Commit Graph
221 Commits
Author SHA1 Message Date
Kai (Tam Nhu) Tran 1ee7cac555 fix: reject case-variant symlinked file paths (#1629)
* fix: reject case-variant symlinked file paths

* fix: validate requested case-variant symlink paths
2026-07-01 01:26:48 -04:00
Kai (Tam Nhu) Tran 343899f6c1 fix: prevent default profile credential collision (#1628)
* fix: prevent default profile credential collision

* fix: isolate default profile credential fallback
2026-07-01 01:15:45 -04:00
Kai (Tam Nhu) Tran 0f9a87619c fix: cap native quota profile refresh fan-out (#1627)
* fix: cap native quota profile refresh fan-out

* fix: preserve native quota live cache state
2026-07-01 01:09:01 -04:00
Kai (Tam Nhu) Tran 0527e276b1 fix: skip paused codex accounts in bar refresh (#1620) 2026-06-30 12:59:54 -04:00
Kai (Tam Nhu) Tran 3f1dce30bc fix: close bar launch case bypass (#1613) 2026-06-30 12:33:46 -04:00
Tam Nhu Tran b514986ddd fix(bar): short-TTL parked rows + keep valid codex subs active
Addresses two review focus areas:

- Stale Parked Rows: profiles with no on-disk credentials cached their parked
  row for the full quota TTL, so a fresh login stayed dimmed for up to 10 min.
  Parked rows (quotaStatus 'unsupported') now use a 30s TTL so a new login is
  picked up within seconds.
- Codex Fallback: a named codex profile whose token authenticated but whose
  response lacked core windows was downgraded to a parked/needsAuth row, hiding
  a real subscription. It now emits an active (quota-less) row; only the bare
  default still falls back to global local session data.

Also fixes a latent coalescing bug the short TTL exposed: a synchronous return
inside the pending IIFE cleared state.pending during its own assignment, leaving
a stale resolved promise that the next call reused. The IIFE now yields once so
the assignment lands before the finally clears it.
2026-06-24 00:52:55 -04:00
Tam Nhu Tran 7b610f0e82 fix(bar): keep is_default on cache-fallback rows
The collector cached each row before the default profile was resolved, so the
cache-fallback path (getCachedNativeAccountRows) served the default account with
is_default:false -- the UI then lost default ordering/tagging when /summary
served from cache. Write the resolved default flag back onto the cached copy so
the fallback stays consistent with a fresh collection.
2026-06-24 00:03:20 -04:00
Tam Nhu Tran a0a2dd00fa fix(bar): cache expired profiles and gate codex local fallback to the default
Addresses two review focus areas:

- Reauth polling: a 401/expired profile now caches its dimmed reauth row and
  opens a cooldown, so it is shown parked and re-checked at most every 10 min
  instead of being re-polled (and re-401'd) on every /summary refresh.
- Wrong fallback: the global ~/.codex session-log fallback now applies ONLY to
  the bare default account. A named codex profile with no on-disk auth parks
  instead of borrowing the default's local usage (no misattribution).
2026-06-23 23:47:06 -04:00
Tam Nhu Tran ed86a089ba feat(bar): enumerate ccs/ccsx subscription profiles with per-profile quota
Replace single-account native quota collection with per-profile enumeration:
read ccs auth (Claude) and ccsx auth (Codex) profile registries plus the bare
~/.codex login, fetch each profile's quota under the existing TTL cache,
per-profile circuit breaker and 2.5s summary deadline. Emit surface, profile
and is_subscription wire fields; account_id becomes "<surface>:<profile>".

