Adds archyBridge.sendChat(text) built on the existing postToParent +
origin-validated listener pattern (same request-id correlation as
requestContext), with a 180s timeout matching the node's
ASSISTANT_HTTP_TIMEOUT. Adds useAI.ts's streamViaArchy, which branches all
three existing send sites on the same __AIUI_EMBEDDED__ signal useArchy.ts
already reads: embedded mode delegates the model call, the tool-calling
loop and the model key to the node; standalone mode is untouched and keeps
using streamClaude/streamOpenRouter with AIUI's own dev proxy (D-17).
CLAUDE_PATH/OPENROUTER_PATH are not removed — 13-02 changes what those
paths resolve to on a node, 13-09 retires them.
Verified: vitest run 332/335 passing (3 pre-existing failures confirmed via
a scratch worktree at the prior HEAD, unrelated to this change — seed
extraction count assertions and a web-search-integration body.webSearch
assertion); vue-tsc --noEmit clean.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Four issues found via live testing of the embedded Chat/AIUI panel
(Archipelago phase 02-07 follow-up), each root-caused rather than
patched over:
1. Loading overlay never dismissed: archyBridge.init() used
window.location.origin (this iframe's OWN origin) as the target for
postMessage calls TO the parent, instead of the parent's actual
origin. Silently correct only when AIUI is served same-origin as
its host (production's /aiui/ proxy) — broken the moment AIUI runs
on a different origin than its embedding page (any dev setup with a
separate AIUI dev server). The 'ready' message, and every
permissions/theme/context/action response after it, was being
dropped by the browser. Fixed by deriving the parent's real origin
from document.referrer (archyBridge.ts).
2. White/black background instead of the branded look: initTheme()
decides light/dark from localStorage or the OS's prefers-color-
scheme, with no awareness of being embedded — App.vue now forces
dark immediately on mount when embedded (before any handshake
completes) and useArchy.ts's theme-update callback now applies
Archy's reported mode too. Separately, body had no background-color
at all, so ChatPage.vue's embedded `background: transparent` fell
through to the browser's white UA default; main.css now paints body
to match the active theme. And ChatPage.vue's embedded branch was
opting out of the same background-image treatment the standalone
dark app uses — it now shares that exact styling instead of a flat
fallback color, matching the standalone look precisely.
3. Dead end when no AI provider credential is available: useAI.ts now
emits a narrow, one-shot needsApiKey signal (401/403, "api key",
"unauthorized", or a proxy-unreachable failure — deliberately not
every transient error) that ChatWindow.vue watches to auto-open
Settings, so the user lands on the fix instead of a silent/dead
chat.
4. claude-proxy.ts's CLI fallback spawned a hardcoded ~/.local/bin/claude
path, breaking with ENOENT on any machine where the CLI lives
elsewhere (e.g. an nvm install). Now resolves via `command -v claude`
first (an optional CLAUDE_BIN env override, then the historical path,
then the bare command name as a last resort so spawn() itself can
still try PATH), and surfaces an actionable in-UI error naming three
ways to fix it when none resolve.
Verified: full send→spawn→response round trip against the local proxy
(both directly and through vite's /api/claude proxy), vue-tsc clean,
vitest 332/335 passing (3 pre-existing unrelated failures, confirmed
present before this commit too), production build clean with both
chatExpanded/mobileChat flags and the new background rule present in
the built assets.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Archipelago's Chat tab (neode-ui) embeds AIUI in an iframe and now
passes two presentation-only query params on the embed URL:
- ?chatExpanded — chat starts in the full message list rather than
the collapsed prompt-index. chatCollapsed's initial ref now checks
for this param before falling back to the existing localStorage
default; never written back to localStorage, so the standalone
app's own persisted preference is untouched.
- ?mobileChat — on mobile, ChatPage opens on the chat tab rather than
whatever tab survived from a prior mount of the module-singleton
content-panel state. mobileTab already defaulted to 'chat'; this
just re-asserts it once on mount when the param is present, so it
doesn't interfere with the hasDetailOpen/panelOpen watchers driving
normal tab switching in response to user taps afterward.
