A terminal panel beside an agent chat
A real shell on the chat's own connection, opened and closed like the inspector and never beside it. The modes govern the model; what a person types is theirs, since they hold the credential and could open the same shell with an ssh client. The model cannot see the panel -- a button copies the output you choose into the composer. The session outlives the socket: closing the panel leaves a build running, and coming back reattaches with the scrollback. Two tabs share one shell and the smaller window decides the size. It ends on an idle timeout, on deleting the chat, on disabling, moving or deleting the connection, and on a restart -- which says why rather than quietly opening a fresh shell that has lost the working directory. The nginx template's `Connection ""` is right for SSE and fails every WebSocket handshake, so `location /` now uses a `map $http_upgrade`; update.sh grows a drift check for it, because the only symptom on a stale vhost is a panel that cannot connect. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
a1824681ae
commit
47791a88c7
@@ -34,9 +34,19 @@ def _set_session_cookie(response: Response, token: str) -> None:
|
||||
# Lax is what makes this application CSRF-safe without tokens: the
|
||||
# cookie is not sent on cross-site POSTs, and every mutating route here
|
||||
# is a POST. Do not relax to "none".
|
||||
#
|
||||
# One route is no longer a POST: the terminal WebSocket is a GET, and
|
||||
# what it opens is a shell. Lax still withholds the cookie from a
|
||||
# handshake a foreign page starts, so the attack is blocked -- but the
|
||||
# sentence above is no longer the whole story, which is why
|
||||
# `api/terminal.py` also *requires* a same-origin Origin header rather
|
||||
# than merely checking one when it happens to be there.
|
||||
samesite="lax",
|
||||
# Only over HTTPS when the deployment is not plain local http. Marking
|
||||
# it secure on http would silently break sign-in for a LAN install.
|
||||
# It has always meant "a network attacker on plain http can steal a
|
||||
# session"; with the terminal it also means they get a shell on the
|
||||
# machine behind that chat. See deploy/README.md.
|
||||
secure=False,
|
||||
path="/",
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user