Commit Graph
4378 Commits
Author SHA1 Message Date
Tam Nhu Tran fdb043083f feat(cliproxy): pool routing defaults and safety rails
- pool opt-in writes disable-cooling: false, routing.strategy fill-first,
  session-affinity on (1h TTL), max-retry-credentials 3; all emissions
  pool-gated so non-pool generated config stays content-identical
- cooling re-enable is safe on current CLIProxy binaries: the v5
  disable-cooling workaround targeted upstream cooldown bugs fixed by
  Apr 2026 (see plan archaeology report)
- informed-consent prompt at the 1->2 account-add transition enumerates
  every provider with multiple accounts (instance-global effect) and is
  gated per provider on spike-verified limit signals
- disablePoolRouting restores the non-pool config including
  disable-cooling: true and prints single-account rollback guidance
- cross-lane guard warns when a pool account email is also active in a
  native Claude profile (concurrency is the documented ban vector)
- routing strategy and affinity subcommands warn when pool routing
  manages those keys

Part of #1464 account pools (phase 3).
2026-06-11 00:12:14 -04:00
Tam Nhu Tran a257016ebb feat(cliproxy): claude pool gap closure - model-neutral launch, shadow warning, provider ban copy
- claude provider launch env no longer pins ANTHROPIC_MODEL/tier defaults;
  one-shot migration strips CCS-written stale pins across all historically
  shipped default generations while preserving explicit user pins
- TTY-gated once-per-install warning when a user profile named claude or
  anthropic is shadowed by the built-in provider, with rename guidance
- account-safety ban messaging parameterized by provider; Anthropic
  patterns gated to claude accounts only
- first-run notice that ccs claude routes through the local CLIProxy
  instance

Part of #1464 account pools (phase 2).
2026-06-10 22:57:24 -04:00
github-actions[bot] 17849c4a32 chore(release): 8.2.0-dev.7 2026-06-10 19:50:44 +00:00
Kai (Tam Nhu) TranandGitHub 27580bc159 Merge pull request #1508 from kaitranntt/kai/feat/bar-header-version
feat(bar): show app version in the panel header
2026-06-10 15:42:54 -04:00
Tam Nhu Tran a5c41864b3 fix(bar): keep header version label rightmost during refresh
The refresh spinner rendered after the version label, pushing the
version away from the header edge while a refresh was in progress. The
spinner now sits between the Spacer and the version label.
2026-06-10 15:33:06 -04:00
Tam Nhu Tran 3aab14ca85 fix(bar): correct the already-running reinstall hint
'open -a' only activates a running app, so suggesting 'ccs bar' as an
alternative to quitting could not load the new binary. The hint now
says to quit from the menu bar first, then run 'ccs bar' to relaunch
the updated app.
2026-06-10 15:25:55 -04:00
Tam Nhu Tran 3438c3940e feat(bar): show running app version in the panel header
A right-aligned v{CFBundleShortVersionString} label fills the unused
header space next to the CCS name, styled like the subtitle and hidden
when no bundle version is available (e.g. swift run). The display
logic lives in CCSBarCore as a pure helper with ccs-bar-check
coverage, making the on-screen build identifiable after reinstalls.
2026-06-10 15:25:45 -04:00
github-actions[bot] 39ede638d6 chore(release): 8.2.0-dev.6 2026-06-10 19:02:13 +00:00
Kai (Tam Nhu) TranandGitHub 1892503555 Merge pull request #1506 from kaitranntt/kai/feat/1504-bar-install-ux
feat(bar): one-flow install with quarantine automation and launch handoff
2026-06-10 14:58:28 -04:00
Kai (Tam Nhu) TranandGitHub 209f4a023b Merge pull request #1505 from kaitranntt/kai/fix/1502-1503-bar-multiscreen
fix(bar): keep the menu bar panel on the clicked screen in multi-display setups
2026-06-10 14:58:17 -04:00
Tam Nhu Tran cf3bd8a5ef fix(bar): stage downloads and swap so reinstall never strands the user
The reinstall guard deleted the existing bundle before download, so a
transient download or extraction failure left no app on disk. The
archive now extracts into a hidden staging directory inside the
Applications folder; the old bundle is removed only after the new one
is verified in staging, then renamed into place. Every failure before
the swap leaves the previous install untouched, and staging is cleaned
up on all paths.
2026-06-10 14:09:28 -04:00
Tam Nhu Tran f68c08ede3 fix(bar): verify server compat before Gatekeeper steps and harden reinstall
Three review/CI corrections to the install flow:

