Commit Graph

1307 Commits

Author SHA1 Message Date
Lyon 6b417cc620 fix: add repo-owned playwright probe guard (#850)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 20:35:58 +08:00
Codex Agent b896db85d4 docs: specify v02 PR auto CD workflow 2026-06-04 20:09:12 +08:00
Lyon ef527d3ecd feat(v02): add final response session verifier (#847)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 19:02:13 +08:00
Lyon d23cc410be fix(v02): bound cloud web layout smoke (#846)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 18:50:35 +08:00
Lyon dc74c7c99a Merge pull request #845 from pikasTech/fix/issue844-trace-json-contract
fix(v02): expose trace render json summary
2026-06-04 18:29:33 +08:00
Codex Agent b4e8c0a8b4 fix(v02): expose trace render json summary 2026-06-04 18:28:41 +08:00
Lyon 6a79bc8f15 fix(v02): repair persisted final response fallback (#840)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 18:18:00 +08:00
Lyon 3f26ec0b16 fix(v02): add workspace scroll follow and markdown renderer (#839)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 17:50:47 +08:00
Lyon 2fc3972ddd fix(v02): compact workbench status panels (#838)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 17:47:56 +08:00
Lyon be557c09bc fix(v02): repair final response status (#837)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 17:45:25 +08:00
Lyon 62a99084d7 Merge pull request #835 from pikasTech/fix/issue826-webui-trace
fix(v02): unify web trace final response
2026-06-04 17:30:38 +08:00
Codex Agent 7a58695318 fix(v02): unify web trace final response 2026-06-04 17:29:28 +08:00
Lyon 20199b8215 Merge pull request #832 from pikasTech/fix/v02-device-pod-rg-windows-quote
fix(v02): preserve device-pod rg patterns on Windows
2026-06-04 17:00:15 +08:00
Lyon 6c6a64b414 fix(v02): honor HTTP session cookie security (#831)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 16:59:15 +08:00
Codex Agent a9f81677e7 fix(v02): preserve device-pod rg patterns on Windows 2026-06-04 16:58:00 +08:00
Lyon 7b2f4fa45f fix: wait for device-pod build verify output (#830)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 16:23:35 +08:00
Lyon 8e8f6513a5 Merge pull request #828 from pikasTech/fix/issue820-ls-output-visibility
fix(v02): widen device-pod job output visibility
2026-06-04 16:18:52 +08:00
Codex Agent baa7289ca0 fix(v02): widen device-pod job output visibility 2026-06-04 16:16:56 +08:00
Lyon 9928954ea6 feat: add device-pod build verify (#827)
Co-authored-by: Codex Agent <codex@hwlab.local>
2026-06-04 16:11:00 +08:00
Lyon c1960f1cbc Merge pull request #825 from pikasTech/fix/issue820-rg-name-search
fix(v02): support device-pod filename rg
2026-06-04 15:58:16 +08:00
Codex Agent 37f1b6af22 fix: support device-pod filename rg 2026-06-04 15:56:08 +08:00
Lyon ff7f07434d Merge pull request #824 from pikasTech/fix/issue-814-cloud-web-authorization-proxy
fix(v02): forward API key auth through cloud web
2026-06-04 15:54:57 +08:00
Codex Agent c0879ef764 fix(v02): forward API key auth through cloud web 2026-06-04 15:54:00 +08:00
Lyon 53f76e8724 Merge pull request #823 from pikasTech/fix/issue-814-cloud-web-api-key-proxy
fix(v02): proxy API key writes through cloud web
2026-06-04 15:45:35 +08:00
Codex Agent a312cc7f99 fix(v02): proxy API key writes through cloud web 2026-06-04 15:44:07 +08:00
Lyon 1427ded71f Merge pull request #822 from pikasTech/fix/issue-816-ui-density
fix: compact v0.2 code agent workbench layout
2026-06-04 15:33:59 +08:00
Codex Agent e46350993c fix: compact code agent workbench layout 2026-06-04 15:26:13 +08:00
Lyon f1ade3d56d Merge pull request #819 from pikasTech/fix/issue-814-v02-endpoint-contract
fix(v02): remove stale endpoint contract freeze
2026-06-04 15:20:33 +08:00
Codex Agent 7fc6603c30 fix(v02): remove stale endpoint contract freeze 2026-06-04 15:19:38 +08:00
Lyon 74af0c796b Merge pull request #793 from pikasTech/fix/issue-788-keycloak-auth-migration
feat(v0.2): user API key + 24h session + Keycloak OIDC (rounds 1-9 of #788)
2026-06-04 15:03:26 +08:00
Codex Agent e64ee92fb1 fix(v0.2): align Keycloak auth to HTTPS session API key 2026-06-04 15:01:30 +08:00
Codex Agent 683d7b7459 docs(v02): record Keycloak deployment baseline 2026-06-04 15:01:30 +08:00
Codex Agent e70dab1f88 fix(v02): wire Keycloak OIDC runtime 2026-06-04 15:01:30 +08:00
