Feat/lan remote preview - #343
Open
Jason880902 wants to merge 6 commits into
Open
Conversation
Extend the in-session terminal bridge to spawn commands directly
(e.g. ssh user@host), parse ~/.ssh/config for a host list, and add a
sidebar entry ('运维') that opens a multi-session SSH ops panel with
quick-connect input and xterm rendering.
Add a sidebar entry ('Git') that opens a swimlane git graph panel. The
Electron main process gains an ipollowork:git:graph IPC that builds a
commit DAG from rev-list --parents plus ref -> commit mapping from
for-each-ref; the renderer draws an SVG lane layout with branch badges,
commit selection, and a detail pane.
Add a default-off LAN read-only preview server so phones and tablets on the local network can view the workbench via a pairing flow. The main process gains a lan-preview-server with 6-digit single-use pair codes, challenge-based anti-CSRF, in-memory session tokens, per-IP fail lockout and rate limiting, and a hard 403 on /api/execute (read-only). A new settings tab (Remote Preview) toggles the server, shows the LAN address and pair code with countdown, and lists paired devices.
SSH ops + Git graph + LAN preview remediation pass: - Git graph: detect and surface truncation (rev-list total-count probe, truncated banner, dashed stub edges for parents outside the window); fix lane layout so sibling branches fork to distinct lanes instead of collapsing onto the parent lane. - LAN preview: raise pair-code entropy (8-char uppercase alphabet, ~39.6 bits) and add a global fail lockout with exponential backoff on top of per-IP limits. - Module layout: move ops-panel/git-panel out of domains/session/terminal into domain-owned dirs with pure-logic modules (graph-layout.ts, ops-utils.ts) instead of dodging the single-file-directory audit rule. - Main process: extract ssh-ops.mjs and git-graph.mjs factories from main.mjs; add preview-core.mjs shared read-only renderer bridge with sanitized public summary for LAN/IM channels. - Tests: node:test suites for ssh config parsing, git DAG building, and preview-core redaction; bun:test suites for swimlane layout and SSH target normalization.
Add an IM notification section to the Remote Preview settings tab: paste a DingTalk/Feishu MCP Streamable-HTTP endpoint and push a redacted workbench summary to the group. The main process gains im-bot.mjs, a minimal MCP client that discovers a send tool by name (send_message / sendMessage / send_text / messages_send) and calls it with the sanitized snapshot from preview-core. No lan-preview session tokens are ever sent. Includes node:test coverage for tool discovery, argument mapping, and summary redaction.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Why
Issue
Scope
Out of scope
Testing
Ran
...Result
CI status
Manual verification
Evidence
N/A (docs-only)Risk
Rollback