4ced049ff8
An agent chat will act on a machine you choose, so this is the screen where you choose it. User-owned like a note, not admin-owned like a connection: these are somebody's own machines and somebody's own keys, and "anyone in this group may log in to my server" is a different feature with a different blast radius. services/sharing.py is deliberately not involved either -- sharing grants reading, and a host somebody else can read is a host they can log in to. Trust on first use, made explicit rather than assumed. Adding a host does not connect to it. Check looks at its key and shows you the fingerprint; nothing is sent until you accept, because get_server_host_key completes the key exchange and stops -- no username, no credential. Accepting pins it, and a host that later presents a different key is refused with the reason rather than quietly trusted. Moving a profile to another host or port forgets the pin, since a key belongs to the machine it came from. Four asyncssh defaults are actively wrong here and all four are passed explicitly: every LLeMbas user shares one unix account, so `known_hosts` would be a shared trust store, `client_keys` would authenticate one person with another's key, `config` would let a ProxyCommand redirect the connection, and `agent_path` would silently use $SSH_AUTH_SOCK. There is a test for exactly that, and it needs no server. Files go over SFTP rather than through a shell. The SSH exec protocol carries one command *string* that the far side parses, with no argv form at all, so a model-supplied path in a command line is unavoidably a quoting problem. Over SFTP a path is a path. Chat gains its kind, connection, project directory and mode; the first three are fixed once a chat has a message, because a transcript whose earlier turns ran somewhere else is not one conversation. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
81 lines
2.5 KiB
TOML
81 lines
2.5 KiB
TOML
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[project]
|
|
name = "lembas"
|
|
version = "0.4.0"
|
|
description = "LLeMbas - a Middle-earth themed web UI for OpenAI-compatible LLM endpoints"
|
|
readme = "README.md"
|
|
requires-python = ">=3.11"
|
|
license = { file = "LICENSE" }
|
|
authors = [{ name = "Jaroslav Benes", email = "admin@ecoposta.sk" }]
|
|
keywords = ["llm", "webui", "openai", "chat", "self-hosted"]
|
|
classifiers = [
|
|
"License :: OSI Approved :: GNU General Public License v3 (GPLv3)",
|
|
"Programming Language :: Python :: 3",
|
|
"Topic :: Communications :: Chat",
|
|
]
|
|
|
|
dependencies = [
|
|
"fastapi>=0.115",
|
|
"uvicorn[standard]>=0.32",
|
|
"jinja2>=3.1",
|
|
"sqlalchemy>=2.0",
|
|
"pydantic>=2.9",
|
|
"pydantic-settings>=2.6",
|
|
"httpx>=0.27",
|
|
"python-multipart>=0.0.12",
|
|
"argon2-cffi>=23.1",
|
|
"cryptography>=43.0",
|
|
"markdown-it-py>=3.0",
|
|
"mdit-py-plugins>=0.4",
|
|
"linkify-it-py>=2.0", # bare URLs in model output become links
|
|
"pygments>=2.18",
|
|
"nh3>=0.2.18",
|
|
"pypdf>=5.1", # PDF text extraction for attachments
|
|
"pillow>=11.0", # image validation and downscaling for vision
|
|
"typer>=0.12",
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
dev = [
|
|
"pytest>=8.3",
|
|
"pytest-asyncio>=0.24",
|
|
"ruff>=0.7",
|
|
]
|
|
# DuckDuckGo search. Optional because it brings a compiled HTTP client and an
|
|
# XML parser with it, and the other two search providers need only httpx, which
|
|
# is already a core dependency. Without this the provider is offered in the
|
|
# admin UI with an install hint rather than silently missing.
|
|
search = ["ddgs>=9.0"]
|
|
# Agent chats, which run their commands on a machine reached over SSH. Optional
|
|
# on the same terms as `search`: an instance that never turns agents on should
|
|
# not carry the dependency, and one that does gets told how to install it rather
|
|
# than finding the feature silently missing. `bcrypt` is what decrypts a
|
|
# passphrase-protected OpenSSH key -- without it, pasting one fails opaquely.
|
|
ssh = ["asyncssh[bcrypt]>=2.14"]
|
|
|
|
[project.scripts]
|
|
lembas = "lembas.cli:app"
|
|
|
|
[project.urls]
|
|
Homepage = "https://github.com/homer/LLeMbas"
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["src/lembas"]
|
|
|
|
[tool.ruff]
|
|
line-length = 100
|
|
target-version = "py311"
|
|
src = ["src", "tests"]
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "I", "UP", "B", "SIM", "C4"]
|
|
ignore = ["B008"] # FastAPI Depends() in defaults is idiomatic
|
|
|
|
[tool.pytest.ini_options]
|
|
testpaths = ["tests"]
|
|
asyncio_mode = "auto"
|
|
filterwarnings = ["ignore::DeprecationWarning"]
|