Commit Graph
242 Commits
Author SHA1 Message Date
pastilhasandClaude Opus 4.6 11d95a25ab mount all of ~/.local in sandbox for claude binary resolution
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 07:43:27 +00:00
pastilhasandClaude Opus 4.6 8377da8a77 fix sandbox tool/extension/skill discovery for members
Sandbox now mounts global content at short /officer/* paths to avoid
bwrap intermediate directory traversal issues. Pi uses NODE_PATH for
extension dependency resolution.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 07:13:19 +00:00
pastilhasandClaude Opus 4.6 8264e7b995 fix super admin claude: host cwd, host mcp config paths
Capture HOST_HOME before user-instance overrides process.env.HOME so
Super Admin spawns claude in /home/pastilhas. Generate separate MCP
configs for sandbox (sandbox paths) and host (real filesystem paths),
pick based on role at spawn time.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 01:29:14 +00:00
pastilhasandClaude Opus 4.6 29229c8cb7 fix super admin pi cwd double-prefixing absolute paths
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 01:12:34 +00:00
pastilhasandClaude Opus 4.6 ea31014d72 user-local installs for claude and pi, fix sandbox mounts
Move claude and pi from sudo global installs to ~/.local. Claude
binary is copied to /usr/local/bin for sandbox visibility, pi runs
via node from ~/.local/lib (ro-mounted). Fix bwrap intermediate dir
traversal by setting 0755 perms on auto-created HOME dirs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 01:08:45 +00:00
pastilhasandClaude Opus 4.6 2f15214cdb match selected provider button style to locked state for better visibility
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 00:12:14 +00:00
pastilhasandClaude Opus 4.6 56f8da8907 remove seed directory, clean up provisioning and sync modules
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 00:07:50 +00:00
pastilhasandClaude Opus 4.6 9578110e8b shared bwrap sandbox, skip for super admin, extend to pi and terminals
- extract buildSandboxPrefix/buildRunuserSuffix into shared sandbox.ts
- super admin bypasses bwrap for full host access (claude, pi, terminal)
- member pi processes now use bwrap instead of sudo -u
- member terminals now use bwrap instead of sudo -u
- mount /run for systemd-resolved DNS inside sandbox
- pass role through claude spawn params and channel types

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-08 00:06:44 +00:00
pastilhasandClaude Opus 4.6 c38d5b0ea1 extract stream parser module with tests, add mcp tool call logging
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-07 13:49:26 +00:00
pastilhasandClaude Opus 4.6 86ddcbfead mcp tool server for claude code — native tool execution via stdio protocol
Replaces prompt injection workaround with a proper MCP server that dynamically
discovers marketplace tools and exposes them as callable tools to Claude Code.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-07 13:21:50 +00:00
pastilhasandClaude Opus 4.6 ecd83dc1ec dynamic claude.md regeneration and email db env for claude code
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-07 12:45:41 +00:00
pastilhasandClaude Opus 4.6 49cd559c8a tool registry, claude tool awareness, and model selector fix
- Add agent-agnostic tool registry (tool-registry.ts) that discovers tools from disk
- Embed tool-loader extension as platform infrastructure (ensure-tool-loader.ts)
- Inject tool context into Claude prompts on first message
- Add marketplace tool sync (sync-marketplace.ts)
- Fix model selector defaulting to claude-code when no model explicitly selected
- Exclude tool-loader-source.ts from tsconfig (Pi-specific deps)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-07 11:55:38 +00:00
pastilhas e97b4b2459 deleted old plans 2026-03-07 08:31:48 +00:00
pastilhasandClaude Opus 4.6 b896515b2c fix message duplication on auto-save after resume
The PUT endpoint was re-merging old DB messages (which already included
previous merges) with disk messages on every turn, causing duplication.
Now the client passes resumedMessageCount so the server always slices
only the original pre-resume messages before concatenating.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-07 08:23:31 +00:00
pastilhas 70442ae277 dockerization plan 2026-03-07 08:22:46 +00:00
pastilhas 6c4595279a fine tuning 2026-03-07 00:52:20 +00:00
pastilhasandClaude Opus 4.6 60230ccfec fix save indicator timing and auto-save history loss on resume
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 21:27:31 +00:00
pastilhasandClaude Opus 4.6 0e0be3327e dashboard chats: auto-load latest saved session for context on mount
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 20:46:09 +00:00
pastilhasandClaude Opus 4.6 8f46f9170a fix terminal state key leaking phantom dashboards; fix infinite loop in chat panel resume
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 20:39:44 +00:00
pastilhasandClaude Opus 4.6 406d8f9e54 saved sessions: make routable via /chat/saved/:id URLs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 20:15:36 +00:00
pastilhasandClaude Opus 4.6 2a8df0def1 saved sessions: replace transient history with persistent DB storage and auto-save
- Add saved_sessions table and CRUD endpoints (save, list, resume, update, delete)
- Save is instant (no LLM summarization), stores exact conversation with tool calls
- Resume loads full message history into chat UI, sends transcript to agent on first message
- Auto-save updates DB after every agent response once a session is saved
- Delete old filesystem-based session/group management (sessions router, useChatSessions, useChatGroups)
- Clean up ChatHeader, SessionList, ChatDetailPanel for saved sessions flow

