Commit Graph

251 Commits

Author SHA1 Message Date
m4 9a1775c17d feat(webui): require math captcha after 3 failed logins per IP
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:32:52 +08:00
m4 f91b26670b feat(webui): GET /api/auth/captcha issues math captchas
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:29:29 +08:00
m4 99ddaa6df4 feat(webui): per-IP login failure counter
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:24:48 +08:00
m4 f5776cdf49 feat(webui): stateless signed math-captcha tokens
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:21:28 +08:00
m4 4a652fd67f feat(webui): redirect to /login on any API 401 response
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:17:06 +08:00
m4 ce01a6022b docs: implementation plan for login captcha and 401 redirect
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:58:01 +08:00
m4 6e7a1e4898 docs: design spec for login captcha and session-expiry redirect
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:50:44 +08:00
m4 b53d58fa35 fix(webui): preserve remaining session TTL on password change
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:30:43 +08:00
m4 a7625fc38f feat(webui): remember-me checkbox on the login page
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:19:23 +08:00
m4 a047129622 feat(webui): rememberMe login flag with 30-day persistent cookie
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:12:10 +08:00
m4 8a59ec59d8 feat(webui): parameterize session TTL and cookie maxAge
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:06:51 +08:00
m4 ed7de2a017 feat(webui): rememberTtlSeconds config for remember-me sessions
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 07:54:24 +08:00
m4 804447047e docs(webui): remember-me implementation plan
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 07:48:41 +08:00
m4 9c25b3a9e5 docs(webui): remember-me (30-day session) design spec
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-07 17:08:01 +08:00
m4 6d2b2f4d80 docs(webui): mark error-log bell UI as implemented
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 21:16:29 +08:00
m4 0953e403e5 feat(webui): mount error-log bell in the header
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 20:10:09 +08:00
m4 47420514bd feat(webui): error-log bell with unread badge and clear-all
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 19:32:57 +08:00
m4 a67f16651d feat(webui): useErrorLogs hook with unread cursor and clear-all
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 19:31:59 +08:00
m4 bc2f83591a feat(webui): unread-cursor helpers for the error-log bell
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 19:30:01 +08:00
m4 6b0cc81ded docs(webui): design doc for per-user error logging
Records the approved four-part design (store, collection, BFF API, bell
UI) and the current implementation status.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 16:59:14 +08:00
m4 2aeccea036 docs(webui): implementation plan for the error-log bell UI
Covers the remaining piece of the per-user error-log feature: unread
cursor module, useErrorLogs hook, ErrorLogBell component, header mount.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 16:58:22 +08:00
m4 09d9f49e9f feat(webui): record BFF route errors in the acting user's error log
routeErrorResponse gains an optional actor; every route that resolves an
actor now passes it, so API failures survive the toast. Unauthenticated
failures and the error-logs route itself are never logged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 11:01:31 +08:00
m4 dd4b63a0ee feat(webui): report user-visible errors to the per-user error log
Add errorReporter (errorToast = toast.error + fire-and-forget POST to
/api/error-logs) and wire it into the operational error toasts across
chat, threads, tasks, agents, models, files and clipboard. Pure form
validation hints stay on toast.error.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:46:07 +08:00
m4 a4e47e1b5d style(webui): render the idle status dot as a hollow ring
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:43:40 +08:00
m4 8d455a08e2 feat(webui): add /api/error-logs GET/POST/DELETE for per-user error logs
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:25:37 +08:00
m4 61c2aba187 feat(webui): add per-user error log store
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:21:19 +08:00
m4 cbc343963c feat(webui): show a running indicator on busy threads in the list
Three mechanisms, merged in ThreadList: a 10s heartbeat polling the new
?status=busy filter (out-of-band runs: scheduled tasks, other clients),
a module-level running store fed by useChat's own run lifecycle (zero
latency for this client's runs), and a spinner replacing the status dot
while either source marks the thread busy. The BFF list route now
validates and forwards the status filter, which also unbreaks the
previously ignored status dropdown.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 09:57:08 +08:00
m4 a171db23f8 perf(webui): strip agent-internal state and dedupe snapshot fetches
Thread state carried ~1.9MB of internal runtime data
(_quickjs_snapshot_payload, skills_metadata) that no WebUI code reads,
and opening a conversation fired three independent fetches of it. The
BFF now strips those keys (1.9MB -> ~15KB) and getConversation shares
one in-flight request across concurrent callers.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 09:21:35 +08:00
m4 bd1ef8abf5 perf(webui): slim the conversation list payload to derived summaries
The list route forwarded each thread's full values.messages to the
browser (~47MB for 20 threads), blocking the main thread on JSON.parse
and making the list appear suddenly after a long wait. The BFF now
derives title/description/pinned/needsUserInput server-side via the
shared conversationSummary module and never sends values or interrupts;
useThreads consumes the slim shape directly.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 08:23:39 +08:00
m4 b81386c375 docs(usage): rename injected deployment id to EVOSCIENTIST_USAGE_DEPLOYMENT_ID
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-30 22:15:39 +08:00
m4 c8e8305107 fix(webui): read usage deployment id from EVOSCIENTIST_USAGE_DEPLOYMENT_ID
Matches the backend split: usage attribution no longer shares
EVOSCIENTIST_DEPLOYMENT_ID with workspace scope partitioning.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-30 22:11:31 +08:00
m4 fbf88fbf8a fix(webui): stop probing the scope registry for unscoped threads in the list
Every conversation-list load fanned out getByThread per visible thread;
legacy threads without a scope each logged a 404 warning and added a
round-trip. A thread whose metadata claims no workspace_scope_id can
never pass the scope assertion, so skip the probe and filter it directly.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-30 11:43:50 +08:00
m4 7c121ce019 feat(webui): thinking timer at the bottom of the message area while a run is active
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-30 11:21:58 +08:00
m4 cfaf704652 feat(webui): segmented default/temperature/top_p sampling picker in the chat bar
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-30 10:41:32 +08:00
m4 a4202e149a feat(webui): mutually-exclusive sampling_override in thread model selection
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-30 10:25:36 +08:00
m4 f83cd431c7 feat(webui): exact-value keyboard input on generation sliders
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-29 08:44:21 +08:00
m4 7b14ab5251 fix(webui): correct reset-affordance tooltip copy
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-29 08:17:23 +08:00
m4 8f1ba6ad6f feat(webui): inline temperature/top_p sliders in the chat bar
Adds a GenerationParamSlider next to the reasoning-effort slider so a
per-thread temperature/top_p override can be set from the chat bar.
