Commit Graph

4934 Commits

Author SHA1 Message Date
diegosouzapw
1196d08aad test(mitm): handlers + targets + detection unit tests (F3)
- mitm-handler-base: hookBufferStart returns InterceptedRequest with
  sanitized headers, extractSourceModel parses body.model, writeError
  emits JSON with sanitized message (Hard Rule #12).
- mitm-handler-<id>: nine per-agent happy-path tests (antigravity,
  kiro, copilot, codex, cursor, zed, claude-code, open-code) exercise
  full intercept() with mocked fetch via _mitmHandlerHarness.ts;
  asserts mapped model is forwarded and AgentBridge correlation
  headers are present. Trae test confirms intercept() rejects with a
  structured error.
- mitm-targets-resolve: ALL_TARGETS contains 9 entries; resolveTarget
  is case-insensitive and returns null for unknown hosts.
- mitm-targets-route: bypass > target > passthrough precedence
  validated against representative hostnames.
- mitm-detection: DETECTORS covers every AgentId; detectAgent never
  throws and returns DetectionResult-shaped objects for all probes.
2026-05-27 22:33:56 -03:00
diegosouzapw
1ca703657a feat(cli): add shared CLI UI components — CliToolCard/ConceptCard/ComparisonCard/BaseUrlSelect/ApiKeySelect/ManualConfigModal + useToolBatchStatuses hook (plan 14 F4) 2026-05-27 22:32:27 -03:00
diegosouzapw
f211fcf509 merge: F7 enforce wiring (chatCore PRE/POST + combo soft penalty + spendRecorder) 2026-05-27 22:23:33 -03:00
diegosouzapw
c04aec0550 merge: F5 ComplianceTab actor filter + CompressionLogTab namespace fix 2026-05-27 22:23:31 -03:00
diegosouzapw
14436c6051 merge: F4 Activity page + audit-log level=high filter + delete AuditLogTab 2026-05-27 22:23:30 -03:00
diegosouzapw
d78e33858d test(quota): cover enforce 7 scenarios + spendRecorder fail-open (B/F7)
quota-enforce.test.ts — 8 assertions:
  - Scenarios 1/7: fail-open when DB unavailable (no pool, store errors).
  - Scenarios 2-6: generous/strict/soft/burst/cap-absolute via fairShare integration.
  - Extra: Promise.all with multiple inputs always resolves to valid kind shape.
quota-spend-recorder.test.ts — 5 assertions:
  - Fire-and-forget timing, silent no-op for unknown keys, rejection catch,
    no-logger path, usd cost type accepted.
2026-05-27 22:17:44 -03:00
diegosouzapw
891cd0b256 feat(open-sse): apply QUOTA_SOFT_DEPRIORITIZE_FACTOR in combo scoring (B/F7)
Adds exported constant QUOTA_SOFT_DEPRIORITIZE_FACTOR (default 0.7, env override).
Extends AutoProviderCandidate with optional quotaSoftPenalty?: boolean field.
scoreAutoTargets() multiplies score by the factor when quotaSoftPenalty === true,
deprioritizing over-fair-share keys under soft policy without fully blocking them.
2026-05-27 22:17:36 -03:00
diegosouzapw
6d81a048b6 feat(open-sse): wire quotaShare PRE/POST hooks in chatCore handler (B/F7)
PRE-hook (before executor dispatch):
  - Calls enforceQuotaShare via dynamic import (lazy load, fail-open).
  - Returns 429 JSON via buildErrorBody() when decision.kind === 'block' (B25).
  - Sets quotaSoftDeprioritize=true when decision.deprioritize=true (B17).
POST-hook (after successful response):
  - Calls scheduleRecordConsumption for both streaming and non-streaming paths.
  - Fire-and-forget via setImmediate; never blocks the client response (B29).
Both hooks use try/catch outer guards so any unexpected error fails open (B16).
2026-05-27 22:17:28 -03:00
diegosouzapw
2b47a81d54 merge(F7): integrate W3 frente F7 into base 2026-05-27 22:17:26 -03:00
diegosouzapw
0e357a9cc7 merge(F6): integrate W3 frente F6 into base 2026-05-27 22:17:24 -03:00
diegosouzapw
95312401b6 merge(F5): integrate W3 frente F5 into base 2026-05-27 22:17:23 -03:00
diegosouzapw
1d44f5d35d merge(F4): integrate W3 frente F4 into base 2026-05-27 22:17:21 -03:00
diegosouzapw
8ed2c02808 merge(F3): integrate W3 frente F3 into base 2026-05-27 22:17:20 -03:00
diegosouzapw
0181348cee feat(quota): add spendRecorder fire-and-forget wrapper (B/F7)
scheduleRecordConsumption() wraps recordConsumption() in setImmediate so it
never adds latency to the client response path. Errors are caught and logged
via pino warn but NEVER propagated to the caller (B29 fail-open contract).
2026-05-27 22:17:16 -03:00
diegosouzapw
d80e1b63eb feat(quota): add enforce.ts (enforceQuotaShare + recordConsumption) (B/F7)
Implements the quota share enforcement gate and consumption recorder:
- enforceQuotaShare(): PRE-request check that returns allow/block/deprioritize
  based on fair-share algorithm, saturation signals, and pool allocations.
- recordConsumption(): POST-response tracker that increments per-key counters
  for each active plan dimension.
Both functions fail-open per B16/B29: any infra error → allow + warn log.
2026-05-27 22:17:10 -03:00
diegosouzapw
3a711d1c0d feat(cli-tools): add settings handlers for new "custom" configType tools (plan 14 F3)
Adds 5 new settings route handlers for CLIs introduced by plan 14 that
declare configType:"custom" and need automated config file persistence:
forge (~/.forge/config.toml), jcode (~/.jcode/config.json),
deepseek-tui (~/.config/deepseek-tui/config.toml),
smelt (~/.smelt/config.json), pi (~/.pi/config.json).