Active profiles (valid token) are live-polled and shown undimmed regardless of
default status; profiles without resolvable on-disk credentials are parked
(cache-only, dimmed). Claude per-profile credentials are read from disk only --
no macOS Keychain access -- so a profile without a credentials file renders as
needs-reauth instead of triggering a keychain prompt.
2026-06-23 22:56:38 -04:00
Kai (Tam Nhu) Tran 05c203aff2 Merge pull request #1575 from walker1211/codex/fix-cliproxy-provider-routes
Fix CLIProxy provider routes for original backend
2026-06-22 16:11:28 -04:00
Tam Nhu Tran 6ed5b2d62b feat(bar): live Codex usage sync with force refresh and spend-chart periods
Codex quota in the menu bar came only from frozen local session logs, so it
showed stale data ("older session") that no refresh could update. Fetch it live
from the same source the dashboard uses, under the existing Claude-style safety
controls (10-min TTL, in-flight coalescing, 429 backoff, circuit breaker,
serve-stale), falling back to local logs when offline or rate-limited. A success
with no usable 5h/weekly window keeps the local reading rather than caching a
contentless row. The footer refresh and a new inline button on the Codex card
force a live pull past the open debounce, and a forced /summary re-pulls native
rows while serving the last-known cached rows if the live pull overruns its
budget, so the Claude/Codex cards never blank mid-refresh.

The spend strip gains a Today / 7d / 30d selector (default 7d), a taller chart,
and bottom time-axis labels (local hours for today, weekday for 7d, dates for
30d). The analytics endpoint now exposes a 24-bucket hourly series for today,
converted from the pipeline's UTC hour keys to the user's local clock so the
intra-day chart matches the dashboard.
2026-06-20 18:37:18 -04:00
Kai (Tam Nhu) Tran e37a87c3a2 fix: ignore malformed bar analytics date keys (#1556)
* fix: ignore malformed bar analytics date keys

* style: apply prettier formatting to dynamic imports
2026-06-20 16:23:22 -04:00
walker1211 99ed8090b1 fix(cliproxy): 按 backend 生成 provider 路由 2026-06-20 13:40:23 +08:00
Kai (Tam Nhu) Tran b6ef4e5782 fix(cliproxy): guard unsupported Qwen account auth 2026-06-18 21:34:27 -04:00
Tam Nhu Tran 1462823be8 fix(logging): harden structured trace redaction
Redact StageOptions error payloads and summarize debug launch args.

Propagate request IDs through Cursor daemon and dashboard completion logs.

Mark remaining P2/P3 maintainability targets as partial instead of overclaiming.
2026-06-18 18:48:13 -04:00
Tam Nhu Tran 5e1b8640ab feat(logging): P2 traceability foundation - requestId wrap, daemon forwarding (#NNN)
Epic P2. Closes the three real traceability gaps so every diagnostic log can
carry a requestId from origin (ccs.ts main) through HTTP edges and spawned
daemons.

- log-context: add REQUEST_ID_HEADER/ENV/PATTERN, resolveRequestIdFromEnv,
  forwardRequestIdEnv. runWithRequestId now reuses a forwarded CCS_REQUEST_ID
  when well-formed (child re-anchor), else mints fresh.
- request-logging-middleware: wrap the Express dashboard handler chain in
  withRequestContext so downstream route-handler logs carry requestId (mirrors
  src/proxy/server/proxy-server.ts, which is untouched prior art).
- forward CCS_REQUEST_ID at the 4 child-daemon spawn sites: delegation
  headless-executor, cursor-daemon, cursor-profile-executor, copilot-executor.
- cursor-daemon-entry: re-anchor via runWithRequestId so daemon startup logs
  correlate with the spawning CLI invocation (ALS does not cross spawn).
- logger adoption toe-hold: delegation/session-manager (load/save failures) and
  docker/supervisord-lifecycle (restart failure) now use createLogger.

api/channels/shared have no touchable diagnostic console.error (CLI-UX only or
pure data); dispatcher's only diagnostic is in pre-dispatch.ts, owned by plan
#1165. Those defer to P3's full per-site sweep.