Unset sliders rest at the registry-catalog default in a muted style;
dragging commits an override, and clicking the value resets to the
default. Hidden below the sm breakpoint, and disabled while the
thread inherits the registry model.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-29 08:03:10 +08:00
m4 c4411d209f feat(webui): parse generation defaults from the model catalog
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-29 07:42:08 +08:00
m4 dc6fd39341 feat(webui): forward generation overrides into run snapshots
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-29 07:36:28 +08:00
m4 5557690e0e feat(webui): accept temperature/top_p in thread model selection 2026-07-28 17:56:18 +08:00
m4 4cd3d2e9a4 feat: add image models config dialog 2026-07-24 09:54:08 +08:00
m4 222cb0b84e feat: drop auxiliary model from thread selection and registry defaults
ThreadModelSelection is now "inherit" or { primary, reasoning_effort };
the BFF validator tolerates and drops legacy auxiliary keys, the runs
route no longer snapshots an auxiliary ref, and the Registry Editor's
default-auxiliary field is removed, matching the backend's single-role
snapshot resolution.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-23 10:19:03 +08:00
m4 7a61ac11cb feat: keep the model registry dialog open on overlay click and Escape
Editing a large registry draft is easy to lose to a stray click; the
dialog now only closes via the X or Close button.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-22 11:03:24 +08:00
m4 18107d99e9 feat: collapsible model parameter sections in the Registry Editor
Saved models start collapsed to a compact status row (key, availability,
enabled, Test); new unsaved models start expanded for editing. Test
outcomes stay visible regardless of collapse state.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-22 11:01:18 +08:00
m4 340136ebc1 feat: save changed models as disabled instead of auto-testing
Saving no longer runs live provider tests: changed enabled models are
saved as disabled (defaults repointed when needed) and the user
re-verifies manually with the per-model Test button, then re-enables and
saves again. A successful test now refreshes the local availability so
re-enabling is a plain save.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-22 10:11:04 +08:00
m4 1ff30b677a feat: wrap enabled-model edits in a save & re-verify flow
Editing an enabled model invalidated its verification record, so the
backend rejected the save with MODEL_NOT_AVAILABLE. The editor now
detects changed enabled models (mirroring configuration_hash inputs plus
credential rotation) and runs the documented disable & save -> test ->
enable & save sequence as one click, temporarily repointing defaults
when the edited model is the default primary.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-22 08:35:46 +08:00
m4 cec1fa04d7 feat: left-right layout for the Registry Editor
With multiple providers configured, the vertical stack required long
scrolling. The left pane now lists providers with enabled markers and
per-model availability dots plus the template picker; the right pane
shows the selected provider's editor, auto-selecting newly added
providers and clamping selection on remove.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-21 22:59:11 +08:00
m4 2bf1127af2 feat: new-provider templates in Registry Editor (design doc 7.1)
Add the six phase-1 templates (智谱 GLM, OpenAI, Anthropic,
OpenAI-compatible, Anthropic-compatible, Ollama) that prefill adapter,
Base URL, auth mode, and suggested models; saved providers remain
ordinary profiles. Verified in browser against the live dev server.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-21 21:14:51 +08:00
m4 9f702e230d feat: adapter-spec-driven Registry Editor replaces legacy provider editors
- New RegistryEditor renders providers, models, runtime parameters and
  capabilities from the backend's AdapterParameterSpec contract, with
  ModelAvailability badges, write-once credential staging, provider tests
  showing effective_request_options, revision CAS on save, and 422 detail
  paths surfaced verbatim (design doc sections 9, 11.8)
- ConfigDialog now hosts the Registry Editor (admin-only; non-admins see a
  notice from the 403 path)
- AccountDialog shows the session role and embeds an admin user-management
  section (list/create/promote/demote/password reset/delete, last-admin
  guard enforced server-side)
- Deleted legacy ProviderProfiles/BuiltinProviders/RegistryBuiltinProviders
  editors, providerProfiles/legacyLlmConfig libs, the admin-token proxy and
  the /api/provider-profiles, /api/provider-actions, /api/default-model and
  /api/config BFF routes (design doc section 10 legacy removals)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-21 19:02:17 +08:00