Files
Triple-C/app/src/components/projects/ClaudeCodeSettingsEditor.tsx
T
shadow-testandClaude Opus 5 9472cb3c4c Resolve host paths before mounting them, and stop reading stored data as choice
Four fixes that share a shape: a value already on disk, or one spelled
around a check, being taken at face value.

`/..` bind-mounted the entire host filesystem read-write. `is_filesystem_root`
was purely lexical — trim trailing separators, refuse what was left only if it
was empty or a bare `C:` — and nothing in the file ever called `canonicalize`,
so `/..`, `/./`, `/home/..`, `/etc/../` and `C:\..` all passed. The daemon
resolves them: `docker run -v /..:/mnt/probe` mounts the host root, and the app
mounts read-*write* into a container whose agent has passwordless sudo. It is
the escalation `check_mount_name_stays_under_workspace` exists to close,
reached through the host-path half of the mount instead of the mount-name half.

`classify_mount_source` replaces it and asks the OS: `canonicalize` applies
`..`, follows symlinks, and resolves 8.3 aliases and UNC spellings on Windows.
A path that cannot be resolved — `projects.json` synced from another machine,
a folder not created yet — falls back to a lexical collapse rather than being
refused, because refusing would make such a project unsavable; the gap is
bounded, since what resolution adds is a property of paths that exist. A path
that names no location at all (`C:x`, a relative path) is refused rather than
guessed at. Same check now guards `ssh_key_path` and `ca_cert_path`, whose
read-only mounts were whole-host disclosure at /tmp/.host-ssh.

Custom env var names had no charset check anywhere, so `BASH_FUNC_stat%%` —
bash's wire format for an exported shell function, body in the value — reached
the container environment verbatim. Latent today because the image's /bin/sh is
dash, but the pre-commit scrub runs `/bin/sh -c` as root and nothing pins that.
Keys are now shell identifiers, on the project and the global list both, with
the same grandfathering the folder rows get: a stored key is admitted, a new or
edited one is not.

The blank workspace row was persisted. The comment said it was dropped on save;
the code computed the filtered list and then saved the unfiltered one, so
"+ Add folder" plus a blur stored `{"Target": "/workspace/", "Source": ""}` and
the project could never be started or recreated again. Every save in the
section now goes through one filter, and a blur that changed nothing saves
nothing.

Widening the five `ClaudeCodeSettings` booleans to `Option<bool>` reinterpreted
every stored record. They were plain `bool`s that always serialised, so every
project ever saved carries an explicit `"env_scrub": false` that nobody chose —
and under the new merge that `Some(false)` beats a global `Some(true)`, where
the old rule let the global win. Upgrading silently turned five settings off,
"strip credentials from subprocess environments" among them. Deserialisation
now goes through a shim that dates the record by the presence of the
pre-widening `enable_session_recap` key and reads its `false`s as unset. The
fields skip serialising when unset, so an older binary can still parse
`projects.json` after a downgrade — a `null` would fail to parse and take the
whole list down, since `ProjectsStore` parses all-or-nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GBq2rGum6GX7xXgsas1fDc
2026-08-23 17:02:03 -07:00

