {
newBranch?: boolean; newBranch?: boolean;
} }
// ---- « Démarrer le projet » : lancement multi-terminaux ----
/**
* POST /api/v1/repos/:id/launch : lance un terminal par commande de démarrage activée du repo.
* Le worktree cible est résolu côté serveur (le client ne passe jamais de chemin absolu brut) :
* `worktreePath` prioritaire, sinon worktree de `branch`, sinon checkout principal.
*/
export interface StartLaunchRequest {
/** worktree cible (chemin absolu d'un worktree connu du repo) ; défaut : checkout principal. */
worktreePath?: string;
/** alternative à `worktreePath` : worktree portant cette branche. */
branch?: string;
/** ids des commandes à lancer (défaut : toutes les commandes activées du repo). */
commandIds?: string[];
}
export interface StartLaunchResponse {
/** un terminal (session managée) par commande lancée, partageant le même launchRunId. */
sessions: SessionSummary[];
/** commandes non lancées (répertoire cible introuvable, cwd invalide…). */
skipped: Array<{ id: string; reason: string }>;
}
/** GET /api/v1/repos/:id/launch/detect : suggestions de commandes détectées dans le projet. */
export interface DetectLaunchResponse {
suggestions: LaunchCommand[];
}
// ---- Groupes de travail (P5) ---- // ---- Groupes de travail (P5) ----
export interface GroupsListResponse { export interface GroupsListResponse {
groups: GroupSummary[]; groups: GroupSummary[];
+1
View File
@@ -1,3 +1,4 @@
export * from './protocol.js'; export * from './protocol.js';
export * from './api.js'; export * from './api.js';
export * from './wt-key.js'; export * from './wt-key.js';
export * from './path-match.js';
+71
View File
@@ -0,0 +1,71 @@
// Corrélation session ↔ worktree par contenance de chemin. Source unique partagée par le daemon, le
// front web et l'extension VS Code : la règle doit être identique partout, sinon un terminal apparaît
// sous un worktree côté serveur et sous un autre côté UI.
//
// Historiquement la corrélation était une égalité stricte `session.cwd === worktree.path`. Deux cas
// réels y échappent :
// 1. « Démarrer le projet » autorise un sous-répertoire par commande (`LaunchCommand.cwd`, borné par
// `resolveLaunchSubdir`) : le terminal tourne DANS le worktree, mais pas à sa racine ;
// 2. une session de groupe (P6) couvre plusieurs repos via `--add-dir` : son cwd est le parent commun
// et les worktrees couverts n'apparaissent que dans `addedDirs`.
// Dans les deux cas la session appartient bel et bien au worktree.
//
// Aucune dépendance à `node:path` (le front tourne dans un navigateur) : la comparaison se fait par
// segments, en tolérant les deux séparateurs pour rester correcte sur Windows. La comparaison reste
// SENSIBLE à la casse : les chemins comparés viennent tous de la même source (git et la base), et
// insensibiliser casserait deux répertoires ne différant que par la casse sous Linux.
/** Segments non vides d'un chemin, séparateurs POSIX et Windows confondus. */
function segments(p: string): string[] {
return p.split(/[\\/]+/).filter((s) => s.length > 0 && s !== '.');
}
/** true si `child` est `parent` lui-même ou un descendant. */
export function containsPath(parent: string, child: string): boolean {
const p = segments(parent);
const c = segments(child);
if (c.length < p.length) return false;
return p.every((seg, i) => c[i] === seg);
}
/** Répertoires qu'une session occupe : son cwd, plus les répertoires reliés d'une session de groupe. */
export function sessionDirs(session: { cwd: string; addedDirs?: string[] }): string[] {
return [session.cwd, ...(session.addedDirs ?? [])];
}
/**
* Attribue une session au worktree `worktreePath`. `others` = les autres worktrees connus (au moins
* ceux du même repo) : sans eux, une session lancée dans un worktree imbriqué (`repo/.worktrees/x`)
* serait aussi listée sous le checkout principal `repo`. Le worktree le plus spécifique gagne.
*/
export function sessionBelongsToWorktree(
session: { cwd: string; addedDirs?: string[] },
worktreePath: string,
others: string[] = [],
): boolean {
const depth = segments(worktreePath).length;
return sessionDirs(session).some((dir) => {
if (!containsPath(worktreePath, dir)) return false;
// un autre worktree plus profond contient aussi ce répertoire → il est le propriétaire légitime.
return !others.some((o) => segments(o).length > depth && containsPath(o, dir));
});
}
/**
* Worktree auquel rattacher un répertoire, parmi une liste hétérogène (tous repos confondus) : le plus
* spécifique qui le contient. Sert à épingler le watcher FS du worktree d'une session vivante et à
* étiqueter un terminal.
*/
export function findWorktreeForCwd<T extends { path: string }>(cwd: string, worktrees: T[]): T | null {
let best: T | null = null;
let bestDepth = -1;
for (const w of worktrees) {
if (!containsPath(w.path, cwd)) continue;
const depth = segments(w.path).length;
if (depth > bestDepth) {
best = w;
bestDepth = depth;
}
}
return best;
}
+21
View File
@@ -122,6 +122,9 @@ export interface SessionSummary {
addedDirs?: string[]; addedDirs?: string[];
/** groupe propriétaire d'une session de groupe (couvre plusieurs repos) ; null/absent sinon. */ /** groupe propriétaire d'une session de groupe (couvre plusieurs repos) ; null/absent sinon. */
groupId?: string | null; groupId?: string | null;
// ---- Lancement de projet multi-terminaux (additif) ----
/** identifiant partagé par tous les terminaux d'un même « Démarrer le projet » ; null/absent sinon. */
launchRunId?: string | null;
// ---- Masquage (additif) ---- // ---- Masquage (additif) ----
/** true = session découverte masquée par l'utilisateur (exclue de la liste sauf includeHidden). */ /** true = session découverte masquée par l'utilisateur (exclue de la liste sauf includeHidden). */
hidden?: boolean; hidden?: boolean;
@@ -139,6 +142,22 @@ export interface PostCreateHook {
enabled: boolean; enabled: boolean;
} }
/**
* Commande de démarrage d'un projet (« Démarrer le projet ») : une commande shell longue durée
* lancée dans un terminal PTY managé (serveur front, back, base…). Plusieurs commandes activées
* = plusieurs terminaux ouverts d'un seul geste. Persistée en JSON sur le repo.
*/
export interface LaunchCommand {
id: string;
/** libellé court affiché dans l'onglet du terminal (ex. « web », « api »). */
label: string;
/** commande shell auto-tapée dans un shell de login interactif (ex. `npm run dev`). */
run: string;
/** sous-répertoire relatif au worktree où exécuter la commande (borné, jamais hors du worktree). */
cwd?: string;
enabled: boolean;
}
export interface RepoSummary { export interface RepoSummary {
id: string; id: string;
/** chemin absolu de la racine du repo (main worktree). */ /** chemin absolu de la racine du repo (main worktree). */
@@ -146,6 +165,8 @@ export interface RepoSummary {
label: string; label: string;
defaultBranch: string | null; defaultBranch: string | null;
postCreateHooks: PostCreateHook[]; postCreateHooks: PostCreateHook[];
/** commandes de démarrage du projet (« Démarrer le projet ») ; [] si aucune définie. */
launchCommands: LaunchCommand[];
/** pré-écrire hasTrustDialogAccepted dans ~/.claude.json à la création d'un worktree. */ /** pré-écrire hasTrustDialogAccepted dans ~/.claude.json à la création d'un worktree. */
preTrust: boolean; preTrust: boolean;
createdAt: string; createdAt: string;
+75
View File
@@ -0,0 +1,75 @@
import { describe, expect, it } from 'vitest';
import { containsPath, findWorktreeForCwd, sessionBelongsToWorktree } from '../src/path-match.js';
describe('containsPath', () => {
it('vrai pour le répertoire lui-même et ses descendants', () => {
expect(containsPath('/p/repo', '/p/repo')).toBe(true);
expect(containsPath('/p/repo', '/p/repo/packages/api')).toBe(true);
});
it('compare par segment, pas par préfixe de chaîne', () => {
// piège du startsWith nu : /p/repo n'est pas le parent de /p/repo-wt-feature
expect(containsPath('/p/repo', '/p/repo-wt-feature')).toBe(false);
});
it('faux pour un ancêtre', () => {
expect(containsPath('/p/repo/api', '/p/repo')).toBe(false);
});
it('tolère les deux séparateurs (chemins Windows)', () => {
expect(containsPath('C:\\dev\\repo', 'C:\\dev\\repo\\packages\\api')).toBe(true);
expect(containsPath('C:\\dev\\repo', 'C:/dev/repo/packages')).toBe(true);
expect(containsPath('C:\\dev\\repo', 'C:\\dev\\repo2')).toBe(false);
});
it('reste sensible à la casse', () => {
expect(containsPath('/p/Repo', '/p/repo/api')).toBe(false);
});
it('ignore les séparateurs redondants et un slash final', () => {
expect(containsPath('/p/repo/', '/p//repo/api')).toBe(true);
});
});
describe('sessionBelongsToWorktree', () => {
it('rattache une session lancée dans un sous-répertoire', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/repo/packages/api' }, '/p/repo')).toBe(true);
});
it('donne un worktree imbriqué au plus spécifique, pas au principal', () => {
const session = { cwd: '/p/repo/.worktrees/feat/src' };
const all = ['/p/repo', '/p/repo/.worktrees/feat'];
expect(sessionBelongsToWorktree(session, '/p/repo/.worktrees/feat', all)).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/repo', all)).toBe(false);
});
it('rattache une session de groupe via ses répertoires reliés', () => {
const session = { cwd: '/p', addedDirs: ['/p/api', '/p/web'] };
expect(sessionBelongsToWorktree(session, '/p/api')).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/docs')).toBe(false);
});
it('ne rattache pas une session d’un worktree frère', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/repo-wt-feat' }, '/p/repo')).toBe(false);
});
});
describe('findWorktreeForCwd', () => {
const worktrees = [
{ repoId: 'r1', path: '/p/api' },
{ repoId: 'r1', path: '/p/api-wt-feat' },
{ repoId: 'r2', path: '/p/api/vendor/web' },
];
it('choisit le worktree le plus spécifique', () => {
expect(findWorktreeForCwd('/p/api/vendor/web/src', worktrees)?.repoId).toBe('r2');
});
it('choisit le worktree frère exact', () => {
expect(findWorktreeForCwd('/p/api-wt-feat/src', worktrees)?.path).toBe('/p/api-wt-feat');
});
it('renvoie null hors de tout worktree connu', () => {
expect(findWorktreeForCwd('/tmp/ailleurs', worktrees)).toBeNull();
});
});
+2 -2
View File
@@ -5,12 +5,12 @@
<meta name="viewport" content="width=device-width, initial-scale=1" /> <meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="color-scheme" content="dark" /> <meta name="color-scheme" content="dark" />
<meta name="theme-color" content="#09090b" /> <meta name="theme-color" content="#09090b" />
<!-- Anti-FOUC : applique la préférence de thème (arb-theme) avant le premier paint. <!-- Anti-FOUC : applique la préférence de thème (arb.theme, même clé que l'app) avant le premier paint.
