mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-09-10 18:22:20 +02:00
e5ab6322702a08e071d4efdac1a227e8c819b457
16
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
b19d327f03 |
fix(auth): derive the session cookie Secure flag from the request scheme (#6048)
* fix(auth): derive the session cookie Secure flag from the request scheme SECURE_COOKIES only marked the login cookie Secure when it was explicitly set to true, so an HTTPS login on an install that never set it handed out a session cookie the browser is happy to send back in cleartext. Unset now derives the flag from the request: the connection scheme, which uvicorn's proxy-headers middleware rewrites for the proxies it trusts, or X-Forwarded-Proto for a terminator that is not on a trusted address. That is the same test core/middleware.py already applies before sending HSTS, so the two stop disagreeing about whether a request arrived over TLS. An explicit true still forces the flag on and an explicit false turns it off for an install still answering on both HTTP and HTTPS. Strictly more Secure flags than before and never fewer. Empty counts as unset, because docker-compose pinned SECURE_COOKIES=false for every container; the compose files now pass the variable through unset, the way FASTEMBED_CACHE_PATH already does. The helper and its decision order come from #3799, which was closed for being too large to review and whose six replacement PRs dropped this fix. Part of #3803. * docs(setup): flag the leftover SECURE_COOKIES=false on upgrades The old default was false, so an install set up before scheme derivation can still carry an explicit SECURE_COOKIES=false in its own .env. That value stays authoritative, so HTTPS logins keep getting a non-Secure session cookie even after the tracked compose defaults are updated by a pull. Say so where people look: the security notes and the variable's own comment in .env.example. * docs(setup): align TLS guidance with scheme-derived cookies --------- Co-authored-by: Alexandre Teixeira <alexandremagteixeira@gmail.com> |
||
|
|
d0bf771f9d |
perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994)
* fix(static): vendor KaTeX and Mermaid instead of loading them from a CDN
index.html pulled katex.min.{js,css} and mermaid.min.js from cdn.jsdelivr.net on
every page load. For self-hosted software that is three problems at once: an
air-gapped or offline install renders no math and no diagrams at all, every
session announces its IP, User-Agent and Referer to a third party, and the "runs
on your own hardware" promise quietly isn't true.
static/lib/ already vendors highlight.js, docx, xlsx, mammoth, html2pdf and
qrcode, so the CDN usage was an inconsistency rather than a policy. Vendoring
also pins Mermaid, which was floating on the `11` tag, to 11.16.1.
Behaviour is unchanged: both libraries still load eagerly from <head>, just from
this machine.
- KaTeX goes in its own directory because its stylesheet resolves fonts with a
relative url(fonts/...), so the vendored CSS needs no rewrite. Only the .woff2
variants ship, matching static/fonts/, since a browser that supports woff2
never requests the .woff/.ttf alternatives the stylesheet also lists.
- The service worker precaches KaTeX and its fonts so offline math is typeset
rather than falling back to system glyphs, and CACHE_NAME is bumped. Mermaid
is left to the existing cache-first rule: at 3.5 MB, precaching it would mean
re-downloading it on every cache bump for a library most sessions never touch.
- Licence texts travel with the bundles in licenses/, following the convention
the repo already uses for OpenDyslexic and DeepResearch.
- .gitattributes turns the whitespace check off for static/lib/ so `git diff
--check` passes without stripping bytes from the published npm artifacts,
which would desync them from upstream.
* perf(markdown): load KaTeX and Mermaid on first use, not on every page load
Both libraries loaded eagerly from <head>, costing every session ~985 KB on the
wire (929 KB of that Mermaid) even though most chats contain neither a formula
nor a diagram. Measured on a cold profile via the Resource Timing API: JS bytes
per page load drop from 3,102,141 to 2,098,634, a saving of 1,003,507 bytes, and
third-party requests per load go from 3 to 0.
markdown.js now fetches each library the first time one is actually needed:
- renderMermaid() checks for an unprocessed mermaid fence before touching the
network, and re-queries the DOM after the load so a diagram replaced mid-stream
still renders.
- mdToHtml() is synchronous, so when KaTeX is not in yet it banks the math source
in an inert placeholder and schedules a flush that loads the library and swaps
the placeholders in. Once KaTeX is loaded it typesets inline exactly as before,
so callers that never call a render helper still get their math.