The compat handshake now runs before the quarantine-clear and launch
block. It is a server-side check unrelated to Gatekeeper, and the
previous ordering let a failed quarantine clear (always the case where
xattr is absent, e.g. Linux CI) skip the handshake entirely.

Reinstalls remove the existing bundle before extraction so the
post-extraction existence check actually proves the fresh bundle
landed; an unremovable bundle aborts install instead of extracting
over it.

Declining the launch prompt now prints the same run-ccs-bar hint as
the non-TTY path instead of ending silently. Install tests inject the
newer deps (clearQuarantine, isBarRunning, promptLaunch) everywhere
the defaults could touch host binaries, keeping results identical on
macOS and Linux runners.
2026-06-10 13:59:08 -04:00
Tam Nhu Tran 015cc4dd32 fix(bar): stop install at the manual step when quarantine clearing fails
A failed quarantine clear previously fell through to the launch
handoff, so a default-yes prompt (or --launch) opened the still
quarantined app straight into the Gatekeeper block. Install now ends
after printing the manual xattr guidance, with a hint to run 'ccs bar'
once quarantine is cleared; --launch does not override a failed clear.
2026-06-10 13:42:52 -04:00
Tam Nhu Tran dfc8b7d1dc fix(bar): harden install handoff per review
Pin xattr and pgrep to absolute /usr/bin paths so quarantine clearing
and process detection cannot be hijacked through a caller-controlled
PATH. Gate the launch prompt on stdin being a TTY instead of stdout, so
piping install output through tee no longer silently skips the
handoff. Detect an already-running CCS Bar via pgrep before prompting:
a running instance gets a quit-and-reopen hint instead of a redundant
launch prompt, while --launch still proceeds explicitly.
2026-06-10 13:36:35 -04:00
Tam Nhu Tran 54a670c943 fix(bar): capture click location synchronously before async panel anchoring
NSEvent.mouseLocation was sampled inside the DispatchQueue.main.async
block that anchors the panel, so a cursor move between the click and
the block run could anchor to the wrong display. The location is now
captured in makeNSView at click time and threaded through apply() into
anchorToClickedScreen, making the chosen screen deterministic.
2026-06-10 13:28:34 -04:00
Tam Nhu Tran 4eef3f77a4 feat(bar): one-flow install with quarantine automation and launch handoff
'ccs bar install' previously ended with two manual steps: clearing the
Gatekeeper quarantine by hand and running 'ccs bar' separately.

Install now detects an existing installation and says so before
reinstalling, clears the quarantine attribute itself via execFile with
a graceful fallback to the printed hint when xattr fails, and ends with
a TTY-aware 'Launch CCS Bar now?' prompt (default yes) that hands off
to the existing launch flow. --launch forces the handoff and
--no-launch suppresses it for scripted installs; non-TTY runs skip the
prompt and print the manual command instead.

Closes #1504
2026-06-10 13:25:07 -04:00
Tam Nhu Tran 70dc53d947 fix(bar): keep menu bar panel on the clicked screen in multi-display setups
The MenuBarExtra panel's default collectionBehavior included
canJoinAllSpaces, so the bar could be visible on every Space and
display at once. The WindowAppearanceForcer bridge now strips
canJoinAllSpaces and applies moveToActiveSpace.

Panel and Settings window placement also keyed off the key-window
screen (NSScreen.main / window.center()) rather than the display where
the status item was clicked. Both now anchor to the screen under the
cursor at click time via the pure BarScreenPicker helper, covered by
new ccs-bar-check geometry assertions.