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 13:36:25 +00:00
pastilhasandClaude Opus 4.6 d88fe3cac7 task logs: migrate from filesystem to postgresql; refactor sidecars into submodules
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 11:49:39 +00:00
pastilhasandClaude Opus 4.6 5129f7827f dashboards: migrate from filesystem to postgresql
Replace JSON file storage with DB tables for dashboard layouts,
screens, projects, and terminal defaults. Fresh drizzle migration
with dashboardDefaults table and new columns on screens/projects.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 11:35:11 +00:00
pastilhasandClaude Opus 4.6 daf5580c39 vnc sidecar: per-user desktop sessions via sidecar architecture
replaces the single hardcoded systemd VNC service with a dynamic
sidecar that manages per-user VNC sessions on demand. any authenticated
user can now access their own desktop, not just Super Admin.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 10:49:53 +00:00
pastilhasandClaude Opus 4.6 a0d9ea63f9 sidecar self-registration: sidecars connect to API server instead of vice versa
Flips the connection model so sidecars register themselves with the API
server via WebSocket at /api/sidecar/register, enabling dynamic discovery,
location independence, and automatic reconnection from either side.

- Add registration protocol types and PTY command/event types
- Create sidecar-registry.ts (replaces sidecar-client.ts) as passive registry
- Create sidecar connector (connect.ts) with exponential backoff reconnect
- Convert process sidecar from WS server to WS client
- Convert PTY sidecar from WS server to multiplexed WS client
- Simplify terminal bridge to thin adapter using registry
- Add PTY sidecar as PM2-managed process
- Update all consumer imports

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 08:48:19 +00:00
pastilhas 6cfa40bad1 Merge remote-tracking branch 'origin/email-imap' 2026-03-06 07:27:45 +00:00
pastilhasandClaude Opus 4.6 7bbcccabf1 wip: remove opencode, searxng, resources; fix user settings read
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 07:27:19 +00:00
pastilhasandClaude Opus 4.6 bd7ece80cf email list sync button uses new email-sync handler, job duration logging
Rewired EmailList sync button to call /email/accounts/:id/sync instead
of the old gmail-sync job. Shows sync button for connected and synced
accounts. Allow manual incremental sync for synced accounts.

Added duration logging to queue runner: start/complete/fail markers
with elapsed time.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 07:25:26 +00:00
pastilhasandClaude Opus 4.6 4ececbe748 email sync: API passes full config at enqueue, auto-reconnect on IMAP drops
Sidecar/queue runner no longer needs job-specific context. API server
resolves account details, IMAP auth, and user email at enqueue time —
all persisted in the job file. Handler reads directly from job meta.

Removed "Load account" step. Sync step auto-reconnects up to 10 times
when Gmail drops the connection, resuming from saved UIDs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 07:02:51 +00:00
pastilhasandClaude Opus 4.6 170bd6d41b wip: email sync via imap with status tracking and auto cron
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 04:57:30 +00:00
pastilhasandClaude Opus 4.6 5925ac49a1 fix sidecar websocket: routes handler was intercepting upgrade requests
The Bun routes option matched "/" before fetch could handle the
WebSocket upgrade, so the API server could never connect. Moved
route handling into fetch after the upgrade check.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 09:53:31 +00:00
pastilhasandClaude Opus 4.6 28f5cefb5b gmail sync: locale-agnostic folder mapping and import all mail
[Google Mail] locale variant was not matched by hardcoded [Gmail] paths,
so Sent/Starred/Important/Drafts were never labeled. All Mail was skipped
entirely, losing ~9k archived emails. Now normalizes the prefix, imports
everything with proper labels, and processes All Mail last so specific
folder labels take priority.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 09:29:22 +00:00
pastilhasandClaude Opus 4.6 5e86fcff88 add future possibilities section to sidecar docs
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 07:44:36 +00:00
pastilhasandClaude Opus 4.6 86c2d6333a process sidecar: independent process manager for long-running work
Introduces a separate Bun process (port 5100) that owns all spawned
processes and long-running work, so the API server can restart freely
without disrupting active sessions.

