Add Project Home, Auth Bridge, shared auth token, and Tier-1 polish
Project Home (DESIGN-REVIEW §B2): the project is promoted from a 280px
sidebar card to a first-class main-area view. ProjectCard.tsx (1,257
lines) is replaced by a select-only ProjectRow plus tabs for Overview,
Sessions, Automation, Config and Files. The PortMappings, FileManager
and ContainerProgress modals are absorbed rather than reimplemented.
Config gains a Saved/Saving/Failed indicator — save-on-blur failures
previously reached only console.error.
Tier-1 polish (DESIGN-REVIEW §A): new elevation, muted-accent, disabled
and focus-ring tokens; a global :focus-visible ring with every
focus:outline-none removed; filled buttons moved to --accent-emphasis
and white-on-success toggles retired, fixing three WCAG AA failures
(2.1:1, 2.5:1, 2.4:1); a shared Modal primitive with role="dialog",
focus trap and restore, adopted by all remaining modals; status
indicators that carry a glyph and word rather than colour alone.
Ctrl+Shift+W closes a tab, deliberately not Ctrl+W — that is readline's
kill-word, used constantly in the terminal this app is built around.
Auth Bridge: a general loopback-callback bridge so browser logins run
inside a container (aws sso login, Concourse fly login, claude login)
can complete against the host browser. Listeners are discovered from
/proc/net/tcp{,6} — ss/netstat/lsof are absent from the image — bound on
host 127.0.0.1 only, and tunnelled in over the Docker API via socat,
which keeps working on Docker Desktop where container IPs are not
routable. Falls back to [::1] because Node resolves localhost to IPv6
first, so claude login often binds ::1 alone. Opt-in per project.
This extracts create_attached_exec() and moves the existing terminal
session path onto it, so there is one attached-exec implementation
rather than two.
Shared auth token: `claude setup-token` is run in a container, the token
is stored in the OS keychain and injected as CLAUDE_CODE_OAUTH_TOKEN
into Anthropic-backend projects. Contrary to the initial design note,
setup-token uses an Anthropic-hosted redirect and blocks on a stdin
paste prompt rather than a loopback callback, so a stdin command is
required for the flow to complete.
The token is never logged, never returned to the frontend, and is
redacted from the streamed output with a stateful matcher that withholds
any tail that could still grow into a secret. Change detection uses a
random rotation id rather than a hash, since a hash in a docker-inspect
readable label would be an offline verification oracle.
Frontend 33 -> 51 tests; Rust 34 tests. Both builds clean.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,140 @@
|
||||
import { describe, it, expect, vi, beforeEach } from "vitest";
|
||||
import { render, screen, fireEvent } from "@testing-library/react";
|
||||
import PermissionModeControl, {
|
||||
effectivePermissionMode,
|
||||
permissionModePatch,
|
||||
} from "./PermissionModeControl";
|
||||
import type { Project } from "../../lib/types";
|
||||
|
||||
const baseProject: Project = {
|
||||
id: "p1",
|
||||
name: "api-server",
|
||||
paths: [{ host_path: "/src/api", mount_name: "api" }],
|
||||
container_id: null,
|
||||
status: "running",
|
||||
backend: "anthropic",
|
||||
bedrock_config: null,
|
||||
ollama_config: null,
|
||||
openai_compatible_config: null,
|
||||
allow_docker_access: false,
|
||||
sandbox_mode_enabled: true,
|
||||
mission_control_enabled: false,
|
||||
full_permissions: false,
|
||||
permission_mode: null,
|
||||
ssh_key_path: null,
|
||||
git_token: null,
|
||||
git_user_name: null,
|
||||
git_user_email: null,
|
||||
custom_env_vars: [],
|
||||
port_mappings: [],
|
||||
claude_instructions: null,
|
||||
claude_code_settings: null,
|
||||
renamed_session_names: {},
|
||||
created_at: "2026-01-01T00:00:00Z",
