mirror of
https://github.com/alkimake/paperclip.git
synced 2026-06-15 02:20:38 +09:00
## Thinking Path > - Paperclip is a control plane for AI-agent companies. > - External adapters can provide UI parser code that the board loads dynamically for run transcript rendering. > - Running adapter-provided parser code directly in the board page gives that parser access to same-origin browser state. > - This PR narrows that surface by evaluating dynamically loaded external adapter UI parser code in a dedicated browser Web Worker with a constrained postMessage protocol. > - The worker here is a frontend isolation boundary for adapter UI parser JavaScript; it is not Paperclip's server plugin-worker system and it is not a server-side job runner. ## What Changed - Runs dynamically loaded external adapter UI parsers inside a dedicated Web Worker instead of importing/evaluating them directly in the board page. - Adds a narrow postMessage protocol for parser initialization and line parsing. - Caches completed async parse results and notifies the adapter registry so transcript recomputation can synchronously drain the final parsed line. - Disables common worker network, persistence, child worker, Blob/object URL, and WebRTC escape APIs inside the parser worker bootstrap. - Handles worker error messages after initialization and drains pending callbacks on worker termination or mid-session worker error. - Adds focused regression coverage for the parser worker lockdown and unused protocol removal. ## Verification - `pnpm exec vitest run --config ui/vitest.config.ts ui/src/adapters/sandboxed-parser-worker.test.ts` - `pnpm exec tsc --noEmit --target es2021 --moduleResolution bundler --module esnext --jsx react-jsx --lib dom,es2021 --skipLibCheck ui/src/adapters/dynamic-loader.ts ui/src/adapters/sandboxed-parser-worker.ts ui/src/adapters/sandboxed-parser-worker.test.ts` - `pnpm --filter @paperclipai/ui typecheck` was attempted; it reached existing unrelated failures in HeartbeatRun test/storybook fixtures and missing Storybook type resolution, with no adapter-module errors surfaced. - PR #4225 checks on current head `34c9da00`: `policy`, `e2e`, `verify`, `security/snyk`, and `Greptile Review` are all `SUCCESS`. - Greptile Review on current head `34c9da00` reached 5/5. ## Risks - Medium risk: parser execution is now asynchronous through a worker while the existing parser interface is synchronous, so transcript updates should be watched with external adapters. - Some adapter parser bundles may rely on direct ESM `export` syntax or browser APIs that are no longer available inside the worker lockdown. - The worker lockdown is a hardening layer around external parser code, not a complete browser security sandbox for arbitrary untrusted applications. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, GPT-5-based coding agent runtime, shell/git tool use enabled. Exact hosted model build and context window are not exposed in this Paperclip heartbeat environment. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] If this change affects the UI, I have included before/after screenshots - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] I will address all Greptile and reviewer comments before requesting merge
262 lines
9.7 KiB
TypeScript
262 lines
9.7 KiB
TypeScript
import type { UIAdapterModule } from "./types";
|
|
import { claudeLocalUIAdapter } from "./claude-local";
|
|
import { codexLocalUIAdapter } from "./codex-local";
|
|
import { cursorLocalUIAdapter } from "./cursor";
|
|
import { geminiLocalUIAdapter } from "./gemini-local";
|
|
import { openCodeLocalUIAdapter } from "./opencode-local";
|
|
import { piLocalUIAdapter } from "./pi-local";
|
|
import { openClawGatewayUIAdapter } from "./openclaw-gateway";
|
|
import { hermesLocalUIAdapter } from "./hermes-local";
|
|
import { processUIAdapter } from "./process";
|
|
import { httpUIAdapter } from "./http";
|
|
import { loadDynamicParser, invalidateDynamicParser, setDynamicParserResultNotifier } from "./dynamic-loader";
|
|
import { SchemaConfigFields, buildSchemaAdapterConfig } from "./schema-config-fields";
|
|
|
|
const uiAdapters: UIAdapterModule[] = [];
|
|
const adaptersByType = new Map<string, UIAdapterModule>();
|
|
|
|
// Types registered at module load time — allowed to be overridden by
|
|
// external adapters that ship their own ui-parser.js via the server.
|
|
const builtinTypes = new Set<string>();
|
|
|
|
// Original builtin adapters stored for restoration when external overrides
|
|
// are deactivated or removed.
|
|
const builtinAdaptersByType = new Map<string, UIAdapterModule>();
|
|
|
|
// Tracks which builtin types currently have an active external override.
|
|
const activeExternalOverrides = new Set<string>();
|
|
|
|
// Generation counter to discard stale dynamic parser loads. When an override
|
|
// is deactivated while a load is in-flight, the generation is bumped and the
|
|
// stale result is discarded in its .then() handler.
|
|
const overrideGeneration = new Map<string, number>();
|
|
|
|
// Subscriber list — components can register to be notified when adapters change
|
|
// (e.g., when a dynamic parser replaces a placeholder).
