mirror of
https://github.com/NanmiCoder/claude-code-haha.git
synced 2026-10-10 03:43:11 +08:00
94168b3b57
Since v0.5.1 every IM channel listed only the default project. All five adapters passed the default work dir to AdapterHttpClient as the sole allowed project root, so listRecentProjects filtered out everything else; matchProject, listSessions, sessionExists, createSession and listSkills were clamped the same way. Feishu is where it was reported, but telegram, wechat, dingtalk and whatsapp were identical. defaultWorkDir is documented as where a new IM session starts, not as an access boundary. Using it as the boundary failed both ways: configured, it hid every other project; blank, it falls back to PWD/cwd(), which is "/" for a GUI-launched sidecar, so the boundary allowed the whole filesystem. Split the two concepts. allowedProjectRoots is now its own setting (global, per-platform, or ADAPTER_ALLOWED_PROJECT_ROOTS), resolved together with the work dir by resolveAdapterWorkspace so the default project is always inside the boundary and /new cannot fail on inconsistent config. The default is the home directory; it refuses to inherit "/" or any ancestor of home. Pairing remains the primary authorization control, so unusable roots warn and fall back rather than locking the bot out. All five entrypoints now build their client through createAdapterClient instead of repeating the wiring, which is what let one defect appear in five places at once. Known gap, left for a follow-up: a project outside the boundary is still reported as "not found" rather than "outside the allowed directories".
35 lines
1.3 KiB
TypeScript
35 lines
1.3 KiB
TypeScript
import {
|
|
resolveAdapterWorkspace,
|
|
type AdapterConfig,
|
|
type AdapterPlatformConfig,
|
|
} from './config.js'
|
|
import { AdapterHttpClient } from './http-client.js'
|
|
|
|
export type AdapterWorkspace = {
|
|
httpClient: AdapterHttpClient
|
|
/** Where a new IM session starts. Guaranteed to sit inside the allowed roots. */
|
|
defaultWorkDir: string
|
|
}
|
|
|
|
/**
|
|
* Build the HTTP client and the default work dir for an IM adapter.
|
|
*
|
|
* Every adapter entrypoint goes through here instead of constructing the client
|
|
* itself. The five entrypoints previously repeated the wiring, and all five
|
|
* repeated the same defect (#1191): they passed the default work dir as the only
|
|
* allowed project root, so /projects listed a single project. Keeping the
|
|
* construction in one importable place makes that class of mistake unreachable
|
|
* without editing this file, and makes it testable — the entrypoints boot a live
|
|
* bot on import and cannot be exercised directly.
|
|
*/
|
|
export function createAdapterClient(
|
|
config: AdapterConfig,
|
|
platformConfig: AdapterPlatformConfig,
|
|
): AdapterWorkspace {
|
|
const { defaultWorkDir, allowedProjectRoots } = resolveAdapterWorkspace(config, platformConfig)
|
|
return {
|
|
httpClient: new AdapterHttpClient(config.serverUrl, { allowedProjectRoots }),
|
|
defaultWorkDir,
|
|
}
|
|
}
|