mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-10-11 12:18:59 +00:00
* refactor(bitrix24): rename "Path B" framing to maintainer-specified naming [B24:2794] Per maintainer hard rule #10 (no generic "Path A/B" framing) from PR #1061 review. The Bitrix24 MCP auto-onboard flow is Bitrix-specific glue ("Bitrix24 OAuth -> existing mcp_user_credentials bridge"), NOT a generic MCP architecture pattern. Naming convention applied consistently: - First mention per file: full "Bitrix24 OAuth -> existing mcp_user_credentials bridge" (matches maintainer comment verbatim). - Subsequent mentions in same file: shortened "mcp_user_credentials bridge". - Test/log context referencing literal endpoint /api/auto-onboard: keep "auto-onboard" reference (it's the actual API endpoint name). Changes are documentation-only: - Rename in code comments + test descriptions + plan docs. - Clarify framing in mcp_client.go + provisioner.go doc comments to emphasize Bitrix-specific glue (not generic MCP infra). - Reuse existing mcp_user_credentials table + MCPServerStore methods (no schema / store / abstraction change). Files: - cmd/gateway.go (factory registration doc) - internal/channels/bitrix24/{channel,factory,mcp_client,provisioner}.go - internal/channels/bitrix24/{mcp_client,provisioner}_test.go - plan/goclaw-mcp-integration.md (21 occurrences) Verified: go build + MCP-related tests pass (TestProvision*, TestInitMCPProvisioner*, TestMCPClient*). Phase 1 of Path C execution per plans/reports/decision-log-260519-1555-bitrix24-pr-fork-decision.md. * fix: confine outbound media paths to agent workspace [B24:2794] Tool MEDIA:<path> output reached channel file-upload sinks (Bitrix imbot.v2.File.upload, Telegram sendDocument, etc.) verbatim via parseMediaResult, with no workspace-boundary check. A malicious or buggy tool emitting MEDIA:/etc/passwd could exfiltrate arbitrary files to chat. Extract the EvalSymlinks+Rel containment from extractMediaFromContent into a shared confineToWorkspace helper and apply it at the parseMediaResult sink in processToolResult. Fixing at the source/egress boundary protects every channel at once rather than per-channel. Paths that escape the workspace are dropped and logged (security.media_path_rejected). Add TestConfineToWorkspace (boundary unit) and TestParseMediaResultConfinedToWorkspace (sink regression for H2). * feat(bitrix24): support inbound + outbound media via imbot.v2 File API [B24:2794] Bitrix24 channel was text-only; attachments were parsed but dropped. - Inbound: download chat files via imbot.v2.File.download (one-time URL), forward to the agent with MIME preserved (internal/channels/bitrix24/download.go). - Outbound: upload agent media to the chat via imbot.v2.File.upload (internal/channels/bitrix24/send_media.go). - Add BaseChannel.HandleMessageMedia to preserve MIME/filename through the bus. - Per-channel media_max_mb cap (default 20) applies to both directions. Tests: 92 pass (internal/channels/bitrix24 + internal/channels), go vet clean (PG + sqliteonly). * refactor(bitrix24): migrate messaging/bot-list/unregister to imbot v2 API [B24:2794] Move outbound REST calls to the imbot v2 family (keeps register on v1): - imbot.message.add -> imbot.v2.Chat.Message.send (fields.message shape, live-verified) - imbot.bot.list (+ legacy imbot.list fallback) -> imbot.v2.Bot.list; add botListRows to normalize the v2 {bots:[...]} envelope, legacy array, and id-keyed map forms - imbot.unregister -> imbot.v2.Bot.unregister Bot registration stays on v1 imbot.register: v2 imbot.v2.Bot.register changes the event-delivery model (per-event handler URLs -> eventMode), which would require rewriting the inbound event parser. No user-facing behavior change. Tests: bitrix24 package green; go vet ./... clean. * feat(bitrix24): route whisper via v1 SKIP_CONNECTOR + add v2 replyId [B24:2794] Bot was leaking HiddenMessage (whisper) replies to the external Zalo connector because every outbound call went through imbot.v2.Chat.Message.send, which has no equivalent