Both loaders memoise the promise rather than the module, so concurrent callers
share one fetch and a double trigger cannot start two loads; a failed load clears
the memo so the next formula retries instead of being poisoned for the session.
The flush is scheduled with setTimeout rather than requestAnimationFrame, which
is throttled to a stop in a background tab and never fires at all in a headless
browser, so math would have sat as plain source text until the tab was focused.
If neither library ever loads, math degrades to readable source text and diagrams
to their fence contents, rather than to nothing.
* fix(markdown): unescape & last so math entities survive intact
The math pass unescaped & before < and >. mdToHtml escapes the source
first, so a literal "<" typed inside a formula arrives here as "&lt;",
turns back into "<" on the ampersand pass, and is then eaten by the very next
one. Typing $a < b$ rendered as "a < b" instead of the literal text.
The code-block pass in the same function already unescapes & last; only the
math paths were the outlier, in all four of the copies this branch consolidated
into pushMath(). Reordering to match makes them consistent and clears the
js/double-escaping alert CodeQL raised on this PR.
Math containing a genuinely typed "<" is unaffected, which is why this went
unnoticed for so long. Covered by a regression test asserting both cases.
* fix(markdown): decode entity-spelled math in one pass
mdToHtml escapes the source before the math pass, so a typed "<" reaches
the delimiters as "<" and a typed "<" reaches them as "&lt;".
KaTeX has no entity syntax and reads the leftover "&" as an alignment
marker, so "$a < b$" rendered as a red .katex-error instead of a
formula, on both the inline and the deferred path.
Chained replaces cannot fix it in either order: unescaping "&" first
lets the next pass eat the "<" it just wrote, and unescaping it last
leaves the entity spelling for KaTeX to choke on. One alternation,
longest form first, decodes every spelling and never rescans its own
output.
The tests now drive the vendored KaTeX build rather than a renderer that
echoes its input, which is why the old assertion looked correct.
* fix(document): typeset deferred math before the PDF export
exportAsPdf() renders the document into a detached container and hands
it straight to html2pdf. On a page where KaTeX has not loaded yet,
mdToHtml() returns pending placeholders and schedules a flush scoped to
document, which never reaches a node that was never attached, so the
PDF printed raw formula source.
Render the container's own math first. renderMath() returns immediately
without fetching anything when there is nothing pending, so a document
with no formulas still exports without pulling KaTeX.
|
||
|
|
04b8829fb2 |
perf(frontend): share one cached fetch for /api/auth/settings and /api/tools (#5997)
* perf(frontend): share one cached fetch for settings and tools /api/auth/settings was fetched independently by eight modules and /api/tools by three on a single load — 4 and 3 requests measured — and any two of those callers could observe a different snapshot of the same object. chatRenderer.js is imported under three different ?v= query strings, so it is three separate module instances each issuing its own /api/tools request. appConfig.js holds one promise per endpoint, so concurrent and later callers share it. Every writer invalidates: the settings panel routes its 16 saves through a single helper, and the admin tools save drops both snapshots because that route persists disabled_tools into the same settings store. A rejected fetch clears its slot rather than being memoised, so one blip at boot cannot leave keybinds, TTS and the search provider on defaults for the session. The settings panel keeps reading directly: it is the writer and edits what it reads, so it must see authoritative state. Cold load, Resource Timing: /api/auth/settings 4 -> 1, /api/tools 3 -> 1, and 0 settings requests on the first load after a login, because the cache now consumes the sessionStorage prefetch that login.html writes. Fixes #5996 * fix(admin): refetch tool state when the Agent Tools panel opens The shared cache made Admin > Tools render the boot snapshot on every reopen. Its save posts the whole disabled list rebuilt from the checkboxes, so a tool disabled out of band (the manage_settings tool, another tab) came back enabled on the next unrelated toggle. Reproduced against the running app: with api_call disabled by a separate client, toggling app_api off posted ['app_api'] and silently re-enabled api_call. The panel now drops the shared entry before reading it, which restores what dev does today and keeps the startup read that chatRenderer.js shares. Cold load is still 1 request each for /api/auth/settings and /api/tools, and the panel costs the same 2 requests per open as dev. * fix(static): preserve concurrent tool setting changes --------- Co-authored-by: Alexandre Teixeira <alexandremagteixeira@gmail.com> |
