7456525d19
Four pieces of work.
**Installable.** A manifest carrying the instance name, PWA icons rasterised
from the existing mark at design time, a service worker and a themed offline
page. The worker caches the shell only and bails out on /api/, /auth/, /admin/
and anything accepting text/event-stream -- passing a reply stream through a
worker turns it into one delivery at the end, or nothing. It is served from
GET /sw.js rather than the static mount because a worker's scope is the path it
came from.
**Send and Stop are one button.** They were two, and the hidden one was never
hidden: `.btn` is display: inline-flex, which outranks the browser's own
`[hidden] { display: none }`, so Stop sat permanently beside Send. app.css now
forces the attribute to win -- every control toggled with `hidden` depended on
that -- and the composer renders one button carrying both icons, with ui.js
flipping data-composer-action and the type with it.
**Audio.** Speech to text and text to speech against any OpenAI-shaped
/v1/audio/* endpoint: dictate into the composer, have a reply read out.
Instance settings in Admin, per-reader overrides in Settings, with the voice
list discovered from the server where it offers one. Recorded audio is capped
and never written to disk -- it is not an attachment, it has no owner, and
nothing would ever sweep it.
**Web search, as a tool.** This is the tool loop PLAN.md described as the real
work: one reply is now a bounded sequence of requests rather than one. The model
asks, the tool runs, the result goes back and it is asked again, up to three
rounds. Providers are DuckDuckGo (no setup), SearXNG and Firecrawl.
Two decisions worth stating. Tools are only offered to models flagged `tools`,
because an endpoint without support rejects the whole request rather than
ignoring the array -- the same reason images only reach models flagged
`vision`. And tool results are not replayed as context on the next turn, for the
same reasons reasoning is not: the answer already contains what the model made
of them, and replaying stale results into every later request wastes the window
and reliably sends a small model into a search loop. The sources stay visible in
the transcript instead.
Search results are untrusted third-party text and are treated as such: escaped,
and only http/https URLs rendered as links.
338 tests, ruff clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
167 lines
5.7 KiB
Python
167 lines
5.7 KiB
Python
"""Per-user preferences set from the browser."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import contextlib
|
|
import logging
|
|
|
|
from fastapi import APIRouter, Body, Form, Request, status
|
|
from fastapi.responses import RedirectResponse, Response
|
|
|
|
from lembas.api.deps import Db, RequiredUser
|
|
from lembas.config import settings
|
|
from lembas.security.passwords import hash_password, validate_password, verify_password
|
|
from lembas.security.sessions import COOKIE_NAME, create_session, revoke_all_for_user
|
|
|
|
log = logging.getLogger(__name__)
|
|
|
|
router = APIRouter(prefix="/api/preferences", tags=["preferences"])
|
|
|
|
THEMES = ("moria", "shire")
|
|
|
|
|
|
@router.post("/theme")
|
|
async def set_theme(db: Db, user: RequiredUser, theme: str = Body(..., embed=True)) -> dict:
|
|
"""Mirror the browser's theme choice onto the account.
|
|
|
|
localStorage is the source of truth for the current tab; this is what makes
|
|
the choice follow the user to another browser, and what lets the server
|
|
render the right theme on first paint instead of flashing the default.
|
|
"""
|
|
if theme not in THEMES:
|
|
return {"ok": False, "detail": "Unknown theme."}
|
|
|
|
# Replaced rather than mutated in place: SQLAlchemy only reliably detects
|
|
# a change to a JSON column when the whole value is reassigned.
|
|
user.settings_json = {**(user.settings_json or {}), "theme": theme}
|
|
db.commit()
|
|
return {"ok": True, "theme": theme}
|
|
|
|
|
|
@router.post("/default-model")
|
|
async def set_default_model(
|
|
db: Db, user: RequiredUser, model_id: str = Form("")
|
|
) -> Response:
|
|
"""Choose which model new chats start with.
|
|
|
|
An empty value clears the choice and falls back to the instance default.
|
|
Validated against what this user can actually reach, so a model they lose
|
|
access to cannot linger as a preference that silently fails later.
