Files
handler/.env.example
T
0xWheatyz bbb01d0882 feat(phase-3): web UI served same-origin by the API
Add a no-build, same-origin web frontend so an operator can open a URL,
see every agent's state, and answer a paused question with no terminal
(Phase 3 DoD). The UI is a client of the existing API — no endpoint,
schema, or auth change — so the 106 existing tests pass unchanged.

- app.py serves the bundled UI from / and /static, gated on UI_ENABLED
  (default on); optional CORS_ORIGINS (default empty => no middleware)
  for hosting the UI on a separate origin. Dedicated /static prefix +
  explicit / route so API routes are never shadowed. Zero new runtime
  deps (StaticFiles/CORSMiddleware ship with Starlette).
- static/: vanilla fetch + plain CSS + vendored alpine.min.js (v3.14.8,
  no CDN). Token captured once into localStorage; all API values render
  via x-text (never x-html) to block agent-authored markup injection.
  Project switcher, agent list, checkmark panel, paginated log, shared
  feed, and Answer / Answer & Resume. Polling scoped to the selected
  agent to avoid an N+1 over the fleet.
- config.py: ui_enabled, cors_origins (+ cors_origin_list); documented
  in .env.example.
- tests/test_api_ui.py: serving, unauthenticated shell, non-shadowing
  401 regression, CORS toggle, UI_ENABLED=false. 114 tests, ruff clean.

The static assets ship in the wheel by default (they live inside the
packaged src/handler tree) — no force-include needed.
2026-07-09 20:43:23 -04:00

52 lines
2.4 KiB
Bash

# Handler configuration — copy to .env and fill in. Never commit real secrets.
# Database. SQLite fallback (single-node) or Postgres (centralized, default for real deploys).
# SQLite: sqlite:////absolute/path/to/handler.db
# Postgres: postgresql+psycopg://user:pass@host:5432/handler
DATABASE_URL=sqlite:////var/lib/handler/handler.db
# Single global bearer token gating every API route. Required for the API to start.
AUTH_TOKEN=change-me-to-a-long-random-string
# Optional higher-trust token gating PUT /shared/context/:key.
# Falls back to AUTH_TOKEN if unset.
# SHARED_CONTEXT_WRITE_TOKEN=
# Optional generic webhook target for the Notification hook (ntfy, Pushover, Slack, ...).
# Fully bring-your-own; the Notification hook is a no-op when unset.
# WEBHOOK_URL=https://ntfy.sh/my-topic
# Base directory under which per-project roots and agent worktrees live (isolation).
PROJECTS_ROOT=/var/lib/handler/projects
# Binary overrides (defaults shown). Point at fakes in tests/CI.
# CLAUDE_BIN=claude
# MISE_BIN=mise
# TMUX_BIN=tmux
# FORGE_BIN=forge
# GIT_BIN=git
# Phase 2 (forge integration). Pin the forge version your base image installs; spawn
# verifies the injected forge matches and warns on drift. Leave unset to skip the check.
# FORGE_VERSION=1.2.3
# Branches a direct `git push` may not reach without a standing approval (comma-separated).
# Closes the "merge locally, push to main" path around the forge-merge approval gate.
# PROTECTED_BRANCHES=main,master
# Phase 3 (web UI). Serve the bundled UI from "/" and "/static". Set false for a
# headless, API-only deployment. Applied at process start (restart to change).
# UI_ENABLED=true
# Extra origins allowed to call the API cross-origin (comma-separated). Only needed if
# you host the UI on a DIFFERENT origin than the API; the shipped UI is same-origin and
# needs none. Empty => no CORS middleware.
# CORS_ORIGINS=https://handler.example.ts.net
# Per-project credentials are NOT set here — they live on each project's `credential_ref`
# as a POINTER (env:VAR / file:/path / cmd:...), resolved and injected only at spawn.
# The database never stores the raw token. Example, when registering a project:
# credential_ref = "env:LEEWORKS_TOKEN" (then export LEEWORKS_TOKEN where the control
# layer runs; it's injected as FORGE_TOKEN +
# the host-specific var, e.g. GITHUB_TOKEN)