Codex Agent 36b264f212 fix(keycloak): use supported admin bootstrap env 2026-06-04 15:01:30 +08:00
Codex 4d48db9e7c feat(hwlab-cli): client auth oidc-login returns Keycloak authorize URL 2026-06-04 15:01:30 +08:00
Codex 6b93ebd0ef fix(k8s): keycloak admin bootstrap Job - simpler mount and script 2026-06-04 15:01:30 +08:00
Codex 0370135a35 feat(k8s+tests): keycloak bootstrap Job + AgentRun actor trace tests
- new deploy/k8s/keycloak/keycloak-bootstrap-job.yaml: one-shot Job that waits for Keycloak, authenticates as admin, creates hwlab realm + hwlab-cloud-web OIDC client via REST API
- secret hwlab-cloud-web-client holds the OIDC client_secret used by cloud-api
- kustomization.yaml picks up the new Job and Secret
- access-control.test.ts: cloud api AgentRun trace records real actor.userId from OIDC-upserted user (issue 788 spec)
- access-control.test.ts: cloud api /v1/users/me returns actor with authMethod=api-key for HWLAB_API_KEY Bearer token
- 31 pass / 4 pre-existing fail
2026-06-04 15:01:30 +08:00
Codex 84cca71bef feat(cloud-api): v0.2 OIDC login/callback (state, nonce, user upsert) 2026-06-04 15:01:30 +08:00
Codex 1ba5103d33 fix(k8s): add --bootstrap-admin-username/password CLI args to keycloak 2026-06-04 15:01:30 +08:00
Codex ca5ff418dd feat(k8s): keycloak namespace manifests + apply on G14
- new deploy/k8s/keycloak/ kustomization with namespace, keycloak-postgres StatefulSet, keycloak Deployment
- keycloak Deployment uses quay.io/keycloak/keycloak:25.0 with --hostname-strict=false, postgres backend
- PVC data-keycloak-postgres-0 (5Gi local-path) bound to the StatefulSet
- secrets keycloak-postgres / keycloak-admin provisioned in keycloak namespace
- OIDC discovery endpoint confirmed reachable via port-forward; master realm issuer http://.../realms/master
- next round will provision the hwlab realm + OIDC client
2026-06-04 15:01:30 +08:00
Codex 6a8e9b3d79 feat(agentrun): inject owner HWLAB_API_KEY into runner transient env
- submitAgentRunChatTurn resolves owner user API key via accessController.store.findActiveDefaultApiKeyForUser
- buildAgentRunRunnerJobInput accepts ownerApiKey; when present, removes HWLAB_DEVICE_POD_API_KEY and adds HWLAB_API_KEY as sensitive
- buildAgentRunTransientEnv no longer emits HWLAB_DEVICE_POD_API_KEY
- codex-stdio child env now reads HWLAB_API_KEY (not HWLAB_DEVICE_POD_API_KEY)
- server-code-agent-http codeAgentAuthEnv looks up user default API key; URL env vars still set unconditionally
- tests: code-agent-session-registry Codex child env carries only device-pod API key now checks HWLAB_API_KEY
- tests: server-agent-chat delegates v0.2 turns removes HWLAB_DEVICE_POD_API_KEY assertion
- 58 pass / 4 pre-existing fail
2026-06-04 15:01:30 +08:00
Codex bcec7e6934 feat(device-pod-cli): v0.2 hwpod prefers HWLAB_API_KEY over legacy key
- authHeaders now reads HWLAB_API_KEY (env or --apiKey/--bearerToken) first; only when hwl_live_ prefix is present
- when both are set, HWLAB_API_KEY wins and x-hwlab-device-pod-api-key is suppressed
- new test asserts the precedence using a fake API key against a local http server
- help auth hint updated to mention the preferred credential
2026-06-04 15:01:30 +08:00
Codex ad53ff6ffb feat(hwlab-cli): v0.2 client auth whoami reads HWLAB_API_KEY first
- requestJson now prefers HWLAB_API_KEY (env or --apiKey / --bearerToken) and sends Authorization: Bearer hwl_live_...
- new client auth whoami command returns actor + authMethod via /v1/users/me
- client auth status reports apiKey.source and apiKey.prefix
- authVisibility + authDiagnosis surface apiKeySource/Prefix; invalid key returns api_key_invalid diagnosis
- legacy cookie / auto-login paths still work when no HWLAB_API_KEY is set
2026-06-04 15:01:30 +08:00
Codex 49dc7cc6e1 feat(cloud-api): v0.2 24h Web session + Secure cookie
- SESSION_MAX_AGE_SECONDS 7d -> 24h
- Cookie now sets Secure + SameSite=Lax (preserves HttpOnly)
- /v1/auth/session exposes authMethod, sessionExpiresAt, sessionTtlSeconds
- setSessionCookie/clearSessionCookie use new builders
- New test covers first-admin, /auth/login and /auth/logout cookie shape + expiresAt
2026-06-04 15:01:30 +08:00
Codex 13c779ed11 feat(cloud-api): v0.2 user API key auth (api_keys table + Bearer hwl_live_)
Adds the user API key foundation called out in #788:

