feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(dev): add Agent Inspector HTTP layer (server, security, assets) - #2082

Merged
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer
Aug 26, 2026
Merged

feat(dev): add Agent Inspector HTTP layer (server, security, assets)#2082
tejaskash merged 2 commits into
refactorfrom
feat/inspector-http-layer

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

What

First of three stacked PRs re-authoring the Agent Inspector from feat/agent-inspector against current refactor APIs. This one lands the HTTP contract and SPA delivery only — a pure request to response handler the dev command will compose with io/startHttpServer. It is not yet reachable from the CLI.

Stacked on #2041 (feat/dev-supervisor); retarget to refactor once that merges.

Scope

  • src/core/dev/inspector/{types,respond,server,testkit}.ts — DI interfaces (InspectorSupervisor, InspectorTraces, InspectorAssets, InspectorDeps), response helpers, and createInspectorHandler.
  • src/core/dev/inspectorAssets.ts — reads the staged SPA through AssetSource with an AGENT_INSPECTOR_PATH override and a node_modules fallback.
  • src/io/packagedAssets.ts — raw file reads and package-dir resolution, so node:fs/node:module stay out of core/dev.
  • scripts/build.tsstageInspectorAssets() copies @aws/agent-inspector/dist-assets into the asset tree before bundle and compile.

Routes registered this PR: GET /api/status, POST /api/start, GET /api/traces, GET /api/traces/:id, static SPA (with index.html fallback), and a graceful { success:false, error } 404 for everything else. Agent-proxy routes (invocations, MCP, A2A, resources) and the CLI wiring land in the following PRs, so no stub routes appear here.

Security model

Loopback-only Host check (accepts localhost, 127.0.0.1, [::1]), server-side Origin allowlist (plus the Vite :5173 dev origins), X-Agentcore-Local required on POSTs, CORS preflight, and a CSP on served HTML.

Design notes vs the reference branch

  • Route matching hardened: exact /api/traces for the list route and slice + decodeURIComponent for :id, so /api/tracesXYZ no longer matches the list route and encoded ids decode. Covered by tests.
  • Boundary of concern: filesystem and package resolution moved into src/io/packagedAssets.ts; inspectorAssets.ts no longer imports node:fs/node:module.
  • Trace list capped to the newest 200 per poll, matching TraceStore.list's existing limit contract, since each summary carries full spans/logs.
  • Security-guard rejection cases parameterized with test.each.

Verification

  • bun test src/core/dev/inspector + inspectorAssets.test.ts — 26 pass.
  • Full bun test (1812 pass), bun run typecheck, bun run lint:check, bun run format:check all green.
  • bun run build stages the four SPA files into src/assets/agent-inspector/ (gitignored) and mirrors them into dist/assets/.

@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 24, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 24, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from e59cda5 to 1b3491bCompareAugust 25, 2026 17:35
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from 1b3491b to f84a91fCompareAugust 25, 2026 17:45
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.90164% with 10 lines in your changes missing coverage. Please review.
✅ Project coverage is 97.41%. Comparing base (f1a651c) to head (31df625).

Files with missing linesPatch %Lines
src/core/dev/inspector/server.ts96.42%4 Missing ⚠️
src/core/dev/inspector/testkit.ts93.75%3 Missing ⚠️
src/io/packagedAssets.ts84.61%2 Missing ⚠️
src/core/dev/inspector/respond.ts96.87%1 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## refactor #2082 +/- ##
============================================
- Coverage 97.42% 97.41% -0.02% 
============================================
Files 429 434 +5 Lines 26314 26558 +244 ============================================
+ Hits 25637 25871 +234 - Misses 677 687 +10 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tejaskashtejaskash changed the title feat(dev): Agent Inspector HTTP layer (server, security, assets)feat(dev): add Agent Inspector HTTP layer (server, security, assets)Aug 25, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from f84a91f to ac74941CompareAugust 25, 2026 19:01
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from ac74941 to a0dd0f6CompareAugust 25, 2026 19:39
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
Base automatically changed from feat/dev-supervisor to refactorAugust 25, 2026 20:25
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from a0dd0f6 to defd2b1CompareAugust 25, 2026 20:25
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
import { dirname } from "node:path";

/** Read a file's raw bytes, or undefined when it is absent or unreadable. */
export async function readOptionalBytes(path: string): Promise<Uint8Array | undefined> {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this helper necessary? Looking at where it's used, it doesn't seem to be reducing complexity or cognitive load? In other words, the code above would be just as easy to follow, or even easier, without this little helper.

@AlexanderRicheyAlexanderRichey left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primarily copy/pasting stuff as is, right?

@tejaskash

tejaskash commented Aug 26, 2026

Copy link
Copy Markdown
ContributorAuthor

Primarily copy/pasting stuff as is, right?

Yep, split up into smaller chunks to make it easier to read

Port the reference WebUIServer as a pure request to response handler the
dev command composes with io/startHttpServer. This lands the HTTP contract
and SPA delivery only; agent-proxy routes (invocations, MCP, A2A, resources)
and the CLI wiring follow in later PRs.
- security: loopback-only Host check (incl. IPv6 [::1]), server-side origin
allowlist, X-Agentcore-Local on POSTs, CORS preflight, CSP on served HTML
- routes: GET /api/status, POST /api/start, GET /api/traces[/:id], static SPA
with index.html fallback, graceful JSON 404 for everything else
- exact-match trace routing with decodeURIComponent :id extraction
- InspectorAssets reads the staged SPA through AssetSource with an
AGENT_INSPECTOR_PATH override and node_modules fallback; raw filesystem and
package resolution live in src/io/packagedAssets, keeping node:fs/node:module
out of core/dev
- build stages @aws/agent-inspector/dist-assets into the asset tree before
bundle and compile
- serve static assets over a zero-copy Buffer view of the cached bytes
- hoist the constant CORS headers to module scope; the per-request origin
pick reduces to origin || primary now that the guard runs first
- drop the single-use InspectorAssetReader alias; inline read's signature
- hoist the asset TextEncoder to module scope
@tejaskash
tejaskashforce-pushed the feat/inspector-http-layer branch from defd2b1 to 31df625CompareAugust 26, 2026 13:13
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 26, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 26, 2026
@tejaskash
tejaskash merged commit 3bafeae into refactorAug 26, 2026
19 of 20 checks passed
@tejaskash
tejaskash deleted the feat/inspector-http-layer branch August 26, 2026 15:05
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@tejaskash@codecov-commenter@AlexanderRichey