Both params are read directly from window.location.search and are
no-ops when absent, so the standalone (non-embedded) app and its
existing desktop layout are unaffected.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
12-phase plan covering security fixes, proxy hardening, state bugs,
content extraction, cache bounds, accessibility, and test coverage.
42 atomic tasks structured for sequential agent execution.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add [[app_ext:...]] tag format and rewrite extractApps() for reliable app extraction
- Wire AppsGrid and RecipeGrid into ContentGridView (was missing on wide desktop)
- Add mock Archy node data for standalone dev testing (VITE_MOCK_ARCHY=true)
- Fix PromptPalette: z-50 + opaque bg so slash menu renders above chat content
- Fix detail banner not updating: add :key to all detail components in ContentPanel
- Guide page moved to /guide, chat is now root route, guide auto-selected on first load
- Code browser: click opens file in viewer, separate checkbox for chat context selection
- Restore folder context selector (round checkbox on hover) in FileTreeNode
- Demo projects for prod deployment instead of hardcoded personal paths
- Improve Archy context injection with media breakdown and better error logging
- Add 11 Claude Code skills for efficient development workflows
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The old claude-3-5-haiku-20241022 model ID returns 404 from the Anthropic API.
Updated proxy mapping and test to use claude-haiku-4-5-20251001.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Create useContentImages<T> composable eliminating ~240 lines of duplicated
image loading/fallback logic across 6 grid components
- Fix book covers: use full fetchBookImage chain (Open Library → Google Books → Wikipedia)
- Fix TV series images: try disambiguated Wikipedia title first (e.g. "Chernobyl (TV series)")
- Add Wikipedia image fetching for places (fetchPlaceImage)
- Rewrite all SVG fallbacks to consistent text-only style (no icons)
- Add generateWebsiteFallback for NewsGrid websites variant
- Fix song extraction regex catching raw song_ext: prefix in titles
- Fix player bar: clean song_ext: prefix from display, mute error text
- Fix Code panel: auto-load projects on mount when list is empty
- Improve chat bubble spacing (py-2.5) and first message top margin (pt-6)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Fix dev.sh unbound variable crash with ${VITE_DEV_API_TOKEN:-}
- Kill stale proxy on startup instead of skipping (token mismatch)
- Fix RSS middleware blocking all GET requests (check path before auth)
- Read dev auth token lazily from process.env (not cached at import)
- Restore network binding (host: true) for Vite dev server
- Add macOS keychain lookup for Claude Code OAuth token in proxy
- Rewrite proxy streaming to pipe SSE directly instead of await json()
- Prevent double web search (client-side + proxy) in useAI
- Reduce SearXNG timeout 6s→3s and max tries 8→3
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Require https: protocol for remote content pack imports, rejecting
http:, file:, javascript:, and other schemes. Add schema validation
to verify required fields (id, name, items) and item shape (type,
title) before accepting imported packs.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Track accumulated body size during req.on('data') and abort with 413
if it exceeds 1MB, preventing unbounded memory allocation from
oversized payloads.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Remove --host flag from dev.sh that was overriding vite.config.ts to
bind on 0.0.0.0. Server now defaults to localhost; use VITE_HOST env
var to opt-in to LAN access for mobile testing.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
storeApiKey() now throws when encryption is not available instead of
storing keys in plaintext. ApiKeyManager.vue catches the error and
displays a warning message.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add sliding-window rate limiter in server/dev-auth.ts (60 req/min reads,
10 req/min writes per IP). Apply checkRateLimit() in all Vite plugins
and claude-proxy.ts after auth validation.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Change default allowedOrigin from '*' to null. Derive from
window.location.origin when init() is called without explicit origin.
Always validate event.origin — reject messages when origin is not set.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Install dompurify and replace the hand-rolled DOM walker sanitizer
with DOMPurify.sanitize() configured with the same allowed tags.
Handles mutation XSS edge cases the custom version couldn't.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace localStorage.getItem/setItem with storeApiKey/getApiKey/deleteApiKey
from key-vault. Make loadConnection(), connect(), and disconnect() async.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Track accumulated body length during PUT /api/dev-chats and abort
with 413 if payload exceeds 5MB.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add post-DNS SSRF validation using dns.lookup() to verify resolved IPs
are not in private ranges. Block non-http(s) schemes (file://, ftp://)
in discoverFeedUrl(). Extract isPrivateIp() helper for reuse.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add SENSITIVE_PATTERNS denylist to handleRead() in vite-fs.ts.