of the v1 SKIP_CONNECTOR flag. Branch the outbound path on inbound visibility: whisper → imbot.message.add + SKIP_CONNECTOR=Y (v1, send_v1.go) public → imbot.v2.Chat.Message.send + fields.replyId (v2, send_v2.go) Pipeline: events.go parse data[PARAMS][PARAMS][COMPONENT_ID]=HiddenMessage into EventParams.IsHiddenMessage (form + JSON variants) handle.go set bitrix_visibility on InboundMessage.Metadata consumer forward visibility + message_id into OutboundMessage send.go resolveSendOptions + sendChunk dispatcher + shared callWithRateLimitRetry helper metadata_keys.go single source of truth for the keys + values Defaults preserve pre-refactor behaviour: callers that don't populate bitrix_visibility still go through v2 public, and replyId is omitted unless a numeric bitrix_message_id arrives in metadata. Tests: TestParseEvent_FormURLEncoded_IsHiddenMessage (3 cases) TestParseEvent_JSON_IsHiddenMessage (3 cases) TestResolveSendOptions (8 cases) TestSend_BranchesOnVisibility (4 cases) * feat(bitrix24): openline sender-tag echo on replies [B24:2794] Openline sender-tag echo (this change): - Capture the connector sender tag ("[name #id]:" or "[name] #id:") from inbound openline group messages, strip it from the body the agent sees, and re-prepend the canonical "[name] #id:" form to the reply so the Open Channel connector routes the answer back to the right external user. - New sender_prefix.go helper (+ test) accepts both inbound layouts and emits one canonical form; scoped to messages carrying the tag, so plain chats are unaffected. - metadata_keys.go: MetaKeySenderPrefix; handle.go capture/strip/stash; gateway_consumer_normal.go forwards the key; send.go prepends it on the first chunk before chunking. Bundled bitrix24 channel-core work already on this branch: - handle.go: @mention is the sole trigger for both staff and connector customers; unmentioned traffic is dropped (was: drop all connector msgs). - isGroupMessageType: treat SONET_GROUP "B" as a group. - handle_test.go, mcp_client_test.go: cover the above. * feat(bitrix24): accept colon-less openline sender tag, echo [name] #id [B24:2794] The Open Channel connector dropped the trailing colon from its sender tag: inbound now arrives as "[Name] #id <msg>" (was "[Name] #id: <msg>"). The id-bearing patterns required the colon, so the tag fell through to the name-only branch and the reply echoed "[Name]" — dropping the #id the connector needs to route the answer back. - sender_prefix.go: make the trailing ":" optional on both id layouts ([name #id] / [name] #id, with or without colon) and echo the canonical "[name] #id" (no colon) to match the connector's current format. Bare "[name]" (no id) still echoes "[name]" for Open Channel only. - handle.go: gate the bare name-only layout to Open Channel (isOpenChannel) so ordinary group chats starting with "[x] ..." are left untouched. - sender_prefix_test.go: cover colon/no-colon x id-inside/id-outside, the name-only openline case, and the non-openline no-op. * fix: security and robustness fixes from the bitrix24 channel review [B24:2794] - download.go: block redirect-based SSRF on inbound media. CheckRedirect re-validates each hop (http(s) only, reject private/loopback/link-local hosts, cap hops); the initial portal-domain pin is no longer bypassable via a 3xx to an internal service. Public-host redirects still allowed. - handle.go: extract/echo the openline sender tag only for Open Channel sessions (was: any group chat), removing bogus prefixes in CRM group chats and narrowing the forged-tag misroute surface. - loop_tools.go + loop_media.go: confine result.Media to the agent / team / tenant-allowed roots (new confineToAnyRoot) before a channel uploads it, so a prompt-injected out-of-workspace path (e.g. /etc/passwd) cannot exfiltrate, while legitimate cross-workspace media (team files, delegatee output) still flows. - send_media.go: bounded outbound read via io.LimitReader replaces the os.Stat + os.ReadFile pair, closing the TOCTOU size-cap bypass; cap a single