mirror of
https://github.com/NanmiCoder/claude-code-haha.git
synced 2026-10-10 11:53:10 +08:00
814c02a786
Connecting Feishu meant creating a bot by hand on the open platform and pasting an App ID and App Secret back. Feishu also exposes an RFC 8628 device-authorization flow, so the desktop can now render a QR code, and confirming it in the app creates the bot and stores its credentials directly. `adapters/feishu/registration.ts` implements that protocol rather than importing `registerApp` from `@larksuiteoapi/node-sdk@1.73`: the repository pins 1.60 for the chat client, and the SDK runs the whole poll inside one un-cancellable promise where the desktop needs the stateless begin/poll pair the DingTalk registration already uses. The scan is create-only, so it can never rewrite the configuration of a bot the user already runs, and it pre-fills exactly the scopes, events and callbacks this adapter calls. International tenants finish on Lark's domain, which is now persisted and honoured by the client. WeCom, QQ and Slack join the same session model. WeCom and QQ bind by scanning; Slack has no scan flow, so it uses an app manifest that pre-fills the scopes and Socket Mode. All three run over long connections, so no public callback URL is needed, and all three accept private chats only — pairing authorizes one person, and answering in a group would extend that authorization to everyone else in the room. They are built on a new `adapters/common/chat-runtime.ts` instead of a fourth copy of the loop the five existing adapters each carry. A platform supplies a `ChatPort` — how to say something, how to open a streaming reply, optionally how to send an image — and the runtime owns pairing, command routing, session restore, permission bookkeeping and the translation of the server's stream. The existing five are deliberately left on their own copies; migrating them is a separate change with its own regression surface. Attachments are downloaded through a deferred loader that runs after the pairing gate and inside the per-chat queue. Resolving them eagerly would let an unpaired stranger make the adapter fetch bytes and write them under ~/.claude/im-downloads — on Slack with the bot token attached — and would let a slow attachment overtake a text message sent after it. The sidecar launcher's per-adapter branches become one table. It is declared above the mode dispatch on purpose: `runAdapters` is hoisted and runs at module top level, so a table declared below it is still in its temporal dead zone when the adapters mode reads it — which type checks, lints and unit tests all miss, and only the compiled binary reveals. Verified with the checks `check:impact` selects: adapters, server, desktop, electron, policy, chat-contract, agent-flow, docs, native (sidecar compile, packaging and an adapters-mode smoke against the real binary) and coverage. The scan flows themselves are not verified against live platforms — that needs real WeCom, QQ and Slack accounts and would create real bots. Claude-Session: https://claude.ai/code/session_01CCGoP316AK7wdQG3Ms6Uwq
114 lines
3.5 KiB
TypeScript
114 lines
3.5 KiB
TypeScript
/**
|
|
* Enterprise WeChat inbound media.
|
|
*
|
|
* WeCom hands the bot an encrypted CDN URL plus a per-download AES key; the
|
|
* SDK's `downloadFile` does the fetch and the decryption. This module only
|
|
* decides *what* to download (from a message body) and where to stage it, so
|
|
* the extraction rules can be tested without a live WebSocket client.
|
|
*/
|
|
|
|
import type { AttachmentStore } from '../common/attachment/attachment-store.js'
|
|
import type { LocalAttachment } from '../common/attachment/attachment-types.js'
|
|
import { attachmentKindForMime, inferMimeFromFileName } from '../common/attachment/mime.js'
|
|
|
|
export type WecomMediaCandidate = {
|
|
kind: 'image' | 'file'
|
|
/** Fallback name; the real one may arrive with the download. */
|
|
name: string
|
|
url: string
|
|
aesKey?: string
|
|
mimeType?: string
|
|
}
|
|
|
|
type WecomMediaBody = {
|
|
msgid?: string
|
|
msgtype?: string
|
|
image?: { url?: string; aeskey?: string }
|
|
file?: { url?: string; aeskey?: string }
|
|
mixed?: { msg_item?: Array<{ msgtype?: string; image?: { url?: string; aeskey?: string } }> }
|
|
/** Listed so the deliberate omission is visible: WeCom delivers voice notes
|
|
* already transcribed, so they belong in the text path, not here. */
|
|
voice?: { content?: string }
|
|
}
|
|
|
|
export type WecomDownload = (
|
|
url: string,
|
|
aesKey?: string,
|
|
) => Promise<{ buffer: Buffer; filename?: string }>
|
|
|
|
function imageCandidate(
|
|
media: { url?: string; aeskey?: string } | undefined,
|
|
seed: string,
|
|
): WecomMediaCandidate | null {
|
|
if (!media?.url) return null
|
|
return {
|
|
kind: 'image',
|
|
name: `wecom-image-${seed}.jpg`,
|
|
url: media.url,
|
|
aesKey: media.aeskey,
|
|
mimeType: 'image/jpeg',
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Downloadable attachments carried by one inbound message.
|
|
*
|
|
* Voice messages are deliberately absent: WeCom delivers them already
|
|
* transcribed as `voice.content`, so they belong in the text path, not here.
|
|
*/
|
|
export function collectWecomMediaCandidates(body: WecomMediaBody | undefined): WecomMediaCandidate[] {
|
|
if (!body) return []
|
|
const seed = body.msgid || String(Date.now())
|
|
const candidates: WecomMediaCandidate[] = []
|
|
|
|
const image = imageCandidate(body.image, seed)
|
|
if (image) candidates.push(image)
|
|
|
|
if (body.file?.url) {
|
|
candidates.push({
|
|
kind: 'file',
|
|
name: `wecom-file-${seed}`,
|
|
url: body.file.url,
|
|
aesKey: body.file.aeskey,
|
|
})
|
|
}
|
|
|
|
body.mixed?.msg_item?.forEach((item, index) => {
|
|
if (item.msgtype !== 'image') return
|
|
const mixedImage = imageCandidate(item.image, `${seed}-${index}`)
|
|
if (mixedImage) candidates.push(mixedImage)
|
|
})
|
|
|
|
return candidates
|
|
}
|
|
|
|
export class WecomMediaService {
|
|
constructor(
|
|
private readonly store: AttachmentStore,
|
|
private readonly download: WecomDownload,
|
|
) {}
|
|
|
|
async downloadCandidate(
|
|
candidate: WecomMediaCandidate,
|
|
sessionId: string,
|
|
): Promise<LocalAttachment> {
|
|
const { buffer, filename } = await this.download(candidate.url, candidate.aesKey)
|
|
const name = filename?.trim() || candidate.name
|
|
const mimeType = candidate.mimeType
|
|
?? inferMimeFromFileName(name)
|
|
?? (candidate.kind === 'image' ? 'image/jpeg' : 'application/octet-stream')
|
|
const target = this.store.resolvePath('wecom', sessionId, name)
|
|
const path = await this.store.write(target, buffer)
|
|
return {
|
|
// Trust the resolved MIME over the candidate's guess: a `file` message
|
|
// carrying a .png is an image to the Agent, and the limits differ.
|
|
kind: attachmentKindForMime(mimeType),
|
|
name,
|
|
path,
|
|
buffer,
|
|
size: buffer.length,
|
|
mimeType,
|
|
}
|
|
}
|
|
}
|