Doit rester inline/synchrone. Synchronisé avec src/lib/theme.ts. --> Doit rester inline/synchrone. Synchronisé avec src/lib/theme.ts. -->
<script> <script>
(function () { (function () {
try { try {
var mode = localStorage.getItem('arb-theme') || 'dark'; var mode = localStorage.getItem('arb.theme') || 'dark';
var dark = mode === 'dark' || (mode === 'system' && matchMedia('(prefers-color-scheme: dark)').matches); var dark = mode === 'dark' || (mode === 'system' && matchMedia('(prefers-color-scheme: dark)').matches);
var theme = dark ? 'dark' : 'light'; var theme = dark ? 'dark' : 'light';
var bg = dark ? '#09090b' : '#fafafa'; var bg = dark ? '#09090b' : '#fafafa';
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
"name": "@arboretum/site", "name": "@arboretum/site",
"private": true, "private": true,
"version": "0.3.0", "version": "0.4.0",
"type": "module", "type": "module",
"scripts": { "scripts": {
"dev": "vite", "dev": "vite",
+1 -1
View File
@@ -2,7 +2,7 @@
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url> <url>
<loc>https://git-arboretum.com/</loc> <loc>https://git-arboretum.com/</loc>
<lastmod>2026-06-19</lastmod> <lastmod>2026-08-04</lastmod>
<changefreq>monthly</changefreq> <changefreq>monthly</changefreq>
<priority>1.0</priority> <priority>1.0</priority>
</url> </url>
+6
View File
@@ -7,7 +7,9 @@ import ProblemSection from './components/ProblemSection.vue';
import FeaturesSection from './components/FeaturesSection.vue'; import FeaturesSection from './components/FeaturesSection.vue';
import ShowcaseSection from './components/ShowcaseSection.vue'; import ShowcaseSection from './components/ShowcaseSection.vue';
import WorkspaceShowcase from './components/WorkspaceShowcase.vue'; import WorkspaceShowcase from './components/WorkspaceShowcase.vue';
import LaunchShowcase from './components/LaunchShowcase.vue';
import DownloadSection from './components/DownloadSection.vue'; import DownloadSection from './components/DownloadSection.vue';
import AccessSection from './components/AccessSection.vue';
import RemoteGitSection from './components/RemoteGitSection.vue'; import RemoteGitSection from './components/RemoteGitSection.vue';
import WorkGroupsSection from './components/WorkGroupsSection.vue'; import WorkGroupsSection from './components/WorkGroupsSection.vue';
import HowItWorksSection from './components/HowItWorksSection.vue'; import HowItWorksSection from './components/HowItWorksSection.vue';
@@ -15,6 +17,7 @@ import SecuritySection from './components/SecuritySection.vue';
import FaqSection from './components/FaqSection.vue'; import FaqSection from './components/FaqSection.vue';
import FinalCta from './components/FinalCta.vue'; import FinalCta from './components/FinalCta.vue';
import AppFooter from './components/AppFooter.vue'; import AppFooter from './components/AppFooter.vue';
import BackToTop from './components/BackToTop.vue';
const { locale } = useI18n(); const { locale } = useI18n();
@@ -68,7 +71,9 @@ const glowStyle = {
<FeaturesSection /> <FeaturesSection />
<ShowcaseSection /> <ShowcaseSection />
<WorkspaceShowcase /> <WorkspaceShowcase />
<LaunchShowcase />
<DownloadSection /> <DownloadSection />
<AccessSection />
<RemoteGitSection /> <RemoteGitSection />
<WorkGroupsSection /> <WorkGroupsSection />
<HowItWorksSection /> <HowItWorksSection />
@@ -78,5 +83,6 @@ const glowStyle = {
</main> </main>
<AppFooter /> <AppFooter />
<BackToTop />
</div> </div>
</template> </template>
@@ -0,0 +1,74 @@
<script setup lang="ts">
// Les trois façons d'utiliser Arboretum. Le « mode serveur web » (le daemon servi à ses propres
// appareils) n'était décrit nulle part sur le site, alors que c'est l'usage central du produit ; et
// l'extension VS Code n'avait qu'une carte de fonctionnalité, sans lien ni mode d'emploi.
import { useI18n } from 'vue-i18n';
import { DOWNLOADS, DESKTOP_SRC } from '../lib/links';
const { t } = useI18n();
const ways = [
{
key: 'wayDesktop',
body: 'wayDesktopBody',
code: null,
link: { href: DOWNLOADS.deb, label: 'wayDesktopLink' },
},
{
key: 'wayServer',
body: 'wayServerBody',
code: 'tailscale serve --bg 7317',
link: null,
},
{
key: 'wayVscode',
body: 'wayVscodeBody',
code: null,
link: { href: DOWNLOADS.vsix, label: 'wayVscodeLink' },
},
] as const;
</script>
<template>
<section id="access" class="mx-auto max-w-[1200px] scroll-mt-[84px] px-6 pb-[100px]">
<div v-reveal class="mb-[40px] max-w-[720px]">
<div class="mb-3 font-mono text-xs uppercase tracking-[0.12em] text-accent">{{ t('wayKicker') }}</div>
<h2 class="m-0 mb-4 text-[clamp(26px,3vw,38px)] font-semibold leading-[1.15] tracking-[-0.025em] text-fg">
{{ t('wayTitle') }}
</h2>
<p class="m-0 text-[16.5px] leading-[1.6] text-fg-muted">{{ t('wayBody') }}</p>
</div>
<div v-reveal class="grid gap-4 md:grid-cols-3">
<div
v-for="w in ways"
:key="w.key"
class="flex flex-col gap-3 rounded-[14px] border border-border bg-surface-0 p-5 shadow-card"
>
<h3 class="m-0 text-[15px] font-semibold text-fg">{{ t(w.key) }}</h3>
<p class="m-0 flex-1 text-[14px] leading-[1.55] text-fg-muted">{{ t(w.body) }}</p>
<code
v-if="w.code"
class="block overflow-x-auto whitespace-nowrap rounded-lg border border-border bg-surface-1 px-3 py-2 font-mono text-[12.5px] text-fg"
>
<span class="text-accent">$ </span>{{ w.code }}
</code>
<a
v-if="w.link"
:href="w.link.href"
class="text-[13.5px] font-medium text-accent no-underline hover:underline"
>
{{ t(w.link.label) }} →
</a>
</div>
</div>
<p v-reveal class="mt-6 max-w-[760px] text-[13.5px] leading-[1.6] text-fg-subtle">{{ t('wayOriginNote') }}</p>
<p v-reveal class="mt-2 max-w-[760px] text-[13.5px] leading-[1.6] text-fg-subtle">
{{ t('wayBuildNote') }}
<a :href="DESKTOP_SRC" target="_blank" rel="noopener" class="text-fg-muted underline decoration-border underline-offset-2 hover:text-accent">
packages/desktop
</a>
</p>
</section>
</template>
+5 -1
View File
@@ -1,7 +1,7 @@
<script setup lang="ts"> <script setup lang="ts">
import { useI18n } from 'vue-i18n'; import { useI18n } from 'vue-i18n';
import { INSTALL_COMMAND } from '../composables/useCopy'; import { INSTALL_COMMAND } from '../composables/useCopy';
import { REPO, LICENSE, COFFEE } from '../lib/links'; import { COFFEE, LICENSE, REPO, VERSIONS } from '../lib/links';
import IconGitea from './icons/IconGitea.vue'; import IconGitea from './icons/IconGitea.vue';
import CopyButton from './CopyButton.vue'; import CopyButton from './CopyButton.vue';
@@ -44,6 +44,10 @@ const { t } = useI18n();
<code class="font-mono text-[12.5px] text-fg-subtle">{{ INSTALL_COMMAND }}</code> <code class="font-mono text-[12.5px] text-fg-subtle">{{ INSTALL_COMMAND }}</code>
<CopyButton variant="icon" :text="INSTALL_COMMAND" :label="t('copyCommand')" /> <CopyButton variant="icon" :text="INSTALL_COMMAND" :label="t('copyCommand')" />
</div> </div>
<!-- Versions publiées : le site n'en affichait aucune, impossible de savoir ce qu'il décrit. -->
<span class="font-mono text-[12px] text-fg-subtle">
daemon {{ VERSIONS.daemon }} · desktop {{ VERSIONS.desktop }} · vscode {{ VERSIONS.vscode }}
</span>
</div> </div>
</div> </div>
</footer> </footer>
+98 -17
View File
@@ -1,4 +1,5 @@
<script setup lang="ts"> <script setup lang="ts">
import { onBeforeUnmount, onMounted, ref } from 'vue';
import { useI18n } from 'vue-i18n'; import { useI18n } from 'vue-i18n';
import { REPO } from '../lib/links'; import { REPO } from '../lib/links';
import LangToggle from './LangToggle.vue'; import LangToggle from './LangToggle.vue';
@@ -7,22 +8,50 @@ import IconGitea from './icons/IconGitea.vue';
const { t } = useI18n(); const { t } = useI18n();
/**
* Navigation du site. `tier` = largeur à partir de laquelle le lien apparaît dans la barre :
* 1 = dès 900px, 2 = à partir de 1024px, 3 = à partir de 1180px.
*
* Les huit liens ne tiennent qu'au-delà de ~1180px. En dessous, la barre flex les compressait au lieu
* de les masquer, cassant « Start project », « Git services » et « How it works » sur deux ou trois
* lignes, chevauchant le logo et expulsant le bouton Gitea. Le menu compact, lui, montre toujours la
* liste complète : aucun lien n'est perdu, il change juste de place.
*/
const navLinks = [ const navLinks = [
{ href: '#features', key: 'navFeatures' }, { href: '#features', key: 'navFeatures', tier: 1 },
{ href: '#workspace', key: 'navWorkspace' }, { href: '#workspace', key: 'navWorkspace', tier: 1 },
{ href: '#download', key: 'navDownload' }, { href: '#launch', key: 'navLaunch', tier: 2 },
{ href: '#how', key: 'navHow' }, { href: '#remotegit', key: 'navRemoteGit', tier: 3 },
{ href: '#security', key: 'navSecurity' }, { href: '#download', key: 'navDownload', tier: 1 },
{ href: '#faq', key: 'navFaq' }, { href: '#how', key: 'navHow', tier: 3 },
{ href: '#security', key: 'navSecurity', tier: 2 },
{ href: '#faq', key: 'navFaq', tier: 1 },
] as const; ] as const;
/** Tailwind ne génère que des classes littérales : la table évite toute classe construite à la volée. */
const TIER_CLASS: Record<number, string> = {
1: '',
2: 'hidden min-[1024px]:inline',
3: 'hidden min-[1180px]:inline',
};
const menuOpen = ref(false);
const closeMenu = (): void => {
menuOpen.value = false;
};
function onKey(e: KeyboardEvent): void {
if (e.key === 'Escape') closeMenu();
}
onMounted(() => window.addEventListener('keydown', onKey));
onBeforeUnmount(() => window.removeEventListener('keydown', onKey));
</script> </script>
<template> <template>
<header <header class="sticky top-0 z-50 border-b border-border-soft bg-surface-0/72 backdrop-blur-[14px]">
class="sticky top-0 z-50 border-b border-border-soft bg-surface-0/72 backdrop-blur-[14px]" <div class="mx-auto flex h-16 max-w-[1200px] items-center gap-4 px-6">
> <!-- shrink-0 : le logo ne doit jamais être rogné ni recouvert par la nav. -->
<div class="mx-auto flex h-16 max-w-[1200px] items-center justify-between gap-6 px-6"> <a href="#top" class="flex shrink-0 items-center gap-2.5 text-fg no-underline" @click="closeMenu">
<a href="#top" class="flex items-center gap-2.5 text-fg no-underline">
<img <img
src="/assets/arboretum-mark.png" src="/assets/arboretum-mark.png"
alt="Arboretum" alt="Arboretum"
@@ -33,31 +62,83 @@ const navLinks = [
<span class="font-mono text-[17px] font-semibold tracking-[-0.01em]">Arboretum</span> <span class="font-mono text-[17px] font-semibold tracking-[-0.01em]">Arboretum</span>
</a> </a>
<nav class="hidden items-center gap-[30px] min-[900px]:flex"> <nav class="hidden min-w-0 flex-1 items-center justify-center gap-6 min-[900px]:flex min-[1180px]:gap-[30px]">
<a <a
v-for="link in navLinks" v-for="link in navLinks"
:key="link.href" :key="link.href"
:href="link.href" :href="link.href"
class="text-[14.5px] text-fg-muted no-underline transition-colors hover:text-fg" class="shrink-0 whitespace-nowrap text-[14.5px] text-fg-muted no-underline transition-colors hover:text-fg"
:class="TIER_CLASS[link.tier]"
> >
{{ t(link.key) }} {{ t(link.key) }}
</a> </a>
</nav> </nav>
<div class="flex items-center gap-3.5"> <div class="ml-auto flex shrink-0 items-center gap-2 min-[900px]:ml-0 min-[900px]:gap-3.5">
<ThemeToggle /> <ThemeToggle />
<LangToggle /> <LangToggle />
<!-- Sous 900px, Gitea vit dans le panneau : à 390px, logo + 3 contrôles + menu débordaient et
le bouton menu se retrouvait tronqué au bord de l'écran. -->
<a <a
:href="REPO" :href="REPO"
target="_blank" target="_blank"
rel="noopener" rel="noopener"
aria-label="Gitea" aria-label="Gitea"
class="inline-flex items-center gap-[7px] rounded-lg border border-border px-[13px] py-[7px] text-[13.5px] font-medium text-fg-muted no-underline transition-colors hover:border-accent hover:text-accent" class="hidden items-center gap-[7px] rounded-lg border border-border px-[13px] py-[7px] text-[13.5px] font-medium text-fg-muted no-underline transition-colors hover:border-accent hover:text-accent min-[900px]:inline-flex"
>
<IconGitea :size="16" />
<!-- Libellé masqué tant que la barre est serrée : l'icône suffit, l'aria-label reste. -->
<span class="hidden min-[1180px]:inline">Gitea</span>
</a>
<button
type="button"
class="inline-flex items-center justify-center rounded-lg border border-border p-[7px] text-fg-muted transition-colors hover:border-accent hover:text-accent focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-accent/70 min-[900px]:hidden"
:aria-label="t('navMenu')"
:aria-expanded="menuOpen"
aria-controls="site-mobile-nav"
@click="menuOpen = !menuOpen"
>
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true">
<template v-if="menuOpen">
<path d="M18 6 6 18" />
<path d="m6 6 12 12" />
</template>
<template v-else>
<path d="M4 7h16" />
<path d="M4 12h16" />
<path d="M4 17h16" />
</template>
</svg>
</button>
</div>
</div>
<!-- Panneau compact sous 900px : liste complète, une entrée par ligne, refermée au choix d'un lien. -->
<nav
v-if="menuOpen"
id="site-mobile-nav"
class="border-t border-border-soft bg-surface-0/95 px-6 py-2 backdrop-blur-[14px] min-[900px]:hidden"
>
<a
v-for="link in navLinks"
:key="link.href"
:href="link.href"
class="block py-2 text-[15px] text-fg-muted no-underline transition-colors hover:text-fg"
@click="closeMenu"
>
{{ t(link.key) }}
</a>
<a
:href="REPO"
target="_blank"
rel="noopener"
class="mt-1 flex items-center gap-2 border-t border-border-soft py-2.5 text-[15px] text-fg-muted no-underline transition-colors hover:text-accent"
@click="closeMenu"
> >
<IconGitea :size="16" /> <IconGitea :size="16" />
Gitea Gitea
</a> </a>
</div> </nav>
</div>
</header> </header>
</template> </template>
@@ -0,0 +1,65 @@
<script setup lang="ts">
// Bouton « remonter en haut », en bas à droite. Reprend les tokens existants (bordure `border`, fond
// `surface-1`, accent au survol, radius 12px, ombre `shadow-card`) : rien de neuf visuellement.