|
|
"""
|
|
from lembas.security import permissions
|
|
|
|
model_id = model_id.strip()
|
|
if model_id and not permissions.can_use_model(db, user, model_id):
|
|
return RedirectResponse(
|
|
"/settings?error=That+model+is+not+available+to+you.", status_code=303
|
|
)
|
|
|
|
settings_map = {**(user.settings_json or {})}
|
|
if model_id:
|
|
settings_map["default_model"] = model_id
|
|
else:
|
|
settings_map.pop("default_model", None)
|
|
user.settings_json = settings_map
|
|
db.commit()
|
|
|
|
return RedirectResponse("/settings?saved=Default+model+updated.", status_code=303)
|
|
|
|
|
|
@router.post("/audio")
|
|
async def set_audio(
|
|
db: Db,
|
|
user: RequiredUser,
|
|
voice: str = Form(""),
|
|
speed: str = Form(""),
|
|
language: str = Form(""),
|
|
autoplay: bool = Form(False),
|
|
) -> Response:
|
|
"""Per-reader audio choices, overriding the instance defaults.
|
|
|
|
The voice is deliberately not checked against the discovered list. Voices
|
|
come and go when a speech server is reconfigured, and rejecting a saved
|
|
preference because a list fetched a moment ago did not mention it would be
|
|
a confusing failure with no obvious fix.
|
|
"""
|
|
chosen: dict[str, object] = {"autoplay": autoplay}
|
|
if voice.strip():
|
|
chosen["voice"] = voice.strip()[:120]
|
|
if language.strip():
|
|
chosen["language"] = language.strip()[:16]
|
|
if speed.strip():
|
|
# An unreadable speed leaves the default in place rather than failing:
|
|
# nothing else on the form should be lost to a typo in one field.
|
|
with contextlib.suppress(ValueError):
|
|
chosen["speed"] = min(max(float(speed), 0.25), 4.0)
|
|
|
|
# Whole-dict reassignment: an in-place edit of a JSON column is not
|
|
# reliably detected as a change.
|
|
user.settings_json = {**(user.settings_json or {}), "audio": chosen}
|
|
db.commit()
|
|
return RedirectResponse("/settings?saved=Audio+preferences+updated.", status_code=303)
|
|
|
|
|
|
@router.post("/password")
|
|
async def change_password(
|
|
request: Request,
|
|
db: Db,
|
|
user: RequiredUser,
|
|
current_password: str = Form(...),
|
|
new_password: str = Form(...),
|
|
confirm_password: str = Form(...),
|
|
) -> Response:
|
|
"""Change your own password.
|
|
|
|
Every other session is revoked on success. If the reason for changing a
|
|
password is that someone else knows it, leaving their session alive would
|
|
defeat the point.
|
|
"""
|
|
|
|
def back(message: str, ok: bool = False) -> Response:
|
|
from urllib.parse import quote
|
|
|
|
field = "saved" if ok else "error"
|
|
return RedirectResponse(
|
|
f"/settings?{field}={quote(message)}", status_code=status.HTTP_303_SEE_OTHER
|
|
)
|
|
|
|
if not verify_password(current_password, user.password_hash):
|
|
log.info("failed password change for %s: current password wrong", user.email)
|
|
return back("Your current password is not correct.")
|
|
|
|
if new_password != confirm_password:
|
|
return back("The new passwords do not match.")
|
|
|
|
if (problem := validate_password(new_password)) is not None:
|
|
return back(problem)
|
|
|
|
if verify_password(new_password, user.password_hash):
|
|
return back("That is already your password.")
|
|
|
|
user.password_hash = hash_password(new_password)
|
|
db.commit()
|
|
|
|
revoke_all_for_user(db, user)
|
|
token = create_session(
|
|
db,
|
|
user,
|
|
user_agent=request.headers.get("user-agent", ""),
|
|
ip_address=request.client.host if request.client else "",
|
|
)
|
|
log.info("password changed for %s; other sessions revoked", user.email)
|
|
|
|
# revoke_all_for_user killed this session too, so hand back a fresh cookie
|
|
# -- otherwise changing your password would sign you out of the tab you are
|
|
# standing in.
|
|
response = back("Password changed. Any other sessions have been signed out.", ok=True)
|
|
response.set_cookie(
|
|
COOKIE_NAME,
|
|
token,
|
|
max_age=settings.session_ttl,
|
|
httponly=True,
|
|
samesite="lax",
|
|
secure=False,
|
|
path="/",
|
|
)
|
|
return response
|