||
|
|
895bf896e3 |
refactor(static): load the image editor on first use (#6074)
galleryEditor.js and its js/editor/ graph are 54 modules / 576 KB, and gallery.js imported them statically. Every page load paid for the whole image editor even though most sessions never open the Edit tab: 54 of the 173 JS files on a cold load, and 576 KB of the decoded JS, were for a panel that was never displayed. Add a small panel-loader registry (static/js/panels.js) that imports a panel's module on first use and memoises the promise, so a double-click cannot start two loads and a failed load can still be retried. Convert the image editor to it, and route the two existing dynamic imports in chat.js and chatRenderer.js through the same entry so all three call sites share one module instance instead of two. closeEditor() and isEditorOpen() stay synchronous: if the module was never loaded there is no edit session to close and none can be open. The service worker keeps precaching the editor, in a separate PANEL_PRECACHE list, so the panel stays available offline even though index.html no longer loads it. The two lists now serve different purposes and the header comment says so. |
||
|
|
cc42f38a89 |
fix(ci): match the screenshot checkbox by wording, not emphasis (#6073)
The PR-description check folded the template's asterisks into the pattern, so a ticked box written without them read as unchecked while rendering identically on the PR page. `ready for review` was silently withheld and the bot reported missing visual evidence even with screenshots attached, with no way to tell from the rendered PR what was wrong. The two attestations directly above it already anchor on the wording alone. This one now does the same, accepting `**bold**`, `*italic*`, `__underscores__` and plain text. Fixes #6071 |
||
|
|
2e2bb5231e |
fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032)
* fix(mcp): stop assuming http://localhost:7000 for the OAuth callback The MCP OAuth callback origin is wrong on any install not reached at http://localhost:7000, and on Docker it cannot be corrected at all. Three sites, one assumption: - The redirect base fell back to a fixed port 7000. The app binds APP_PORT natively (app.py, launcher.py) and the macOS launcher defaults to 7860, where 7000 is AirPlay Receiver, so the callback lands on another service entirely. The fallback now follows APP_PORT. The hostname stays localhost rather than internal_api_base()'s 127.0.0.1: this URI is registered with the authorization server, so changing the host would invalidate the registrations that already exist. - The paste-back form hardcoded an http:// action. Serving the page over HTTPS, Chrome raises its insecure-form interstitial, and overriding that posts plain HTTP at a TLS port, which fails too. Either way the authorization code never reaches Odysseus. The action now carries the scheme the request arrived on. - OAUTH_REDIRECT_BASE_URL is the only fix available to a Docker install, because the container listens on 7000 and cannot see the host port map, but compose never forwarded it and nothing documented it. Both fixed. * fix(mcp): make the paste-back form action relative and export APP_PORT Answers the review on #6032. Three of the fixes did not survive contact with the deployments they targeted. - The form action derived its scheme from request.url.scheme. uvicorn only honours X-Forwarded-Proto from a peer inside --forwarded-allow-ips, which defaults to 127.0.0.1; the Dockerfile CMD sets no override, so a proxy arriving over the Docker bridge is untrusted and the scheme stays http. That is mixed content on exactly the HTTPS installs paste-back exists for. A relative action is resolved by the browser against the origin the page came from, which is right under every proxy setup, and it drops the Host header from the page entirely. - The APP_PORT fallback never fired for the shipped launchers. start-macos.sh, the generated .app launcher and launch-windows.ps1 all pass --port to uvicorn without putting the value in the environment, so the motivating case, macOS on 7860, still registered localhost:7000. Each now exports it. internal_api_base() and companion pairing read APP_PORT too and were wrong in the same way. - .env.example pointed Google MCP servers at OAUTH_REDIRECT_BASE_URL. add_server writes Desktop App credentials, and Google only accepts loopback redirects for that client type, so a public origin comes back as redirect_uri_mismatch. The variable is for the DCR flow; Google stays on the loopback default and finishes remotely through paste-back. The Host header is no longer reflected into the page, so the escaping regression test asserts its absence instead of its escaping. |
||
|
|
60bed54703 |
fix(chat): centre the agent-thread terminating dot on the rail (#6059)