message's outbound attachments at 10 (mirrors inbound). - register.go: paginate imbot.v2.Bot.list (limit/offset + hasNextPage, capped at 40 pages) so verify/lookup see bots past the first 50. - mcp_client.go: redact access_token / refresh_token / client_secret from an echoed MCP error body before it is logged or returned (+ test). * fix(security): validate resolved dial IP on Bitrix media redirects [B24:2794] The inbound media download redirect guard only string-checked the redirect hostname (isPrivateOrLoopback on req.URL.Hostname()), so a redirect to a public hostname that resolves to 127.0.0.1 / 169.254.169.254 / an RFC1918 address — or a DNS-rebinding swap between check and dial — still passed the guard and the client would connect. Reported in PR review. Add security.NewRedirectFollowingSafeClient: it follows redirects but validates the RESOLVED destination IP of every hop at dial time via net.Dialer.Control, reusing the existing blocked-CIDR list. The IP it checks is the IP actually dialed, so both redirect-to-internal and DNS rebinding are refused, while legitimate public CDN redirects still succeed. download.go now uses it instead of the hostname-string guard. Tests: deterministic dial-control table (loopback / link-local / private / multicast / unspecified / public, v4 + v6), malformed/non-IP addr, test bypass, loopback-dial-blocked client wiring, and redirect cap + scheme checks. * feat(bitrix24): per-participant Zalo openline identity from 3-token sender tag [B24:2794] Parse the connector's "[Name] #uid #msgId" sender tag so each external customer in a shared Open Channel group gets its own contact + USER.md instead of collapsing onto the connector proxy id. Identity minting is gated on IS_CONNECTOR=Y to reject operator forged tags. Echo back the msgId only ("#msgId") on replies; keep the legacy single-number and name-only layouts unchanged. Zero DB migration. - sender_prefix.go: parseOpenlineSenderTag() classifies 3-token / legacy / name-only - handle.go: synthetic senderID "openlines:{instance}:{chat}:{uid}" + participant_user_id metadata, gated on FromIsConnector - gateway_consumer_normal.go: deriveGroupUserID() routes participant -> per-person scope, group fallback otherwise - send.go: buildAddressMention numeric-id guard so synthetic ids don't emit invalid [USER=...] BBCode - MetaKeyMessageID kept as Bitrix MESSAGE_ID (drives v2 fields.replyId); connector msgId surfaced only via echo prefix --------- Co-authored-by: DangTinh311 <dangtinh31193@gmail.com> Co-authored-by: Chinh Dang <chinhdang@192.168.68.104>
382 lines
14 KiB
Go
382 lines
14 KiB
Go
package bitrix24
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"log/slog"
|
|
"strconv"
|
|
"strings"
|
|
"time"
|
|
"unicode/utf8"
|
|
|
|
"github.com/nextlevelbuilder/goclaw/internal/bus"
|
|
)
|
|
|
|
// sendOptions captures per-message routing context extracted from
|
|
// OutboundMessage.Metadata once in Send() and threaded through every
|
|
// chunk. Avoids re-parsing the same keys for each chunk in the loop.
|
|
type sendOptions struct {
|
|
// visibility picks the outbound API: VisibilityWhisper → v1
|
|
// imbot.message.add + SKIP_CONNECTOR=Y; VisibilityPublic → v2
|
|
// imbot.v2.Chat.Message.send. Default public for backward-compat.
|
|
visibility string
|
|
// replyToMID is the MESSAGE_ID of the inbound that triggered this
|
|
// reply. > 0 means the v2 path will set fields.replyId so the
|
|
// Bitrix UI links bot reply to the original. 0 = no link.
|
|
// v1 whisper path ignores this — imbot.message.add has no
|
|
// equivalent parameter.
|
|
replyToMID int
|
|
}
|
|
|
|
// rateLimitRetryDelay is how long we wait after Bitrix24 returns
|
|
// QUERY_LIMIT_EXCEEDED before retrying. Bitrix's own recommendation is
|
|
// 2 seconds; we only retry once per chunk to avoid queueing storms.
|
|
const rateLimitRetryDelay = 2 * time.Second
|
|
|
|
// Send implements channels.Channel by delivering a goclaw OutboundMessage to
|
|
// the Bitrix24 portal as one or more imbot.message.add calls.
