Clawbox UI - #15
Clawbox UI#15yalexx wants to merge 12 commits into
Conversation
… steps - Move desktop UI to / as the default landing page, setup wizard at /setup - Add Security (password/hotspot) and Telegram steps to setup wizard (6 steps total) - Deduplicate getGatewayToken() into shared gateway-proxy module - Update Chromium icon to proper Chromium SVG - Parallelize browser lock file cleanup - Move system update button from setup to settings app - Remove stats from DoneStep (already in desktop UI) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Remove DoneStep from wizard — completing/skipping Telegram marks setup complete and redirects to desktop UI - Setup wizard now 5 steps: WiFi, Update, Security, AI Model, Telegram - Center setup cards vertically on desktop Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…s check Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add loading spinner to UpdateStep while checking for updates - Show "System Up to Date" with green indicator when on latest version - Fix OpenClaw version comparison (includes vs exact match) - Fix double "v" prefix in sidebar version display - Move update modal to top-level so it works from any settings tab - Add Discord Community link to About section - Use real version in About instead of hardcoded v2.2.3 - Remove /boot/efi from storage, interfaces from Network, network/processes from System - Default wallpaper opacity to 50% Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. 🗂️ Base branches to auto review (4)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughThis PR restructures the application's UI/UX architecture by moving the desktop interface from the setup page to the main page, adding desktop window management with persistent state, installing VNC remote access, GitHub CLI, and AI tools via the installer, reconfiguring gateway authentication to token-based mode, and refactoring terminal server lifecycle management. Changes
Sequence DiagramsequenceDiagram
participant Client as Browser Client
participant SetupAPI as Setup API
participant MainPage as Main Page (Desktop)
participant WindowMgr as Window Manager
participant Installer as Installer Service
Client->>SetupAPI: GET /setup-api/setup/status
alt Setup Incomplete
SetupAPI-->>Client: setup_complete: false
Client->>SetupAPI: Redirect to /setup
else Setup Complete
SetupAPI-->>Client: setup_complete: true
Client->>MainPage: Render Desktop
end
MainPage->>SetupAPI: GET /setup-api/preferences?all=1
SetupAPI-->>MainPage: Return saved preferences (apps, wallpaper, windows, etc.)
MainPage->>MainPage: Restore desktop state from localStorage
Client->>WindowMgr: Launch app (click desktop icon)
WindowMgr->>WindowMgr: Create window, manage z-index
WindowMgr->>MainPage: Update window state
MainPage->>SetupAPI: POST /setup-api/preferences (debounced save)
SetupAPI-->>MainPage: Persisted
Client->>MainPage: Drag icon / manage desktop
MainPage->>MainPage: Update icon grid positions
MainPage->>SetupAPI: POST /setup-api/preferences (sync)
alt User accesses VNC
Client->>WindowMgr: Click VNC app
WindowMgr->>SetupAPI: VNC window opens
SetupAPI-->>WindowMgr: X11 stream via noVNC
end
alt User triggers system update
Client->>SetupAPI: POST /setup-api/update/run
SetupAPI->>Installer: Run update steps (including vnc_install)
Installer-->>SetupAPI: Poll /setup-api/update/status
SetupAPI-->>Client: Update progress
Client->>Client: Reload on completion
end
Estimated code review effort🎯 4 (Complex) | ⏱️ ~70 minutes Possibly related PRs
Suggested labels
Poem
🚥 Pre-merge checks | ✅ 1 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (1 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
✅ Test Report
|
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
- Add ChatPopup component with direct WebSocket gateway connection, draggable window, and HTTP-safe UUID fallback (crypto.randomUUID requires HTTPS secure context) - Implement tamagotchi game engine with life stages (egg → baby → child → teen → adult), 4-heart hunger/happiness, discipline, poop/sickness mechanics, evolution tree, and hall of fame - Refactor Mascot to use tamagotchi engine with context-sensitive actions (meal/snack/play/scold/medicine/lights off) - Fix OpenClaw app: proxy through Next.js for token injection, auto-retry health check during gateway startup - Fix sudo from systemd: remove NoNewPrivileges=true, add sudoers file for passwordless service management - Fix power/hotspot routes: use full /usr/bin/sudo paths - Add gateway ws-config endpoint for chat popup token retrieval - Add temperature and GPU stats to system API - Hide clock on mobile, anchor power menu to bottom-right Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Add VNC app with noVNC integration and start-vnc script - Add noVNC type declarations - Refactor config-store to use SQLite (better-sqlite3) - Simplify installer with cleaner structure - Update ChromeWindow icon prop, credentials and reset routes - Update updater and dependency lockfile Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- New ChatApp component: full-screen chat window (replaces floating popup) - Mascot tap opens chat as proper app window - Image attachment support (gallery picker + camera capture) - Vision attachments sent via gateway WebSocket - Auto-detect ws/wss protocol for HTTPS compatibility - HTTPS support (self-signed certificate) - Self-signed cert at data/certs/ (10-year, clawbox.local + SANs) - production-server.js serves HTTPS on port 443 alongside HTTP - WSS proxy using ws library (bun TLS upgrade workaround) - PWA