mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 18:56:26 +00:00
fa2e97130d
Two changes so an operator can stand up and authenticate Handler entirely from the browser, with a self-contained control image. Bundle executables in the control image (Dockerfile.control) - Node.js (NodeSource) + the Claude Code CLI, mise (official apt repo), and forge (git-pkgs/forge, built in a Go stage) join the existing git/tmux/ssh. No more bring-your-own binaries: live agent spawning, the verification gate, CI resolution, and the login flow all work out of the box. Installed under /usr so the /var/lib/handler VOLUME never masks them; mise apt source pinned to $TARGETARCH for the multi-arch (amd64/arm64) build. Claude login from the web UI - New login_start / login_submit command types (migration 0005) drive the interactive `claude /login` through the same enqueue→worker handoff every other control action uses — the API container has no claude binary. - control/login.py opens `claude` in a dedicated tmux session, sends /login, selects the subscription account, and scrapes the claude.com authorization URL (tmux.capture_pane, -pJ so a wrapped URL rejoins); a second command feeds back the pasted code. Fully mockable via the tmux seam. - API: POST /login/start, POST /login/submit (admin-gated). - Dashboard: a "Claude Login" pane — a button that starts the flow, embeds the URL in an iframe (with a new-tab fallback, since claude.com may refuse framing), and takes the code to finish. Also un-ignores frontend/lib/ (a broad Python `lib/` rule was swallowing the UI's own api client + formatters, breaking rebuilds from a fresh clone) and reconstructs those two source files; rebuilt static export committed. Tests: control/login unit tests (tmux faked), worker dispatch, and API route tests. Full suite green (195 tests), ruff clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YKVyBmKvWDVgrFC9WER2f2
205 lines
5.5 KiB
TypeScript
205 lines
5.5 KiB
TypeScript
/* Typed client for the Handler API + the row shapes it returns (mirrors the FastAPI
|
|
* pydantic schemas in src/handler/api/schemas.py). The browser calls the API same-origin
|
|
* with relative paths; set NEXT_PUBLIC_API_BASE to point `npm run dev` at another origin.
|
|
*
|
|
* NOTE: this file lives under frontend/lib/, now un-ignored in .gitignore so the source
|
|
* ships and the build works from a fresh clone (the built export under
|
|
* src/handler/api/static/ is what the package serves). */
|
|
|
|
const BASE = process.env.NEXT_PUBLIC_API_BASE ?? "";
|
|
|
|
export type CommandStatus = "queued" | "running" | "done" | "failed";
|
|
|
|
export interface Project {
|
|
id: string;
|
|
root_dir: string;
|
|
git_remote?: string | null;
|
|
credential_ref?: string | null;
|
|
created_at: string;
|
|
/* Present on the registration response in git-server mode: the enqueued clone. */
|
|
sync_command_id?: number | null;
|
|
}
|
|
|
|
export interface Agent {
|
|
id: number;
|
|
project_id: string;
|
|
name: string;
|
|
working_dir: string;
|
|
status: string;
|
|
role?: string | null;
|
|
created_at: string;
|
|
}
|
|
|
|
export interface Checkmark {
|
|
agent_id: number;
|
|
checkpoint_at: string;
|
|
status: string;
|
|
where_it_stopped?: string | null;
|
|
next_steps?: string[] | null;
|
|
open_question?: string | null;
|
|
log_entry_id?: number | null;
|
|
tests_status: string;
|
|
tested_at?: string | null;
|
|
build_status: string;
|
|
built_at?: string | null;
|
|
}
|
|
|
|
export interface LogEntry {
|
|
id: number;
|
|
agent_id: number;
|
|
created_at: string;
|
|
session_id?: string | null;
|
|
status: string;
|
|
summary?: string | null;
|
|
decisions?: string | null;
|
|
question?: string | null;
|
|
answer?: string | null;
|
|
visibility: string;
|
|
push_sha?: string | null;
|
|
ci_status: string;
|
|
ci_checked_at?: string | null;
|
|
}
|
|
|
|
export interface Approval {
|
|
id: number;
|
|
project_id: string;
|
|
branch: string;
|
|
approved_sha?: string | null;
|