|
|
const adapterChangeListeners = new Set<() => void>();
|
|
|
|
/** Subscribe to adapter registry changes. Returns unsubscribe function. */
|
|
export function onAdapterChange(fn: () => void): () => void {
|
|
adapterChangeListeners.add(fn);
|
|
return () => adapterChangeListeners.delete(fn);
|
|
}
|
|
|
|
function notifyAdapterChange(): void {
|
|
for (const fn of adapterChangeListeners) fn();
|
|
}
|
|
|
|
setDynamicParserResultNotifier(notifyAdapterChange);
|
|
|
|
function registerBuiltInUIAdapters() {
|
|
for (const adapter of [
|
|
claudeLocalUIAdapter,
|
|
codexLocalUIAdapter,
|
|
geminiLocalUIAdapter,
|
|
hermesLocalUIAdapter,
|
|
openCodeLocalUIAdapter,
|
|
piLocalUIAdapter,
|
|
cursorLocalUIAdapter,
|
|
openClawGatewayUIAdapter,
|
|
processUIAdapter,
|
|
httpUIAdapter,
|
|
]) {
|
|
builtinTypes.add(adapter.type);
|
|
builtinAdaptersByType.set(adapter.type, adapter);
|
|
registerUIAdapter(adapter);
|
|
}
|
|
}
|
|
|
|
export function registerUIAdapter(adapter: UIAdapterModule): void {
|
|
const existingIndex = uiAdapters.findIndex((entry) => entry.type === adapter.type);
|
|
if (existingIndex >= 0) {
|
|
uiAdapters.splice(existingIndex, 1, adapter);
|
|
} else {
|
|
uiAdapters.push(adapter);
|
|
}
|
|
adaptersByType.set(adapter.type, adapter);
|
|
notifyAdapterChange();
|
|
}
|
|
|
|
export function unregisterUIAdapter(type: string): void {
|
|
if (type === processUIAdapter.type || type === httpUIAdapter.type) return;
|
|
const existingIndex = uiAdapters.findIndex((entry) => entry.type === type);
|
|
if (existingIndex >= 0) {
|
|
uiAdapters.splice(existingIndex, 1);
|
|
}
|
|
adaptersByType.delete(type);
|
|
}
|
|
|
|
export function findUIAdapter(type: string): UIAdapterModule | null {
|
|
return adaptersByType.get(type) ?? null;
|
|
}
|
|
|
|
registerBuiltInUIAdapters();
|
|
|
|
export function getUIAdapter(type: string): UIAdapterModule {
|
|
const builtIn = adaptersByType.get(type);
|
|
|
|
if (!builtIn) {
|
|
let loadStarted = false;
|
|
return {
|
|
type,
|
|
label: type,
|
|
parseStdoutLine: (line: string, ts: string) => {
|
|
if (!loadStarted) {
|
|
loadStarted = true;
|
|
loadDynamicParser(type).then((parserModule) => {
|
|
if (parserModule) {
|
|
registerUIAdapter({
|
|
type,
|
|
label: type,
|
|
parseStdoutLine: parserModule.parseStdoutLine,
|
|
createStdoutParser: parserModule.createStdoutParser,
|
|
ConfigFields: SchemaConfigFields,
|
|
buildAdapterConfig: buildSchemaAdapterConfig,
|
|
});
|
|
}
|
|
});
|
|
}
|
|
return processUIAdapter.parseStdoutLine(line, ts);
|
|
},
|
|
ConfigFields: SchemaConfigFields,
|
|
buildAdapterConfig: buildSchemaAdapterConfig,
|
|
};
|
|
}
|
|
|
|
return builtIn;
|
|
}
|
|
|
|
/**
|
|
* Keep the UI adapter registry in sync with the server's adapter list.
|
|
*
|
|
* Two concerns:
|
|
*
|
|
* 1. **Builtin overrides** — when an external adapter ships a ui-parser.js for a
|
|
* builtin type, the external parser takes priority. When the external is
|
|
* disabled or removed the original builtin parser is restored transparently.
|
|
* A generation counter guards against stale loads that resolve after the
|
|
* override has been torn down.
|
|
*
|
|
* 2. **Non-builtin externals** — register a bridge adapter that lazily loads the
|
|
* dynamic parser on first stdout line, falling back to the generic process
|
|
* adapter. Once the parser resolves the bridge is replaced.