enhancements - Install button in SystemTray power menu - Updated manifest with display_override, fullscreen support - Service worker v2: cache-first for assets, network-first for pages - Fullscreen splash on mobile browser load - Mobile optimizations - Settings app: responsive sidebar → full-screen nav on mobile - Android back button handler (closes windows/menus) - Safe area insets (notch, rounded corners, taskbar) - Pull-to-refresh prevention (overscroll-behavior) - Dynamic viewport height (100dvh) for keyboard handling - interactive-widget: resizes-content viewport meta - Haptic feedback on interactions - Slide-up animation for mobile windows - Fullscreen toggle button on mobile taskbar - Test fixes (864/864 passing) - gateway.test.ts: fix import path for catch-all route - gateway-proxy.test.ts: fix token assertion - openclaw-config.test.ts: update for sudo + 60s timeout - config-store.test.ts: align with sync fs implementation
…740) * security: close the CodeRabbit deep-scan findings that still hold on beta The 2026-09-05 scan of main reported 23 findings; each was re-verified against beta before anything changed. Five were already fixed on beta (#1 #2 #5 #8 #18), three are the appliance's documented design (#3 #13 #15), two need a design decision rather than a patch (#12 the self-updating root steps, #16 system_power via the bearer) and are deferred with their designs written up. This closes the rest: - #21/#8: root units (clawbox-ap, ap-watchdog, the NM failover hook, first-boot VNC, recover) run the root-owned /usr/local/libexec/clawbox copies and load /etc/clawbox/network.env, never the clawbox-owned tree; clawbox-heartbeat runs as User=clawbox; a class-wide test pins the rule. - #11: the Files API refuses to rename or delete a protected container (data/, the checkout, ~/.config, the browse root) — protected_container. - #19: the MCP path guard judges the canonical path (nearest existing ancestor) as well as the typed one, and the file tools open the vetted target with O_NOFOLLOW. - #17: the webapp document carries a sandbox CSP wherever it is opened (shipped through next.config.ts, since a route header is dropped in production), and installed_* preference writes are owner-only. - #20/#22: clawkeep restore derives every destination on the box and refuses the manifest's before anything moves; link members must resolve inside the staging root; restore/unpair/snapshot/encryption/reset-state are owner-only and same-origin. - #7: CF-Connecting-IP and its siblings are stripped unless the socket peer is loopback (cloudflared's), so a LAN client cannot pick its lockout bucket. - #4: regex code search is gone (400 regex_unsupported). - #6: uploads are bounded by a free-space reserve with busboy limits and partials unlinked; the attachments route gets the same teardown deferral. - #14: the Kokoro/Whisper sockets are 0600 with SO_PEERCRED, and Kokoro's output path is confined to a .wav regular file under /tmp. - #9 (part): the MCP server scrubs CLAWBOX_MCP_TOKEN from its environment at startup; allow_dangerous is documented as a typo override, not consent. - #10: issue-triage/pr-review validate the model's JSON on both transports, derive labels from fixed tables and sanitise comment text. - #23: e2e-install writes repository secrets only off pull_request events. - #1/#5 residuals: setup/complete checks the session in-handler; the middleware matcher no longer skips /fonts/ and /images/. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SuyrrYnKgrUkBXECWqW1gb * fix: vouch for the path at the two sinks CodeQL flagged The multipart cleanup unlinked paths whose containment check governed the write inside the promise, not the catch block; and the dangling-link resolver lstat/readlink'd a name straight off the caller's path. Both now resolve and prefix-check right before the call, the shape safePath already uses (js/path-injection alerts 519-521). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SuyrrYnKgrUkBXECWqW1gb * fix: address CodeRabbit's review of the security sweep - e2e-install: the one job names its Environment by event (e2e-credentials off pull_request, an empty e2e-pull-request on one), documented for the owner; the schema strip for the SDK transport is schema-aware and covers Anthropic's whole unsupported set, and the local validator refuses any constraint it cannot check so no cap is silently unenforced. - clawkeep: a Hermes sessions asset that omits sqlite still retires the sidecars (the box's own flag wins); OPENCLAW_STATE_DIR placeholders count as unset; the no-state fallback matches both CLI message forms, with one shared recorded-CLI fixture. - install.sh: a libexec copy that did not land is never a success — collected, recorded as root_libexec, and the units that name the copies are not written over it. - root-unit tests parse User= (User=root is root) and refuse /home/clawbox anywhere in a directive value; the code search route refuses a non-string pattern; notebook_edit has its symlink regression case. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SuyrrYnKgrUkBXECWqW1gb * test: give the libexec test in root-steps both ceilings It runs install_root_libexec under a real bash, and the timeout-hygiene rule (test-timeout-hygiene.test.ts) asks every spawning suite for a declared testTimeout and hookTimeout — the one CI failure on the previous commit. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SuyrrYnKgrUkBXECWqW1gb --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Summary by CodeRabbit
Release Notes
New Features
Improvements
Configuration