|
pr_ref?: string | null;
|
|
status: string;
|
|
approved_by_agent_id?: number | null;
|
|
actor?: string | null;
|
|
note?: string | null;
|
|
created_at: string;
|
|
}
|
|
|
|
export interface Host {
|
|
hostname: string;
|
|
forge_type: string;
|
|
token_env_var?: string | null;
|
|
base_url?: string | null;
|
|
ssh_public_key?: string | null;
|
|
has_token: boolean;
|
|
created_at: string;
|
|
}
|
|
|
|
export interface Command {
|
|
id: number;
|
|
project_id?: string | null;
|
|
agent_name?: string | null;
|
|
type: string;
|
|
payload?: Record<string, unknown> | null;
|
|
status: CommandStatus;
|
|
result?: Record<string, unknown> | null;
|
|
error?: string | null;
|
|
requested_by?: string | null;
|
|
claimed_by?: string | null;
|
|
created_at: string;
|
|
claimed_at?: string | null;
|
|
finished_at?: string | null;
|
|
}
|
|
|
|
export interface Schedule {
|
|
id: number;
|
|
project_id: string;
|
|
name_prefix: string;
|
|
task: string;
|
|
role?: string | null;
|
|
worktree?: string | null;
|
|
subdir?: string | null;
|
|
interval_seconds: number;
|
|
enabled: boolean;
|
|
next_run_at: string;
|
|
last_run_at?: string | null;
|
|
last_command_id?: number | null;
|
|
created_at: string;
|
|
}
|
|
|
|
export interface SharedContext {
|
|
key: string;
|
|
value: string;
|
|
set_by_agent_id?: number | null;
|
|
updated_at: string;
|
|
}
|
|
|
|
/* Thrown on a 401 so callers can distinguish "token rejected" from real errors and stay
|
|
* quiet while the app re-prompts for a token. */
|
|
export class AuthError extends Error {
|
|
constructor(message = "unauthorized") {
|
|
super(message);
|
|
this.name = "AuthError";
|
|
}
|
|
}
|
|
|
|
/* Any non-2xx (other than 401); carries the HTTP status so callers can branch on 404 etc. */
|
|
export interface ApiError extends Error {
|
|
status: number;
|
|
}
|
|
|
|
interface ApiOptions {
|
|
method?: string;
|
|
body?: unknown;
|
|
}
|
|
|
|
interface TrackOptions {
|
|
attempts?: number;
|
|
intervalMs?: number;
|
|
}
|
|
|
|
export interface ApiClient {
|
|
api: <T>(path: string, opts?: ApiOptions) => Promise<T>;
|
|
/* Poll GET /commands/{id} until it reaches done/failed; null if still running after the
|
|
* budget (worker down or a very slow command). */
|
|
trackCommand: (id: number, opts?: TrackOptions) => Promise<Command | null>;
|
|
}
|
|
|
|
export function createClient(token: string, onUnauthorized: () => void): ApiClient {
|
|
async function api<T>(path: string, opts?: ApiOptions): Promise<T> {
|
|
const hasBody = opts?.body !== undefined && opts?.body !== null;
|
|
const res = await fetch(BASE + path, {
|
|
method: opts?.method ?? (hasBody ? "POST" : "GET"),
|
|
headers: {
|
|
Authorization: `Bearer ${token}`,
|
|
...(hasBody ? { "Content-Type": "application/json" } : {}),
|
|
},
|
|
body: hasBody ? JSON.stringify(opts!.body) : undefined,
|
|
});
|
|
|
|
if (res.status === 401) {
|
|
onUnauthorized();
|
|
throw new AuthError();
|
|
}
|
|
if (!res.ok) {
|
|
let detail: string = res.statusText;
|
|
try {
|
|
const j = await res.json();
|
|
if (j && typeof j.detail !== "undefined") {
|
|
detail = typeof j.detail === "string" ? j.detail : JSON.stringify(j.detail);
|
|
}
|
|
} catch {
|
|
/* non-JSON error body; keep statusText */
|
|
}
|
|
const err = new Error(detail) as ApiError;
|
|
err.status = res.status;
|
|
throw err;
|
|
}
|
|
|
|
if (res.status === 204) return undefined as T;
|
|
const text = await res.text();
|
|
return (text ? JSON.parse(text) : undefined) as T;
|
|
}
|
|
|
|
async function trackCommand(id: number, opts?: TrackOptions): Promise<Command | null> {
|
|
const attempts = opts?.attempts ?? 60;
|
|
const intervalMs = opts?.intervalMs ?? 500;
|
|
for (let i = 0; i < attempts; i++) {
|
|
const cmd = await api<Command>(`/commands/${id}`);
|
|
if (cmd.status === "done" || cmd.status === "failed") return cmd;
|
|
await new Promise((r) => setTimeout(r, intervalMs));
|
|
}
|
|
return null;
|
|
}
|
|
|
|
return { api, trackCommand };
|
|
}
|