// Il n'apparaît qu'après un vrai défilement et disparaît en haut de page, pour ne jamais recouvrir le
// contenu sans raison.
import { onBeforeUnmount, onMounted, ref } from 'vue';
import { useI18n } from 'vue-i18n';
const { t } = useI18n();
/** Au-delà d'un écran de défilement, remonter rend un vrai service. */
const SHOW_AFTER = 600;
const visible = ref(false);
const onScroll = (): void => {
visible.value = window.scrollY > SHOW_AFTER;
};
function toTop(): void {
// Respecte la préférence système : pas de défilement animé si l'utilisateur les a réduites.
const reduce = window.matchMedia('(prefers-reduced-motion: reduce)').matches;
window.scrollTo({ top: 0, behavior: reduce ? 'auto' : 'smooth' });
}
onMounted(() => {
onScroll();
window.addEventListener('scroll', onScroll, { passive: true });
});
onBeforeUnmount(() => window.removeEventListener('scroll', onScroll));
</script>
<template>
<Transition name="btt">
<button
v-if="visible"
type="button"
class="fixed right-5 bottom-5 z-40 inline-flex h-11 w-11 items-center justify-center rounded-[12px] border border-border bg-surface-1/90 text-fg-muted shadow-card backdrop-blur-[10px] transition-colors hover:border-accent hover:text-accent focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-accent/70 sm:right-7 sm:bottom-7"
:aria-label="t('backToTop')"
:title="t('backToTop')"
@click="toTop"
>
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
<path d="m18 15-6-6-6 6" />
</svg>
</button>
</Transition>
</template>
<style scoped>
.btt-enter-active,
.btt-leave-active {
transition: opacity 0.18s ease, transform 0.18s ease;
}
.btt-enter-from,
.btt-leave-to {
opacity: 0;
transform: translateY(6px);
}
@media (prefers-reduced-motion: reduce) {
.btt-enter-active,
.btt-leave-active {
transition: none;
}
}
</style>
@@ -1,13 +1,17 @@
<script setup lang="ts"> <script setup lang="ts">
// Téléchargements réels : chaque plateforme porte son lien direct vers l'asset de la release flottante
// `desktop-latest` (le tag est recréé par la CI à chaque version, les URL restent donc valables).
// Avant, les trois cartes étaient décoratives et un unique bouton renvoyait vers la page des releases.
import { useI18n } from 'vue-i18n'; import { useI18n } from 'vue-i18n';
import { RELEASES, DESKTOP_SRC } from '../lib/links'; import { DOWNLOADS, DESKTOP_SRC, RELEASES, VERSIONS } from '../lib/links';
const { t } = useI18n(); const { t } = useI18n();
const platforms = [ const platforms = [
{ key: 'dlLinux', hint: 'dlLinuxHint' }, { key: 'dlLinux', hint: 'dlLinuxHint', href: DOWNLOADS.deb },
{ key: 'dlWin', hint: 'dlWinHint' }, { key: 'dlWin', hint: 'dlWinHint', href: DOWNLOADS.windows },
{ key: 'dlMac', hint: 'dlMacHint' }, // macOS n'est pas buildé par la CI (aucun runner) : la carte renvoie donc vers les sources.
{ key: 'dlMac', hint: 'dlMacHint', href: DESKTOP_SRC },
] as const; ] as const;
const bullets = ['dlNoNode', 'dlBundled', 'dlAutoUpdate'] as const; const bullets = ['dlNoNode', 'dlBundled', 'dlAutoUpdate'] as const;
@@ -21,21 +25,38 @@ const bullets = ['dlNoNode', 'dlBundled', 'dlAutoUpdate'] as const;
{{ t('dlTitle') }} {{ t('dlTitle') }}
</h2> </h2>
<p class="m-0 text-[16.5px] leading-[1.6] text-fg-muted">{{ t('dlBody') }}</p> <p class="m-0 text-[16.5px] leading-[1.6] text-fg-muted">{{ t('dlBody') }}</p>
<p class="mt-2 font-mono text-[12.5px] text-fg-subtle">{{ t('dlVersion', { version: VERSIONS.desktop }) }}</p>
</div> </div>
<div v-reveal class="grid gap-4 md:grid-cols-3"> <div v-reveal class="grid gap-4 md:grid-cols-3">
<div <a
v-for="p in platforms" v-for="p in platforms"
:key="p.key" :key="p.key"
class="flex flex-col gap-1 rounded-[14px] border border-border bg-surface-0 p-5 shadow-card" :href="p.href"
class="group flex flex-col gap-1 rounded-[14px] border border-border bg-surface-0 p-5 no-underline shadow-card transition-colors hover:border-accent/50 focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-accent/70"
> >
<div class="flex items-center gap-2 text-fg"> <div class="flex items-center gap-2 text-fg">
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="text-accent" aria-hidden="true"><path d="M21 15v4a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-4" /><polyline points="7 10 12 15 17 10" /><line x1="12" x2="12" y1="15" y2="3" /></svg> <svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="text-accent" aria-hidden="true"><path d="M21 15v4a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2v-4" /><polyline points="7 10 12 15 17 10" /><line x1="12" x2="12" y1="15" y2="3" /></svg>
<span class="text-[15px] font-semibold">{{ t(p.key) }}</span> <span class="text-[15px] font-semibold group-hover:text-accent">{{ t(p.key) }}</span>
</div> </div>
<span class="pl-[26px] font-mono text-[12.5px] text-fg-subtle">{{ t(p.hint) }}</span> <span class="pl-[26px] font-mono text-[12.5px] text-fg-subtle">{{ t(p.hint) }}</span>
</a>
</div> </div>
</div>
<p v-reveal class="mt-3 flex flex-wrap items-center gap-x-4 gap-y-1 text-[13px] text-fg-subtle">
<a
:href="DOWNLOADS.appImage"
class="text-fg-muted underline decoration-border underline-offset-2 hover:text-accent"
>
{{ t('dlLinuxAlt') }}
</a>
<a :href="RELEASES" target="_blank" rel="noopener" class="text-fg-muted underline decoration-border underline-offset-2 hover:text-accent">
{{ t('dlAllAssets') }}
</a>
<a :href="DESKTOP_SRC" target="_blank" rel="noopener" class="text-fg-muted underline decoration-border underline-offset-2 hover:text-accent">
{{ t('dlSource') }}
</a>
</p>
<ul v-reveal class="mt-6 flex flex-wrap gap-x-6 gap-y-2"> <ul v-reveal class="mt-6 flex flex-wrap gap-x-6 gap-y-2">
<li v-for="b in bullets" :key="b" class="flex items-center gap-2 text-[14px] text-fg-muted"> <li v-for="b in bullets" :key="b" class="flex items-center gap-2 text-[14px] text-fg-muted">
@@ -44,25 +65,9 @@ const bullets = ['dlNoNode', 'dlBundled', 'dlAutoUpdate'] as const;
</li> </li>
</ul> </ul>
<div v-reveal class="mt-7 flex flex-wrap items-center gap-3"> <!-- Premier lancement : ni l'installeur Windows ni l'app macOS ne sont signés. Le dire ICI évite
<a qu'un visiteur conclue à un binaire cassé. -->
:href="RELEASES" <p v-reveal class="mt-6 max-w-[720px] text-[13.5px] leading-[1.55] text-fg-subtle">{{ t('dlUnsigned') }}</p>
target="_blank" <p v-reveal class="mt-2 max-w-[720px] text-[13.5px] leading-[1.55] text-fg-subtle">{{ t('dlNote') }}</p>
rel="noopener"
class="inline-flex items-center gap-2 rounded-lg bg-accent-solid px-4 py-2.5 text-[14.5px] font-semibold text-white no-underline transition-colors hover:bg-accent-hover focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-accent/70"
>
{{ t('dlGet') }}
</a>
<a
:href="DESKTOP_SRC"
target="_blank"
rel="noopener"
class="inline-flex items-center gap-2 rounded-lg border border-border px-4 py-2.5 text-[14.5px] font-medium text-fg-muted no-underline transition-colors hover:border-accent/50 hover:text-accent focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-accent/70"
>
{{ t('dlSource') }}
</a>
</div>
<p v-reveal class="mt-4 max-w-[720px] text-[13.5px] leading-[1.55] text-fg-subtle">{{ t('dlNote') }}</p>
</section> </section>
</template> </template>
@@ -120,6 +120,27 @@ const { t } = useI18n();
</template> </template>
{{ t('feat15Desc') }} {{ t('feat15Desc') }}
</FeatureCard> </FeatureCard>
<FeatureCard :title="t('feat16Title')">
<template #icon>
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M4.5 16.5c-1.5 1.26-2 5-2 5s3.74-.5 5-2c.71-.84.7-2.13-.09-2.91a2.18 2.18 0 0 0-2.91-.09z" /><path d="m12 15-3-3a22 22 0 0 1 2-3.95A12.88 12.88 0 0 1 22 2c0 2.72-.78 7.5-6 11a22.35 22.35 0 0 1-4 2z" /><path d="M9 12H4s.55-3.03 2-4c1.62-1.08 5 0 5 0" /><path d="M12 15v5s3.03-.55 4-2c1.08-1.62 0-5 0-5" /></svg>
</template>
{{ t('feat16Desc') }}
</FeatureCard>
<FeatureCard :title="t('feat17Title')">
<template #icon>
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M3 3v5h5" /><path d="M3.05 13A9 9 0 1 0 6 5.3L3 8" /><path d="M12 7v5l4 2" /></svg>
</template>
{{ t('feat17Desc') }}
</FeatureCard>
<FeatureCard :title="t('feat18Title')">
<template #icon>
<svg width="21" height="21" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M12 20a8 8 0 1 0 0-16 8 8 0 0 0 0 16Z" /><path d="M12 14a2 2 0 1 0 0-4 2 2 0 0 0 0 4Z" /><path d="M12 2v2" /><path d="M12 20v2" /><path d="m4.93 4.93 1.41 1.41" /><path d="m17.66 17.66 1.41 1.41" /><path d="M2 12h2" /><path d="M20 12h2" /></svg>
</template>
{{ t('feat18Desc') }}
</FeatureCard>
</div> </div>
</section> </section>
</template> </template>
@@ -1,6 +1,7 @@
<script setup lang="ts"> <script setup lang="ts">
import { useI18n } from 'vue-i18n'; import { useI18n } from 'vue-i18n';
import { INSTALL_COMMAND } from '../composables/useCopy'; import { INSTALL_COMMAND } from '../composables/useCopy';
import { NPMRC_LINE } from '../lib/links';
import CopyButton from './CopyButton.vue'; import CopyButton from './CopyButton.vue';
const { t } = useI18n(); const { t } = useI18n();
@@ -15,6 +16,20 @@ const LOCAL_URL = 'http://localhost:7317';
<h2 class="m-0 text-[clamp(28px,3.4vw,40px)] font-semibold tracking-[-0.025em] text-fg">{{ t('howTitle') }}</h2> <h2 class="m-0 text-[clamp(28px,3.4vw,40px)] font-semibold tracking-[-0.025em] text-fg">{{ t('howTitle') }}</h2>
</div> </div>
<!-- Prérequis : le paquet vit sur un registre npm PRIVÉ. Sans cette ligne dans ~/.npmrc, le `npx`
de l'étape 1 renvoie un 404. C'était le premier mur pour tout nouvel arrivant. -->
<div v-reveal class="mb-4 rounded-xl border border-border bg-surface-1/50 p-[26px]">
<h3 class="m-0 mb-2.5 text-lg font-semibold text-fg">{{ t('prereqTitle') }}</h3>
<p class="m-0 mb-4 text-[14.5px] leading-[1.55] text-fg-muted">{{ t('prereqDesc') }}</p>
<div class="flex items-center gap-2 rounded-lg border border-border bg-surface-0 p-[11px]">
<code class="min-w-0 flex-1 overflow-x-auto whitespace-nowrap font-mono text-[12.5px] text-fg">
{{ NPMRC_LINE }}
</code>
<CopyButton variant="icon" :text="NPMRC_LINE" :label="t('copyCommand')" />
</div>
<p class="m-0 mt-3 text-[13.5px] leading-[1.55] text-fg-subtle">{{ t('prereqNote') }}</p>
</div>
<div v-reveal class="grid grid-cols-[repeat(auto-fit,minmax(280px,1fr))] gap-4"> <div v-reveal class="grid grid-cols-[repeat(auto-fit,minmax(280px,1fr))] gap-4">
<div class="rounded-xl border border-border bg-surface-1/50 p-[26px]"> <div class="rounded-xl border border-border bg-surface-1/50 p-[26px]">
<div class="mb-[18px] font-mono text-[13px] text-accent">01</div> <div class="mb-[18px] font-mono text-[13px] text-accent">01</div>
@@ -0,0 +1,84 @@
<script setup lang="ts">
import { useI18n } from 'vue-i18n';
const { t } = useI18n();
// Commandes de démarrage du mockup (fidele a LaunchProjectModal : label + commande mono).