Also registers the 5 tools in cliRuntime.ts path table so
getCliPrimaryConfigPath() resolves their config paths correctly.

Each handler follows the established pattern: requireCliToolsAuth guard on
every exported method, Zod body validation on POST, buildErrorBody/
sanitizeErrorMessage on all error paths (Hard Rule #12), fs/promises only
(no exec/spawn — Hard Rule #13), saveCliToolLastConfigured on success.

Integration tests: 7 subtests per handler (401 without auth, 200 GET,
400 missing-baseUrl, 400 missing-model, 200 POST writes file, 200 DELETE,
error sanitization + no exec/spawn static audit).
2026-05-27 22:13:59 -03:00
diegosouzapw
07605d05cb Merge F4 (NewBatchWizard 4-step modal + tests) into orchestrator branch
# Conflicts:
#	src/app/(dashboard)/dashboard/batch/components/NewBatchWizard.tsx
2026-05-27 22:11:12 -03:00
diegosouzapw
56d1418de7 Merge F4 (NewBatchWizard 4-step modal + tests) into orchestrator branch 2026-05-27 22:10:40 -03:00
diegosouzapw
14d4c7cbcd test(agent-skills): unit tests for AgentSkillsPageClient + filters + selection 2026-05-27 22:10:19 -03:00
diegosouzapw
d27b86568b feat(agent-skills): wire AgentSkillsPageClient with split grid + preview + actions 2026-05-27 22:10:14 -03:00
diegosouzapw
0d89630a31 Merge F5 (UploadFileModal + Files tab refinements + Used by column) into orchestrator branch 2026-05-27 22:10:11 -03:00
diegosouzapw
1aaf43d89e feat(agent-skills): add SkillCard, SkillPreviewPane, CoverageBar, McpA2aLinksBar 2026-05-27 22:10:08 -03:00
diegosouzapw
dff8524d3d refactor(agent-skills): rewrite dashboard page as server wrapper + client 2026-05-27 22:10:01 -03:00
diegosouzapw
9607225a16 test(ui): cover ComplianceTab actor filter + CompressionLogTab namespace (B/F5)
- compliance-tab-actor-filter.test.tsx: 4 tests verifying actor input
  presence, initial fetch has no actor param, re-fetch with actor=X
  after typing, and clearFilters does not throw.
- compression-log-namespace.test.tsx: 4 tests verifying that the logs
  namespace is used (not settings), no _MISSING_ sentinels, and all 4
  required keys are covered.
2026-05-27 22:07:30 -03:00
diegosouzapw
1b0f22fbf8 chore(i18n): pt-BR + en compliance.actor + copy compression keys to logs ns (B/F5)
- compliance.actor / compliance.actorPlaceholder added to pt-BR + en
- logs.compressionLogTitle, logs.compressionLogEmpty, logs.tokens copied
  from settings to logs namespace in both locales (original keys kept in
  settings to avoid breaking other components)
2026-05-27 22:06:52 -03:00
diegosouzapw
bec422726b fix(logs): correct CompressionLogTab i18n namespace settings->logs (B/F5)
The component was calling useTranslations("settings") which would cause
key misses once the settings namespace is reorganized. Keys used
(loading, compressionLogTitle, compressionLogEmpty, tokens) are now
sourced from the canonical "logs" namespace.
2026-05-27 22:06:45 -03:00
diegosouzapw
a4200186e2 feat(audit): add actor filter to ComplianceTab (B/F5)
Adds state, fetch param, reset and input+datalist for filtering audit
entries by actor. The actor field is inserted between eventType and
severity in the filter grid. Filter value is sent as ?actor= to the
compliance audit-log API on every change.
2026-05-27 22:06:39 -03:00
diegosouzapw
e404649d43 feat(batch): add concept card, New batch button, cost/expiration columns, row actions, 30s polling on /batch (F6) 2026-05-27 22:05:30 -03:00
diegosouzapw
c45781f0d6 test(audit): cover timeline helpers + audit-log level filter + activity page redirect (B/F4) 2026-05-27 22:01:23 -03:00
diegosouzapw
2cf40cafcc chore(i18n): pt-BR + en activity namespace (eventVerb + filters + relative) (B/F4) 2026-05-27 22:01:16 -03:00
diegosouzapw
ec3aa40aae chore(logs): delete deprecated AuditLogTab.tsx duplicate (B/F4) 2026-05-27 22:01:10 -03:00
