Files, open beside the conversation

A third side panel, built the way the terminal is and filled the way the
inspector is: tabs holding open files. Project files over SFTP in an agent
chat; notes, skills, knowledge documents, this chat's text attachments and its
own scratch document everywhere. Read with pygments, edited in a plain
textarea, saved with a conflict check.

A bug found on the way in, and the reason this needed its own read path.
`ssh.read_file` ends in `clean_output`, which strips ANSI escapes and decodes
with errors="replace" -- right for the output of a command, and fatal for an
editor: open a file containing an escape byte, press Save, and you have
silently rewritten it with the escapes gone and every undecodable byte replaced
by U+FFFD. `read_text`/`write_text` decode strictly, report binary rather than
mangling it, carry an mtime:size token for a file that moved underneath, and
refuse an oversize write rather than truncating -- `write_file` truncates
because a model is told how many bytes it wrote, and somebody pressing Save is
not. The model-facing pair is untouched: what it returns is a contract a model
has been shown. A truncated read opens read-only for the mirror-image reason.

Six sources go through one dispatch table, for the reason tool_labels.py is a
table: six independently written permission checks is how one ends up written
slightly differently, and that failure looks like editing somebody else's note.

A save on a project file bypasses agent/policy.py, which makes it the fourth
documented exception to "the modes do not govern the keyboard" and the first
that writes. Same argument as the terminal panel -- whoever owns the credential
could write the file with scp -- but the consequence is larger and is now said
out loud rather than left to be inferred.

The model opens tabs from the file tools it was already calling, so no new
schema and no tokens. It never brings one to the front: an agent reads forty
files in a long reply, and taking the screen each time would drag somebody
through all of them and lose any edit in progress. Only the strip is streamed,
guarded on truthiness so the frame can never blank itself -- an empty one would
close every open tab, the approval card you could press twice with the sign
reversed. Both halves are settled on the server, which is why canvas.js needs
no guard against a swap at all.

No vendored editor. CodeMirror 6 needs a bundler, which is hard rule 1;
CodeMirror 5 would be a larger payload than xterm on every page, and xterm is
the one heavy dependency precisely because it loads only where it can be used.
So: server-rendered highlighting for reading, a textarea for writing, and the
panel says there is no colour while you type rather than pretending.

Also here: a scratch document per chat, with `scratch_write` at RISK_READ on
plan_update's argument, and a test pinning the three numbers that decide a
panel's width -- LAYOUT_BOUNDS drops an unknown variable silently, so a panel
missing from it has a drag handle that works and forgets.