The timeline's terminating dot used a single left offset (-17px) at both breakpoints, but the thread's padding-left differs (22px desktop, 18px mobile) and the step dots already carry a per-breakpoint offset. The 6px dot therefore landed 2px right of the 2px rail on desktop and 2px left of it on mobile, which is the visible kink under an expanded last step. Derive each offset from the rail's centre instead: the rail sits at left:5px and is 2px wide, so the dot's left edge belongs at 3px, giving 3px - padding-left per breakpoint. |
||
|
|
f9235ebbf1 |
docs(setup): document the HTTP/2 reverse-proxy setup (#6046)
* docs(setup): document the HTTP/2 reverse-proxy setup The "private or proxied deployments" section named Caddy, nginx and Traefik but gave no runnable config, and never mentioned the main reason to bother: the frontend is unbundled ES modules, so a page load is a few hundred small same-origin requests. Over HTTP/1.1 the 6-connection cap serialises those into dozens of round trips, which is invisible on localhost and dominates load time over a LAN or VPN. Adds a five-step setup you can paste: a Caddyfile for each of the three ways people reach these boxes (public domain, Tailscale, own certificate), how to run the proxy in the foreground and then as a service, the .env keys that have to follow the origin, and a curl one-liner to confirm HTTP/2 actually negotiated. Also covers what bites when moving an existing install behind TLS: SECURE_COOKIES applying regardless of the scheme the request arrived on, OAUTH_REDIRECT_BASE_URL still defaulting to localhost because the MCP redirect is registered up front rather than derived per request, and HSTS being host-wide and port-agnostic. Notes that a custom HTTPS port does not stop Caddy binding port 80 for the redirect, which is the failure I hit first. Docs only — no code change is needed to run behind HTTP/2 today. * docs(setup): clarify HTTP/2 and origin migration --------- Co-authored-by: Alexandre Teixeira <alexandremagteixeira@gmail.com> |
||
|
|
c2b9666def |
perf(frontend): preload the two first-paint Fira Code faces (#5992)
The app font faces are declared in static/style.css, so the browser only discovers FiraCode-Regular.woff2 and FiraCode-SemiBold.woff2 once the stylesheet has parsed. On a cold load they start about 145 ms in, behind the module graph. font-display: swap keeps that from blocking render, so the cost is a visible swap rather than a stall, but the fetch can start immediately instead. Two preload hints move the request into the head. Measured cold on a scratch instance with an empty cache, three runs per arm: request start 142-203 ms becomes 15-19 ms, response end 174-248 ms becomes 46-63 ms. The total request count is unchanged and each face is still fetched exactly once. crossorigin is required even though these are same-origin: fonts are always fetched in CORS mode, and without it the preload is discarded and the font fetched again. Dropping the attribute produces four font entries in the Resource Timing list instead of two. Only Fira Code 400 and 600 are preloaded. They are the only faces first paint uses. Inter, OpenDyslexic and Fira Code 300 stay unloaded on both desktop and mobile, with or without a saved font preference. |
||
|
|
663d6879b7 |
fix(ui): stop the whirlpool spinner animating when it is never attached (#5990)
_drawWhirlpool re-armed requestAnimationFrame forever whenever its element had never been connected to the document. The grace period is there so a spinner can keep drawing between start() and the caller appending the element, but it had no deadline: while the element has never been connected _wpWasConnected stays false, so the guard stays true and the else branch is unreachable. Any caller that starts a spinner and then takes an early return, such as an aborted request or a panel that resolved from cache, leaves a loop redrawing an 84-segment spiral into a detached canvas at one frame per displayed frame until the tab closes. Put a 2 second deadline on the grace period. Callers append in the same task as start(), so that is far more slack than any of them need. A spinner that is actually in the document is unaffected. Two supporting changes in the same file: - Both self-terminate paths now call stop() instead of setting isRunning directly, so termination always runs one cancelAnimationFrame and never depends solely on inferring DOM connectivity. Both draw functions bail at the top when they are no longer running, and _requestFrame() clears rafId as the callback enters so it is a truthful "a frame is pending" flag. - start() arms a visibilitychange listener and stop() removes it. A hidden tab cancels the pending frame, a re-shown tab re-arms it. Chrome throttles background rAF but does not reliably stop the canvas work, and owning the listener from start/stop means a dead spinner never leaves one behind. Adds tests/test_spinner_stops_when_never_attached_js.py, which drives the real module under node with a fake clock and a manual frame pump. It covers all four exits and, importantly, the converse: a spinner that is attached keeps running well past the grace window. |