Tests: request-context-middleware (handler log requestId === header),
request-id-forwarding (env resolve/reject, re-anchor, forwardRequestIdEnv).
validate + validate:ci-parity green.
2026-06-18 18:48:12 -04:00
Kai (Tam Nhu) Tran 06e83091be fix: bound Codex rollout tail reads (#1547)
Replaces unbounded rollout-file reads with a bounded backward tail (1 MiB cap), preserving last-N-lines semantics.
2026-06-16 08:45:30 -04:00
Kai (Tam Nhu) Tran b85a3de26e fix(cursor): redact daemon token from dashboard start (#1540)
Redacts the Cursor daemon token from dashboard start output.
2026-06-15 23:24:37 -04:00
Kai (Tam Nhu) Tran 10aff10a67 fix: harden macOS bar launch descriptor (#1533)
Hardens the macOS bar launch.json descriptor against untrusted/foreign-owned files and constrains the decoded descriptor; blocks dashboard file writes to the launch descriptor.
2026-06-15 23:24:13 -04:00
Tam Nhu Tran 7d3a11a452 fix(bar): resolve pre-dev review findings (security gate, honesty, correctness)
Gate /api/bar/* behind the localhost-when-auth-disabled guard (single DRY
choke point) so native quota/tier/cost can't leak on a non-loopback bind with
auth disabled; add a guard test. Delete the dishonest maxRedirections test that
asserted the opposite of the production redirect hardening. Key per-account
today-cost on the local day (matching analytics) instead of UTC. Stop the
inner 429 retry in the Claude usage fetch so the outer cache + circuit breaker
honor Retry-After. Narrow the usage-transformer map type and fix stale
doc-comments; clarify the one-alert-per-reset-window quota rule; gitignore the
local demo scaffolding.
2026-06-09 18:04:31 -04:00
Tam Nhu Tran e96967c224 feat(bar): per-window subscription quota detail + codex multi-session scan
Expose per-window detail (5h / weekly / Opus / Sonnet) on native subscription
rows instead of collapsing to a single percentage, so the bar can show the
binding window, resets, and a burn-rate pace line. Fix the Codex collector to
scan recent session rollouts newest-first for the latest non-null rate_limits
(today's exec-mode session is null) and mark the result stale with its source
time, so Codex quota appears instead of silently vanishing.
2026-06-09 14:39:41 -04:00
Tam Nhu Tran dbeb0c543a feat(bar): native Claude Code + Codex subscription quota (safe, server-side)
Surface the logged-in Claude Code and Codex subscription quota as first-class
summary rows so the existing gauge and alert engine render them with no new UI.

Claude Code: read the native token (~/.claude/.credentials.json, macOS Keychain
fallback) and reuse the existing Anthropic usage fetch+normalize via a new
token-fed entry point. The /oauth/usage endpoint is hostile to polling, so the
fetch is server-side only behind a 10-minute on-demand cache, in-flight
coalescing, Retry-After + exponential backoff with jitter, a 3-strike circuit
breaker with a 15-minute cooldown, and serve-stale-on-failure; logged-out or
unsupported subscriptions never spend a token call. Codex: zero-network read of
the latest rate_limits from local session rollouts, omitted when absent.
Native rows side-load bounded so a slow or failed fetch degrades to CLIProxy
rows, never an error.
2026-06-09 13:37:38 -04:00
Tam Nhu Tran 68f0231f48 feat(bar): add calendar month-to-date spend to analytics
monthToDate (calendar 1st-of-month to now, local) on BarAnalytics in both
compute paths, kept distinct from the rolling last30d so a fresh month resets
toward zero. Feeds the monthly-spend alert and the month-spend glance without
a rolling-window false breach.
2026-06-09 13:03:25 -04:00
Tam Nhu Tran 5f850c4899 feat(bar): honest quota state and merged multi-source analytics
Derive a tri-state quotaStatus (ok|unsupported|error) per account so a
provider with no quota API renders as 'no quota' with a healthy dot instead
of an alarming bare dash, and treat unsupported as healthy in deriveHealth.