const cmds = [
{ label: 'web', run: 'npm run dev' },
{ label: 'api', run: 'npm run api' },
{ label: 'db', run: 'docker compose up' },
];
</script>
<template>
<section id="launch" class="mx-auto max-w-[1200px] scroll-mt-[84px] px-6 pb-[100px]">
<div v-reveal class="flex flex-wrap items-center gap-12">
<!-- texte -->
<div class="min-w-[280px] flex-[1_1_360px]">
<div class="mb-3 font-mono text-xs uppercase tracking-[0.12em] text-accent">{{ t('launchScKicker') }}</div>
<h2 class="m-0 mb-4 text-[clamp(26px,3vw,34px)] font-semibold leading-[1.15] tracking-[-0.025em] text-fg">
{{ t('launchScTitle') }}
</h2>
<p class="m-0 text-[16.5px] leading-[1.6] text-fg-muted">{{ t('launchScBody') }}</p>
</div>
<!-- mockup : modal « Démarrer le projet » puis dock a un onglet terminal par commande -->
<div class="flex min-w-[280px] flex-[1_1_440px] flex-col gap-3">
<!-- modal (fidele a LaunchProjectModal) -->
<div class="overflow-hidden rounded-xl border border-border bg-surface-1 shadow-card">
<header class="flex items-center gap-2 border-b border-border px-3 py-2.5">
<svg width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" class="text-accent" aria-hidden="true"><path d="M4.5 16.5c-1.5 1.26-2 5-2 5s3.74-.5 5-2c.71-.84.7-2.13-.09-2.91a2.18 2.18 0 0 0-2.91-.09z" /><path d="m12 15-3-3a22 22 0 0 1 2-3.95A12.88 12.88 0 0 1 22 2c0 2.72-.78 7.5-6 11a22.35 22.35 0 0 1-4 2z" /><path d="M9 12H4s.55-3.03 2-4c1.62-1.08 5 0 5 0" /><path d="M12 15v5s3.03-.55 4-2c1.08-1.62 0-5 0-5" /></svg>
<span class="text-sm font-semibold text-fg">{{ t('launchModalTitle') }}</span>
<span class="ml-auto rounded bg-surface-2 px-1.5 py-0.5 font-mono text-[11px] text-fg-muted">api</span>
</header>
<div class="flex flex-col gap-2 p-3">
<div v-for="c in cmds" :key="c.label" class="flex items-center gap-2">
<span class="inline-flex h-4 w-4 flex-none items-center justify-center rounded bg-accent-solid text-white">
<svg width="11" height="11" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="3" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M20 6 9 17l-5-5" /></svg>
</span>
<span class="w-16 flex-none truncate rounded bg-surface-2 px-1.5 py-1 text-xs font-medium text-fg">{{ c.label }}</span>
<span class="min-w-0 flex-1 truncate rounded border border-border bg-surface-0 px-2 py-1 font-mono text-xs text-fg-muted">{{ c.run }}</span>
</div>
<div class="mt-1 flex items-center gap-2">
<span class="inline-flex items-center gap-1.5 rounded-lg border border-border bg-surface-2 px-2.5 py-1.5 text-xs font-medium text-fg-muted">
<svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M12 3l1.9 5.8a2 2 0 0 0 1.3 1.3L21 12l-5.8 1.9a2 2 0 0 0-1.3 1.3L12 21l-1.9-5.8a2 2 0 0 0-1.3-1.3L3 12l5.8-1.9a2 2 0 0 0 1.3-1.3z" /></svg>
{{ t('launchDetect') }}
</span>
<span class="ml-auto inline-flex items-center gap-1.5 rounded-lg bg-accent-solid px-2.5 py-1.5 text-xs font-semibold text-white">
<svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2.2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><polygon points="6 3 20 12 6 21 6 3" /></svg>
{{ t('launchStartN') }}
</span>
</div>
</div>
</div>
<!-- fleche vers le dock -->
<div class="flex justify-center text-fg-subtle">
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.8" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="M12 5v14" /><path d="m19 12-7 7-7-7" /></svg>
</div>
<!-- dock IDE : un onglet terminal par commande lancée -->
<div class="overflow-hidden rounded-xl border border-border bg-surface-0 shadow-card">
<div class="flex items-stretch border-b border-border text-[11px]">
<span class="label-mono flex items-center gap-1 px-2 py-1.5">
<svg width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m7 11 2-2-2-2" /><path d="M11 13h4" /><rect width="18" height="18" x="3" y="3" rx="2" /></svg>
{{ t('mTerminal') }}
</span>
<span class="flex items-center gap-1.5 border-l border-border bg-surface-0 px-2.5 py-1.5 font-mono text-fg">
<span class="h-1.5 w-1.5 animate-pulse-sky rounded-full bg-info"></span>web
</span>
<span class="flex items-center gap-1.5 border-l border-border px-2.5 py-1.5 font-mono text-fg-muted">api</span>
<span class="flex items-center gap-1.5 border-l border-border px-2.5 py-1.5 font-mono text-fg-muted">db</span>
</div>
<div class="min-h-[104px] p-[11px] font-mono text-[11px] leading-[1.7] text-fg-muted">
<div class="text-fg-subtle">$ npm run dev</div>
<div class="text-accent">VITE v6 ready in 312 ms</div>
<div class="text-fg-subtle">Local: http://localhost:5173/</div>
<div><span class="text-accent">$</span><span class="ml-1 inline-block h-[11px] w-1.5 animate-blink bg-fg align-middle"></span></div>
</div>
</div>
</div>
</div>
</section>
</template>
@@ -61,6 +61,10 @@ function marker(type: DiffLine['type']): string {
<span class="flex h-9 w-9 items-center justify-center rounded-lg" :title="t('wsTerminal')"> <span class="flex h-9 w-9 items-center justify-center rounded-lg" :title="t('wsTerminal')">
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m7 11 2-2-2-2" /><path d="M11 13h4" /><rect width="18" height="18" x="3" y="3" rx="2" /></svg> <svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m7 11 2-2-2-2" /><path d="M11 13h4" /><rect width="18" height="18" x="3" y="3" rx="2" /></svg>
</span> </span>
<!-- 4e onglet : Groupes (l'app en a quatre, le mockup n'en montrait que trois) -->
<span class="flex h-9 w-9 items-center justify-center rounded-lg" :title="t('wsGroups')">
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><path d="m7.5 4.27 9 5.15" /><path d="M21 8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16Z" /><path d="m3.3 7 8.7 5 8.7-5" /><path d="M12 22V12" /></svg>
</span>
</nav> </nav>
<!-- arbre unifie : plusieurs projets a la fois --> <!-- arbre unifie : plusieurs projets a la fois -->
@@ -77,6 +81,12 @@ function marker(type: DiffLine['type']): string {
<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0 text-fg-subtle" aria-hidden="true"><path d="m6 9 6 6 6-6" /></svg> <svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0 text-fg-subtle" aria-hidden="true"><path d="m6 9 6 6 6-6" /></svg>
<svg width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="var(--color-accent)" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0" aria-hidden="true"><line x1="6" x2="6" y1="3" y2="15" /><circle cx="18" cy="6" r="3" /><circle cx="6" cy="18" r="3" /><path d="M18 9a9 9 0 0 1-9 9" /></svg> <svg width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="var(--color-accent)" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0" aria-hidden="true"><line x1="6" x2="6" y1="3" y2="15" /><circle cx="18" cy="6" r="3" /><circle cx="6" cy="18" r="3" /><path d="M18 9a9 9 0 0 1-9 9" /></svg>
<span class="truncate text-accent">feat/auth</span> <span class="truncate text-accent">feat/auth</span>
<!-- compteurs git compacts : ahead / indexés / non indexés, comme dans l'app -->
<span class="ml-auto flex shrink-0 items-center gap-1 text-[11px]">
<span class="text-accent">↑2</span>
<span class="text-accent">●1</span>
<span class="text-warn">○1</span>
</span>
</div> </div>
<!-- session claude corrélée --> <!-- session claude corrélée -->
<div class="flex items-center gap-1.5 rounded py-0.5 pr-2 pl-[38px] text-fg-muted"> <div class="flex items-center gap-1.5 rounded py-0.5 pr-2 pl-[38px] text-fg-muted">
@@ -94,6 +104,7 @@ function marker(type: DiffLine['type']): string {
<div class="flex items-center gap-1 rounded py-0.5 pr-2 pl-1.5 text-fg-muted"> <div class="flex items-center gap-1 rounded py-0.5 pr-2 pl-1.5 text-fg-muted">
<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0 text-fg-subtle" aria-hidden="true"><path d="m9 18 6-6-6-6" /></svg> <svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0 text-fg-subtle" aria-hidden="true"><path d="m9 18 6-6-6-6" /></svg>
<span class="font-medium">web</span> <span class="font-medium">web</span>
<span class="ml-auto shrink-0 text-[11px] text-warn">○3</span>
</div> </div>
<div class="flex items-center gap-1 rounded py-0.5 pr-2 pl-1.5 text-fg-muted"> <div class="flex items-center gap-1 rounded py-0.5 pr-2 pl-1.5 text-fg-muted">
<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0 text-fg-subtle" aria-hidden="true"><path d="m9 18 6-6-6-6" /></svg> <svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="shrink-0 text-fg-subtle" aria-hidden="true"><path d="m9 18 6-6-6-6" /></svg>
+2 -2
View File
@@ -31,7 +31,7 @@ export const FAQS: Record<AppLocale, FaqItem[]> = {
}, },
{ {
q: 'Can I edit files directly?', q: 'Can I edit files directly?',
a: 'Yes. The /workspace view is a real IDE: a file tree, a full Monaco editor with inline diffs, and the correlated session terminal. Stage changes file by file, write a commit message, amend, then push, all from the browser, on any device.', a: 'Yes. The /ide view is a real IDE: a file tree, a full Monaco editor with inline diffs, and the correlated session terminal. Stage changes file by file, write a commit message, amend, then push, all from the browser, on any device.',
}, },
{ {
q: 'Can I connect GitHub, GitLab or Gitea and clone?', q: 'Can I connect GitHub, GitLab or Gitea and clone?',
@@ -65,7 +65,7 @@ export const FAQS: Record<AppLocale, FaqItem[]> = {
}, },
{ {
q: 'Puis-je éditer les fichiers directement ?', q: 'Puis-je éditer les fichiers directement ?',
a: "Oui. La vue /workspace est un vrai IDE : un arbre de fichiers, un éditeur Monaco complet avec les diffs inline, et le terminal de la session corrélée. Indexez les changements fichier par fichier, rédigez un message de commit, amendez, puis poussez, le tout depuis le navigateur, sur n'importe quel appareil.", a: "Oui. La vue /ide est un vrai IDE : un arbre de fichiers, un éditeur Monaco complet avec les diffs inline, et le terminal de la session corrélée. Indexez les changements fichier par fichier, rédigez un message de commit, amendez, puis poussez, le tout depuis le navigateur, sur n'importe quel appareil.",
}, },
{ {
q: 'Puis-je connecter GitHub, GitLab ou Gitea et cloner ?', q: 'Puis-je connecter GitHub, GitLab ou Gitea et cloner ?',
+51 -19
View File
@@ -2,10 +2,14 @@