||
|
|
3bea7a53ee |
fix(email): derive the Google OAuth redirect URI scheme from the request (#5995)
Both the authorize and callback routes built the redirect URI with a hardcoded `http://` and the Host header. Behind any TLS terminator that produces `http://host:443/api/email/oauth/google/callback` — the wrong scheme and, on a split-port setup, a dead port. Google then refuses the authorize request or the token exchange, so OAuth email is unusable on every HTTPS deployment unless GOOGLE_OAUTH_REDIRECT_URI is pinned by hand. uvicorn's proxy-headers middleware already rewrites the scheme from X-Forwarded-Proto for trusted proxies (on by default, trusting 127.0.0.1), so request.url.scheme is correct both directly and behind a proxy. Google requires the callback's redirect_uri to match the authorize one exactly, so both sites change together. An explicit GOOGLE_OAUTH_REDIRECT_URI still wins, unchanged. |
||
|
|
00de474fef |
fix(notes): fail closed when an unauthenticated request reaches owner-scoped routes (#4062)
* fix(notes): fail closed when an unauthenticated request reaches owner-scoped routes The notes CRUD routes resolved the acting user with bare get_current_user(). A request that reached them with no identity (auth-middleware regression, SSRF from a sibling service) came through as user=None — which every query treats as the single-user mode: list all accounts' notes, read/update/ delete/pin/archive any row, reorder globally. Resolve the owner through require_user() instead, which already encodes the right policy: 401 when auth is configured, while the documented anonymous modes (AUTH_ENABLED=false, LOCALHOST_BYPASS on loopback, unconfigured first-run) still resolve to the single-user path. fire-reminder in the same file already gated this way; the CRUD routes now match, and the inline require_user import there is folded into the module import. Extracted from #2940 (stabilization slice). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(notes): drive fail-closed test via ASGITransport, not sync TestClient The focused fail-closed test hung at `TestClient(app).get(...)` on some environments. Starlette's sync TestClient runs the app in a background event-loop thread (anyio blocking portal) and then dispatches each sync endpoint onto a second worker thread; that handshake deadlocks on certain anyio/httpx/platform combos. The identity injection also used BaseHTTPMiddleware (@app.middleware("http")), the other known TestClient deadlock source. Switch to the repo's existing httpx.ASGITransport + AsyncClient idiom so the whole request runs on the test's own event loop (no portal thread, no BaseHTTPMiddleware). Identity now comes from a pure-ASGI shim that writes the same request.state fields the real auth middleware sets, and a non-loopback client peer keeps require_user's loopback fall-throughs out of the picture. Same assertions and coverage; production code unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
9ca4d4e17c |
Merge pull request #3567 from shdrs/fix/no-scroll-snapping
fix(docs): remove intrusive scroll-snap UX on landing page |
||
|
|
9552d001e4 | Merge branch 'dev' into fix/no-scroll-snapping | ||
|
|
a5fab12546 |
fix(cookbook): don't infer server OS from the browser's user-agent (#3223)
_getPlatform('local') fell back to navigator.userAgent to decide the
*server's* platform. On a Mac/Linux homeserver opened from a Windows
browser this returned 'windows', so the GGUF serve builder emitted the
Windows python-only shape (`python -m llama_cpp.server`, no
`llama-server ||` fallback). That command fails on the Unix host with
"No module named llama_cpp" even though native llama-server is installed,
and the diagnosis then misleadingly tells the user to pip-install
llama-cpp-python.
Trust the server-side hardware probe over the user-agent: a non-empty
probe backend (metal/cuda/rocm/cpu_*) means a Unix server; local Windows
instead carries platform:"windows" which already sets _envState.platform
and short-circuits. Only fall back to the browser hint when there is no
server-side signal at all. Keeps #1389/#2961's local-Windows path intact.
Fixes #3221
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|
|
fcd53c7e92 |
Load .env in start-macos.sh for APP_PORT and APP_BIND (#1008)
* Load .env in start-macos.sh for APP_PORT and APP_BIND Parses .env at startup (consistent with how app.py reads it via python-dotenv) so APP_PORT and APP_BIND are honoured without having to retype them on the command line every run. Resolution order: shell env (ODYSSEUS_PORT / ODYSSEUS_HOST) → .env (APP_PORT / APP_BIND) → built-in defaults. Existing ODYSSEUS_* shell overrides are fully preserved. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * Document .env support for APP_PORT and APP_BIND in macOS section Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |