Commit Graph
273 Commits
Author SHA1 Message Date
Tam Nhu Tran 4d5449a493 Merge remote-tracking branch 'origin/dev' into kai/review/pr-1691
# Conflicts:
#	docs/reports/hardening-inventory.json
#	docs/reports/hardening-inventory.md
2026-08-08 21:31:32 -04:00
Tam Nhu Tran da2de60015 fix(bar): bound native credential and quota waits 2026-08-08 21:12:28 -04:00
poomscandClaude Fable 5 a5a5b742e4 fix(bar): stop false re-auth on non-default native subscription profiles
Fixes the two collector-side root causes of #1601:

1. Claude per-profile credential reads were file-only, but on macOS Claude
   Code stores the OAuth token for an isolated CLAUDE_CONFIG_DIR in a
   per-directory Keychain item ("Claude Code-credentials-<sha256(dir)[0..8]>").
   The .credentials.json file never exists, so every isolated profile was
   parked with needsReauth:true forever. The reader now falls back to that
   Keychain item (file-first, same security-CLI read the shipped global
   fallback already performs; TTL-gated so it is not on every /summary).

2. Non-default profiles were cache-only forever, so they could never leave
   the parked state even with valid credentials. getNativeAccountRows now
   gives each surface ONE rotating live slot: the stalest eligible
   non-default profile is refreshed per pass, skipping profiles inside
   breaker/reauth cooldowns. Every account converges to real quota within a
   few polls while the per-pass upstream budget stays constant (<= 2 calls
   per surface regardless of profile count). Codex named profiles with valid
   auth but sparse payloads now yield an active quota-less row instead of a
   false needsReauth row.

Non-default rows keep paused:true (dimmed) even when freshly refreshed so
only the default renders active and rows do not flicker between polls.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 14:18:00 +07:00
poomscandClaude Fable 5 34608ce291 feat(bar): support --port for ccs bar with sticky port persistence
ccs bar always forced the dashboard onto port 3000 (first free of a
hardcoded candidate list), which collides with other local dev servers, and
bar.json was rewritten to 3000 on every launch.

- `ccs bar [launch] --port N` runs the server on exactly N: reuses a live
  server already on N, moves a running server from another port (SIGTERM via
  server.pid, wait for exit), errors clearly when N is busy or the value is
  invalid.
- The chosen port is persisted into launch.json args, so the Swift app
  self-starts the server on the same port.
- Without --port, launch and serve now try the port recorded in bar.json
  first (sticky), so the server keeps coming back on the port the user last
  chose instead of reverting to 3000.
- Bare flags (`ccs bar --port N`) route to the launch subcommand; --port is
  documented in `ccs bar --help`.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-08 14:09:58 +07:00
Tam Nhu Tran b022d362dd chore(hardening): refresh filesystem inventory 2026-08-02 20:21:19 -04:00
Tam Nhu Tran 8d7446e3ff chore(hardening): refresh Gemini auth inventory 2026-07-29 14:24:20 -04:00
Tam Nhu Tran 32c8c7b767 chore(hardening): refresh routing inventory 2026-07-29 14:02:52 -04:00
Tam Nhu Tran cd9569e726 chore(hardening): refresh context window inventory 2026-07-29 13:46:53 -04:00
Tam Nhu Tran d6346f0663 chore(hardening): refresh source inventory 2026-07-29 13:28:57 -04:00
Tam Nhu Tran f89f136a1b docs: clarify disabled WebSearch launch behavior 2026-07-29 13:22:21 -04:00
Kai (Tam Nhu) Tran 3ad78b43e7 Merge pull request #1674 from kaitranntt/kai/fix/1670-concurrent-account-locks
fix(cliproxy): retry contended state locks
2026-07-29 13:12:32 -04:00
Kai (Tam Nhu) Tran 16abf18075 Merge pull request #1673 from jeffersongoncalves/feat/i18n-pt-br
feat(i18n): add Brazilian Portuguese (pt-BR) locale
2026-07-29 13:01:58 -04:00
Tam Nhu Tran 348d230298 docs: document Brazilian Portuguese locale 2026-07-29 12:56:42 -04:00
Tam Nhu Tran 794983ca13 chore(reports): refresh hardening inventory 2026-07-29 12:53:00 -04:00
Kenneth Wong cd59c49ae8 chore(reports): refresh hardening inventory 2026-07-27 19:41:19 +08:00
Kai (Tam Nhu) Tran b09f8191f3 Merge pull request #1669 from kaitranntt/kai/docs/1666-pruning-freshness
docs: prune stale guides and enforce freshness
2026-07-26 22:09:35 -04:00
Kai (Tam Nhu) Tran a8217bf18d Merge pull request #1668 from kaitranntt/kai/docs/1665-architecture-contracts
docs: reconcile architecture and engineering contracts
2026-07-26 22:09:17 -04:00
Tam Nhu Tran 306a8276b3 fix(metrics): enforce exact runtime inventory 2026-07-26 09:36:00 -04:00
Tam Nhu Tran 426dc541a9 docs(roadmap): replace historical trackers with live guidance 2026-07-26 09:36:00 -04:00
Tam Nhu Tran 75e715eebd docs(hygiene): remove superseded local guides 2026-07-26 09:35:42 -04:00
Tam Nhu Tran 4485fd6406 docs(macos): consolidate CCS Bar maintainer guidance 2026-07-26 09:35:42 -04:00
Tam Nhu Tran fd0d4362b3 docs(config): preserve active developer contracts 2026-07-26 09:35:42 -04:00
Tam Nhu Tran deb1ed0e67 docs(readme): route user guides to canonical docs 2026-07-26 09:35:42 -04:00
Tam Nhu Tran 51e8062995 docs(operations): refresh runtime contracts 2026-07-26 09:35:10 -04:00
Tam Nhu Tran ebe1746459 docs(architecture): reconcile provider and target contracts 2026-07-26 09:35:00 -04:00
Tam Nhu Tran b918783293 docs(product): refresh product and release contracts 2026-07-26 09:34:48 -04:00
Tam Nhu Tran 721ca5fc33 docs(architecture): replace volatile maintainer snapshots 2026-07-26 09:34:09 -04:00
Tam Nhu Tran 3bb2d56778 docs(ai): define documentation truth hierarchy 2026-07-26 09:33:56 -04:00
Kai (Tam Nhu) Tran f066188f0a Merge pull request #1656 from minhbi245/chore/refresh-hardening-inventory
chore(reports): refresh hardening inventory
2026-07-22 14:40:58 -04:00
Kai (Tam Nhu) Tran 3608bf71a1 feat: rebrand CCS as Claude Codex Switch (#1658)
Closes #1657
2026-07-22 14:23:42 -04:00
milesnguyen2405 9ddb3429d4 chore(reports): refresh hardening inventory
The maintainability metrics artifact aged past the 30-day freshness
gate in scripts/ci-parity-gate.sh, so validate:ci-parity fails for
every contributor branch until the committed copy is regenerated.
2026-07-22 23:24:35 +07:00
minhbi245 54a2b4759b feat(cliproxy): add xAI Grok provider 2026-07-17 00:02:12 +07:00
Tam Nhu Tran 3103af5355 docs(codex-auth): document shared plugin cache 2026-07-15 10:24:13 -04:00
Kai (Tam Nhu) Tran 23b2c3d6af fix: restrict bar release workflow to main (#1612) 2026-06-30 12:21:33 -04:00
Kai (Tam Nhu) Tran 9dd9bf2978 feat(websearch): add agy provider and deprecate gemini cli fallback (#1607)
Google retired the gemini CLI on 2026-06-18, so the gemini websearch fallback no longer
works. Add agy (Antigravity) as the primary CLI websearch provider end to end: runtime spawn
in websearch-transformer.cjs (agy --dangerously-skip-permissions --print-timeout Ns -p),
detection (agy.ts), config schema and defaults, hook env, status, dashboard persistence, and docs.

The legacy gemini provider stays present but is marked deprecated for enterprise users who
retain access. Image analysis already supported the agy provider (no change). The CLIProxy
gemini quota fetcher (Gemini API OAuth, not the cli binary) is untouched.

Validation: typecheck, lint, and the websearch + config + web-server unit suites pass.
2026-06-27 10:01:25 -04:00
Kai (Tam Nhu) Tran 87eb4f2154 Merge pull request #1414 from cerebrixos/tuning-engines-provider
Add Tuning Engines provider
2026-06-22 17:18:57 -04:00
Tam Nhu Tran b3a9abffbc ci(bar): auto-build and publish CCS Bar on main via self-hosted macOS runner
Releasing the macOS bar app was fully manual (run package_app.sh on a Mac, then
gh release upload --clobber), so Swift-side changes never reached users until
someone remembered to rebuild and re-upload the floating ccs-bar-latest asset.

