Turn the Files tab into a real file manager
Rename, an in-app viewer for text and images, host-to-container drag and drop, New folder, keyboard operation — plus the pre-existing bugs the new surface would otherwise have been built on top of. New Tauri commands (file_commands.rs, registered in lib.rs): * rename_container_path — `mv -n -- <from> <parent>/<name>` through exec_oneshot_as, so the *exit code* is checked. exec_oneshot discards the status and interleaves stderr into stdout, which would have made a permission failure look like a success. `mv -n` on its own is not enough either: GNU coreutils makes its refusal to clobber silent and exits 0, so an explicit `test -e` on the destination is what turns a name clash into an error the user sees. `mv`'s own words are surfaced, since renames outside /workspace legitimately fail on permissions. The new name is validated in Rust (no `/`, no NUL, not "." / ".." / empty, ≤255 bytes) — it is user text going into argv, and a name with a separator would be a move rather than a rename. * read_container_file — exact bytes via Docker's archive endpoint, returned as base64. Deliberately not exec_oneshot, which runs every chunk through String::from_utf8_lossy and merges stderr, so it would corrupt any non-UTF-8 file and could splice diagnostics into content. Base64 rather than Vec<u8> because Tauri serialises a byte vec as a JSON number array. Capped and truncation-reporting; the caller picks the cap (images get 5 MiB against text's 1 MiB, being the kind that blows a text-sized budget) and Rust clamps it to 8 MiB regardless. * create_container_directory — `mkdir` without -p, so a clash is an error rather than a silent success. Named for its siblings rather than the bare `create_directory` in the brief. The tar-extraction half of download_container_file is now the shared fetch_container_file() both commands use, and it abandons the transfer once a capped read has what it needs. Frontend: * Single click selects, double click opens. Directory navigation moved onto double click too — a single click used to navigate, which made it impossible to select a directory in order to rename it. Rows are now focusable and the table is a real `grid`: Enter opens, F2 renames, arrows walk the rows. No outline suppression; the global :focus-visible ring is what shows focus. * FileViewerModal (built on ui/Modal, the only correct dialog) renders text in a <pre> and images from a revocable blob: URL. tauri.conf.json's img-src had neither `data:` nor `blob:`, so an in-app image was blocked by CSP; `blob:` is added — revocable, and no megabytes of base64 in the DOM. The asset protocol stays disabled. Anything else gets a "Save to host" state instead of a broken preview, decided by extension and then by sniffing the bytes for NUL. * Host drag-and-drop uses Tauri's native onDragDropEvent, mirroring TerminalView: HTML5 ondrop carries no paths and is blocked in the webview on Windows by dragDropEnabled, which the terminal needs. The listener is window-wide, so it routes by hit-testing the payload position (physical pixels, hence the devicePixelRatio divide) against the pane's rect — a hidden pane has a zero-size rect and never matches, which is what keeps this and the terminal's listener apart. enter/over/leave drive a drop highlight. * Per-row Download is now "Save to host…"; directories no longer offer it. Pre-existing bugs fixed: * Uploaded files landed root:root with a 1970 mtime. tar::Header::new_gnu() zeroes uid/gid/mtime and Docker honours the header verbatim, so uploads were not writable by `claude`. All four single-file tar builds now go through build_single_file_tar() with the container user's ids, read from the container because entrypoint.sh remaps them to the host user on Unix and deliberately does not on Windows. * Symlinked directories could not be opened: `find -printf '%y'` reports `l`. The listing now prints `%Y` as well, so is_directory dereferences and a new is_symlink carries what `%y` used to say. The row labels the link. * upload_file_to_container had no size cap and did a synchronous fs::read on an async worker. Now 256 MiB (matching the terminal drop path) with the read and tar build in spawn_blocking, and the host mtime preserved. * A directory passed to upload reached fs::read and produced an opaque "Is a directory". Rejected with an explanation instead — recursive upload is a larger feature than this panel needs. * download_container_file wrote the *first tar entry*, so downloading a directory silently produced a garbage file. Non-regular entries are now an explicit error. Tests: 46 new (33 frontend across FilesTab, useFileManager and filePreview; 12 Rust covering the find-output parser and the rename validator, neither of which had any). 405 frontend / 297 Rust, both green. No drag-out dependency was added — tauri-plugin-drag is not introduced and OS drag-out is not attempted; that stays deferred, with "Save to host…" as the way files leave the container. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GBq2rGum6GX7xXgsas1fDc
This commit is contained in:
@@ -0,0 +1,107 @@
|
||||
/**
|
||||
* What the Files viewer can show, and how much of it to ask for.
|
||||
*
|
||||
* Pure helpers, deliberately separate from the modal: the type sniffing is
|
||||
* where a preview quietly turns into a screenful of mojibake, and it is worth
|
||||
* testing without a container.
|
||||
*/
|
||||
|
||||
/**
|
||||
* Extension → MIME, for the raster/vector types an `<img>` actually renders.
|
||||
* The MIME matters because the bytes are handed to the DOM as a `Blob`, and a
|
||||
* blob with the wrong (or empty) type will not decode.