|
|
//
|
|
// Contract:
|
|
// - msg.ChatID is a Bitrix DIALOG_ID ("chatNN" for group, numeric for DM).
|
|
// It's passed through verbatim — upstream code already built it from
|
|
// the inbound event's DialogID.
|
|
// - Content is chunked at TextChunkLimit (default 4000) so long LLM
|
|
// responses don't hit Bitrix's 4096-character hard cap.
|
|
// - QUERY_LIMIT_EXCEEDED triggers one 2s retry per chunk (not per
|
|
// message) — rate limits are usually transient.
|
|
// - Media: Phase 06 handles this. Until then we best-effort-log and
|
|
// continue so Phase 03 doesn't silently drop text when media is
|
|
// attached. Do not treat media failures as a Send error.
|
|
//
|
|
// Returns the first hard (non-rate-limit) error; partial sends surface
|
|
// through slog so an operator sees them even when the err path swallows.
|
|
func (c *Channel) Send(ctx context.Context, msg bus.OutboundMessage) error {
|
|
if !c.IsRunning() {
|
|
return errors.New("bitrix24: channel not running")
|
|
}
|
|
// Liveness-only check — sendChunk re-fetches client/botID under its
|
|
// own lock so we don't hold stale references across the chunk loop.
|
|
if c.Client() == nil || c.BotID() <= 0 {
|
|
return errors.New("bitrix24: channel not initialised")
|
|
}
|
|
if strings.TrimSpace(msg.ChatID) == "" {
|
|
return errors.New("bitrix24: missing chat_id on outbound message")
|
|
}
|
|
|
|
// Upload any media attachments first via imbot.v2.File.upload. The text body
|
|
// is delivered separately below, so a media failure never drops the text and
|
|
// we never double-post. A media-only message (empty Content) returns at the
|
|
// empty-text guard below after the upload completes.
|
|
if len(msg.Media) > 0 {
|
|
if err := c.sendMedia(ctx, msg); err != nil {
|
|
slog.Warn("bitrix24: one or more media uploads failed; continuing with text",
|
|
"chat_id", msg.ChatID, "err", err)
|
|
}
|
|
}
|
|
|
|
text := strings.TrimSpace(msg.Content)
|
|
if text == "" {
|
|
return nil
|
|
}
|
|
|
|
// Convert LLM Markdown output to Bitrix24 BBCode BEFORE chunking. The
|
|
// chunker then operates on the final wire shape — whatever it cuts on
|
|
// is what Bitrix24 renders, and we can't leak half-converted Markdown
|
|
// markers (e.g. a lone `**`) to the client. See format.go for the full
|
|
// mapping (bold/italic/code/links/headers/lists/tables).
|
|
//
|
|
// Caveat: the chunker is tag-agnostic. A BBCode pair straddling the
|
|
// 4000-rune boundary can still be split across chunks — Bitrix renders
|
|
// the unclosed tag literally. LLM replies rarely push the limit in
|
|
// practice; if this becomes visible, teach findChunkBoundary to avoid
|
|
// cutting inside [tag] or [tag=…] … [/tag] spans.
|
|
//
|
|
// Idempotency: applying markdownToBitrixBBCode to an already-BBCode
|
|
// string is a no-op — the conversion regexes key off Markdown markers
|
|
// that don't appear in [b]/[i]/[code]/[url=…] syntax.
|
|
text = markdownToBitrixBBCode(text)
|
|
|
|
// Prepend an @mention BBCode so multi-user group chats know which user
|
|
// the bot is replying to. Consumer (cmd/gateway_consumer_normal.go) sets
|
|
// the address user_id for group inbounds; DM and synthetic-sender flows
|
|
// leave it empty so this is a no-op there. Prepending BEFORE chunkText
|
|
// guarantees the mention only appears on the first chunk regardless of
|
|
// how the body splits.