Add a tightly-scoped Bar Release workflow that does it automatically:
- triggers ONLY on push to main touching macos-bar/**, or manual dispatch, so
  regular PRs, dev pushes, and non-bar changes never start it
- runs ONLY on the dedicated self-hosted macOS runner (label ccs-bar); the Linux
  CI runners never match it and it never competes for them
- least-privilege contents:write, single-flight via concurrency

Version is sourced from a new macos-bar/VERSION single-line file (the workflow
reads it; the asset is always the latest build regardless). package_app.sh now
defaults to that file when no version arg is passed, so the local manual path and
CI share one source of truth. Documents the release process in docs/ccs-bar.md.
2026-06-20 22:17:40 -04:00
Tam Nhu Tran 1462823be8 fix(logging): harden structured trace redaction
Redact StageOptions error payloads and summarize debug launch args.

Propagate request IDs through Cursor daemon and dashboard completion logs.

Mark remaining P2/P3 maintainability targets as partial instead of overclaiming.
2026-06-18 18:48:13 -04:00
Tam Nhu Tran 2d48488475 docs(hardening): finalize epic metrics + progress log (P1-P7) 2026-06-18 18:48:13 -04:00
Tam Nhu Tran 2f94f35ec3 feat(lint): P7 enforcement gates (no-new-throw-error + max-lines) + docs
Epic P7. Locks in the epic's gains with ESLint gates so the adoption work
does not regress.

- ccs/no-new-throw-error (error): custom flat-config rule that flags NEW
  throw new Error(...) outside a generated baseline allowlist. Forces the
  typed-error taxonomy (src/errors/error-types.ts). Existing 338 sites are
  grandfathered in eslint-rules/throw-error-baseline.json; only NEW violations
  error. Rule normalizes the filename to repo-root-relative to match baseline
  keys regardless of how ESLint reports paths.
- max-lines (warn, 400, skipBlankLines/skipComments): warns on files over
  400 LOC (goal of P5/P6 god-file splits). Currently 51 warnings on the
  not-yet-split god-files (P6 territory).
- scripts/generate-throw-error-baseline.js: emits the allowlist from raw
  source (superset of real throws; never undercounts). Run after intentionally
  grandfathering a site, or quarterly to prune.
- tests/unit/eslint-rules/no-throw-new-error.test.ts: rule logic (flags
  off-allowlist, passes on-allowlist/typed/rethrow, line-sensitivity).
- docs/code-standards.md: Lint Enforcement Gates section.
- docs/logging-contract.md: error.code -> ExitCode table (from P4).

validate + validate:ci-parity green.
2026-06-18 18:48:13 -04:00
Tam Nhu Tran 7234ef8fcf feat(errors): P4 typed-error taxonomy adoption (0->91% locked) + erasable-syntax fix
Epic P4. Migrates plain throw new Error to the typed-error classes in the four
locked subdomains, and makes the taxonomy erasable-syntax-compatible so it can
be adopted across UI-reachable code.

Migration (cliproxy/auth, web-server/routes, auth):
- 21 of 23 throws in the locked subdomains now use typed subclasses
  (ProfileError, AuthError, ConfigError, ValidationError, ProviderError).
- Typed adoption in locked subdomains: 0/23 -> 21/23 (91.3%), > 40% target.
- Overall typed adoption: 0.9% -> 8.6%.
- Messages preserved exactly (message-based tests stable). Exit codes now
  differentiate via handleError (ProfileError=7, AuthError=4, ConfigError=2,
  ProviderError=6). ccs doctor 0/1 contract untouched (outside scope).

Erasable-syntax fix (unblocks the migration in the UI build graph):
- exit-codes.ts: enum ExitCode -> const object + union type (value and type
  usage both preserved; no Object.values(ExitCode) consumers).
- error-types.ts: constructor parameter properties -> explicit readonly field
  declarations + body assignment.
- The web UI build enforces erasableSyntaxOnly (ui/tsconfig.app.json) and
  reaches src/errors via the @shared -> src/auth graph; pre-erasable
  error-types blocked the build once profile-registry adopted typed errors.

Compat audit: docs/reports/typed-error-exit-code-compat-audit.md (Q1 resolved:
migrate freely; only documented contract is ccs doctor, which is untouched).
Behavior-lock: src/errors/__tests__/typed-error-migration-exit-codes.test.ts
(taxonomy -> exit-code mapping, instanceof chains, context fields).

validate + validate:ci-parity green (incl. UI build).
2026-06-18 18:48:12 -04:00
Tam Nhu Tran 87aeb8f193 feat(logging): P3 hotpath console.error migration + redaction gate (928->267)
Epic P3. Migrates hotpath console.error/warn to the structured logger
(diagnostics) or process.stderr.write (user-facing), and adds a redaction
safety gate so the migration cannot leak credentials.

