Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions packages/app/docs/adr/0003-context-tree-top-panel.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -68,7 +68,10 @@ Entry points: a titlebar vault button (both titlebar variants), the command pale
- Vault contents are proprietary knowledge, so browsing is a **local-researcher
capability, not a server API**: the routes refuse on any non-loopback bind (same
signal as the credential-mutation guard; `AMICO_VAULT_BROWSER=1` opts a shared
deployment in, `=0` forces off), and a mount can go fully dark with
`browse = false` in its `.amico-vault.toml` — the agent's read grants are unaffected.
deployment in, `=0` forces off, `=public` serves only public vaults — the
hackathon-box mode). Per-mount browsability is **fail-closed by kind** (Aaron
2026-07-27): personal and public browse by default; team/project/engagement —
and unknown kinds — ship dark until their marker says `browse = true`;
`browse = false` darkens any kind. The agent's read grants are unaffected.
- Keyboard reachability of individual canvas nodes is an open follow-up; every action the
canvas offers also exists via keyboard-reachable surfaces (file tree, Vault panel).
59 changes: 47 additions & 12 deletions packages/opencode/src/server/amicode/vault-browser.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,30 +33,63 @@ const err = (code: string, detail: string) => JSON.stringify({ ok: false, error:
* results); browsing is a LOCAL-researcher capability, not a server API. Same
* loopback family + bind signal as the credential-mutation guard
* (connections.ts) — a 0.0.0.0 / LAN-bound server refuses these routes even
* to authed callers, unless AMICO_VAULT_BROWSER=1 explicitly opts a shared
* deployment in (=0 forces off everywhere). */
* to authed callers, unless AMICO_VAULT_BROWSER explicitly opts the
* deployment in: =1 opens the deployment gate (per-mount rules still apply),
* =0 forces off everywhere, =public serves ONLY kind="public" mounts
* regardless of markers (the hackathon-box mode — Aaron 2026-07-27). */
export function browseAllowed(env: Record<string, string | undefined> = process.env): boolean {
const flag = env.AMICO_VAULT_BROWSER
if (flag === "1" || flag === "true") return true
if (flag === "1" || flag === "true" || flag === "public") return true
if (flag === "0" || flag === "false") return false
return isLoopbackHostname(getBindHostname())
}

const browseRefusal = () =>
err("forbidden", "vault browsing serves loopback servers only (set AMICO_VAULT_BROWSER=1 to override)")

/** A vault opts out of the browser entirely with `browse = false` in its
* .amico-vault.toml marker — the agent's read grants are unaffected, but the
* panel will not list or serve a byte of it. */
export function browseOptedOut(dir: string): boolean {
/** The mount's marker taxonomy: kind plus the explicit browse override. */
export function mountMeta(dir: string): { kind: string; browse: boolean | undefined } {
try {
return /^\s*browse\s*=\s*false\s*$/m.test(readFileSync(path.join(dir, ".amico-vault.toml"), "utf8"))
const text = readFileSync(path.join(dir, ".amico-vault.toml"), "utf8")
const kind = text.match(/^\s*kind\s*=\s*"([^"]*)"/m)?.[1] ?? ""
const browse = /^\s*browse\s*=\s*false\s*$/m.test(text)
? false
: /^\s*browse\s*=\s*true\s*$/m.test(text)
? true
: undefined
return { kind, browse }
} catch {
return false
return { kind: "", browse: undefined }
}
}

const optOutRefusal = (mountId: string) => err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
/** Browsability is FAIL-CLOSED BY KIND (Aaron 2026-07-27): the marker already
* carries the taxonomy, so team/project/engagement/restricted — and anything
* with an unknown kind — ship dark by default; `browse = true` is the
* deliberate opt-in. Personal stays browsable (it is the operator's own
* machine) and public is browsable by definition. `browse = false` darkens
* any kind. Under AMICO_VAULT_BROWSER=public, ONLY public mounts serve,
* markers ignored. Returns a refusal body, or undefined when browsable.
* The agent's read grants are unaffected either way. */
export function mountBrowseRefusal(
mountId: string,
dir: string,
env: Record<string, string | undefined> = process.env,
): string | undefined {
const meta = mountMeta(dir)
if (env.AMICO_VAULT_BROWSER === "public") {
if (meta.kind !== "public")
return err("forbidden", `vault "${mountId}" is not public — this deployment serves public vaults only`)
return undefined
}
if (meta.browse === false) return err("forbidden", `vault "${mountId}" opts out of browsing (browse = false)`)
if (meta.browse === true) return undefined
if (meta.kind === "personal" || meta.kind === "public") return undefined
return err(
"forbidden",
`vault "${mountId}" is kind "${meta.kind || "unknown"}" — browsing is opt-in for shared vaults (browse = true in its marker)`,
)
}