export default { export default {
navFeatures: 'Features', navFeatures: 'Features',
navWorkspace: 'IDE', navWorkspace: 'IDE',
navLaunch: 'Start project',
navRemoteGit: 'Git services',
navDownload: 'Download', navDownload: 'Download',
navHow: 'How it works', navHow: 'How it works',
navSecurity: 'Security', navSecurity: 'Security',
navFaq: 'FAQ', navFaq: 'FAQ',
navMenu: 'Menu',
backToTop: 'Back to top',
themeToggle: 'Toggle theme', themeToggle: 'Toggle theme',
gitea: 'View on Gitea', gitea: 'View on Gitea',
heroBadge: 'Mission control for AI coding agents', heroBadge: 'Mission control for AI coding agents',
@@ -39,6 +43,12 @@ export default {
feat9Desc: 'Drive worktrees and attach sessions in native terminals, right inside your editor.', feat9Desc: 'Drive worktrees and attach sessions in native terminals, right inside your editor.',
feat10Title: 'New project in one click', feat10Title: 'New project in one click',
feat10Desc: 'Create a project folder anywhere (optional git init) and start a Claude session in it, from any device.', feat10Desc: 'Create a project folder anywhere (optional git init) and start a Claude session in it, from any device.',
feat16Title: 'Start your project',
feat16Desc: 'Define your dev commands once (dev server, API, database), then launch each in its own terminal in a single click.',
feat17Title: 'Branch history',
feat17Desc: 'See what is already committed, which commits are not pushed yet, and unfold the full diff of any of them, right next to what is still uncommitted.',
feat18Title: 'Git state at a glance',
feat18Desc: 'Every worktree row carries its own counters: ahead/behind, staged, unstaged, conflicts. They refresh on their own while an agent works, no click needed.',
scAKicker: 'Session supervision', scAKicker: 'Session supervision',
scATitle: 'See what needs you, before anything stalls', scATitle: 'See what needs you, before anything stalls',
scABody: scABody:
@@ -56,6 +66,11 @@ export default {
grpTitle: 'Drive every repo from one Claude session', grpTitle: 'Drive every repo from one Claude session',
grpBody: grpBody:
'Group the repos that move together: a service, its client, its docs. Launch a single Claude session that spans all of them at once: one conversation, one shared context working across every repo, instead of juggling one agent per repo.', 'Group the repos that move together: a service, its client, its docs. Launch a single Claude session that spans all of them at once: one conversation, one shared context working across every repo, instead of juggling one agent per repo.',
prereqTitle: 'Prerequisites',
prereqDesc:
'Arboretum is published on a private npm registry. Declare its scope once in your ~/.npmrc, otherwise npm answers 404.',
prereqNote:
'You also need Node 22.16 or newer (the daemon uses node:sqlite) and the Claude Code CLI on your PATH. The desktop app needs neither: it bundles its own runtime.',
howKicker: 'How it works', howKicker: 'How it works',
howTitle: 'Zero install. Three steps.', howTitle: 'Zero install. Three steps.',
step1Title: 'Launch the daemon', step1Title: 'Launch the daemon',
@@ -82,20 +97,13 @@ export default {
footTag: 'a garden of branches, one pane of glass.', footTag: 'a garden of branches, one pane of glass.',
license: 'MIT License', license: 'MIT License',
coffee: 'Buy me a coffee', coffee: 'Buy me a coffee',
mIde: 'IDE',
mProjects: 'Projects', mProjects: 'Projects',
mWorktrees: 'Worktrees',
mExplorer: 'Explorer', mExplorer: 'Explorer',
mEditor: 'Editor', mEditor: 'Editor',
mTerminal: 'Terminal', mTerminal: 'Terminal',
mGit: 'Git', mGit: 'Git',
mSessions: 'Sessions', mSessions: 'Sessions',
mGroups: 'Groups', mGroups: 'Groups',
mSettings: 'Settings',
mHelp: 'Help',
mGitea: 'Gitea',
mMore: 'More',
mSearch: 'Search',
mAttn: 'Needs attention', mAttn: 'Needs attention',
waiting: 'waiting', waiting: 'waiting',
busy: 'busy', busy: 'busy',
@@ -137,16 +145,18 @@ export default {
wsDiff: 'Diff', wsDiff: 'Diff',
wsFiles: 'Files', wsFiles: 'Files',
wsChanges: 'Changes', wsChanges: 'Changes',
wsStaged: 'Staged',
wsTerminal: 'Terminal', wsTerminal: 'Terminal',
wsCommitMsg: 'Implement token refresh', wsGroups: 'Groups',
wsCommitPlaceholder: 'Commit message…',
wsAmend: 'Amend last commit',
wsCommitBtn: 'Commit', wsCommitBtn: 'Commit',
wsPushBtn: 'Push',
wsStage: 'Stage', // « Start the project » : lancement multi-terminaux
wsUnstage: 'Unstage', launchScKicker: 'Start the project',
wsDiscard: 'Discard', launchScTitle: 'One click, every terminal your project needs',
launchScBody:
'Most projects need more than one long-running command: a dev server, an API, a database. Define them once per project (auto-detected from package.json, Procfile or docker-compose), then launch them all at once. Each command opens in its own docked terminal you can attach to, restart, or stop as a group.',
launchModalTitle: 'Start the project',
launchDetect: 'Detect',
launchStartN: 'Start (3)',
// Remote git services + clone // Remote git services + clone
rgKicker: 'Remote git · encrypted', rgKicker: 'Remote git · encrypted',
@@ -157,7 +167,6 @@ export default {
rgTested: 'tested', rgTested: 'tested',
rgAddConnection: 'Add connection', rgAddConnection: 'Add connection',
rgEncrypted: 'Encrypted at rest', rgEncrypted: 'Encrypted at rest',
rgCloning: 'Cloning',
rgCloneReceiving: 'Receiving objects', rgCloneReceiving: 'Receiving objects',
// Security pillar (encrypted secrets) // Security pillar (encrypted secrets)
@@ -165,20 +174,43 @@ export default {
sec5Desc: 'Remote git credentials are encrypted at rest (AES-256-GCM) and never returned in clear by the API.', sec5Desc: 'Remote git credentials are encrypted at rest (AES-256-GCM) and never returned in clear by the API.',
// Desktop app (download) // Desktop app (download)
wayKicker: 'Three ways to run it',
wayTitle: 'Desktop app, web server, or inside VS Code',
wayBody:
'The same daemon powers all three. Pick the one that fits the machine you are on, they share the same data.',
wayDesktop: 'Desktop app',
wayDesktopBody:
'A native window that starts the daemon for you, already signed in, with a tray icon and launch-at-login. Nothing to install beyond the app itself.',
wayDesktopLink: 'Download',
wayServer: 'Self-hosted web server',
wayServerBody:
'Run the daemon on your workstation and reach its UI from any device you own: laptop, tablet, phone. Tailscale Serve gives you HTTPS inside your tailnet without opening a port, which is also what enables push notifications and PWA install.',
wayVscode: 'VS Code extension',
wayVscodeBody:
'A native extension (not a webview) that connects to the same daemon: live tree of repos, worktrees and sessions, native terminals, a waiting counter with notifications, and git actions.',
wayVscodeLink: 'Get the VSIX',
wayOriginNote:
'One rule to remember when serving it beyond localhost: the daemon rejects any address it was not told about, with a 403. Start it with --allow-origin <your URL> (repeatable) and it is settled. Binding beyond loopback also requires an explicit acknowledgement flag, on purpose.',
wayBuildNote: 'Build the desktop app yourself from',
dlKicker: 'Native desktop app', dlKicker: 'Native desktop app',
dlTitle: 'Download Arboretum for your desktop', dlTitle: 'Download Arboretum for your desktop',
dlBody: dlBody:
'A native app for Linux, Windows and macOS. It bundles the daemon and its Node runtime, so there is nothing else to install: launch it and your multi-project IDE opens, already signed in. Tray, launch at login and auto-update included. Prefer the terminal? Keep running it in the browser with a single command.', 'A native app for Linux, Windows and macOS. It bundles the daemon and its Node runtime, so there is nothing else to install: launch it and your multi-project IDE opens, already signed in. Tray, launch at login and auto-update included. Prefer the terminal? Keep running it in the browser with a single command.',
dlLinux: 'Linux', dlLinux: 'Linux',
dlLinuxHint: 'AppImage and .deb', dlLinuxHint: '.deb (Debian, Ubuntu)',
dlLinuxAlt: 'AppImage (other distributions)',
dlWin: 'Windows', dlWin: 'Windows',
dlWinHint: 'NSIS installer and portable', dlWinHint: 'NSIS installer and portable',
dlMac: 'macOS', dlMac: 'macOS',
dlMacHint: 'dmg (best-effort, unsigned)', dlMacHint: 'build from source (unsigned)',
dlNoNode: 'No Node install needed', dlNoNode: 'No Node install needed',
dlBundled: 'Daemon and runtime bundled', dlBundled: 'Daemon and runtime bundled',
dlAutoUpdate: 'Auto-update on Windows and Linux', dlAutoUpdate: 'Auto-update on Windows and Linux',
dlVersion: 'Latest desktop release: {version}',
dlAllAssets: 'All release assets',
dlUnsigned:
'The binaries are not code-signed. On Windows, SmartScreen shows "unknown publisher": choose More info, then Run anyway. On macOS, right-click the app then Open.',
dlGet: 'Get the app', dlGet: 'Get the app',
dlSource: 'Build from source', dlSource: 'Build from source',
dlNote: 'Installers are published on the releases page once a desktop build is tagged. Until then, build it from source (see packages/desktop).', dlNote: 'macOS builds are produced on demand (no macOS CI runner): build them with npm run dist:mac, or ask for one.',
}; };
+51 -19
View File
@@ -2,10 +2,14 @@
export default { export default {
navFeatures: 'Fonctionnalités', navFeatures: 'Fonctionnalités',
navWorkspace: 'IDE', navWorkspace: 'IDE',
navLaunch: 'Démarrer',
navRemoteGit: 'Services git',
navDownload: 'Télécharger', navDownload: 'Télécharger',
navHow: 'Comment ça marche', navHow: 'Comment ça marche',
navSecurity: 'Sécurité', navSecurity: 'Sécurité',
navFaq: 'FAQ', navFaq: 'FAQ',
navMenu: 'Menu',
backToTop: 'Revenir en haut',
themeToggle: 'Changer de thème', themeToggle: 'Changer de thème',
gitea: 'Voir sur Gitea', gitea: 'Voir sur Gitea',
heroBadge: 'Poste de commandement pour agents de code IA', heroBadge: 'Poste de commandement pour agents de code IA',
@@ -39,6 +43,12 @@ export default {
feat9Desc: 'Pilotez vos worktrees et attachez vos sessions dans des terminaux natifs, directement dans votre éditeur.', feat9Desc: 'Pilotez vos worktrees et attachez vos sessions dans des terminaux natifs, directement dans votre éditeur.',