The sidecar owns:
- Anthropic proxy (port 5051) with persisted secret across restarts
- Claude Code process spawning and session tracking (--resume support)
- Pi agent spawning and RPC lifecycle (prompt/abort/thinking)
- Job queue engine (lane processing, retries, notifications)

The API server becomes a thin client that forwards commands over a
single WebSocket connection with auto-reconnect. send-claude-code.ts
goes from 550 lines of spawn logic to 73 lines of sidecar delegation.

State persisted to data/sidecar/state.json every 30s and on shutdown.
Lockfile prevents duplicate instances. See SIDECAR.md for full docs
and manual testing procedures.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 07:36:47 +00:00
pastilhasandClaude Opus 4.6 726c77e346 show live email count during gmail sync instead of mbsync log lines
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 05:00:18 +00:00
pastilhasandClaude Opus 4.6 ed67cfa8e9 terminal auto-reconnect and connection indicator in panel header
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 04:58:14 +00:00
pastilhasandClaude Opus 4.6 c54ff9da28 bypass anthropic proxy for users with own claude credentials
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 04:35:34 +00:00
pastilhasandClaude Opus 4.6 ba9258cc17 fix pi config dir for non-service users
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 04:24:10 +00:00
pastilhasandClaude Opus 4.6 b7a017d8e2 docker compose setup and .env generation in monorepo scripts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 04:23:49 +00:00
pastilhasandClaude Opus 4.6 038fd16fb2 anthropic auth proxy for multi-user claude code
Local HTTP proxy on 127.0.0.1:5051 intercepts Claude Code API requests
from sandboxed member users, injects the real OAuth token server-side,
and forwards to Anthropic. Users only see a proxy secret, never the
real credentials.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 03:40:14 +00:00
pastilhasandClaude Opus 4.6 e966a71180 isolate user data with personal group ownership
- chown user dirs to pastilhas:<username> instead of pastilhas:officerdev
  so users cannot access each other's data
- chmod 2770 (setgid) gives only the owning user terminal access
- setup.sh: ensure home dir is traversable (o+x) for provisioned users

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 02:44:44 +00:00
pastilhasandClaude Opus 4.6 3df47bb48d shared group provisioning, upload context menu, go path fix
- provision linux users with pastilhas:officerdev ownership so server
  can always read/write, terminal users get group access
- add officerdev shared group setup to setup.sh
- move go install to ~/.local/go with GOPATH at ~/.local/go-path
- add upload file/folder items to file browser context menu

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 02:34:38 +00:00
pastilhasandClaude Opus 4.6 74894b0c35 hide dotfiles in super admin home directory, disable toggle
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 01:37:42 +00:00
pastilhasandClaude Opus 4.6 451a61afb4 fix cliamp panel header, home dir lookup, and go install path
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 01:30:15 +00:00
pastilhasandClaude Opus 4.6 330b882d00 show login form immediately without waiting for landing page data
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 01:05:56 +00:00
pastilhasandClaude Opus 4.6 20589ce845 soften card background to warm pastel in light mode
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 01:00:51 +00:00
pastilhasandClaude Opus 4.6 c7d509b725 scope file search to current directory
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 00:58:10 +00:00
pastilhasandClaude Opus 4.6 c66bbfa379 add dictate and download video toolbar buttons, reorder context menu
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 00:54:45 +00:00
pastilhasandClaude Opus 4.6 9fedbe02d4 use teal icon color for file browser toolbar buttons
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 00:46:59 +00:00
pastilhasandClaude Opus 4.6 9a95773664 fix Videos default dir name and strip tts voice subdir in save-result
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-05 00:42:47 +00:00