diegosouzapw
e75bad3cbf refactor(logs): redirect /dashboard/logs/activity to /dashboard/activity (B/F4) 2026-05-27 22:01:06 -03:00
diegosouzapw
319f52b988 feat(activity): add /dashboard/activity timeline page + ActivityFeed (B/F4) 2026-05-27 22:01:01 -03:00
diegosouzapw
6a19882646 feat(compliance): support level=high filter in audit-log API (B/F4) 2026-05-27 22:00:56 -03:00
diegosouzapw
fb54bcd994 feat(audit): add timeline helpers (groupByDay + relativeTime) (B/F4) 2026-05-27 22:00:51 -03:00
diegosouzapw
4a97b419ae test(mcp): unit tests for agentSkillTools 2026-05-27 21:58:22 -03:00
diegosouzapw
a7a093d066 feat(mcp): register read:catalog scope + add tools to MCP_TOOLS array 2026-05-27 21:58:18 -03:00
diegosouzapw
d96e74bc15 feat(mcp): add agentSkillTools (list/get/coverage) for agent-skills discovery 2026-05-27 21:58:14 -03:00
diegosouzapw
fb0ac17835 test(playground): improve branch coverage to 100% for codeExport and promptImprover
Add tests for default branch paths (model/prompt/stream falsy), completions
params branch, search with model set, web.fetch depth=0, reversed markers
in parseImprovedContent. All new production files reach 100% branch coverage.
2026-05-27 21:57:34 -03:00
diegosouzapw
d1d0ddda0f test(agent-skills): unit tests for generator + scripts smoke
20 tests covering:
- dry-run produces report without writing (filesystem unchanged)
- apply writes SKILL.md for API and CLI skills with correct sections
- apply writes all 42 skills when no filter
- idempotency: second run reports 0 generated, all unchanged
- prune dry-run detects orphans without deleting
- prune apply deletes orphan dirs, preserves catalog dirs
- marker preservation: custom block survives regeneration
- buildSkillMarkdown: valid shape, no escape errors, correct sections per category
- onlyIds filter limits generation
- report shape validation

Also adds gray-matter as dependency (per plan prerequisite check).
2026-05-27 21:55:01 -03:00
diegosouzapw
ca41880bb3 feat(agent-skills): add CLI wrapper scripts/skills/generate-agent-skills.mjs
Implements the CLI wrapper for the generator:
- --apply flag: enables write mode (default: dry-run)
- --prune flag: enables orphan detection/deletion
- --only=<id1,id2>: filters to specific skill IDs
- --json flag: structured JSON output
- Exit codes: 0 success, 1 error, 2 dry-run detected pending changes (CI)
- Human-readable table output with Generated/Unchanged/Pruned/Orphans/Errors summary
- Dynamic import via tsx/esm runtime; falls back to module.register() if needed
2026-05-27 21:54:50 -03:00
diegosouzapw
f86e905efb feat(agent-skills): add generator with idempotent skill md generation + prune
Implements src/lib/agentSkills/generator.ts (§3.4 contract):
- generateAgentSkills(opts): idempotent, dryRun:true default, prune:false default
- buildSkillMarkdown(skillId, sources): generates frontmatter + API/CLI body
- API body: Visão geral + Autenticação + Endpoints (with curl) + Payloads
- CLI body: Visão geral + Instalação rápida + Subcomandos (with flags + examples)
- Prune: detects orphans in skills/{id}/ not in catalog; deletes in apply mode
- Marker preservation: <!-- skill:custom-start --> ... <!-- skill:custom-end -->
- Generated comment: per D24 spec
2026-05-27 21:54:42 -03:00
diegosouzapw
b7efba4727 test(agent-skills): unit tests for REST routes with sanitization assertions
16 tests covering all 5 endpoints:
- GET /agent-skills: 42 total, category/area filters, invalid category → 400
- GET /agent-skills/[id]: found api+cli skills, unknown → 404
- GET /agent-skills/[id]/raw: unknown → 404, valid → 200/502/500 (network-tolerant)
- GET /agent-skills/coverage: SkillCoverage shape (api.total=22, cli.total=20)
- POST /generate: no auth → 401/403, invalid body → 400, no generator → 503