feat10Title: 'Nouveau projet en un clic', feat10Title: 'Nouveau projet en un clic',
feat10Desc: "Créez un dossier de projet où vous voulez (git init optionnel) et lancez-y une session Claude, depuis n'importe quel appareil.", feat10Desc: "Créez un dossier de projet où vous voulez (git init optionnel) et lancez-y une session Claude, depuis n'importe quel appareil.",
feat16Title: 'Démarrez votre projet',
feat16Desc: 'Définissez vos commandes de démarrage une fois (serveur de dev, API, base de données), puis lancez chacune dans son terminal en un seul clic.',
feat17Title: 'Historique de branche',
feat17Desc: 'Voyez ce qui est déjà commité, quels commits ne sont pas encore poussés, et dépliez le diff complet de n’importe lequel, juste à côté de ce qui n’est pas commité.',
feat18Title: 'État git d’un coup d’œil',
feat18Desc: 'Chaque worktree porte ses compteurs : avance/retard, indexés, non indexés, conflits. Ils se rafraîchissent seuls pendant qu’un agent travaille, sans un clic.',
scAKicker: 'Supervision des sessions', scAKicker: 'Supervision des sessions',
scATitle: 'Voyez ce qui vous attend, avant que ça ne bloque', scATitle: 'Voyez ce qui vous attend, avant que ça ne bloque',
scABody: scABody:
@@ -56,6 +66,11 @@ export default {
grpTitle: 'Pilotez tous vos repos depuis une seule session Claude', grpTitle: 'Pilotez tous vos repos depuis une seule session Claude',
grpBody: grpBody:
'Regroupez les repos qui avancent ensemble : un service, son client, sa doc. Lancez une seule session Claude qui les couvre tous à la fois : une conversation, un contexte partagé travaillant à travers chaque repo, au lieu de jongler avec un agent par repo.', 'Regroupez les repos qui avancent ensemble : un service, son client, sa doc. Lancez une seule session Claude qui les couvre tous à la fois : une conversation, un contexte partagé travaillant à travers chaque repo, au lieu de jongler avec un agent par repo.',
prereqTitle: 'Prérequis',
prereqDesc:
'Arboretum est publié sur un registre npm privé. Déclarez son scope une fois dans votre ~/.npmrc, sinon npm répond 404.',
prereqNote:
'Il vous faut aussi Node 22.16 ou plus récent (le daemon utilise node:sqlite) et le CLI Claude Code dans votre PATH. L’app de bureau n’a besoin d’aucun des deux : elle embarque son runtime.',
howKicker: 'Comment ça marche', howKicker: 'Comment ça marche',
howTitle: 'Zéro install. Trois étapes.', howTitle: 'Zéro install. Trois étapes.',
step1Title: 'Lancez le daemon', step1Title: 'Lancez le daemon',
@@ -82,20 +97,13 @@ export default {
footTag: 'un jardin de branches, une seule vitre.', footTag: 'un jardin de branches, une seule vitre.',
license: 'Licence MIT', license: 'Licence MIT',
coffee: 'Paye-moi un café', coffee: 'Paye-moi un café',
mIde: 'IDE',
mProjects: 'Projets', mProjects: 'Projets',
mWorktrees: 'Worktrees',
mExplorer: 'Explorateur', mExplorer: 'Explorateur',
mEditor: 'Éditeur', mEditor: 'Éditeur',
mTerminal: 'Terminal', mTerminal: 'Terminal',
mGit: 'Git', mGit: 'Git',
mSessions: 'Sessions', mSessions: 'Sessions',
mGroups: 'Groupes', mGroups: 'Groupes',
mSettings: 'Réglages',
mHelp: 'Aide',
mGitea: 'Gitea',
mMore: 'Plus',
mSearch: 'Rechercher',
mAttn: 'À traiter', mAttn: 'À traiter',
waiting: 'en attente', waiting: 'en attente',
busy: 'occupée', busy: 'occupée',
@@ -137,16 +145,18 @@ export default {
wsDiff: 'Diff', wsDiff: 'Diff',
wsFiles: 'Fichiers', wsFiles: 'Fichiers',
wsChanges: 'Changements', wsChanges: 'Changements',
wsStaged: 'Indexés',
wsTerminal: 'Terminal', wsTerminal: 'Terminal',
wsCommitMsg: 'Implémente le rafraîchissement du token', wsGroups: 'Groupes',
wsCommitPlaceholder: 'Message de commit…',
wsAmend: 'Amender le dernier commit',
wsCommitBtn: 'Commit', wsCommitBtn: 'Commit',
wsPushBtn: 'Push',
wsStage: 'Indexer', // « Démarrer le projet » : lancement multi-terminaux
wsUnstage: 'Désindexer', launchScKicker: 'Démarrer le projet',
wsDiscard: 'Annuler', launchScTitle: 'Un clic, tous les terminaux dont votre projet a besoin',
launchScBody:
"La plupart des projets exigent plusieurs commandes longue durée : un serveur de dev, une API, une base de données. Définissez-les une fois par projet (détectées depuis package.json, Procfile ou docker-compose), puis lancez-les toutes d'un coup. Chaque commande ouvre son propre terminal en dock, que vous pouvez attacher, relancer ou arrêter en groupe.",
launchModalTitle: 'Démarrer le projet',
launchDetect: 'Détecter',
launchStartN: 'Démarrer (3)',
// Services git distants + clone // Services git distants + clone
rgKicker: 'Git distant · chiffré', rgKicker: 'Git distant · chiffré',
@@ -157,7 +167,6 @@ export default {
rgTested: 'testée', rgTested: 'testée',
rgAddConnection: 'Ajouter une connexion', rgAddConnection: 'Ajouter une connexion',
rgEncrypted: 'Chiffré au repos', rgEncrypted: 'Chiffré au repos',
rgCloning: 'Clonage',
rgCloneReceiving: 'Réception des objets', rgCloneReceiving: 'Réception des objets',
// Pilier sécurité (secrets chiffrés) // Pilier sécurité (secrets chiffrés)
@@ -165,20 +174,43 @@ export default {
sec5Desc: "Les identifiants git distants sont chiffrés au repos (AES-256-GCM) et jamais renvoyés en clair par l'API.", sec5Desc: "Les identifiants git distants sont chiffrés au repos (AES-256-GCM) et jamais renvoyés en clair par l'API.",
// App de bureau (téléchargement) // App de bureau (téléchargement)
wayKicker: 'Trois façons de l’utiliser',
wayTitle: 'App de bureau, serveur web, ou dans VS Code',
wayBody:
'Le même daemon alimente les trois. Choisissez celle qui correspond à la machine où vous êtes : elles partagent les mêmes données.',
wayDesktop: 'Application de bureau',
wayDesktopBody:
'Une fenêtre native qui démarre le daemon pour vous, déjà connectée, avec icône de barre système et lancement au démarrage. Rien à installer d’autre que l’app.',
wayDesktopLink: 'Télécharger',
wayServer: 'Serveur web auto-hébergé',
wayServerBody:
'Faites tourner le daemon sur votre poste et ouvrez son interface depuis n’importe quel appareil qui vous appartient : portable, tablette, téléphone. Tailscale Serve fournit HTTPS dans votre tailnet sans ouvrir de port, ce qui active aussi les notifications et l’installation PWA.',
wayVscode: 'Extension VS Code',
wayVscodeBody:
'Une extension native (pas un webview) connectée au même daemon : arbre temps réel des dépôts, worktrees et sessions, terminaux natifs, compteur de sessions en attente avec notifications, et actions git.',
wayVscodeLink: 'Obtenir le VSIX',
wayOriginNote:
'Une règle à retenir dès qu’on sort de localhost : le daemon rejette toute adresse dont on ne lui a pas parlé, avec un 403. Démarrez-le avec --allow-origin <votre URL> (répétable) et c’est réglé. Sortir de la boucle locale demande en outre un flag d’acquittement explicite, volontairement.',
wayBuildNote: 'Buildez l’app de bureau vous-même depuis',
dlKicker: 'App de bureau native', dlKicker: 'App de bureau native',
dlTitle: 'Téléchargez Arboretum pour votre bureau', dlTitle: 'Téléchargez Arboretum pour votre bureau',
dlBody: dlBody:
"Une app native pour Linux, Windows et macOS. Elle embarque le daemon et son runtime Node : rien d'autre à installer, lancez-la et votre IDE multi-projet s'ouvre, déjà authentifié. Tray, lancement au login et auto-update inclus. Vous préférez le terminal ? Continuez à la lancer dans le navigateur en une commande.", "Une app native pour Linux, Windows et macOS. Elle embarque le daemon et son runtime Node : rien d'autre à installer, lancez-la et votre IDE multi-projet s'ouvre, déjà authentifié. Tray, lancement au login et auto-update inclus. Vous préférez le terminal ? Continuez à la lancer dans le navigateur en une commande.",
dlLinux: 'Linux', dlLinux: 'Linux',
dlLinuxHint: 'AppImage et .deb', dlLinuxHint: '.deb (Debian, Ubuntu)',
dlLinuxAlt: 'AppImage (autres distributions)',
dlWin: 'Windows', dlWin: 'Windows',
dlWinHint: 'Installeur NSIS et portable', dlWinHint: 'Installeur NSIS et portable',
dlMac: 'macOS', dlMac: 'macOS',
dlMacHint: 'dmg (best-effort, non signé)', dlMacHint: 'à builder depuis les sources (non signé)',
dlNoNode: "Pas besoin d'installer Node", dlNoNode: "Pas besoin d'installer Node",
dlBundled: 'Daemon et runtime embarqués', dlBundled: 'Daemon et runtime embarqués',
dlAutoUpdate: 'Auto-update sur Windows et Linux', dlAutoUpdate: 'Auto-update sur Windows et Linux',
dlVersion: 'Dernière version desktop : {version}',
dlAllAssets: 'Tous les fichiers de la release',
dlUnsigned:
'Les binaires ne sont pas signés. Sous Windows, SmartScreen affiche « éditeur inconnu » : choisissez Informations complémentaires, puis Exécuter quand même. Sous macOS, clic droit sur l’app puis Ouvrir.',
dlGet: "Obtenir l'app", dlGet: "Obtenir l'app",
dlSource: 'Builder depuis les sources', dlSource: 'Builder depuis les sources',
dlNote: 'Les installeurs sont publiés sur la page des releases dès qu\'un build desktop est taggé. En attendant, buildez depuis les sources (voir packages/desktop).', dlNote: 'Les builds macOS sont produits à la demande (pas de runner macOS en CI) : construisez-les avec npm run dist:mac, ou demandez-en un.',
}; };
+24
View File
@@ -8,3 +8,27 @@ export const COFFEE = 'https://buymeacoffee.com/johanleroy';
// et sources du paquet Electron pour un build local. // et sources du paquet Electron pour un build local.
export const RELEASES = `${REPO}/releases`; export const RELEASES = `${REPO}/releases`;
export const DESKTOP_SRC = `${REPO}/src/branch/main/packages/desktop`; export const DESKTOP_SRC = `${REPO}/src/branch/main/packages/desktop`;
// Versions publiées, source unique du site (affichées et utilisées pour construire les liens d'assets).
// À bumper avec les tags de release correspondants.
export const VERSIONS = {
daemon: '3.4.0',
desktop: '0.2.0',
vscode: '0.4.1',
} as const;
/**
* Lien direct d'un asset de release desktop. Le canal `desktop-latest` est un tag FLOTTANT recréé par la
* CI à chaque version : ces URL restent donc valides sans être rééditées à chaque release.