243 lines
8.2 KiB
TypeScript

import { useEffect, useState } from "react";
import type { ClaudeCodeSettings } from "../../lib/types";
import Toggle from "../ui/Toggle";
import { SwitchRow, selectClass } from "../ui/Field";
interface Props {
settings: ClaudeCodeSettings | null;
disabled: boolean;
disabledReason?: string;
onSave: (settings: ClaudeCodeSettings | null) => Promise<unknown>;
/**
* `"project"` adds a third "Global" state to every switch, because a project
* has somewhere to inherit *from*. The global editor has no such fallback —
* unset there just means Claude Code's own default — so it stays a plain
* on/off and never renders the extra choice.
*/
scope?: "global" | "project";
}
export const CLAUDE_CODE_DEFAULTS: ClaudeCodeSettings = {
tui_mode: null,
effort: null,
auto_scroll_disabled: null,
focus_mode: null,
show_thinking_summaries: null,
session_recap_disabled: null,
env_scrub: null,
prompt_caching_1h: null,
};
/**
* "Nothing is set at this level", which is saved as `null` rather than as a
* struct of nulls so that a project with no opinion is indistinguishable from
* one that never opened this editor.
*
* Note `false` is *not* a default any more: it is a deliberate off that
* overrides a global on, so a settings object holding one has to be persisted.
*/
function isAllDefaults(s: ClaudeCodeSettings): boolean {
// `== null`, not `===`: an unset field is *absent* on the wire, not null.
// The Rust struct skips serialising one it has no value for, so a project
// whose stored settings were all "unset" arrives here as `{}` — and reading
// that as "off" is exactly the mistake the three-state control exists to
// avoid. See the note on `ClaudeCodeSettings` in `lib/types.ts`.
return (
s.tui_mode == null &&
s.effort == null &&
s.auto_scroll_disabled == null &&
s.focus_mode == null &&
s.show_thinking_summaries == null &&
s.session_recap_disabled == null &&
s.env_scrub == null &&
s.prompt_caching_1h == null
);
}
/**
* Two of Claude Code's settings are **on by default**, so the field behind them
* stores the *disabled* sense (`auto_scroll_disabled`, `session_recap_disabled`)
* — that is what makes an untouched project mean "leave Claude Code alone"
* rather than "the user turned this off". `invert` is what lets those still
* read as an ordinary on/off switch here: the toggle shows the feature's state,
* the field stores the deviation from the default.
*/
const BOOLEAN_FIELDS: {
key: keyof Omit<ClaudeCodeSettings, "tui_mode" | "effort">;
label: string;
hint: string;
invert?: boolean;
}[] = [
{ key: "focus_mode", label: "Focus mode", hint: "Collapses tool output to one-line summaries." },
{
key: "show_thinking_summaries",
label: "Thinking summaries",
hint: "Shows Claude's thinking process as summaries.",
},
{
key: "session_recap_disabled",
label: "Session recap",
hint: "Shows a one-line recap when you return to the terminal after a few minutes away.",
invert: true,
},
{
key: "auto_scroll_disabled",
label: "Auto-scroll",
hint: "Follows new output to the bottom in fullscreen rendering.",
invert: true,
},
{
key: "env_scrub",
label: "Env scrub",
hint: "Strips credentials from subprocess environments.",
},
{
key: "prompt_caching_1h",
label: "Prompt caching (1h)",
hint: "Uses a 1-hour prompt cache TTL instead of 5 minutes.",
},
];
export default function ClaudeCodeSettingsEditor({
settings,
disabled,
disabledReason,
onSave,
scope = "global",
}: Props) {
const [local, setLocal] = useState<ClaudeCodeSettings>(
settings ?? { ...CLAUDE_CODE_DEFAULTS },
);
useEffect(() => {
setLocal(settings ?? { ...CLAUDE_CODE_DEFAULTS });
}, [settings]);
const apply = (patch: Partial<ClaudeCodeSettings>) => {
const next = { ...local, ...patch };
setLocal(next);
onSave(isAllDefaults(next) ? null : next);
};
return (
<div className="space-y-4">
{disabled && disabledReason && (
<p className="px-2 py-1.5 bg-[var(--warning-muted)] border border-[var(--warning)]/30 rounded-[var(--radius-control)] text-xs text-[var(--warning)]">
{disabledReason}
</p>
)}
{/*
Three states, not two. Leaving `tui` unset is what lets Claude Code pick
the renderer for itself, which is not the same as pinning the classic
one — and the key is now always written (or explicitly deleted), so
"Automatic" has to be selectable rather than merely being what you get
when nothing is emitted.
*/}
<SwitchRow
label="TUI mode"
hint="Classic renders in your terminal's scrollback; fullscreen is the flicker-free alt-screen."
control={
<select
value={local.tui_mode ?? ""}
aria-label="TUI mode"
onChange={(e) => apply({ tui_mode: e.target.value || null })}
disabled={disabled}
className={selectClass}
>
<option value="">Automatic</option>
<option value="default">Classic</option>
<option value="fullscreen">Fullscreen</option>
</select>
}
/>
<SwitchRow
label="Effort level"
hint="Controls how much reasoning Claude applies."
control={
<select
value={local.effort ?? ""}
aria-label="Effort level"
onChange={(e) => apply({ effort: e.target.value || null })}
disabled={disabled}
className={selectClass}
>
<option value="">Default</option>
<option value="low">Low</option>
<option value="medium">Medium</option>
<option value="high">High</option>
<option value="xhigh">Extra high</option>
</select>
}
/>
{BOOLEAN_FIELDS.map(({ key, label, hint, invert }) => {
const stored = local[key];
if (scope === "global") {
// No level above this one to inherit from, so "unset" and "off" are
// the same instruction here and a plain switch is the honest control.
// Unset therefore has to *display* as Claude Code's own default —
// which for the two inverted fields is on, not off.
const checked = invert ? stored !== true : stored === true;
return (
<SwitchRow
key={key}
label={label}
hint={hint}
control={
<Toggle
label={label}
checked={checked}
disabled={disabled}
onChange={(v) => {
// Collapse back to null at the default rather than storing
// a redundant `false`, so an untouched global stays
// indistinguishable from one that was never opened.
const atDefault = invert ? v : !v;
apply({
[key]: atDefault ? null : invert ? !v : v,
} as Partial<ClaudeCodeSettings>);
}}
/>
}
/>
);
}
// `stored` holds the deviation from Claude Code's default, so an
// inverted field reads back the other way round — see BOOLEAN_FIELDS.
const selected =
stored == null ? "global" : (invert ? !stored : stored) ? "on" : "off";
return (
<SwitchRow
key={key}
label={label}
hint={hint}
control={
<select
value={selected}
aria-label={label}
disabled={disabled}
onChange={(e) => {
const choice = e.target.value;
const next =
choice === "global" ? null : invert ? choice === "off" : choice === "on";
apply({ [key]: next } as Partial<ClaudeCodeSettings>);
}}
className={selectClass}
>
<option value="global">Global</option>
<option value="off">Off</option>
<option value="on">On</option>
</select>
}
/>
);
})}
</div>
);
}