Blocks access to .env*, .git/, credentials, secrets, .pem, .key,
and SSH key files. Returns 403 for matched paths.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add setCorsHeaders() and handleCorsOptions() helpers in server/dev-auth.ts.
Replace wildcard CORS origin with http://localhost:5173 in all Vite plugins
and claude-proxy.ts. Include Authorization in allowed CORS headers.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Generate random VITE_DEV_API_TOKEN in dev.sh, validate Bearer token
in shared server/dev-auth.ts middleware. Applied to all Vite plugins
(fs, dev-chats, rss, web-search, tmdb, music-search) and claude-proxy.
Client-side uses apiFetch() wrapper to attach the token automatically.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add VideoPlayerOverlay component for free film playback
- Add GuidePage with interactive node setup walkthrough
- Add freeFilms data catalog with public domain films
- Enhance PlayerBar with video support and queue management
- Add video player store for overlay state management
- Refactor music search plugin (Jamendo integration cleanup)
- Add PWA cache version purge mechanism in main.ts
- Add PWA icon cache fix skill for Brave/Chrome
- Improve content grids: loading states, image fallbacks
- Enhance useArchy composable with node context
- Update useNostr with relay pool management
- Expand chat store with guide conversation support
- Add test fixtures for guide and node demo prompts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Remove CSP meta tag from index.html (breaks Vite HMR, should be
set via HTTP headers in production nginx instead)
- isCryptoEnabled() now checks crypto.subtle is available (undefined
over HTTP on non-localhost origins)
- Add try/catch + error feedback to passphrase submit flow
- PassphraseDialog accepts error prop, focuses input on visible
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- iOS: Capacitor vs WKWebView vs React Native WebView analysis
- Mac: Tauri v2 vs Electron comparison with menu bar app patterns
- Plugins: Signature validation, sandboxed iframes, permission system
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Handles 413 status for files > 1MB with user-friendly error message.
Adds fileLoading and fileError state for loading indicator support.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Skips redundant API calls when price was fetched within the last 30
seconds, reducing network requests while keeping data fresh.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Uses defineAsyncComponent to lazy load heavy renderers, reducing
initial bundle size. Shows loading text while components load.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Updates alt attributes to include contextual info: songs include artist,
films include year and director, books include author, TV series include
type label.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Documents WCAG AA contrast ratios in main.css. Increases text-white/40
to /50 for settings labels, section headers, and loading states to
meet 4.5:1 minimum contrast ratio.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds role="dialog", aria-modal, focus trap, auto-focus close button,
and Escape key handling to ZapDialog and SettingsModal.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds descriptive aria-label to card buttons in SongGrid, FilmGrid,
TVSeriesGrid, PlaceGrid, BookGrid, PodcastGrid, NewsGrid, ImageGrid,
and AppsGrid for screen reader accessibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds aria-label to all 6 icon-only buttons in ChatMessage.vue:
edit, regenerate, reply, branch, upvote, downvote.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Documents how file types map to content surfaces, how ContextBroker
filtering works, and adds a reusable HelpSection UI component.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Updates vite-fs tree walker to include .claude directories so users
can browse CLAUDE.md, settings, hooks, and memory files.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds /browse route with project listing, recursive file tree with
expand/collapse, and file preview sidebar (desktop) / overlay (mobile).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Tests keyboard detection, viewport height tracking, debounce behavior.
Includes withSetup test helper for composables with lifecycle hooks.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Tests tab switching, detail open/close, panel state management,
design system mode. 9 test cases.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Tests queue management, state transitions, progress computation,
deduplication, and API shape. 9 test cases.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Restricts script, style, img, connect, media, and frame sources to
known-safe origins. Blocks object embeds and enforces base-uri self.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Configurable origin replaces wildcard '*' for both sending and receiving.
Origin check filters incoming messages when a specific origin is set.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>