Switch the analytics endpoint off the CLIProxy snapshot, which freezes
whenever the proxy restarts (usage is in-memory only), and onto the merged
daily/hourly usage the dashboard uses. Recent activity from Claude Code,
Codex, and Droid now shows, and a per-surface breakdown answers where usage
goes. Add lastActivityAt, daysSinceLastActivity, hasRecentData and a 30-day
series; per-account today_cost reads null (unknown) rather than a misleading 0.
2026-06-09 11:49:36 -04:00
Tam Nhu Tran 78f9fc7c0b feat(bar): harden summary against provider hangs and add analytics endpoint
Summary aggregator could block indefinitely: it ran the full system health
audit (a synchronous execSync) on every request and had no per-account or
request-level timeout. Now:
- per-account fetch is bounded; whole response is raced against a deadline
- health is derived per-account from each quota result (no blocking audit)
- stale-while-revalidate keeps the last value when a refresh is slow/fails

Adds GET /api/bar/analytics plus a pure, tested aggregator rolling up
today/7d/30d/all-time spend, a 7-day sparkline, and top models.
2026-06-08 09:31:18 -04:00
Tam Nhu Tran b9a1084bd4 fix(quota): reject tier-lock for non-managed providers
Only managed-quota providers (agy/claude/codex/gemini/ghcp) enforce tier_lock;
validate the provider against that set so locking a non-managed provider returns
400 instead of persisting a silently-unenforced config entry.
2026-06-07 16:38:18 -04:00
Tam Nhu Tran cc7ac553e3 fix(usage): correct per-account cost attribution
Drop the detail.source fallback and dead numeric-key lookup in the usage
transformer so unmapped auth_index rows go to the 'unknown' bucket instead of
mis-keying cost; null out today_cost when an email cost-key is shared by more
than one account (duplicate-email providers) instead of double-displaying the
combined spend.
2026-06-07 16:37:59 -04:00
Tam Nhu Tran 40f32ebbf0 feat(quota): add per-provider tier-lock account selection
Make tier_lock a per-provider map and honor it in findHealthyAccount and
preflightCheck for the selected provider only, so locking one provider never
disables failover for others. Add POST /api/accounts/tier-lock with tier
validation against known tiers, and serialize quota_management on config write
so the lock persists.
2026-06-07 15:32:40 -04:00
Tam Nhu Tran 6d3fde9ed3 feat(web-server): add /api/bar/summary aggregator with force-fresh
Single endpoint merging per-account quota, tier, paused, health and today cost
for the menu bar. Cached by default; ?refresh=true invalidates the quota cache
and pulls live server-side, debounced ~15s. Per-account errors degrade one row
without failing the payload; force-fresh skips paused accounts and caps fetch
concurrency.
2026-06-07 15:32:29 -04:00
Tam Nhu Tran 1867116472 feat(usage): attribute CLIProxy usage to accounts for per-account cost
Carry the CLIProxy auth_index through the usage transformer and aggregator,
build an auth_index->account map from the auth files, and wire it into the
usage syncer so persisted snapshots stamp accountId. Adds getTodayCostByAccount
and a snapshot detail reader. Backward-compatible: accountId is optional and
profile-based aggregation is unchanged.
2026-06-07 15:32:19 -04:00
Tam Nhu Tran ced9317565 Merge remote-tracking branch 'origin/dev' into codex/fix-cliproxy-v3-snapshot-migration-issue
# Conflicts:
#	src/web-server/usage/cliproxy-usage-transformer.ts
#	tests/unit/web-server/cliproxy-usage-transformer.test.ts
2026-05-30 16:13:49 -04:00
Kai (Tam Nhu) Tran e7db1d65f5 Merge pull request #1452 from kaitranntt/codex/propose-fix-for-codex-target-rejection
Mark Codex as a persisted target and align UI/validation
2026-05-30 16:12:03 -04:00
Kai (Tam Nhu) Tran d028329d2c Merge pull request #1426 from kaitranntt/codex/fix-cliproxy-usage-cache-vulnerability
fix(cliproxy): avoid persisting account identifiers and harden usage cache permissions
2026-05-30 16:08:26 -04:00
Kai (Tam Nhu) Tran ee50c0c59a Merge pull request #1422 from kaitranntt/codex/fix-codex-usage-cache-permissions
fix: restrict Codex usage cache permissions
2026-05-30 16:01:00 -04:00
Kai (Tam Nhu) Tran 484f0a0427 Merge pull request #1427 from kaitranntt/codex/propose-fix-for-local-runtime-probe-vulnerability
fix: restrict local runtime readiness probes
2026-05-30 15:51:43 -04:00
Kai (Tam Nhu) Tran 5151d6d24e Merge pull request #1433 from kaitranntt/codex/fix-issue-with-profile-query-handling
fix: validate usage profile query type
2026-05-30 15:46:47 -04:00
Kai (Tam Nhu) Tran f815db391d Merge pull request #1308 from simonsmh/feat/add-qoder-provider
feat(cliproxy): Qoder provider
2026-05-30 15:35:55 -04:00
Kai (Tam Nhu) Tran 901bad2ec7 fix: validate usage profile query type 2026-05-30 15:20:15 -04:00
Kai (Tam Nhu) Tran 9a7b26eab7 fix: restrict local runtime readiness probes 2026-05-30 15:19:38 -04:00
Kai (Tam Nhu) Tran 6bba193cdd fix: harden cliproxy usage cache 2026-05-30 15:18:11 -04:00
Kai (Tam Nhu) Tran c630ce878e fix: restrict Codex usage cache permissions 2026-05-30 15:17:13 -04:00
Kai (Tam Nhu) Tran 04dc97aaa4 fix: persist codex target selections 2026-05-30 14:57:07 -04:00
Kai (Tam Nhu) Tran 65adab5bec fix: normalize cliproxy v3 usage snapshots 2026-05-30 14:56:18 -04:00
Kai (Tam Nhu) Tran 5f1976f69c fix: add CLIProxy account reauthentication 2026-05-27 10:13:03 -04:00
Kai (Tam Nhu) Tran b35a23a6e4 fix: reject unsupported image analysis backends (#1387)
* fix: reject unsupported image analysis backends