Redaction gate (MR1):
- log-redaction: scrub known credential token shapes (sk-ant, sk-, xoxb,
  ghp, glpat, AIza, JWT bodies, api_key=, Bearer/Basic/Token scheme) in
  string values, Error.message, AND the log message string (defense-in-depth).
- logger: message now passes through maskSecretTokens.

tool-sanitization-proxy: deleted the private file-logging subsystem
(initLogFile/writeLog/log/warn, logFilePath, debugMode); 13 call sites now
route through the existing createLogger('cliproxy:tool-sanitization-proxy').

Sweep (~120 diagnostic -> structured createLogger; ~540 user-facing -> stderr):
- diagnostics converted across proxy, web-server/routes, glmt pipeline, quota
  fetchers, executors, delegation, session-bridge, https-tunnel-proxy.
- user-facing CLI output (flows, arg-parser usage, installers, prompts, adapter
  launch errors, error display) moved to process.stderr.write (preserves stderr).
- src/utils/error-manager.ts reclassified CLI-UX-exempt (user-facing display).

Metric: hotpath console.error 928 -> 267 (71%); createLogger files 35 -> 64.
Residual 267 is user-facing CLI output (not diagnostics); documented in
docs/hardening-debt-burndown.md. Redaction gate makes further conversion safe.

Tests: hotpath-redaction-regression (12 token shapes); updated delegation-handler,
arg-parser, model-warnings spies (console.error -> process.stderr.write).
validate + validate:ci-parity green.
2026-06-18 18:48:12 -04:00
Tam Nhu Tran 95a2864ef3 feat(hardening): P1 maintainability metrics baseline + freshness gate (#1561)
Epic P1. Adds maintainability-metrics script (typed-error adoption, createLogger coverage, hotpath console.error, files>400 LOC), merges maintainability block into hardening-inventory report, adds 30-day freshness gate to ci-parity-gate.sh, re-baselines burndown 2026-06-18. Local validate + validate:ci-parity green.
2026-06-18 18:48:12 -04:00
Kai (Tam Nhu) Tran c776e18434 fix(bar): preserve Gatekeeper quarantine on install (#1534)
Preserves the Gatekeeper quarantine attribute on the installed CCS Bar app so the user makes the right-click to Open trust decision, instead of silently clearing it.
2026-06-15 23:28:24 -04:00
kcfang 8f9795bce2 fix(proxy): keep undici timeouts above the upstream request timeout (#1524)
Sets undici headersTimeout/bodyTimeout to request_timeout+30s so the AbortController is the single authority on upstream request lifetime, preventing premature socket closes on slow self-hosted upstreams. Verified undici v5 ProxyAgent object-signature compat.
2026-06-15 21:57:23 -04:00
Kai (Tam Nhu) Tran b03e2e1cb2 docs(bar): document detached launch model and serve/stop/status (#1529)
Reflect the seamless-launch change: the app self-starts the background
server, ccs bar runs it detached, and add the serve/stop/status commands
plus the launch.json/server.pid/serve.log files.
2026-06-15 19:58:03 -04:00
Tam Nhu Tran 4eef3f77a4 feat(bar): one-flow install with quarantine automation and launch handoff
'ccs bar install' previously ended with two manual steps: clearing the
Gatekeeper quarantine by hand and running 'ccs bar' separately.

Install now detects an existing installation and says so before
reinstalling, clears the quarantine attribute itself via execFile with
a graceful fallback to the printed hint when xattr fails, and ends with
a TTY-aware 'Launch CCS Bar now?' prompt (default yes) that hands off
to the existing launch flow. --launch forces the handoff and
--no-launch suppresses it for scripted installs; non-TTY runs skip the
prompt and print the manual command instead.

Closes #1504
2026-06-10 13:25:07 -04:00
Tam Nhu Tran db1d125f83 docs(bar): troubleshooting reflects reuse-first launch behavior 2026-06-10 11:09:51 -04:00
Tam Nhu Tran e7f3ec0da1 docs(bar): align install docs with Info.plist version pinning and bar-API check 2026-06-10 00:11:38 -04:00
Tam Nhu Tran 1e7ad7e75e feat(bar): add Get CCS Bar dashboard banner and ccs bar docs page
Add a 'Get CCS Bar' promo banner + card to the dashboard (mirroring the
OpenRouter promo pattern + design system) so users discover the macOS menu-bar
app, with a macOS-aware install CTA. Add a user-facing docs/ccs-bar.md covering
what it is, install via 'ccs bar install', launch, what it shows, uninstall,
and the loopback requirement -- closing the docs-sync gap for the new ccs bar
command.
2026-06-09 18:04:53 -04:00