Commit Graph

175 Commits

Author SHA1 Message Date
m4 b7db9fa74f fix(webui): re-checking a partial folder clears its descendant exclusions 2026-08-10 11:56:29 +08:00
m4 9912c7d863 feat(webui): tri-state workspace selection state module 2026-08-10 11:53:32 +08:00
m4 acfb1fc81a docs(webui): implementation plan for workspace selective download
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-10 09:08:59 +08:00
m4 e44a9f0b2c docs(webui): spec for workspace selective download
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-09 15:19:45 +08:00
m4 0e34383aed fix(webui): maximize the DialogContent itself; fixed children are trapped by its translate 2026-08-08 22:53:45 +08:00
m4 cd87138a82 fix(webui): maximize preview to browser window instead of OS fullscreen 2026-08-08 22:48:58 +08:00
m4 bbea13b68a feat(webui): fullscreen toggle for html preview panel 2026-08-08 22:37:24 +08:00
m4 3e705023b6 docs(webui): spec + plan for html preview fullscreen 2026-08-08 22:34:06 +08:00
m4 918cf741ac feat(webui): redirect render=1 html to path-embedded token URL 2026-08-08 14:15:34 +08:00
m4 046129197a feat(webui): token-gated render route for sandboxed html preview 2026-08-08 14:05:48 +08:00
m4 b1ecd2ab46 refactor(webui): extract resolveWorkspaceForThread from request-bound resolver 2026-08-08 13:59:08 +08:00
m4 5143a21ee9 feat(webui): HMAC render token for workspace html preview 2026-08-08 13:50:22 +08:00
m4 b6da97ed78 docs(webui): implementation plan for workspace render token 2026-08-08 13:46:35 +08:00
m4 4b3f4f101e docs(webui): design for workspace render-token html preview fix 2026-08-08 13:36:05 +08:00
m4 0e9334d4cd fix(webui): use Code icon for Source toggle to distinguish from Edit
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 12:00:57 +08:00
m4 9a4141b05e feat(webui): preview/source toggle for html files in workspace dialog
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:46:15 +08:00
m4 666a82ebb0 feat(webui): image zoom/pan and prev-next navigation in file dialog
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:44:15 +08:00
m4 66781a7012 feat(webui): serve html as text/html with allow-scripts sandbox under render=1
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:31:21 +08:00
m4 aaaf83805c feat(webui): fileResponseHeaders with render-mode for html preview
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:17:34 +08:00
m4 ef39d6f532 docs: implementation plan for html preview/source toggle
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:14:17 +08:00
m4 84143435fe docs: clarify nosniff retention in html-preview spec
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:09:52 +08:00
m4 31aa1608af docs: design spec for HTML preview/source toggle in workspace dialog
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 11:09:24 +08:00
m4 b36da152a3 fix(webui): don't redirect on change-password 401 (wrong input, not expired session)
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 10:25:33 +08:00
m4 2db00b5157 feat(webui): captcha input on login page after repeated failures
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:35:44 +08:00
m4 9a1775c17d feat(webui): require math captcha after 3 failed logins per IP
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:32:52 +08:00
m4 f91b26670b feat(webui): GET /api/auth/captcha issues math captchas
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:29:29 +08:00
m4 99ddaa6df4 feat(webui): per-IP login failure counter
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:24:48 +08:00
m4 f5776cdf49 feat(webui): stateless signed math-captcha tokens
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:21:28 +08:00
m4 4a652fd67f feat(webui): redirect to /login on any API 401 response
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 09:17:06 +08:00
m4 ce01a6022b docs: implementation plan for login captcha and 401 redirect
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:58:01 +08:00
m4 6e7a1e4898 docs: design spec for login captcha and session-expiry redirect
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:50:44 +08:00
m4 b53d58fa35 fix(webui): preserve remaining session TTL on password change
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:30:43 +08:00
m4 a7625fc38f feat(webui): remember-me checkbox on the login page
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:19:23 +08:00
m4 a047129622 feat(webui): rememberMe login flag with 30-day persistent cookie
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:12:10 +08:00
m4 8a59ec59d8 feat(webui): parameterize session TTL and cookie maxAge
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 08:06:51 +08:00
m4 ed7de2a017 feat(webui): rememberTtlSeconds config for remember-me sessions
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 07:54:24 +08:00
m4 804447047e docs(webui): remember-me implementation plan
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-08 07:48:41 +08:00
m4 9c25b3a9e5 docs(webui): remember-me (30-day session) design spec
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-07 17:08:01 +08:00
m4 6d2b2f4d80 docs(webui): mark error-log bell UI as implemented
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 21:16:29 +08:00
m4 0953e403e5 feat(webui): mount error-log bell in the header
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 20:10:09 +08:00
m4 47420514bd feat(webui): error-log bell with unread badge and clear-all
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 19:32:57 +08:00
m4 a67f16651d feat(webui): useErrorLogs hook with unread cursor and clear-all
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 19:31:59 +08:00
m4 bc2f83591a feat(webui): unread-cursor helpers for the error-log bell
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 19:30:01 +08:00
m4 6b0cc81ded docs(webui): design doc for per-user error logging
Records the approved four-part design (store, collection, BFF API, bell
UI) and the current implementation status.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 16:59:14 +08:00
m4 2aeccea036 docs(webui): implementation plan for the error-log bell UI
Covers the remaining piece of the per-user error-log feature: unread
cursor module, useErrorLogs hook, ErrorLogBell component, header mount.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 16:58:22 +08:00
m4 09d9f49e9f feat(webui): record BFF route errors in the acting user's error log
routeErrorResponse gains an optional actor; every route that resolves an
actor now passes it, so API failures survive the toast. Unauthenticated
failures and the error-logs route itself are never logged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 11:01:31 +08:00
m4 dd4b63a0ee feat(webui): report user-visible errors to the per-user error log
Add errorReporter (errorToast = toast.error + fire-and-forget POST to
/api/error-logs) and wire it into the operational error toasts across
chat, threads, tasks, agents, models, files and clipboard. Pure form
validation hints stay on toast.error.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:46:07 +08:00
m4 a4e47e1b5d style(webui): render the idle status dot as a hollow ring
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:43:40 +08:00
m4 8d455a08e2 feat(webui): add /api/error-logs GET/POST/DELETE for per-user error logs
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:25:37 +08:00
m4 61c2aba187 feat(webui): add per-user error log store
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-07-31 10:21:19 +08:00