|
||||
*/
|
||||
const IMAGE_MIME: Record<string, string> = {
|
||||
png: "image/png",
|
||||
jpg: "image/jpeg",
|
||||
jpeg: "image/jpeg",
|
||||
gif: "image/gif",
|
||||
webp: "image/webp",
|
||||
bmp: "image/bmp",
|
||||
ico: "image/x-icon",
|
||||
avif: "image/avif",
|
||||
// Safe in an `<img>`: that context cannot run the script an SVG may carry.
|
||||
svg: "image/svg+xml",
|
||||
};
|
||||
|
||||
/** Extensions we are confident are text, so no byte sniffing is needed. */
|
||||
const TEXT_EXTENSIONS = new Set([
|
||||
"txt", "md", "markdown", "rst", "log", "csv", "tsv",
|
||||
"json", "jsonc", "yaml", "yml", "toml", "ini", "cfg", "conf", "env", "properties",
|
||||
"js", "jsx", "mjs", "cjs", "ts", "tsx", "rs", "py", "rb", "go", "java", "kt",
|
||||
"c", "h", "cc", "cpp", "hpp", "cs", "php", "swift", "scala", "lua", "pl", "r",
|
||||
"sh", "bash", "zsh", "fish", "ps1", "bat",
|
||||
"html", "htm", "xml", "svelte", "vue", "css", "scss", "sass", "less",
|
||||
"sql", "graphql", "gql", "proto", "diff", "patch", "lock", "gitignore",
|
||||
"dockerfile", "makefile", "cmake", "gradle", "tf", "tfvars",
|
||||
]);
|
||||
|
||||
/** Extensionless files that are text by convention. */
|
||||
const TEXT_BASENAMES = new Set([
|
||||
"dockerfile", "makefile", "readme", "license", "licence", "changelog",
|
||||
"authors", "notice", "copying", "procfile", "rakefile", "gemfile", "vagrantfile",
|
||||
// Dotfiles: the leading dot is stripped before the lookup.
|
||||
"gitignore", "gitattributes", "gitmodules", "dockerignore", "npmrc", "nvmrc",
|
||||
"editorconfig", "bashrc", "zshrc", "profile", "env",
|
||||
]);
|
||||
|
||||
/** 1 MiB of text is already far more than anyone reads in a modal. */
|
||||
export const TEXT_PREVIEW_LIMIT = 1024 * 1024;
|
||||
/**
|
||||
* Images get five times the budget: they are the file kind that routinely
|
||||
* blows past a text-sized cap, and a half-read image is not a preview at all —
|
||||
* it either decodes whole or it does not.
|
||||
*/
|
||||
export const IMAGE_PREVIEW_LIMIT = 5 * 1024 * 1024;
|
||||
|
||||
/** Lowercased extension, or "" for an extensionless name. */
|
||||
export function extensionOf(name: string): string {
|
||||
const base = name.slice(name.lastIndexOf("/") + 1);
|
||||
const dot = base.lastIndexOf(".");
|
||||
// A leading dot is "hidden file", not "extension" (`.gitignore`).
|
||||
if (dot <= 0) return "";
|
||||
return base.slice(dot + 1).toLowerCase();
|
||||
}
|
||||
|
||||
/** The MIME to build the Blob with, or null if this is not a previewable image. */
|
||||
export function imageMimeFor(name: string): string | null {
|
||||
return IMAGE_MIME[extensionOf(name)] ?? null;
|
||||
}
|
||||
|
||||
export type PreviewKind = "image" | "text" | "unknown";
|
||||
|
||||
/**
|
||||
* A first guess from the name alone. `unknown` is not a refusal — the viewer
|
||||
* reads the bytes and falls back to sniffing them, so a `.bak` of a config
|
||||
* file still previews.
|
||||
*/
|
||||
export function previewKind(name: string): PreviewKind {
|
||||
if (imageMimeFor(name)) return "image";
|
||||
const ext = extensionOf(name);
|
||||
if (ext) return TEXT_EXTENSIONS.has(ext) ? "text" : "unknown";
|
||||
const base = name.slice(name.lastIndexOf("/") + 1).replace(/^\./, "").toLowerCase();
|
||||
return TEXT_BASENAMES.has(base) ? "text" : "unknown";
|
||||
}
|
||||
|
||||
/** How many bytes to ask the backend for, given what we expect to render. */
|
||||
export function previewLimit(name: string): number {
|
||||
return previewKind(name) === "image" ? IMAGE_PREVIEW_LIMIT : TEXT_PREVIEW_LIMIT;
|
||||
}
|
||||
|
||||
/** Base64 → bytes. `atob` yields a binary string; widen it one char at a time. */
|
||||
export function decodeBase64(base64: string): Uint8Array<ArrayBuffer> {
|
||||
const binary = atob(base64);
|
||||
const bytes = new Uint8Array(new ArrayBuffer(binary.length));
|
||||
for (let i = 0; i < binary.length; i++) bytes[i] = binary.charCodeAt(i);
|
||||
return bytes;
|
||||
}
|
||||
|
||||
/**
|
||||
* The classic heuristic: a NUL byte early on means this is not text. Cheap,
|
||||
* and it is what `git` and `grep` use to decide the same question.
|
||||
*/
|
||||
export function looksBinary(bytes: Uint8Array): boolean {
|
||||
const limit = Math.min(bytes.length, 8000);
|
||||
for (let i = 0; i < limit; i++) if (bytes[i] === 0) return true;
|
||||
return false;
|
||||
}
|
||||
Reference in New Issue
Block a user