|
|
if mention := buildAddressMention(msg.Metadata, c.BotID()); mention != "" {
|
|
text = mention + " " + text
|
|
}
|
|
|
|
// Openline: prepend the sender tag captured from the inbound message
|
|
// ("[name] #id:") so the Bitrix Open Channel connector routes this reply
|
|
// back to the right external user. Goes at the very START (before any
|
|
// @mention) because the connector parses the leading tag. Prepended BEFORE
|
|
// chunkText so it only lands on the first chunk. Empty for non-openline
|
|
// replies → no-op.
|
|
if prefix := msg.Metadata[MetaKeySenderPrefix]; prefix != "" {
|
|
text = prefix + " " + text
|
|
}
|
|
|
|
// Resolve outbound routing once for the whole message — same for all
|
|
// chunks. Missing/unknown visibility defaults to public (= legacy v2
|
|
// path), so messages from code paths that don't propagate the key
|
|
// still deliver as before.
|
|
opts := resolveSendOptions(msg.Metadata)
|
|
slog.Debug("bitrix24 send: routing",
|
|
"chat_id", msg.ChatID,
|
|
"visibility", opts.visibility,
|
|
"reply_to_mid", opts.replyToMID,
|
|
)
|
|
|
|
// TextChunkLimit is always populated by applyConfigDefaults (4000) —
|
|
// chunkText also treats limit<=0 as "use default" as a safety net, so we
|
|
// don't duplicate the fallback here.
|
|
chunks := chunkText(text, c.cfg.TextChunkLimit)
|
|
for i, chunk := range chunks {
|
|
if err := ctx.Err(); err != nil {
|
|
return err
|
|
}
|
|
if err := c.sendChunk(ctx, msg.ChatID, chunk, opts); err != nil {
|
|
return fmt.Errorf("bitrix24 send chunk %d/%d: %w", i+1, len(chunks), err)
|
|
}
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// resolveSendOptions pulls routing knobs out of OutboundMessage.Metadata.
|
|
// Unknown / missing values fall back to defaults that preserve the
|
|
// pre-refactor (public v2) behavior so any caller that doesn't populate
|
|
// these keys still works.
|
|
func resolveSendOptions(meta map[string]string) sendOptions {
|
|
out := sendOptions{visibility: VisibilityPublic}
|
|
if v := meta[MetaKeyVisibility]; v == VisibilityWhisper {
|
|
out.visibility = VisibilityWhisper
|
|
}
|
|
// MessageID is the inbound that we're replying to. Parse to int for the
|
|
// v2 fields.replyId param. Non-numeric / zero → skip (no link).
|
|
if s := meta[MetaKeyMessageID]; s != "" {
|
|
if n, err := strconv.Atoi(s); err == nil && n > 0 {
|
|
out.replyToMID = n
|
|
}
|
|
}
|
|
return out
|
|
}
|
|
|
|
// sendChunk dispatches a single chunk to the right outbound API based on
|
|
// the resolved visibility. Whisper → v1 imbot.message.add with
|
|
// SKIP_CONNECTOR=Y (in send_v1.go); public → v2 imbot.v2.Chat.Message.send
|
|
// with optional fields.replyId (in send_v2.go). The split keeps each
|
|
// concrete method's params + quirks in a focused file.
|
|
func (c *Channel) sendChunk(ctx context.Context, chatID, chunk string, opts sendOptions) error {
|
|
if opts.visibility == VisibilityWhisper {
|
|
return c.sendChunkV1Whisper(ctx, chatID, chunk)
|
|
}
|
|
return c.sendChunkV2Public(ctx, chatID, chunk, opts.replyToMID)
|
|
}
|
|
|
|
// callWithRateLimitRetry executes a single client.Call and retries ONCE
|
|
// after rateLimitRetryDelay on QUERY_LIMIT_EXCEEDED / OPERATION_TIME_LIMIT.
|
|
// Non-rate-limit errors bubble unchanged. Used by both v1 and v2 send
|
|
// paths to keep retry semantics identical regardless of which API was
|
|
// chosen.
|
|
func (c *Channel) callWithRateLimitRetry(
|
|
ctx context.Context,
|
|
method string,
|
|
params map[string]any,
|
|
chatID string,
|
|
botID int,
|
|
) error {
|
|
client := c.Client()
|
|
if client == nil || botID <= 0 {
|
|
// Channel was shut down between Send's liveness check and here.