|
|
*/
|
|
export function syncExternalAdapters(
|
|
serverAdapters: {
|
|
type: string;
|
|
label: string;
|
|
disabled?: boolean;
|
|
/** When true, the external override for a builtin type is client-side paused. */
|
|
overrideDisabled?: boolean;
|
|
}[],
|
|
): void {
|
|
const enabledExternalTypes = new Set(
|
|
serverAdapters.filter((a) => !a.disabled && !a.overrideDisabled).map((a) => a.type),
|
|
);
|
|
const allExternalTypes = new Set(
|
|
serverAdapters.map((a) => a.type),
|
|
);
|
|
|
|
// ── Builtin override lifecycle ──────────────────────────────────────────
|
|
|
|
for (const builtinType of builtinTypes) {
|
|
const originalBuiltin = builtinAdaptersByType.get(builtinType);
|
|
if (!originalBuiltin) continue;
|
|
|
|
const hasExternal = allExternalTypes.has(builtinType);
|
|
const externalEnabled = enabledExternalTypes.has(builtinType);
|
|
const wasOverridden = activeExternalOverrides.has(builtinType);
|
|
|
|
if (hasExternal && externalEnabled && !wasOverridden) {
|
|
// Activate: external just became active → replace builtin with bridge.
|
|
activeExternalOverrides.add(builtinType);
|
|
|
|
const gen = (overrideGeneration.get(builtinType) ?? 0) + 1;
|
|
overrideGeneration.set(builtinType, gen);
|
|
|
|
let loadStarted = false;
|
|
const fallbackParser = originalBuiltin.parseStdoutLine;
|
|
const externalEntry = serverAdapters.find((a) => a.type === builtinType);
|
|
const label = externalEntry?.label ?? builtinType;
|
|
|
|
registerUIAdapter({
|
|
type: builtinType,
|
|
label,
|
|
parseStdoutLine: (line: string, ts: string) => {
|
|
if (!loadStarted) {
|
|
loadStarted = true;
|
|
loadDynamicParser(builtinType).then((parserModule) => {
|
|
// Discard if the override was torn down while the load was in-flight.
|
|
if (parserModule && overrideGeneration.get(builtinType) === gen) {
|
|
registerUIAdapter({
|
|
type: builtinType,
|
|
label,
|
|
parseStdoutLine: parserModule.parseStdoutLine,
|
|
createStdoutParser: parserModule.createStdoutParser,
|
|
ConfigFields: originalBuiltin.ConfigFields,
|
|
buildAdapterConfig: originalBuiltin.buildAdapterConfig,
|
|
});
|
|
}
|
|
});
|
|
}
|
|
return fallbackParser(line, ts);
|
|
},
|
|
ConfigFields: originalBuiltin.ConfigFields,
|
|
buildAdapterConfig: originalBuiltin.buildAdapterConfig,
|
|
});
|
|
} else if ((!hasExternal || !externalEnabled) && wasOverridden) {
|
|
// Deactivate: external disabled or removed → restore builtin.
|
|
activeExternalOverrides.delete(builtinType);
|
|
overrideGeneration.delete(builtinType);
|
|
invalidateDynamicParser(builtinType);
|
|
registerUIAdapter(originalBuiltin);
|
|
}
|
|
}
|
|
|
|
// ── Non-builtin externals ───────────────────────────────────────────────
|
|
|
|
for (const { type, label } of serverAdapters) {
|
|
if (builtinTypes.has(type)) continue; // handled above
|
|
|
|
const existing = adaptersByType.get(type);
|
|
|
|
// If this type already has an externally-loaded dynamic parser, skip —
|
|
// it was loaded from disk on a previous sync. Only re-trigger loading
|
|
// when the server returns a new external adapter that hasn't been loaded yet.
|
|
if (existing && existing !== processUIAdapter) continue;
|
|
|
|
let loadStarted = false;
|
|
// Use the existing built-in parser as fallback (if any) so we don't
|
|
// regress to the generic process parser while the dynamic one loads.
|
|
const fallbackParser = existing?.parseStdoutLine ?? processUIAdapter.parseStdoutLine;
|
|
|
|
registerUIAdapter({
|
|
type,
|
|
label,
|
|
parseStdoutLine: (line: string, ts: string) => {
|
|
if (!loadStarted) {
|
|
loadStarted = true;
|
|
loadDynamicParser(type).then((parserModule) => {
|
|
if (parserModule) {
|
|
registerUIAdapter({
|
|
type,
|
|
label,
|
|
parseStdoutLine: parserModule.parseStdoutLine,
|
|
createStdoutParser: parserModule.createStdoutParser,
|
|
ConfigFields: existing?.ConfigFields ?? SchemaConfigFields,
|
|
buildAdapterConfig: existing?.buildAdapterConfig ?? buildSchemaAdapterConfig,
|
|
});
|
|
}
|
|
});
|
|
}
|
|
return fallbackParser(line, ts);
|
|
},
|
|
ConfigFields: existing?.ConfigFields ?? SchemaConfigFields,
|
|
buildAdapterConfig: existing?.buildAdapterConfig ?? buildSchemaAdapterConfig,
|
|
});
|
|
}
|
|
}
|
|
|
|
export function listUIAdapters(): UIAdapterModule[] {
|
|
return [...uiAdapters];
|
|
}
|