|
||||
updated_at: "2026-01-01T00:00:00Z",
|
||||
};
|
||||
|
||||
describe("effectivePermissionMode", () => {
|
||||
it("falls back to the legacy boolean when permission_mode is null", () => {
|
||||
expect(effectivePermissionMode(baseProject)).toBe("default");
|
||||
expect(
|
||||
effectivePermissionMode({ ...baseProject, full_permissions: true }),
|
||||
).toBe("bypass");
|
||||
});
|
||||
|
||||
it("prefers permission_mode when it is set", () => {
|
||||
expect(
|
||||
effectivePermissionMode({
|
||||
...baseProject,
|
||||
permission_mode: "plan",
|
||||
full_permissions: true,
|
||||
}),
|
||||
).toBe("plan");
|
||||
});
|
||||
});
|
||||
|
||||
describe("permissionModePatch", () => {
|
||||
it("keeps the legacy full_permissions flag in sync", () => {
|
||||
expect(permissionModePatch("bypass")).toEqual({
|
||||
permission_mode: "bypass",
|
||||
full_permissions: true,
|
||||
});
|
||||
expect(permissionModePatch("acceptEdits")).toEqual({
|
||||
permission_mode: "acceptEdits",
|
||||
full_permissions: false,
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("PermissionModeControl", () => {
|
||||
const onChange = vi.fn();
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
});
|
||||
|
||||
it("renders all four modes as a radio group with the effective one checked", () => {
|
||||
render(<PermissionModeControl project={baseProject} onChange={onChange} />);
|
||||
const group = screen.getByRole("radiogroup", { name: "Permission mode" });
|
||||
expect(group).toBeInTheDocument();
|
||||
expect(screen.getAllByRole("radio")).toHaveLength(4);
|
||||
expect(screen.getByRole("radio", { name: "Default" })).toHaveAttribute(
|
||||
"aria-checked",
|
||||
"true",
|
||||
);
|
||||
});
|
||||
|
||||
it("reports the picked mode", () => {
|
||||
render(<PermissionModeControl project={baseProject} onChange={onChange} />);
|
||||
fireEvent.click(screen.getByRole("radio", { name: "Accept Edits" }));
|
||||
expect(onChange).toHaveBeenCalledWith("acceptEdits");
|
||||
});
|
||||
|
||||
it("moves selection with the arrow keys", () => {
|
||||
render(<PermissionModeControl project={baseProject} onChange={onChange} />);
|
||||
fireEvent.keyDown(screen.getByRole("radiogroup", { name: "Permission mode" }), {
|
||||
key: "ArrowRight",
|
||||
});
|
||||
expect(onChange).toHaveBeenCalledWith("acceptEdits");
|
||||
});
|
||||
|
||||
it("shows sandbox state beside the control", () => {
|
||||
render(<PermissionModeControl project={baseProject} onChange={onChange} />);
|
||||
expect(screen.getByTestId("sandbox-state")).toHaveTextContent(
|
||||
/Sandbox\s*ON/,
|
||||
);
|
||||
});
|
||||
|
||||
it("does not paint Bypass as dangerous while the sandbox contains it", () => {
|
||||
render(
|
||||
<PermissionModeControl
|
||||
project={{ ...baseProject, permission_mode: "bypass" }}
|
||||
onChange={onChange}
|
||||
/>,
|
||||
);
|
||||
const bypass = screen.getByRole("radio", { name: "Bypass" });
|
||||
expect(bypass.className).toContain("--accent-emphasis");
|
||||
expect(bypass.className).not.toContain("--warning-emphasis");
|
||||
expect(screen.getByTestId("permission-mode-hint")).toHaveTextContent(
|
||||
/contained by the sandbox/i,
|
||||
);
|
||||
});
|
||||
|
||||
it("uses caution colour only when Bypass runs with the sandbox off", () => {
|
||||
render(
|
||||
<PermissionModeControl
|
||||
project={{
|
||||
...baseProject,
|
||||
permission_mode: "bypass",
|
||||
sandbox_mode_enabled: false,
|
||||
}}
|
||||
onChange={onChange}
|
||||
/>,
|
||||
);
|
||||
const bypass = screen.getByRole("radio", { name: "Bypass" });
|
||||
expect(bypass.className).toContain("--warning-emphasis");
|
||||
expect(screen.getByTestId("permission-mode-hint")).toHaveTextContent(
|
||||
/Caution/i,
|
||||
);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user