mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 05:26:23 +00:00
feat: bundle agent executables + web-driven claude login
Two changes so an operator can stand up and authenticate Handler entirely from the browser, with a self-contained control image. Bundle executables in the control image (Dockerfile.control) - Node.js (NodeSource) + the Claude Code CLI, mise (official apt repo), and forge (git-pkgs/forge, built in a Go stage) join the existing git/tmux/ssh. No more bring-your-own binaries: live agent spawning, the verification gate, CI resolution, and the login flow all work out of the box. Installed under /usr so the /var/lib/handler VOLUME never masks them; mise apt source pinned to $TARGETARCH for the multi-arch (amd64/arm64) build. Claude login from the web UI - New login_start / login_submit command types (migration 0005) drive the interactive `claude /login` through the same enqueue→worker handoff every other control action uses — the API container has no claude binary. - control/login.py opens `claude` in a dedicated tmux session, sends /login, selects the subscription account, and scrapes the claude.com authorization URL (tmux.capture_pane, -pJ so a wrapped URL rejoins); a second command feeds back the pasted code. Fully mockable via the tmux seam. - API: POST /login/start, POST /login/submit (admin-gated). - Dashboard: a "Claude Login" pane — a button that starts the flow, embeds the URL in an iframe (with a new-tab fallback, since claude.com may refuse framing), and takes the code to finish. Also un-ignores frontend/lib/ (a broad Python `lib/` rule was swallowing the UI's own api client + formatters, breaking rebuilds from a fresh clone) and reconstructs those two source files; rebuilt static export committed. Tests: control/login unit tests (tmux faked), worker dispatch, and API route tests. Full suite green (195 tests), ruff clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YKVyBmKvWDVgrFC9WER2f2
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
"""The web-login API surface: enqueue login_start / login_submit, admin-gated."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
|
||||
def _admin(env):
|
||||
# ADMIN_TOKEN is unset in the test env, so the admin gate falls back to AUTH_TOKEN.
|
||||
return {"Authorization": f"Bearer {env['token']}"}
|
||||
|
||||
|
||||
def test_login_start_enqueues_command(client, env):
|
||||
r = client.post("/login/start", headers=_admin(env))
|
||||
assert r.status_code == 202
|
||||
body = r.json()
|
||||
assert body["type"] == "login_start"
|
||||
assert body["status"] == "queued"
|
||||
assert body["requested_by"] == "operator:web"
|
||||
|
||||
|
||||
def test_login_submit_enqueues_command_with_code(client, env):
|
||||
r = client.post("/login/submit", headers=_admin(env), json={"code": "auth-xyz"})
|
||||
assert r.status_code == 202
|
||||
body = r.json()
|
||||
assert body["type"] == "login_submit"
|
||||
assert body["payload"] == {"code": "auth-xyz"}
|
||||
|
||||
|
||||
def test_login_submit_rejects_blank_code(client, env):
|
||||
r = client.post("/login/submit", headers=_admin(env), json={"code": ""})
|
||||
assert r.status_code == 422
|
||||
|
||||
|
||||
def test_login_start_requires_auth(client):
|
||||
assert client.post("/login/start").status_code in (401, 403)
|
||||
|
||||
|
||||
def test_login_endpoints_require_admin_token(client, env, monkeypatch):
|
||||
# With a distinct admin token set, the plain auth token must be refused.
|
||||
monkeypatch.setenv("ADMIN_TOKEN", "admin-secret")
|
||||
from handler import config
|
||||
|
||||
config.get_settings.cache_clear()
|
||||
try:
|
||||
r = client.post("/login/start", headers={"Authorization": f"Bearer {env['token']}"})
|
||||
assert r.status_code == 403
|
||||
ok = client.post("/login/start", headers={"Authorization": "Bearer admin-secret"})
|
||||
assert ok.status_code == 202
|
||||
finally:
|
||||
config.get_settings.cache_clear()
|
||||
Reference in New Issue
Block a user