- New api_keys table with idx_api_keys_user and idx_api_keys_prefix
- users extended with auth_provider/keycloak_issuer/keycloak_sub/email/last_login_at
- Authorization: Bearer hwl_live_... resolves to the same AuthPrincipal
- /v1/api-keys, /v1/api-keys/default, /v1/api-keys/{id}/regenerate, DELETE /v1/api-keys/{id}
- First-admin and /auth/login bootstrap a Default API key
- Short-test mode keeps display_secret; production化 will switch to hash-only later
- Legacy HWLAB_DEVICE_POD_API_KEY and Bearer <session-token> paths preserved
- 4 new access-control.test.ts cases

Refs pikasTech/HWLAB#788
2026-06-04 15:01:30 +08:00
Lyon 10962a5406 Merge pull request #818 from pikasTech/fix/v02-browser-launcher-817-627
fix(v0.2): unify browser launcher for Playwright smokes
2026-06-04 14:53:36 +08:00
Codex Agent 52af835500 fix: unify v02 browser launcher 2026-06-04 14:51:54 +08:00
Lyon 63b68914f7 Merge pull request #815 from pikasTech/fix/issue-803-system-intro
fix(web): v0.2 drop Agent workspace intro System cards, fold 界面模式 into panel title hint (HWLAB #803 followup)
2026-06-04 13:50:31 +08:00
Codex Agent caf5e6cde5 fix(web): v0.2 drop Agent workspace intro System cards, fold 界面模式 into panel title hint (HWLAB #803 followup)
PR #807 collapsed the top #code-agent-summary and per-message debug panels
into a 调试信息 dialog, but the conversation list still showed two hard-coded
System cards (界面模式 / Code Agent 状态) that fed availability into the
agent run path. Both appeared as full <article class="message-card
message-system"> bubbles before any user message on every session load,
contradicting the issue goal of a clean agent / user conversation feed.

- remove the ConversationPanel intro useMemo + [...intro, ...messages]
  spread; the conversation list now only contains real agent / user
  messages.
- move the static 界面模式 content to a small muted hint line under the
  panel title (id=workspace-hint, .conversation-panel-hint).
- the live Code Agent availability snapshot is already covered by the
  existing #code-agent-summary + 调试信息 dialog, so it is dropped.
- add a conversation-list empty-state placeholder so the panel keeps
  height for layout smoke (messages.length === 0).
- delete the now-orphan MessageRuntimePath / MessageSessionContinuity /
  MessagePendingContext components (no remaining callers per rg).
- extend tools/capture-issue-803-noise.mjs to report each .message-card
  role plus systemMessageCount / roleCounts so layout-level evidence
  can assert "no message-system in the conversation list".

web:check 12 pass / 0 fail; web:layout:build pass (desktop, narrow,
mobile). Issue: pikasTech/HWLAB#803
2026-06-04 13:48:29 +08:00
Lyon 4dea7c6ea4 Merge pull request #813 from pikasTech/fix/issue812-v02-resume-metadata
fix(cloud): expose persistent thread resume metadata
2026-06-04 13:05:47 +08:00