* style: apply prettier formatting
2026-05-23 22:37:44 -04:00
Kai (Tam Nhu) Tran 0db9705d75 fix(claude-extension): enforce private permissions for settings writes (#1378) 2026-05-23 21:45:07 -04:00
Kai (Tam Nhu) Tran e6f764c79b fix(cursor): block cross-origin runtime probe requests (#1371) 2026-05-23 21:44:50 -04:00
Kai (Tam Nhu) Tran 9a420988bc fix(analytics): support sqlite3 path resolution on Windows and NixOS (#1354)
- Add CCS_SQLITE_BIN env-var override; validated with fs.realpathSync so
  symlinks are fully resolved before prefix check
- Reject any override whose realpath does not start under a trusted system
  prefix (prevents PATH-hijack reintroduction from #1347)
- Add TRUSTED_PREFIX_UNIX covering /nix/store/, /opt/local/ (MacPorts),
  /snap/, /run/current-system/ in addition to existing /usr/* and
  /opt/homebrew/ entries
- Add TRUSTED_PREFIX_WINDOWS covering Program Files, System32, and the
  Chocolatey managed bin dir (no canonical winget/Scoop path exists)
- Keep TRUSTED_SQLITE_PATHS_WINDOWS empty — Windows users set CCS_SQLITE_BIN
- Pass env as optional third param to querySqliteJson (backward compatible)
- Add 16-test suite covering env-var acceptance, /tmp rejection, symlink
  traversal, NixOS paths, MacPorts, Windows fallback, and prefix safety
2026-05-23 17:29:52 -04:00
Tam Nhu Tran fc5851e3a2 fix: ensure dashboard cliproxy restart waits for recovery 2026-05-22 13:37:21 -04:00
Kai (Tam Nhu) Tran fa17ad5af1 Merge pull request #1318 from kaitranntt/kai/feat/1255-analytics-profile-filter
feat: filter analytics dashboard by profile
2026-05-22 12:38:50 -04:00