Commit Graph

210 Commits

Author SHA1 Message Date
m4 ae32cc72df feat(webui): consume system branding in layout metadata and login page 2026-08-11 12:04:01 +08:00
m4 7353afbec9 feat(webui): security + data backup tabs in system config dialog
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 11:55:07 +08:00
m4 0e83ab73af fix(webui): keep unsaved system config edits across branding uploads
Uploading or restoring a logo/favicon revalidated /api/system/config,
which re-ran the dialog's sync effect and replaced the whole draft,
silently wiping unsaved wordmark/login-terms edits. Now only the
draft's file field is updated from the response and only the public
config key is revalidated. Also fix the favicon fallback preview src
from the nonexistent /favicon.ico to /icon.png.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 11:47:46 +08:00
m4 5634abdbd5 feat(webui): system config dialog shell with general + login terms tabs 2026-08-11 11:32:28 +08:00
m4 7bd43a39a0 feat(webui): backup run/history/download/delete API routes 2026-08-11 11:20:39 +08:00
m4 c7d6c65130 feat(webui): scheduled backups via instrumentation-started interval
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 11:00:52 +08:00
m4 6b009e2c32 fix(webui): exclude *.tmp files from backup archives
Spec 2026-08-11-system-config-design section 6 requires the backup tar
to exclude both backups/ itself and *.tmp files; only the backups/
exclusion was implemented. Adds a <base>/*.tmp exclusion for the webui
data dir and the configured backend data dir, mirroring the existing
top-level exclusion style. Excludes are emitted before any -C operand
so bsdtar does not treat them as member operands.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 10:49:29 +08:00
m4 72dedba64e feat(webui): tar.gz backup archive module with prune and mutex 2026-08-11 10:40:10 +08:00
m4 1532a9de3e feat(webui): honor security overrides in auth, captcha, login, and proxy
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 10:08:45 +08:00
m4 74516fd7c8 feat(webui): branding upload + public asset routes 2026-08-11 09:23:28 +08:00
m4 e8f09f240e fix(webui): reject malformed JSON body in system config PUT
An unparseable request body was silently converted to null, merged over
defaults, and saved — wiping the admin's config while returning 200.
Throw SystemConfigError on JSON parse failure so the route returns 400
INVALID_REQUEST without touching the saved config file.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 09:06:11 +08:00
m4 3ddd953e1b feat(webui): admin + public system config API routes 2026-08-11 08:51:46 +08:00
m4 0a9148d178 feat(webui): system config override store with effective security derivation
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-11 08:35:52 +08:00
m4 7c9193df2e docs(webui): implementation plan for admin system config 2026-08-11 08:29:08 +08:00
m4 aa0f308208 docs(webui): spec for admin system config (branding, login terms, security, backup) 2026-08-11 07:51:14 +08:00
m4 b75de8b5e6 Revert "feat(webui): pin sidebar collapse button to the resize divider"
This reverts commit adc59ba. The divider-mounted tab broke the header's
visual consistency; the collapse toggle stays in the top header.
2026-08-11 07:22:20 +08:00
m4 adc59ba9a9 feat(webui): pin sidebar collapse button to the resize divider
The collapse control now hangs off the top of the ResizableHandle so it
tracks the divider as the sidebar is resized, instead of sitting in the
header far from the boundary it controls. The header toggle remains for
the collapsed and mobile-overlay states. ResizableHandle now renders
passed children (previously shadowed by the withHandle element).
2026-08-10 23:44:28 +08:00
m4 17271d6ebd style(webui): show title only in thread list rows 2026-08-10 22:44:55 +08:00
m4 39e126beab style(webui): gradient brand mark and larger welcome title 2026-08-10 22:35:23 +08:00
m4 62005109a4 style(webui): pastel-tinted stat cards on welcome screen
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-10 22:32:34 +08:00
m4 92acc7802e docs(webui): implementation plan for welcome screen polish 2026-08-10 22:26:11 +08:00
m4 37f9944ca1 docs(webui): spec for welcome screen gradient brand + pastel cards 2026-08-10 22:23:48 +08:00
m4 cc1218bdaf docs(webui): sync spec focus-ring and link color with cyan-700 code 2026-08-10 21:44:30 +08:00
m4 e0d38afa0c fix(webui): composer shadow and single cyan focus ring 2026-08-10 21:34:29 +08:00
m4 535d1b4955 fix(webui): deepen light brand to cyan-700 for WCAG AA contrast
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-10 21:00:37 +08:00
m4 c388fa4838 fix(webui): register layered shadows in theme, use ring-ring/20 for focus rings
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-10 21:00:22 +08:00
m4 11aa88d4f9 style(webui): cyan active states in sidebar, premium login card 2026-08-10 20:02:13 +08:00
m4 7b6bac0c53 style(webui): polish composer, user bubble, and tool-call box 2026-08-10 19:58:47 +08:00
m4 934e8de7c8 style(webui): restyle ui primitives (gradient primary, cyan focus, layered shadows) 2026-08-10 15:56:01 +08:00
m4 50e5871184 style(webui): bright zinc+cyan design tokens and Inter font 2026-08-10 14:13:12 +08:00
m4 d0ab5b6e7f docs(webui): implementation plan for UI polish 2026-08-10 14:06:13 +08:00
m4 a9ee44e7dd docs(webui): spec for bright/premium UI polish
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-10 13:33:19 +08:00
m4 10904c13fb fix(webui): prefix zip include paths with ./ to defeat option injection 2026-08-10 12:25:48 +08:00
m4 9984c6bdc4 feat(webui): checkbox multi-select download in workspace tree 2026-08-10 12:14:46 +08:00
m4 1d813c18d6 feat(webui): selective include/exclude download for workspace zips 2026-08-10 12:06:39 +08:00
m4 b7db9fa74f fix(webui): re-checking a partial folder clears its descendant exclusions 2026-08-10 11:56:29 +08:00
m4 9912c7d863 feat(webui): tri-state workspace selection state module 2026-08-10 11:53:32 +08:00
m4 acfb1fc81a docs(webui): implementation plan for workspace selective download
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-10 09:08:59 +08:00
m4 e44a9f0b2c docs(webui): spec for workspace selective download
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-09 15:19:45 +08:00
m4 0e34383aed fix(webui): maximize the DialogContent itself; fixed children are trapped by its translate 2026-08-08 22:53:45 +08:00
m4 cd87138a82 fix(webui): maximize preview to browser window instead of OS fullscreen 2026-08-08 22:48:58 +08:00
m4 bbea13b68a feat(webui): fullscreen toggle for html preview panel 2026-08-08 22:37:24 +08:00
m4 3e705023b6 docs(webui): spec + plan for html preview fullscreen 2026-08-08 22:34:06 +08:00
m4 918cf741ac feat(webui): redirect render=1 html to path-embedded token URL 2026-08-08 14:15:34 +08:00
m4 046129197a feat(webui): token-gated render route for sandboxed html preview 2026-08-08 14:05:48 +08:00
m4 b1ecd2ab46 refactor(webui): extract resolveWorkspaceForThread from request-bound resolver 2026-08-08 13:59:08 +08:00
m4 5143a21ee9 feat(webui): HMAC render token for workspace html preview 2026-08-08 13:50:22 +08:00
m4 b6da97ed78 docs(webui): implementation plan for workspace render token 2026-08-08 13:46:35 +08:00
m4 4b3f4f101e docs(webui): design for workspace render-token html preview fix 2026-08-08 13:36:05 +08:00
m4 0e9334d4cd fix(webui): use Code icon for Source toggle to distinguish from Edit
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 12:00:57 +08:00