Closes #1502
Closes #1503
2026-06-10 13:23:47 -04:00
github-actions[bot] dd82f99046 chore(release): 8.2.0-dev.5 2026-06-10 17:21:08 +00:00
Kai (Tam Nhu) TranandGitHub f743677d5d Merge pull request #1501 from kaitranntt/kai/fix/1500-bar-launch-reuse
fix(bar): reuse a running CCS web-server instead of failing to bind
2026-06-10 13:17:18 -04:00
github-actions[bot] 16e8531568 chore(release): 8.2.0-dev.4 2026-06-10 17:07:50 +00:00
SergeyandGitHub 298c89f2c3 feat(catalog): add Claude Fable 5 to Anthropic model registry 2026-06-10 13:03:38 -04:00
walker1211andGitHub cf90f48240 fix(mcp): retry Claude user config locks 2026-06-10 13:03:25 -04:00
kastrupproandGitHub f59536a81f fix(cliproxy): guard upstream response timeout cleanup against detached socket 2026-06-10 13:03:17 -04:00
Tam Nhu Tran 2fd90fff9b perf(bar): probe reuse candidates concurrently to avoid launch stalls
Sequential probing of up to 10 loopback targets at 1.5s timeout each
could stall 'ccs bar' for ~15s when a non-CCS service occupied a
candidate port without answering. All probes now run concurrently and
the first success in priority order (bar.json port first, IPv4 before
IPv6 per port) is selected, bounding detection at roughly one probe
timeout.
2026-06-10 12:57:39 -04:00
Tam Nhu Tran 3569297b6d fix(bar): probe IPv6 loopback when detecting a running CCS server
'ccs config' starts the web-server on host 'localhost', which macOS
resolves to ::1, so a reuse probe limited to 127.0.0.1 missed the most
common already-running server and launch started a redundant second
instance. Each candidate port is now probed on 127.0.0.1 first and then
[::1]; an IPv6 hit writes the bracketed-literal baseUrl into bar.json,
which URLSession in the Swift app resolves correctly.
2026-06-10 12:04:10 -04:00
Tam Nhu Tran db1d125f83 docs(bar): troubleshooting reflects reuse-first launch behavior 2026-06-10 11:09:51 -04:00
Tam Nhu Tran af1a2a0f5d fix(bar): reuse a running CCS web-server and probe ports on the bind host
'ccs bar' always tried to start its own web-server. With a CCS server
already listening on 127.0.0.1:3000, get-port (probing the unspecified
address, which macOS allows to bind alongside a specific loopback
listener) reported 3000 as free, and the subsequent 127.0.0.1 bind
failed with EADDRINUSE, aborting launch.

Launch now probes candidate ports (bar.json port first, then the
default list) with a short-timeout GET /api/bar/summary and reuses the
first live CCS server it finds; only when none responds does it start a
new server. The get-port probe also passes host 127.0.0.1 so the
availability check matches the actual bind target. Probe failures are
treated as no-server-found and never break launch.

Closes #1500
2026-06-10 11:09:41 -04:00
github-actions[bot] 67d93e6722 chore(release): 8.2.0-dev.3 2026-06-10 04:22:48 +00:00
Kai (Tam Nhu) TranandGitHub 9a3cee3653 Merge pull request #1498 from kaitranntt/kai/fix/1497-bar-install-version
fix(bar): install version from app bundle and bar-API capability handshake
2026-06-10 00:19:04 -04:00
Tam Nhu Tran e7f3ec0da1 docs(bar): align install docs with Info.plist version pinning and bar-API check 2026-06-10 00:11:38 -04:00
Tam Nhu Tran c572d9f860 fix(bar): read app version from Info.plist and verify bar API instead of version majors
The floating ccs-bar-latest release tag carries no version, so deriving the
app version from tag_name printed 'vccs-bar-latest' and pinned that literal
string. The version now comes from CFBundleShortVersionString in the
extracted bundle's Info.plist; an unreadable plist skips pinning and clears
any stale pin.

The post-install check compared app semver major against the CCS server
major, but the app is versioned independently of the CLI, so the mismatch
warning fired on every install. It is now a capability handshake against
GET /api/bar/summary: 200 confirms the server serves the bar API, 404 warns
the server predates CCS Bar, and anything else keeps the soft warning.
Install never hard-fails on the handshake.

Closes #1497
2026-06-10 00:11:29 -04:00
Tam Nhu Tran 9ae6f85fa7 feat(bar): add ccs bar --help with docker-style help screen
--help and -h are honored anywhere in the args so 'ccs bar install --help'
shows help instead of running the installer. Also wires the 'ccs help bar'
topic, shell-completion flag suggestions, and a more-help table entry.
2026-06-10 00:11:19 -04:00
github-actions[bot] b24c943afc chore(release): 8.2.0-dev.2 2026-06-10 03:15:32 +00:00
Kai (Tam Nhu) TranandGitHub b966ba369a Merge pull request #1495 from kaitranntt/kai/fix/bar-launch-ipv4-bind
fix(bar): real-deployment fixes from normal-user install + CI test isolation
2026-06-09 23:11:48 -04:00
Tam Nhu Tran ad9bdd5794 fix(test): restore real account modules in tier-lock to fully stop mock leak
The prior fix only corrected PROVIDERS_WITHOUT_EMAIL, but the mock still stubbed
validateNickname -> null, hasAccountNameConflict -> false, and registry paths -> '',
which leak to cliproxy-auth-routes (same bun worker) and broke nickname validation
+ registry ops (9 CI failures). Now every mock factory spreads the REAL
account-manager and overrides only the account-DATA reads + IO; afterAll restores
the real account-manager/account-safety modules. tier-lock 8/0, combined ordering
39/0, tsc clean.
2026-06-09 21:25:21 -04:00
Tam Nhu Tran 0770b89037 fix(test): stop tier-lock mock.module leaking an empty PROVIDERS_WITHOUT_EMAIL
bun's mock.module is global and sticky; this test mocked account-manager with
PROVIDERS_WITHOUT_EMAIL: [] at top level and in beforeEach, poisoning the module
registry for later files in the same bun worker. cliproxy-auth-routes imports
PROVIDERS_WITHOUT_EMAIL at load time, got [], and getStartAuthNicknameError's
guard returned null for all providers -> 9 flaky CI failures (ordering-dependent).
Use the real ['kiro','ghcp'] in every mock factory and re-register safe defaults
in afterAll. Verified: worst-case ordering 39/39, full fast bucket 2500/0.
2026-06-09 21:11:10 -04:00
Tam Nhu Tran 2e99b58d09 fix(bar): read codex rollout tail via fs so quota surfaces under node
defaultTailLines used Bun.spawn(['tail',...]), but the ccs server (and
'ccs bar launch') runs under node where Bun is undefined — it threw, the
per-path catch swallowed it, and Codex quota silently never appeared in real
deployments (it only worked under the bun-run dev harness). Replace with a
pure fs read: runtime- and OS-agnostic, no subprocess. Verified under node:
surfaces a live rollout's rate_limits (primary/secondary).
2026-06-09 21:11:01 -04:00
Tam Nhu Tran 2f8745bc1f fix(bar): bind 'ccs bar launch' server to IPv4 loopback
startServer was called without a host, defaulting to 'localhost' which
resolves to ::1 (IPv6) on macOS, while bar.json's baseUrl and the menu-bar
app use 127.0.0.1 — so the app could not reach its own server (connection
refused) and showed offline. Pass host 127.0.0.1 explicitly to match.
2026-06-09 20:08:07 -04:00
github-actions[bot] 7537fd79b3 chore(release): 8.2.0-dev.1 2026-06-09 22:53:22 +00:00
Kai (Tam Nhu) TranandGitHub 2dbfa6a845 Merge pull request #1493 from kaitranntt/kai/feat/ccs-bar
feat(bar): CCS Bar — native macOS menu-bar app for live quota & usage
2026-06-09 18:49:29 -04:00
Tam Nhu Tran 28fef67a45 fix(bar-app): periodic background refresh so the glance self-heals
The menu only re-polled on open or after a mutation, so if the server briefly
dropped rows (e.g. a backend restart mid-session) the dropdown could stay stuck
showing stale/missing rows until reopened. Add a 60s background poll that
reconnects if the client was lost and reloads non-force (respecting server-side
caches, so it never hammers providers). As a bonus, alerts now evaluate every