|
|
// Report as a transport error so the caller can retry if desired.
|
|
return errors.New("bitrix24: channel lost during send")
|
|
}
|
|
|
|
_, err := client.Call(ctx, method, params)
|
|
if err == nil {
|
|
return nil
|
|
}
|
|
if !isRateLimitErr(err) {
|
|
slog.Warn("bitrix24: send failed",
|
|
"method", method, "chat_id", chatID, "bot_id", botID, "err", err)
|
|
return err
|
|
}
|
|
|
|
// One retry after a short backoff. Use a context-aware sleep so shutdown
|
|
// doesn't hang for 2 seconds.
|
|
slog.Warn("bitrix24: rate limit hit — retrying once",
|
|
"method", method, "chat_id", chatID, "bot_id", botID)
|
|
select {
|
|
case <-time.After(rateLimitRetryDelay):
|
|
case <-ctx.Done():
|
|
return ctx.Err()
|
|
}
|
|
_, err = client.Call(ctx, method, params)
|
|
return err
|
|
}
|
|
|
|
// buildAddressMention returns the Bitrix24 BBCode @mention prefix for the
|
|
// addressee of an outbound message, or "" when no addressee is set or the
|
|
// addressee is the bot itself (self-mention guard).
|
|
//
|
|
// Format is `[USER=<id>][/USER]` — empty inner content. Bitrix renders the
|
|
// user's current display name from the id at delivery time, sidestepping
|
|
// any escaping concerns with names that contain BBCode metacharacters or
|
|
// were renamed since the inbound event was captured.
|
|
//
|
|
// The metadata key is set by cmd/gateway_consumer_normal.go for group-chat
|
|
// outbounds. DM, synthetic-sender, and non-Bitrix channels leave it empty.
|
|
func buildAddressMention(meta map[string]string, botID int) string {
|
|
userID := strings.TrimSpace(meta["bitrix_address_user_id"])
|
|
if userID == "" {
|
|
return ""
|
|
}
|
|
// [USER=<id>] BBCode is only valid for a numeric Bitrix user id. Synthetic
|
|
// scope ids — notably the openline per-participant id
|
|
// "openlines:{instance}:{chat}:{uid}" set by handle.go — are not real Bitrix
|
|
// users; emitting them would render as literal garbage in the chat. The
|
|
// external customer behind a connector relay has no Bitrix user id to mention
|
|
// anyway (routing is driven by the leading "#msgId" echo), so skip the
|
|
// mention for any non-numeric addressee.
|
|
if !isNumericID(userID) {
|
|
return ""
|
|
}
|
|
// Self-mention guard: bot replying to its own synthetic relay, or a
|
|
// future code path injecting the bot's id by mistake. Don't @mention
|
|
// the bot to itself — Bitrix would render "@Bot Synity" in the bot's
|
|
// own message which is confusing.
|
|
if botID > 0 && userID == strconv.Itoa(botID) {
|
|
return ""
|
|
}
|
|
return "[USER=" + userID + "][/USER]"
|
|
}
|
|
|
|
// isNumericID reports whether s is a non-empty run of ASCII digits — the shape
|
|
// of a real Bitrix user id. Used to gate [USER=<id>] BBCode emission.
|
|
func isNumericID(s string) bool {
|
|
if s == "" {
|
|
return false
|
|
}
|
|
for _, r := range s {
|
|
if r < '0' || r > '9' {
|
|
return false
|
|
}
|
|
}
|
|
return true
|
|
}
|
|
|
|
// isRateLimitErr detects Bitrix24's rate-limit response. The canonical code
|
|
// is QUERY_LIMIT_EXCEEDED on the RawResult envelope; net timeouts aren't
|
|
// classified here — caller treats them as transport errors.
|
|
func isRateLimitErr(err error) bool {
|
|
if err == nil {
|
|
return false
|
|
}
|
|
var apiErr *APIError
|
|
if errors.As(err, &apiErr) {
|
|
return apiErr.Code == "QUERY_LIMIT_EXCEEDED" || apiErr.Code == "OPERATION_TIME_LIMIT"
|
|
}
|
|
return false
|
|
}
|
|
|
|
// chunkText splits s into pieces no larger than limit *runes* (not bytes).
