m4
b7db9fa74f
fix(webui): re-checking a partial folder clears its descendant exclusions
2026-08-10 11:56:29 +08:00
m4
9912c7d863
feat(webui): tri-state workspace selection state module
2026-08-10 11:53:32 +08:00
m4
acfb1fc81a
docs(webui): implementation plan for workspace selective download
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-10 09:08:59 +08:00
m4
e44a9f0b2c
docs(webui): spec for workspace selective download
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-09 15:19:45 +08:00
m4
0e34383aed
fix(webui): maximize the DialogContent itself; fixed children are trapped by its translate
2026-08-08 22:53:45 +08:00
m4
cd87138a82
fix(webui): maximize preview to browser window instead of OS fullscreen
2026-08-08 22:48:58 +08:00
m4
bbea13b68a
feat(webui): fullscreen toggle for html preview panel
2026-08-08 22:37:24 +08:00
m4
3e705023b6
docs(webui): spec + plan for html preview fullscreen
2026-08-08 22:34:06 +08:00
m4
918cf741ac
feat(webui): redirect render=1 html to path-embedded token URL
2026-08-08 14:15:34 +08:00
m4
046129197a
feat(webui): token-gated render route for sandboxed html preview
2026-08-08 14:05:48 +08:00
m4
b1ecd2ab46
refactor(webui): extract resolveWorkspaceForThread from request-bound resolver
2026-08-08 13:59:08 +08:00
m4
5143a21ee9
feat(webui): HMAC render token for workspace html preview
2026-08-08 13:50:22 +08:00
m4
b6da97ed78
docs(webui): implementation plan for workspace render token
2026-08-08 13:46:35 +08:00
m4
4b3f4f101e
docs(webui): design for workspace render-token html preview fix
2026-08-08 13:36:05 +08:00
m4
0e9334d4cd
fix(webui): use Code icon for Source toggle to distinguish from Edit
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 12:00:57 +08:00
m4
9a4141b05e
feat(webui): preview/source toggle for html files in workspace dialog
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:46:15 +08:00
m4
666a82ebb0
feat(webui): image zoom/pan and prev-next navigation in file dialog
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:44:15 +08:00
m4
66781a7012
feat(webui): serve html as text/html with allow-scripts sandbox under render=1
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:31:21 +08:00
m4
aaaf83805c
feat(webui): fileResponseHeaders with render-mode for html preview
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:17:34 +08:00
m4
ef39d6f532
docs: implementation plan for html preview/source toggle
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:14:17 +08:00
m4
84143435fe
docs: clarify nosniff retention in html-preview spec
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:09:52 +08:00
m4
31aa1608af
docs: design spec for HTML preview/source toggle in workspace dialog
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 11:09:24 +08:00
m4
b36da152a3
fix(webui): don't redirect on change-password 401 (wrong input, not expired session)
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 10:25:33 +08:00
m4
2db00b5157
feat(webui): captcha input on login page after repeated failures
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 09:35:44 +08:00
m4
9a1775c17d
feat(webui): require math captcha after 3 failed logins per IP
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 09:32:52 +08:00
m4
f91b26670b
feat(webui): GET /api/auth/captcha issues math captchas
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 09:29:29 +08:00
m4
99ddaa6df4
feat(webui): per-IP login failure counter
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 09:24:48 +08:00
m4
f5776cdf49
feat(webui): stateless signed math-captcha tokens
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 09:21:28 +08:00
m4
4a652fd67f
feat(webui): redirect to /login on any API 401 response
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 09:17:06 +08:00
m4
ce01a6022b
docs: implementation plan for login captcha and 401 redirect
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 08:58:01 +08:00
m4
6e7a1e4898
docs: design spec for login captcha and session-expiry redirect
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 08:50:44 +08:00
m4
b53d58fa35
fix(webui): preserve remaining session TTL on password change
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 08:30:43 +08:00
m4
a7625fc38f
feat(webui): remember-me checkbox on the login page
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 08:19:23 +08:00
m4
a047129622
feat(webui): rememberMe login flag with 30-day persistent cookie
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 08:12:10 +08:00
m4
8a59ec59d8
feat(webui): parameterize session TTL and cookie maxAge
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 08:06:51 +08:00
m4
ed7de2a017
feat(webui): rememberTtlSeconds config for remember-me sessions
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 07:54:24 +08:00
m4
804447047e
docs(webui): remember-me implementation plan
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-08 07:48:41 +08:00
m4
9c25b3a9e5
docs(webui): remember-me (30-day session) design spec
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-08-07 17:08:01 +08:00
m4
6d2b2f4d80
docs(webui): mark error-log bell UI as implemented
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 21:16:29 +08:00
m4
0953e403e5
feat(webui): mount error-log bell in the header
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 20:10:09 +08:00
m4
47420514bd
feat(webui): error-log bell with unread badge and clear-all
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 19:32:57 +08:00
m4
a67f16651d
feat(webui): useErrorLogs hook with unread cursor and clear-all
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 19:31:59 +08:00
m4
bc2f83591a
feat(webui): unread-cursor helpers for the error-log bell
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 19:30:01 +08:00
m4
6b0cc81ded
docs(webui): design doc for per-user error logging
...
Records the approved four-part design (store, collection, BFF API, bell
UI) and the current implementation status.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 16:59:14 +08:00
m4
2aeccea036
docs(webui): implementation plan for the error-log bell UI
...
Covers the remaining piece of the per-user error-log feature: unread
cursor module, useErrorLogs hook, ErrorLogBell component, header mount.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 16:58:22 +08:00
m4
09d9f49e9f
feat(webui): record BFF route errors in the acting user's error log
...
routeErrorResponse gains an optional actor; every route that resolves an
actor now passes it, so API failures survive the toast. Unauthenticated
failures and the error-logs route itself are never logged.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 11:01:31 +08:00
m4
dd4b63a0ee
feat(webui): report user-visible errors to the per-user error log
...
Add errorReporter (errorToast = toast.error + fire-and-forget POST to
/api/error-logs) and wire it into the operational error toasts across
chat, threads, tasks, agents, models, files and clipboard. Pure form
validation hints stay on toast.error.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 10:46:07 +08:00
m4
a4e47e1b5d
style(webui): render the idle status dot as a hollow ring
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 10:43:40 +08:00
m4
8d455a08e2
feat(webui): add /api/error-logs GET/POST/DELETE for per-user error logs
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 10:25:37 +08:00
m4
61c2aba187
feat(webui): add per-user error log store
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-07-31 10:21:19 +08:00