export function isTextFile(name: string): boolean {
const ext = path.extname(name).toLowerCase()
Expand DownExpand Up@@ -102,7 +135,8 @@ export function vaultFilesBody(mountId: string | undefined, root: string = vault
if (!mountId) return err("bad_request", "mount is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
try {
realRoot = realpathSync(dir)
Expand DownExpand Up@@ -164,7 +198,8 @@ export function vaultFileBody(mountId: string | undefined, relPath: string | und
if (!relPath) return err("bad_request", "path is required")
const dir = mountDir(mountId, root)
if (!dir) return err("not_found", `no attached vault named "${mountId}"`)
if (browseOptedOut(dir)) return optOutRefusal(mountId)
const refusal = mountBrowseRefusal(mountId, dir)
if (refusal) return refusal
let realRoot: string
let realTarget: string
try {
Expand Down
41 changes: 38 additions & 3 deletions packages/opencode/test/server/amicode-vault-browser.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,7 +2,7 @@ import { afterEach, describe, expect, test } from "bun:test"
import { mkdirSync, mkdtempSync, symlinkSync, writeFileSync } from "node:fs"
import { tmpdir } from "node:os"
import path from "node:path"
import { browseAllowed, browseOptedOut, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { browseAllowed, mountBrowseRefusal, mountMeta, isTextFile, mountDir, vaultFileBody, vaultFilesBody } from "@/server/amicode/vault-browser"
import { setBindHostname } from "@/server/amicode/connections"

// The suite runs with no listener bound (bindHostname undefined = in-process,
Expand DownExpand Up@@ -50,13 +50,48 @@ describe("browse gates (proprietary vaults never serve off-box)", () => {
})
test("browse = false in the marker darkens the mount for listing AND reads", () => {
const { root, mount } = fixtureRoot()
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "team"\nname = "armonia-test"\nbrowse = false\n')
expect(browseOptedOut(mount)).toBe(true)
writeFileSync(path.join(mount, ".amico-vault.toml"), 'kind = "personal"\nname = "armonia-test"\nbrowse = false\n')
expect(mountMeta(mount).browse).toBe(false)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).error).toMatch(/^forbidden: vault "armonia-test" opts out/)
expect(JSON.parse(vaultFileBody("armonia-test", "STRATEGY.md", root)).error).toMatch(/^forbidden:/)
})
})

describe("fail-closed by kind (Aaron 2026-07-27): shared vaults ship dark", () => {
const marker = (mount: string, body: string) => writeFileSync(path.join(mount, ".amico-vault.toml"), body)
test("team/project/engagement/unknown kinds refuse by default; browse = true is the opt-in", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["team", "project", "engagement", "restricted", ""]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
const out = JSON.parse(vaultFilesBody("armonia-test", root))
expect(out.ok).toBe(false)
expect(out.error).toMatch(/browsing is opt-in for shared vaults/)
}
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
})
test("personal and public stay browsable by default", () => {
const { root, mount } = fixtureRoot()
for (const kind of ["personal", "public"]) {
marker(mount, `kind = "${kind}"\nname = "armonia-test"\n`)
expect(JSON.parse(vaultFilesBody("armonia-test", root)).ok).toBe(true)
}
})
test("AMICO_VAULT_BROWSER=public serves ONLY public mounts, markers ignored (hackathon boxes)", () => {
const { mount } = fixtureRoot()
const env = { AMICO_VAULT_BROWSER: "public" }
marker(mount, 'kind = "team"\nname = "armonia-test"\nbrowse = true\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "personal"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toMatch(/serves public vaults only/)
marker(mount, 'kind = "public"\nname = "armonia-test"\n')
expect(mountBrowseRefusal("armonia-test", mount, env)).toBeUndefined()
// and =public also opens the deployment gate (the boxes are exposed binds)
setBindHostname("0.0.0.0")
expect(browseAllowed(env)).toBe(true)
})
})

describe("isTextFile", () => {
test("markdown and source are text; binaries are not", () => {
expect(isTextFile("note.md")).toBe(true)
Expand Down
Loading