Add web UI and worker capture/approval command channel
Introduces the browser-facing surface and the worker-side protocol that backs it: - internal/ui: joined read model plus per-task lifecycle and approval controls, kept separate from the raw endpoints workers and harnesses depend on. - internal/webui + web/: Vite/React app, build output embedded via go:embed and served as an SPA fallback. - federation: per-(worker, task) captures with a monotonic revision that advances only when pane text actually changes, and a command queue restricted to grant_approval / deny_approval, each bound to the capture revision the operator acted on. - orchestra-worker: publishes captures and executes commands only after re-reading the pane and confirming the revision still matches. Sends keystrokes only for a visible y/n prompt or OpenCode's fully labelled selector, and refuses to deny through that selector rather than guess at unobservable navigation. This is the ownership boundary AUDIT.md's B14 and B17 call for: approval becomes an explicit, revision-bound operation executed by the worker that owns the pane, instead of a side effect of prompting over a coordinator-driven remote socket. Also ignores the web build inputs and outputs. node_modules ships vendored Go packages, so go build and go test walk into it if it is merely untracked; both node_modules and .node_modules are excluded. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01535A3Y8RtkAi8wYuWhtkEd
This commit is contained in:
@@ -995,6 +995,61 @@ func (c *Coordinator) Session(taskID string) (herdr.Session, bool) {
|
||||
return s, ok
|
||||
}
|
||||
|
||||
// RequestHandoff asks the live harness to prepare its agent-authored handoff.
|
||||
// It deliberately does not release the pane: a later validated handoff is the
|
||||
// only evidence that can make a rotation safe.
|
||||
func (c *Coordinator) RequestHandoff(ctx context.Context, taskID string) error {
|
||||
c.loadSessions()
|
||||
c.mu.Lock()
|
||||
s, ok := c.sessions[taskID]
|
||||
c.mu.Unlock()
|
||||
if !ok {
|
||||
return fmt.Errorf("session not found for task %s", taskID)
|
||||
}
|
||||
if s.HandoffRequested {
|
||||
return nil
|
||||
}
|
||||
a, err := c.adapterFor(taskID, s)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
req, ok := a.(herdr.HandoffRequester)
|
||||
if !ok {
|
||||
return fmt.Errorf("harness does not support handoff requests")
|
||||
}
|
||||
if err := req.RequestHandoff(ctx, s); err != nil {
|
||||
return err
|
||||
}
|
||||
s.HandoffRequested = true
|
||||
c.mu.Lock()
|
||||
c.sessions[taskID] = s
|
||||
err = c.saveSessionsLocked()
|
||||
c.mu.Unlock()
|
||||
return err
|
||||
}
|
||||
|
||||
// RespondApproval is the local implementation of the same guarded command
|
||||
// contract used by federation workers. It rechecks the displayed capture at
|
||||
// the owning herdr immediately before input is sent.
|
||||
func (c *Coordinator) RespondApproval(ctx context.Context, taskID string, grant bool, expectedCapture string) error {
|
||||
c.loadSessions()
|
||||
c.mu.Lock()
|
||||
s, ok := c.sessions[taskID]
|
||||
c.mu.Unlock()
|
||||
if !ok {
|
||||
return fmt.Errorf("session not found for task %s", taskID)
|
||||
}
|
||||
a, err := c.adapterFor(taskID, s)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
responder, ok := a.(herdr.ApprovalResponder)
|
||||
if !ok {
|
||||
return fmt.Errorf("harness does not support approval responses")
|
||||
}
|
||||
return responder.RespondApproval(ctx, s, grant, expectedCapture)
|
||||
}
|
||||
|
||||
func (c *Coordinator) Capture(ctx context.Context, taskID, source string) (string, error) {
|
||||
s, ok := c.Session(taskID)
|
||||
if !ok {
|
||||
|
||||
Reference in New Issue
Block a user