Hard Rule #12 verified explicitly in every error case: error.message must
not match /\bat \/|\bat file:\/\// (no stack trace exposure). Final test
collects all error paths and asserts sanitization in a single sweep.
2026-05-27 21:49:32 -03:00
diegosouzapw
ccda3cf0f0 feat(agent-skills): add POST /generate with management auth + dryRun default
Implements POST /api/agent-skills/generate (F4):

- Requires management auth via requireManagementAuth (same pattern as
  usage/combo-health-dashboard and other management routes)
- Validates body via GenerateBodySchema (dryRun defaults true, prune
  defaults false — safe preview mode)
- Dynamic import of @/lib/agentSkills/generator so the route coexists
  before F3 (generator.ts) is merged; returns 503 if module unavailable
- Hard Rule #12: all error paths use buildErrorBody (400/401/403/503/500)
- Hard Rule #7: Zod validates both JSON parse and schema shape
2026-05-27 21:49:21 -03:00
diegosouzapw
d1160120c0 feat(agent-skills): add REST GET endpoints (list, get, raw, coverage)
Implements four read-only endpoints for the Agent Skills REST API (F4):

- GET /api/agent-skills — catalog with ?category= and ?area= filters,
  returns { skills, count, coverage }
- GET /api/agent-skills/[id] — single skill by canonical ID (404 if absent)
- GET /api/agent-skills/[id]/raw — SKILL.md as text/markdown with
  Cache-Control: public, max-age=3600; 502 on GitHub fallback failure
- GET /api/agent-skills/coverage — SkillCoverage (filesystem vs catalog)

All routes: export const dynamic = "force-dynamic" (filesystem reads),
error responses via buildErrorBody (Hard Rule #12), Zod input validation
(Hard Rule #7). coverage/route.ts force-added to git because .gitignore
matches the directory name "coverage/" — this is an API route, not a
report directory.
2026-05-27 21:49:12 -03:00
diegosouzapw
754806e0f8 test(a2a): unit tests for listCapabilities + Agent Card route
Adds 6 tests for executeListCapabilities (§3.7 shape, 42-skill IDs in markdown,
coverage bounds, ISO datetime, handler registration) and 5 tests for the Agent
Card route (6 skills total, list-capabilities presence + tags + examples, all
original 5 skills preserved). All 11 pass.
2026-05-27 21:49:03 -03:00
diegosouzapw
c91decf543 feat(a2a): register list-capabilities in A2A_SKILL_HANDLERS + Agent Card
Adds "list-capabilities" entry to A2A_SKILL_HANDLERS in taskExecution.ts
(dynamic import pattern, consistent with the 5 existing skills) and adds
the 6th skill entry to /.well-known/agent.json with tags [discovery, capabilities]
and example questions for agent discovery.
2026-05-27 21:48:57 -03:00
diegosouzapw
6bad368dcb feat(a2a): add list-capabilities skill with markdown table of 42 skills
Implements executeListCapabilities() which calls getCatalog() + computeCoverage()
from the agentSkills catalog (F1/F2) and returns a markdown table covering all
42 skills (22 API + 20 CLI) with ID, name, category, area, endpoints/commands,
and raw SKILL.md URL, matching the §3.7 result contract.
2026-05-27 21:48:50 -03:00
diegosouzapw
75b3e916bc test(inspector): unit tests for F4 inspector core (7 specs) 2026-05-27 21:44:53 -03:00
diegosouzapw
c5f697dbc6 feat(inspector): add harExport (F4) 2026-05-27 21:44:46 -03:00