interval instead of only on menu-open, making them genuinely proactive.
2026-06-09 18:32:26 -04:00
Kai (Tam Nhu) TranandGitHub 7d7f033134 Merge pull request #1491 from kaitranntt/kai/feat/ccs-bar-harden-discover
fix+feat(bar): pre-dev hardening + dashboard banner & docs
2026-06-09 18:05:57 -04:00
Tam Nhu Tran 1e7ad7e75e feat(bar): add Get CCS Bar dashboard banner and ccs bar docs page
Add a 'Get CCS Bar' promo banner + card to the dashboard (mirroring the
OpenRouter promo pattern + design system) so users discover the macOS menu-bar
app, with a macOS-aware install CTA. Add a user-facing docs/ccs-bar.md covering
what it is, install via 'ccs bar install', launch, what it shows, uninstall,
and the loopback requirement -- closing the docs-sync gap for the new ccs bar
command.
2026-06-09 18:04:53 -04:00
Tam Nhu Tran 7d3a11a452 fix(bar): resolve pre-dev review findings (security gate, honesty, correctness)
Gate /api/bar/* behind the localhost-when-auth-disabled guard (single DRY
choke point) so native quota/tier/cost can't leak on a non-loopback bind with
auth disabled; add a guard test. Delete the dishonest maxRedirections test that
asserted the opposite of the production redirect hardening. Key per-account
today-cost on the local day (matching analytics) instead of UTC. Stop the
inner 429 retry in the Claude usage fetch so the outer cache + circuit breaker
honor Retry-After. Narrow the usage-transformer map type and fix stale
doc-comments; clarify the one-alert-per-reset-window quota rule; gitignore the
local demo scaffolding.
2026-06-09 18:04:31 -04:00
Kai (Tam Nhu) TranandGitHub ce98a69830 Merge pull request #1490 from kaitranntt/kai/feat/ccs-bar-inline-chart-toggle
feat(bar): inline spend chart bars/line toggle
2026-06-09 17:34:00 -04:00
Tam Nhu Tran a700a92171 feat(bar-app): inline spend chart bars/line toggle in the Spend header
Move the bars/line choice out of Settings and into the Spend section header's
blank space as a small inline toggle, so the user flips the chart style right
where the chart is. Persistence unchanged.
2026-06-09 17:33:40 -04:00
Kai (Tam Nhu) TranandGitHub 0787c445ca Merge pull request #1489 from kaitranntt/kai/feat/ccs-bar-density-spend-chart
feat(bar): density tuning + spend chart Bars/Line toggle
2026-06-09 17:06:53 -04:00
Tam Nhu Tran 0b1c4e4908 feat(bar-app): tune density and add spend chart style toggle
Narrow the dropdown (380 to 360) and give it more vertical room (620 to 700).
Tighten the subscription cards (less spacing/padding) since they carry only a
few window rows. Make the spend chart taller (18 to 30) and let the user pick
its style in Settings: chunk bars (default) or a line graph with a subtle area
fill. Persist the choice in UserDefaults.
2026-06-09 17:06:33 -04:00
Kai (Tam Nhu) TranandGitHub b9a4a4a3a4 Merge pull request #1488 from kaitranntt/kai/feat/ccs-bar-settings-window
fix(bar): standalone Settings window, real theme forcing, roomier layout
2026-06-09 16:44:31 -04:00
Tam Nhu Tran b950b41503 fix(bar-app): settings as standalone window, real theme forcing, roomier layout
Move Settings out of the menu-bar popover into a standalone resizable AppKit
window so clicking it no longer steals focus and dismisses the bar (the .sheet
inside MenuBarExtra(.window) was the root cause). Force the actual NSWindow
appearance (aqua/darkAqua/system) on both the popover and the settings window
so Light/Dark visibly flips materials and semantic colors, not just custom
tokens. Replace the fragile popover quit dialog with an inline two-step
arm/confirm. Widen the dropdown and increase spacing/type for readability. Fill
the settings window responsively and make Done close it via the window
controller (dismiss() is a no-op in a hosted NSWindow).
2026-06-09 16:44:10 -04:00