*/
const DESKTOP_LATEST = `${REPO}/releases/download/desktop-latest`;
export const DOWNLOADS = {
deb: `${DESKTOP_LATEST}/Arboretum-${VERSIONS.desktop}-amd64.deb`,
appImage: `${DESKTOP_LATEST}/Arboretum-${VERSIONS.desktop}-x86_64.AppImage`,
windows: `${DESKTOP_LATEST}/Arboretum-${VERSIONS.desktop}-x64.exe`,
vsix: `${REPO}/releases/tag/vscode-v${VERSIONS.vscode}`,
} as const;
/** Registre npm privé à déclarer avant tout `npx` : sans lui, npm renvoie un 404. */
export const NPM_REGISTRY = 'https://git.lidge.fr/api/packages/johanleroy/npm/';
export const NPMRC_LINE = '@johanleroy:registry=https://git.lidge.fr/api/packages/johanleroy/npm/';
+6 -2
View File
@@ -1,12 +1,16 @@
// Thème clair / sombre du site vitrine (aligné sur l'app : lib/theme.ts de packages/web). // Thème clair / sombre du site vitrine (aligné sur l'app : lib/theme.ts de packages/web).
// Singleton module Vue : `themeMode` (persisté en localStorage, clé `arb-theme`), `resolvedTheme` // Singleton module Vue : `themeMode` (persisté en localStorage, clé `arb.theme`), `resolvedTheme`
// (résout `system` via prefers-color-scheme), application au <html> (dataset.theme + metas). // (résout `system` via prefers-color-scheme), application au <html> (dataset.theme + metas).
import { computed, ref, watch, type ComputedRef } from 'vue'; import { computed, ref, watch, type ComputedRef } from 'vue';
export type ThemeMode = 'dark' | 'light' | 'system'; export type ThemeMode = 'dark' | 'light' | 'system';
export type ResolvedTheme = 'dark' | 'light'; export type ResolvedTheme = 'dark' | 'light';
const STORAGE_KEY = 'arb-theme'; // Même NOM de clé que l'app (packages/web/src/lib/theme.ts), par cohérence de nommage. À noter que la
// préférence n'est pas partagée pour autant : le site et une instance Arboretum vivent sur des
// origines différentes (donc des localStorage séparés), et l'app sérialise sa valeur en JSON là où le
// site stocke la chaîne brute, lue telle quelle par le script anti-FOUC de index.html.
const STORAGE_KEY = 'arb.theme';
// Doit rester synchronisé avec --color-surface-0 (style.css) : fond du <html> + metas. // Doit rester synchronisé avec --color-surface-0 (style.css) : fond du <html> + metas.
const BG: Record<ResolvedTheme, string> = { dark: '#09090b', light: '#fafafa' }; const BG: Record<ResolvedTheme, string> = { dark: '#09090b', light: '#fafafa' };
+16
View File
@@ -1,5 +1,21 @@
# Changelog # Changelog
## 0.4.1
- Marketplace metadata completed: a PNG icon (required to publish anywhere), gallery banner, homepage,
issue tracker, and an explicit untrusted-workspace declaration (the extension only talks to your
daemon over HTTP/WS, it never executes workspace code).
## 0.4.0
Reflects the daemon's **"Start the project"** milestone in supervision (no editor duplicated here).
- **Start Project.** A new command on repos and worktrees launches the project's configured start
commands, one native terminal per command. The commands themselves are defined in the web IDE; when
none are set yet, the action offers to open it.
- Sessions started by a launch are badged `launch` in the tree, and a **Stop Launch** action stops the
whole set (all terminals sharing the launch run) at once.
## 0.3.0 ## 0.3.0
Aligns with the daemon's **multi-project IDE** milestone: the web UI is now a single IDE that holds all Aligns with the daemon's **multi-project IDE** milestone: the web UI is now a single IDE that holds all
+2 -2
View File
@@ -53,13 +53,13 @@ The extension is bundled with esbuild (`@arboretum/shared` is inlined → the VS
npm install npm install
npm run build:vscode # builds @arboretum/shared then bundles the extension npm run build:vscode # builds @arboretum/shared then bundles the extension
cd packages/vscode && npx @vscode/vsce package --no-dependencies cd packages/vscode && npx @vscode/vsce package --no-dependencies
# → git-arboretum-0.3.0.vsix # → git-arboretum-<version>.vsix
``` ```
Install it with **Extensions: Install from VSIX…** in the Command Palette, or: Install it with **Extensions: Install from VSIX…** in the Command Palette, or:
```bash ```bash
code --install-extension git-arboretum-0.3.0.vsix # also: codium / cursor code --install-extension git-arboretum-<version>.vsix # also: codium / cursor
``` ```
### Other distribution channels (optional) ### Other distribution channels (optional)
Binary file not shown.

After

Width:  |  Height:  |  Size: 9.9 KiB

+58 -7
View File
@@ -2,7 +2,7 @@
"name": "git-arboretum", "name": "git-arboretum",
"displayName": "Arboretum", "displayName": "Arboretum",
"description": "Pilot your git worktrees and Claude Code sessions from VS Code: native terminals, live tree, waiting alerts.", "description": "Pilot your git worktrees and Claude Code sessions from VS Code: native terminals, live tree, waiting alerts.",
"version": "0.3.0", "version": "0.4.1",
"private": true, "private": true,
"publisher": "johanleroy", "publisher": "johanleroy",
"license": "MIT", "license": "MIT",
@@ -121,7 +121,7 @@
}, },
{ {
"command": "arboretum.answerSession", "command": "arboretum.answerSession",
"title": "Answer Prompt…", "title": "Answer Prompt\u2026",
"category": "Arboretum", "category": "Arboretum",
"icon": "$(comment-discussion)" "icon": "$(comment-discussion)"
}, },
@@ -151,13 +151,13 @@
}, },
{ {
"command": "arboretum.createWorktree", "command": "arboretum.createWorktree",
"title": "Create Worktree…", "title": "Create Worktree\u2026",
"category": "Arboretum", "category": "Arboretum",
"icon": "$(add)" "icon": "$(add)"
}, },
{ {
"command": "arboretum.commitWorktree", "command": "arboretum.commitWorktree",
"title": "Commit…", "title": "Commit\u2026",
"category": "Arboretum", "category": "Arboretum",
"icon": "$(git-commit)" "icon": "$(git-commit)"
}, },
@@ -175,7 +175,7 @@
}, },
{ {
"command": "arboretum.pullWorktree", "command": "arboretum.pullWorktree",
"title": "Pull…", "title": "Pull\u2026",
"category": "Arboretum", "category": "Arboretum",
"icon": "$(arrow-down)" "icon": "$(arrow-down)"
}, },
@@ -199,10 +199,22 @@
}, },
{ {
"command": "arboretum.startGroupSession", "command": "arboretum.startGroupSession",
"title": "Start Group Session…", "title": "Start Group Session\u2026",
"category": "Arboretum", "category": "Arboretum",
"icon": "$(play)" "icon": "$(play)"
}, },
{
"command": "arboretum.startProject",
"title": "Start Project",
"category": "Arboretum",
"icon": "$(rocket)"
},
{
"command": "arboretum.stopLaunch",
"title": "Stop Launch",
"category": "Arboretum",
"icon": "$(stop-circle)"
},
{ {
"command": "arboretum.startSessionHere", "command": "arboretum.startSessionHere",
"title": "Start Session in Current Folder", "title": "Start Session in Current Folder",
@@ -210,7 +222,7 @@
}, },
{ {
"command": "arboretum.createWorktreeHere", "command": "arboretum.createWorktreeHere",
"title": "Create Worktree for Current Folder…", "title": "Create Worktree for Current Folder\u2026",
"category": "Arboretum" "category": "Arboretum"
}, },
{ {
@@ -253,6 +265,11 @@
"when": "viewItem == arboretum:repo", "when": "viewItem == arboretum:repo",
"group": "1_session" "group": "1_session"
}, },
{
"command": "arboretum.startProject",
"when": "viewItem == arboretum:repo",
"group": "1_session"
},
{ {
"command": "arboretum.openWorktreeIde", "command": "arboretum.openWorktreeIde",
"when": "viewItem == arboretum:worktree", "when": "viewItem == arboretum:worktree",
@@ -293,6 +310,11 @@
"when": "viewItem == arboretum:worktree", "when": "viewItem == arboretum:worktree",
"group": "3_session" "group": "3_session"
}, },
{
"command": "arboretum.startProject",
"when": "viewItem == arboretum:worktree",
"group": "3_session"
},
{ {
"command": "arboretum.attachSession", "command": "arboretum.attachSession",
"when": "viewItem =~ /arboretum:session:live/", "when": "viewItem =~ /arboretum:session:live/",
@@ -313,6 +335,11 @@
"when": "viewItem =~ /arboretum:session:live/", "when": "viewItem =~ /arboretum:session:live/",
"group": "9_danger" "group": "9_danger"
}, },
{
"command": "arboretum.stopLaunch",
"when": "viewItem =~ /arboretum:session:live.*:launch/",
"group": "9_danger"
},
{ {
"command": "arboretum.resumeSession", "command": "arboretum.resumeSession",
"when": "viewItem =~ /arboretum:session:dead/", "when": "viewItem =~ /arboretum:session:dead/",
@@ -407,6 +434,14 @@
"command": "arboretum.startGroupSession", "command": "arboretum.startGroupSession",
"when": "false" "when": "false"
}, },
{
"command": "arboretum.startProject",
"when": "false"
},
{
"command": "arboretum.stopLaunch",
"when": "false"
},
{ {
"command": "arboretum.revealWorktree", "command": "arboretum.revealWorktree",
"when": "false" "when": "false"
@@ -430,5 +465,21 @@
"esbuild": "^0.21.0", "esbuild": "^0.21.0",
"typescript": "^5.7.0", "typescript": "^5.7.0",
"ws": "^8.18.0" "ws": "^8.18.0"
},
"icon": "media/icon.png",
"galleryBanner": {
"color": "#09090b",
"theme": "dark"
},
"homepage": "https://git-arboretum.com",
"bugs": {
"url": "https://git.lidge.fr/johanleroy/arboretum/issues"
},
"qna": false,
"capabilities": {
"untrustedWorkspaces": {
"supported": true,
"description": "The extension only talks to your Arboretum daemon over HTTP/WS; it never executes workspace code."
}
} }
} }
+7
View File
@@ -20,6 +20,8 @@ import type {
ReposListResponse, ReposListResponse,
SessionResponse, SessionResponse,
SessionsListResponse, SessionsListResponse,
StartLaunchRequest,
StartLaunchResponse,
StartRepoSessionRequest, StartRepoSessionRequest,
WorktreeResponse, WorktreeResponse,
WorktreesListResponse, WorktreesListResponse,
@@ -111,6 +113,11 @@ export class RestClient {
return this.request<SessionResponse>('POST', `/api/v1/repos/${encodeURIComponent(repoId)}/session`, body); return this.request<SessionResponse>('POST', `/api/v1/repos/${encodeURIComponent(repoId)}/session`, body);
} }
/** « Démarrer le projet » : lance un terminal par commande de démarrage activée du repo. */
startLaunch(repoId: string, body: StartLaunchRequest): Promise<StartLaunchResponse> {
return this.request<StartLaunchResponse>('POST', `/api/v1/repos/${encodeURIComponent(repoId)}/launch`, body);
}
// ---- sessions ---- // ---- sessions ----
createSession(body: CreateSessionRequest): Promise<SessionResponse> { createSession(body: CreateSessionRequest): Promise<SessionResponse> {
return this.request<SessionResponse>('POST', '/api/v1/sessions', body); return this.request<SessionResponse>('POST', '/api/v1/sessions', body);
+59
View File
@@ -236,6 +236,21 @@ export function registerCommands(context: vscode.ExtensionContext, deps: Command
if (group) void startGroupSessionFlow(deps, group); if (group) void startGroupSessionFlow(deps, group);
}); });
// ---- « Démarrer le projet » (lancement multi-terminaux) ----
cmd('arboretum.startProject', (node) => {
const wt = asWorktree(node as AnyNode);
if (wt) {
void startProjectFlow(deps, wt.repoId, { worktreePath: wt.worktree.path });
return;
}
const repo = asRepo(node as AnyNode);
if (repo) void startProjectFlow(deps, repo.id, {});
});
cmd('arboretum.stopLaunch', (node) => {
const s = asSession(node as AnyNode);
if (s?.launchRunId) void stopLaunchFlow(deps, s.launchRunId);
});
// ---- conscience du workspace (Phase D) ---- // ---- conscience du workspace (Phase D) ----
cmd('arboretum.startSessionHere', () => { cmd('arboretum.startSessionHere', () => {
const repoId = workspace.currentRepoId(); const repoId = workspace.currentRepoId();
@@ -331,3 +346,47 @@ async function startGroupSessionFlow(deps: CommandDeps, group: GroupSummary): Pr
} }
}); });
} }
/**
* Lance les commandes de démarrage du repo (un terminal natif par commande activée). L'édition des
* commandes reste dans l'IDE web : si aucune n'est configurée, on propose de l'ouvrir.
