Working chat: auth, connections, streaming, folders

LLeMbas now runs end to end. Register, add an OpenAI-compatible
connection, and hold a real streaming conversation organised into
folders. Verified against the local llama-swap instance.

Streaming is the one genuinely tricky part. Sending a message returns
two HTML fragments -- the user bubble and an empty assistant bubble
carrying an sse-connect -- and that attribute is the ONLY thing that
starts a generation. Rendering an incomplete assistant message as a
streaming shell falls out of the same template, which means loading a
page whose last reply never finished simply picks it up again.

Details worth knowing about, each commented where it matters:

- SSE payloads are split across several data: lines. A raw newline in
  one data: line truncates the event, which shows up the first time a
  model emits a code block.
- Markdown is rendered server-side by the same helper for both the page
  and the final streamed frame, so the two cannot disagree. The fence
  renderer is replaced outright rather than using markdown-it's
  highlight option, which re-wraps output in a second <pre>.
- escape_text is html.escape, not nh3.clean_text: it escapes character
  by character, so escaping stream chunks separately equals escaping
  the whole string.
- The stream opens its own session via session_scope(); it outlives the
  request handler and the dependency-scoped session may be closed.
- Deleting a folder keeps the chats inside it (FK is SET NULL). Losing
  a conversation to a mis-clicked folder delete is unforgivable.
- Login failures use one message for "no such account" and "wrong
  password" so the form cannot enumerate registered addresses.

Also adds deploy/ for the gamebox install at https://chat.lan: system
unit, nginx vhost with buffering off (buffering on turns streaming into
one lump at the end), and install/update scripts following the same
service-user and /srv bind-mount conventions as llama-swap and comfyui.

70 tests, ruff clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jaroslav Beneš
2026-07-21 11:04:13 +02:00
parent 5ef2af6a9f
commit dd9e0e9440
59 changed files with 6273 additions and 12 deletions
@@ -0,0 +1,76 @@
{% extends "admin/_layout.html" %}
{% from "_macros.html" import icon %}
{% set section = "connections" %}
{% block title %}Connections - LLeMbas{% endblock %}
{% block heading %}Connections{% endblock %}
{% block admin_content %}
<p class="admin-lede">
Any endpoint that speaks the OpenAI HTTP API: OpenAI itself, or a local
runner such as LM Studio, vLLM, llama.cpp or Ollama. LLeMbas asks each one
for its model list and offers those models in the chat picker.
</p>
{% if message %}
<div class="alert alert--success">{{ message }}</div>
{% endif %}
<section class="card">
<h2 class="card__title">Add a connection</h2>
<form method="post" action="/admin/connections" class="form-grid">
<div class="field">
<label class="field__label" for="new-name">Name</label>
<input class="input" id="new-name" name="name" required placeholder="Local LM Studio">
</div>
<div class="field">
<label class="field__label" for="new-url">Base URL</label>
<input class="input input--mono" id="new-url" name="base_url" required
placeholder="http://localhost:1234/v1">
<p class="field__hint">
With or without the trailing <code>/v1</code> — both are accepted.
</p>
</div>
<div class="field">
<label class="field__label" for="new-key">API key</label>
<input class="input input--mono" id="new-key" name="api_key" type="password"
autocomplete="off" placeholder="sk-…">
<p class="field__hint">
Encrypted before it is stored, and never sent back to the browser.
Leave empty for endpoints that need no key.
</p>
</div>
<div class="field field--actions">
<button class="btn btn--primary" type="submit">
{{ icon("plus", "icon--sm") }} Add and load models
</button>
</div>
</form>
</section>
<h2 class="admin-section-title">
Configured connections
<span class="badge">{{ connections|length }}</span>
</h2>
{% if not connections %}
<div class="empty" style="padding: var(--sp-10) 0">
{{ icon("server", "empty__mark") }}
<p class="empty__text">
Nothing configured yet. Add a connection above and its models appear here.
</p>
</div>
{% endif %}
<div id="connection-list">
{% for connection in connections %}
{% with masked = masked[connection.id],
model_count = model_counts[connection.id] %}
{% include "admin/_connection_row.html" %}
{% endwith %}
{% endfor %}
</div>
{% endblock %}