|
|
// Prefers to break on newline, then whitespace, then hard rune boundary.
|
|
// Each returned chunk is a valid UTF-8 string; no trailing whitespace.
|
|
//
|
|
// The function is intentionally simple — Bitrix24 renders BBCode and
|
|
// doesn't need LLM-style sentence-aware splitting. Phase 05 (streaming)
|
|
// can layer smarter boundaries on top if prefix flicker becomes a problem.
|
|
func chunkText(s string, limit int) []string {
|
|
s = strings.TrimSpace(s)
|
|
if s == "" {
|
|
return nil
|
|
}
|
|
if limit <= 0 {
|
|
limit = 4000
|
|
}
|
|
// Count by runes so we don't cut a multi-byte UTF-8 codepoint.
|
|
if utf8.RuneCountInString(s) <= limit {
|
|
return []string{s}
|
|
}
|
|
|
|
var out []string
|
|
remaining := s
|
|
for utf8.RuneCountInString(remaining) > limit {
|
|
cut := findChunkBoundary(remaining, limit)
|
|
chunk := strings.TrimRight(remaining[:cut], " \t")
|
|
if chunk == "" {
|
|
// Hard-break fallback: emit the first `limit` runes.
|
|
chunk, remaining = sliceRunes(remaining, limit)
|
|
out = append(out, chunk)
|
|
remaining = strings.TrimLeft(remaining, " \t\r\n")
|
|
continue
|
|
}
|
|
out = append(out, chunk)
|
|
remaining = strings.TrimLeft(remaining[cut:], " \t\r\n")
|
|
}
|
|
if remaining != "" {
|
|
out = append(out, remaining)
|
|
}
|
|
return out
|
|
}
|
|
|
|
// findChunkBoundary returns the byte index in s where we'll cut. Preference
|
|
// order: last newline within the first `limit` runes → last whitespace →
|
|
// rune boundary at exactly `limit` runes.
|
|
func findChunkBoundary(s string, limit int) int {
|
|
// Walk runes until we've counted `limit` of them, tracking last newline
|
|
// and last whitespace offsets as byte indices.
|
|
lastNL := -1
|
|
lastWS := -1
|
|
runes := 0
|
|
for i, r := range s {
|
|
if runes >= limit {
|
|
break
|
|
}
|
|
if r == '\n' {
|
|
lastNL = i
|
|
} else if r == ' ' || r == '\t' {
|
|
lastWS = i
|
|
}
|
|
runes++
|
|
}
|
|
|
|
// `>= 0` not `> 0`: a newline / whitespace at byte 0 IS a valid cut point.
|
|
// In practice the outer chunkText TrimSpaces the input and TrimLeft's the
|
|
// remainder every iteration, so byte-0 whitespace "shouldn't" happen — but
|
|
// the `> 0` form silently falls through to the hard-break path when it
|
|
// does, which is the wrong answer. Accept offset 0 so the invariant is
|
|
// expressed here, not only in the caller.
|
|
if lastNL >= 0 {
|
|
return lastNL + 1 // cut AFTER the newline so \n goes in the prior chunk
|
|
}
|
|
if lastWS >= 0 {
|
|
return lastWS + 1
|
|
}
|
|
|
|
// Hard break: find the byte offset for rune #limit.
|
|
runes = 0
|
|
for i := range s {
|
|
if runes == limit {
|
|
return i
|
|
}
|
|
runes++
|
|
}
|
|
return len(s)
|
|
}
|
|
|
|
// sliceRunes returns (head, tail) split at exactly `n` runes. head contains
|
|
// the first n runes; tail contains the rest. Used as the hard-break fallback
|
|
// inside chunkText.
|
|
func sliceRunes(s string, n int) (string, string) {
|
|
count := 0
|
|
for i := range s {
|
|
if count == n {
|
|
return s[:i], s[i:]
|
|
}
|
|
count++
|
|
}
|
|
return s, ""
|
|
}
|