Driven under a DOM stub and against the running application.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jaroslav Beneš
2026-08-04 09:21:03 +02:00
co-authored by Claude Opus 5
parent 2c914993aa
commit 5766446b84
36 changed files with 2974 additions and 12 deletions
+89 -2
View File
@@ -35,6 +35,7 @@ from sqlalchemy.orm import Session as DBSession
from lembas.db.models import AUTHOR_MODEL, Chat, User
from lembas.db.session import session_scope
from lembas.services import prompts as prompts_service
from lembas.services import scratch as scratch_service
from lembas.services import search as search_service
from lembas.services import settings_store
from lembas.services.library import documents as documents_service
@@ -94,6 +95,13 @@ FAMILY_MCP = "mcp"
# is the only tool the model cannot resolve by itself.
FAMILY_ASK = "ask"
# The chat's own working surface -- the canvas panel's scratch document.
# Deliberately not part of `notes`: a note is a durable artefact of the reader's
# that outlives the chat and is searchable, while this is the chat's own record
# of what it is doing, which is the line `plan_update` sits on. It is also its
# own switch, because narrowing notes off must not silently take the pad too.
FAMILY_SCRATCH = "scratch"
# Acting on the machine an agent chat is pointed at. Offered only when the chat
# is one, has a usable connection, and the feature is switched on -- see
# services/agent/session.py:resolve, which answers all three at once.
@@ -107,6 +115,7 @@ FAMILIES = (
FAMILY_NOTES,
FAMILY_MEMORY,
FAMILY_SKILLS,
FAMILY_SCRATCH,
FAMILY_ASK,
FAMILY_AGENT,
)
@@ -507,6 +516,51 @@ async def _run_notes_delete(context: ToolContext, args: dict[str, Any]) -> ToolO
)
# --- The chat's scratch document ---------------------------------------------
async def _run_scratch_write(context: ToolContext, args: dict[str, Any]) -> ToolOutcome:
"""Write into the pad the person can see beside the conversation.
Opens its own session, like every other runner: a generation outlives the
session that resolved it.
`append` is a service function rather than a read-and-concatenate here,
because two calls in one round would otherwise each read the same body and
the second would drop the first.
"""
with session_scope() as db:
chat = db.get(Chat, context.chat_id) if context.chat_id else None
if chat is None:
return ToolOutcome(
"There is no chat to write into.",
{"name": "scratch_write", "status": "error", "error": "No chat."},
)
doc = scratch_service.for_chat(db, chat)
text = str(args.get("text") or "")
if str(args.get("mode") or "append").strip().lower() == "replace":
scratch_service.update(db, doc, body=text, author=AUTHOR_MODEL)
what = "Replaced"
else:
scratch_service.append(db, doc, text, author=AUTHOR_MODEL)
what = "Added to"
return ToolOutcome(
f"{what} the scratch document ({len(doc.body)} characters). "
"It is on screen beside the conversation.",
{
"name": "scratch_write",
"query": doc.title,
"status": "ok",
"results": [],
# Opens the tab, the same way a file tool does. Never brings it
# to the front -- see `canvas.open_tab`.
"canvas": {
"key": f"scratch:{chat.id}",
"title": doc.title,
"source": "scratch",
},
},
)
# --- Memory ------------------------------------------------------------------
async def _run_memory_add(context: ToolContext, args: dict[str, Any]) -> ToolOutcome:
content = str(args.get("content") or "").strip()
@@ -819,6 +873,38 @@ REGISTRY: dict[str, ToolDef] = {
run=_run_notes_delete,
risk=RISK_WRITE,
),
ToolDef(
name="scratch_write",
family=FAMILY_SCRATCH,
description=(
"Write into this chat's scratch document, which the person can "
"see and edit beside the conversation. Use it for something you "
"are building up as you work — a draft, a table of findings, a "
"list you keep adding to — rather than putting it in the reply "
"and rewriting the whole thing each turn. It is not searchable "
"later and belongs to this chat alone; use a note for anything "
"worth keeping beyond it."
),
parameters=_object(
{
"mode": {
**_STRING,
"enum": ["append", "replace"],
"description": "append is the default.",
},
"text": {**_STRING, "description": "Markdown."},
},
["text"],
),
run=_run_scratch_write,
# What a tool does to the *world the four modes govern*, which is the
# machine -- and this cannot touch it. RISK_WRITE would put an
# approval card on screen every time the model jotted a paragraph,
# which is exactly the interruption batching exists to prevent. The
# same argument `plan_update` carries. An administrator who
# disagrees puts it in `deny_default`.
risk=RISK_READ,
),
ToolDef(
name="memory_add",
family=FAMILY_MEMORY,
@@ -990,11 +1076,12 @@ def _family_allowed(
# attach path keeps working, because that one is a person's instruction
# rather than a model's choice.
return bool(allowed.get("tools.fetch") and config.get("fetch_enabled"))
if gate in (FAMILY_CUSTOM, FAMILY_MCP, FAMILY_ASK, FAMILY_AGENT):
if gate in (FAMILY_CUSTOM, FAMILY_MCP, FAMILY_ASK, FAMILY_AGENT, FAMILY_SCRATCH):
# Deliberately without `library.use`: an HTTP endpoint an administrator
# wrote has nothing to do with this person's own documents and notes,
# and requiring the library permission for it would be a coincidence of
# naming rather than a rule. The same goes for being asked a question.
# naming rather than a rule. The same goes for being asked a question,
# and for a pad that belongs to this chat and goes nowhere else.
return bool(allowed.get(f"tools.{gate}"))
return bool(allowed.get(f"tools.{gate}") and allowed.get("library.use"))