*/
async function startProjectFlow(
deps: CommandDeps,
repoId: string,
body: { worktreePath?: string },
): Promise<void> {
await run('start project', async () => {
const res = await deps.rest.startLaunch(repoId, body);
for (const s of res.sessions) deps.terminals.open(s, 'interactive');
if (res.sessions.length === 0) {
const OPEN = 'Open web IDE';
const pick = await vscode.window.showInformationMessage(
'Arboretum: no launch commands configured for this project. Define them in the web IDE.',
OPEN,
);
if (pick === OPEN) void vscode.env.openExternal(vscode.Uri.parse(deps.rest.url));
return;
}
if (res.skipped.length > 0) {
void vscode.window.showWarningMessage(
`Arboretum: ${res.skipped.length} command(s) skipped: ${res.skipped.map((s) => s.reason).join('; ')}`,
);
}
});
}
/** Arrête d'un coup tous les terminaux vivants d'un même lancement (partageant le launchRunId). */
async function stopLaunchFlow(deps: CommandDeps, launchRunId: string): Promise<void> {
const live = deps.store.allSessions().filter((s) => s.live && s.launchRunId === launchRunId);
if (live.length === 0) return;
const ok = await vscode.window.showWarningMessage(
`Stop all ${live.length} launch terminal(s)?`,
{ modal: true },
'Stop all',
);
if (ok !== 'Stop all') return;
await run('stop launch', async () => {
await Promise.all(live.map((s) => deps.rest.killSession(s.id)));
});
}
Binary file not shown.
+4
View File
@@ -58,6 +58,9 @@ export function sessionContextValue(s: SessionSummary): string {
let v = `arboretum:session:${s.live ? 'live' : 'dead'}`; let v = `arboretum:session:${s.live ? 'live' : 'dead'}`;
if (s.source === 'discovered') v += ':discovered'; if (s.source === 'discovered') v += ':discovered';
if (s.live && s.activity === 'waiting') v += ':waiting'; if (s.live && s.activity === 'waiting') v += ':waiting';
// Session issue de « Démarrer le projet » : suffixe additif (les regex de menu existantes,
// ancrées sur le préfixe, restent valides) qui gate l'action « Stop launch ».
if (s.launchRunId) v += ':launch';
return v; return v;
} }
@@ -94,6 +97,7 @@ function sessionDescription(s: SessionSummary): string {
if (s.archived) parts.push('archived'); if (s.archived) parts.push('archived');
if (s.source === 'discovered') parts.push('external'); if (s.source === 'discovered') parts.push('external');
if (s.groupId) parts.push('group'); if (s.groupId) parts.push('group');
if (s.launchRunId) parts.push('launch');
if (s.waitingFor) parts.push(`· ${s.waitingFor}`); if (s.waitingFor) parts.push(`· ${s.waitingFor}`);
return parts.join(' '); return parts.join(' ');
} }
+12
View File
@@ -62,6 +62,18 @@ describe('RestClient', () => {
expect(JSON.parse(String(captured[1]?.init.body))).toEqual({ path: '/w', mode: 'rebase' }); expect(JSON.parse(String(captured[1]?.init.body))).toEqual({ path: '/w', mode: 'rebase' });
}); });
it('startLaunch POST /repos/:id/launch avec le corps (commandIds / worktreePath)', async () => {
const captured: Captured[] = [];
const rest = new RestClient(
{ baseUrl: 'http://h:1', token: 't' },
fakeFetch({ ok: true, status: 200, body: { sessions: [], skipped: [] } }, captured),
);
await rest.startLaunch('repo id', { worktreePath: '/w', commandIds: ['a', 'b'] });
expect(captured[0]?.url).toBe('http://h:1/api/v1/repos/repo%20id/launch');
expect(captured[0]?.init.method).toBe('POST');
expect(JSON.parse(String(captured[0]?.init.body))).toEqual({ worktreePath: '/w', commandIds: ['a', 'b'] });
});
it('listSessions construit la query includeHidden/includeArchived', async () => { it('listSessions construit la query includeHidden/includeArchived', async () => {
const captured: Captured[] = []; const captured: Captured[] = [];
const rest = new RestClient( const rest = new RestClient(
+1
View File
@@ -9,6 +9,7 @@ function repo(id: string): RepoSummary {
label: id, label: id,
defaultBranch: 'main', defaultBranch: 'main',
postCreateHooks: [], postCreateHooks: [],
launchCommands: [],
preTrust: false, preTrust: false,
createdAt: '2026-01-01T00:00:00Z', createdAt: '2026-01-01T00:00:00Z',
valid: true, valid: true,
+4 -21
View File
@@ -5,27 +5,10 @@
<meta name="viewport" content="width=device-width, initial-scale=1.0" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="color-scheme" content="dark" /> <meta name="color-scheme" content="dark" />
<meta name="theme-color" content="#09090b" /> <meta name="theme-color" content="#09090b" />
<!-- Anti-FOUC : applique la préférence de thème (arb.theme) avant le premier paint, <!-- Anti-FOUC : pose le thème (arb.theme) avant le premier paint. Externalisé dans
sinon un utilisateur en thème clair verrait un flash sombre au rechargement. public/theme-boot.js car la CSP du daemon impose `script-src 'self'` et refusait ce
Doit rester inline/synchrone (pas de module async). Synchronisé avec lib/theme.ts. --> script quand il était inline. Doit rester synchrone (ni defer ni module). -->
<script> <script src="/theme-boot.js"></script>
(function () {
try {
var raw = localStorage.getItem('arb.theme');
var mode = raw ? JSON.parse(raw) : 'dark';
var dark = mode === 'dark' || (mode === 'system' && matchMedia('(prefers-color-scheme: dark)').matches);
var theme = dark ? 'dark' : 'light';
var bg = dark ? '#09090b' : '#fafafa';
var el = document.documentElement;
el.dataset.theme = theme;
el.style.backgroundColor = bg;
var cs = document.querySelector('meta[name=color-scheme]');
if (cs) cs.setAttribute('content', theme);
var tc = document.querySelector('meta[name=theme-color]');
if (tc) tc.setAttribute('content', bg);
} catch (e) {}
})();
</script>
<link rel="manifest" href="/manifest.webmanifest" /> <link rel="manifest" href="/manifest.webmanifest" />
<link rel="icon" type="image/svg+xml" href="/icon.svg" /> <link rel="icon" type="image/svg+xml" href="/icon.svg" />
<link rel="icon" type="image/x-icon" href="/favicon.ico" /> <link rel="icon" type="image/x-icon" href="/favicon.ico" />
+77 -4
View File
@@ -1,15 +1,88 @@
{ {
"id": "/",
"name": "Arboretum", "name": "Arboretum",
"short_name": "Arboretum", "short_name": "Arboretum",
"description": "A self-hosted dashboard for your git worktrees and Claude Code sessions.", "description": "Self-hosted multi-project AI IDE for your git worktrees and Claude Code sessions.",
"lang": "en",
"dir": "ltr",
"categories": [
"developer",
"productivity",
"utilities"
],
"start_url": "/", "start_url": "/",
"scope": "/", "scope": "/",
"display": "standalone", "display": "standalone",
"display_override": [
"window-controls-overlay",
"standalone"
],
"orientation": "any",
"background_color": "#09090b", "background_color": "#09090b",
"theme_color": "#09090b", "theme_color": "#09090b",
"launch_handler": {
"client_mode": "focus-existing"
},
"icons": [ "icons": [
{ "src": "/icon.svg", "sizes": "any", "type": "image/svg+xml", "purpose": "any" }, {
{ "src": "/icon-192.png", "sizes": "192x192", "type": "image/png", "purpose": "maskable" }, "src": "/icon.svg",
{ "src": "/icon-512.png", "sizes": "512x512", "type": "image/png", "purpose": "maskable" } "sizes": "any",
"type": "image/svg+xml",
"purpose": "any"
},
{
"src": "/icon-192.png",
"sizes": "192x192",
"type": "image/png",
"purpose": "any"
},
{
"src": "/icon-512.png",
"sizes": "512x512",
"type": "image/png",
"purpose": "any"
},
{
"src": "/icon-192.png",
"sizes": "192x192",
"type": "image/png",
"purpose": "maskable"
},
{
"src": "/icon-512.png",
"sizes": "512x512",
"type": "image/png",
"purpose": "maskable"
}
],
"screenshots": [
{
"src": "/screenshot-ide-dark.png",
"type": "image/png",
"sizes": "2340x1196",
"form_factor": "wide",
"label": "Multi-project IDE, dark theme"
},
{
"src": "/screenshot-ide-light.png",
"type": "image/png",
"sizes": "2340x1196",
"form_factor": "wide",
"label": "Multi-project IDE, light theme"
}
],
"shortcuts": [
{
"name": "IDE",
"url": "/ide"
},
{
"name": "Sessions",
"url": "/sessions"
},
{
"name": "Settings",
"url": "/settings"
}
] ]
} }
Binary file not shown.

After

Width:  |  Height:  |  Size: 113 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 113 KiB

+26
View File
@@ -0,0 +1,26 @@
// Anti-FOUC : applique la préférence de thème (arb.theme) avant le premier paint, sinon un
// utilisateur en thème clair verrait un flash sombre au rechargement.
//
// Pourquoi un fichier séparé plutôt qu'un <script> inline dans index.html : la CSP du daemon
// impose `script-src 'self'` (cf. SECURITY_HEADERS dans server/src/app.ts), qui refuse tout
// script inline. Inline, ce code ne s'exécutait pas du tout et le thème n'était posé qu'au
// montage de la SPA. Chargé en <script src> synchrone dans le <head>, il garde le même timing
// (avant le premier paint) sans exiger 'unsafe-inline' ni un hash à regénérer à chaque édition.
//
// Doit rester synchrone (pas de module, pas de defer). Synchronisé avec lib/theme.ts.
(function () {
try {
var raw = localStorage.getItem('arb.theme');
var mode = raw ? JSON.parse(raw) : 'dark';
var dark = mode === 'dark' || (mode === 'system' && matchMedia('(prefers-color-scheme: dark)').matches);
var theme = dark ? 'dark' : 'light';
var bg = dark ? '#09090b' : '#fafafa';
var el = document.documentElement;
el.dataset.theme = theme;
el.style.backgroundColor = bg;
var cs = document.querySelector('meta[name=color-scheme]');
if (cs) cs.setAttribute('content', theme);
var tc = document.querySelector('meta[name=theme-color]');
if (tc) tc.setAttribute('content', bg);
} catch (e) {}
})();
+3
View File
@@ -12,6 +12,7 @@
import { computed } from 'vue'; import { computed } from 'vue';
import { wsClient } from './lib/ws-client'; import { wsClient } from './lib/ws-client';
import { useRealtimeBootstrap } from './composables/useRealtimeBootstrap'; import { useRealtimeBootstrap } from './composables/useRealtimeBootstrap';
import { useWatchedWorktrees } from './composables/useWatchedWorktrees';
import WsBanner from './components/layout/WsBanner.vue'; import WsBanner from './components/layout/WsBanner.vue';
import ToastContainer from './components/ToastContainer.vue'; import ToastContainer from './components/ToastContainer.vue';
import CommandPalette from './components/CommandPalette.vue'; import CommandPalette from './components/CommandPalette.vue';
@@ -21,4 +22,6 @@ const wsReconnecting = computed(() => wsClient.status.value === 'reconnecting');
// Propriétaire unique du chargement initial + temps réel : hissé ici (App.vue toujours monté) // Propriétaire unique du chargement initial + temps réel : hissé ici (App.vue toujours monté)
// pour couvrir l'IDE plein écran comme le login. // pour couvrir l'IDE plein écran comme le login.
useRealtimeBootstrap(); useRealtimeBootstrap();
// Idem pour les abonnements ciblés `watch` : ils doivent survivre au démontage des panneaux.
useWatchedWorktrees();
</script> </script>

Some files were not shown because too many files have changed in this diff Show More