Commit Graph
53 Commits
Author SHA1 Message Date
Algis DumbrisandClaude Opus 4.6 0469a7d2e1 plan: implementation plan for 005-hybrid-mcp-tools
3-phase plan: foundation (jsruntime, actions, pagination, CLI),
MCP rewrite (4 tools), website docs. Phase 1 runs in parallel.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:48:50 +02:00
Algis DumbrisandClaude Opus 4.6 7502c9fbd7 spec: address review feedback for 005-hybrid-mcp-tools
- Enumerate all 23 actions explicitly in FR-003 action catalog table
- Remove esbuild reference from FR-032 (moved to Assumptions)
- Add FR-043 (channel broadcast semantics), FR-044 (reply_to validation)
- Add FR-039a (memory limit enforcement for code execution)
- Rephrase FR-039 as testable concurrent behavior requirement
- Clarify search tool is for action discovery only (not message search)
- Add relevance score to search results (FR-021)
- Add edge cases: reply_to, memory limits, search vs search_messages
- Add breaking change migration note to Assumptions
- Fix SC-001 to be objectively measurable (count, not token estimate)
- Fix checklist self-assessment accuracy

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:36:39 +02:00
Algis DumbrisandClaude Opus 4.6 babf6b89e2 spec: hybrid MCP tool architecture (005)
Redesign 30 MCP tools into 4-tool hybrid architecture:
my_status, search, execute, send_message. Includes JS/TS
code execution engine, BM25 tool discovery, pagination,
advanced filtering, and CLI subcommands for admin ops.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:32:55 +02:00
Algis DumbrisandClaude Opus 4.6 67783566d7 feat: embeddings management, message retention & agent inbox improvements
Release / Build darwin/amd64 (push) Canceled after 0s
Release / Build linux/amd64 (push) Canceled after 0s
Release / Build darwin/arm64 (push) Canceled after 0s
Release / Build linux/arm64 (push) Canceled after 0s
Release / Generate Homebrew Formula (push) Canceled after 0s
Release / GitHub Release (push) Canceled after 0s
Release / Docker Image (push) Canceled after 0s
- Add `my_status` MCP tool: single call returns agent identity, pending
  DMs, channel mentions, system notifications, channel summaries, and
  stats with truncation for large inboxes
- Add embeddings CLI: `synapbus embeddings status|reindex|clear` for
  managing vectors when switching embedding providers
- Add automatic message retention worker with configurable period
  (--message-retention, default 12m), warning notifications 1 month
  before deletion, cascade cleanup, and incremental vacuum
- Add manual purge: `synapbus messages purge --older-than --agent --channel`
  and `synapbus db vacuum` for on-demand cleanup
- Add `synapbus retention status` CLI for admin visibility
- Create system agent at startup for sending retention warnings
- Filter system agent from discover_agents results

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
v0.2.0
2026-03-14 19:20:07 +02:00
Algis DumbrisandClaude Opus 4.6 15bbccf668 fix: drop Windows from release matrix (hnsw dep uses renameio !windows)
Release / Build darwin/amd64 (push) Canceled after 0s
Release / Build linux/amd64 (push) Canceled after 0s
Release / Build darwin/arm64 (push) Canceled after 0s
Release / Build linux/arm64 (push) Canceled after 0s
Release / Generate Homebrew Formula (push) Canceled after 0s
Release / GitHub Release (push) Canceled after 0s
Release / Docker Image (push) Canceled after 0s
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
v0.1.0
2026-03-14 18:21:25 +02:00
Algis DumbrisandClaude Opus 4.6 b23cea2649 merge: webhooks & Kubernetes Job runner
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 18:16:42 +02:00
Algis DumbrisandClaude Opus 4.6 46d3b7be89 merge: production readiness (CI, Docker, Helm, metrics, health probes)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 18:16:38 +02:00
Algis DumbrisandClaude Opus 4.6 42775df65f feat: webhooks & Kubernetes Job runner for event-driven agents
- Webhook registration via MCP (register_webhook, list_webhooks, delete_webhook)
- HMAC-SHA256 payload signing, SSRF-safe HTTP client, loop detection (depth 5)
- 8-worker goroutine delivery pool with exponential backoff retry (1s/5s/30s)
- Dead letter queue with auto-purge, auto-disable after 50 consecutive failures
- Per-agent rate limiting (60 deliveries/min)
- K8s Job runner (register_k8s_handler, list_k8s_handlers, delete_k8s_handler)
- Auto-detect in-cluster via InClusterConfig, NoopRunner fallback
- REST API for webhook deliveries, dead letters, K8s job runs and logs
- Web UI: webhook management, K8s handler pages, dead letters view
- MultiDispatcher fan-out pattern for webhook + K8s event dispatch
- SQLite migration 009: webhooks, webhook_deliveries, k8s_handlers, k8s_job_runs
- 51 tests across 9 test packages, all passing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 18:14:04 +02:00
Algis DumbrisandClaude Opus 4.6 6b6285c014 chore: rebuild embedded web assets
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 16:26:53 +02:00
Algis DumbrisandClaude Opus 4.6 f16e4b3872 feat: add E2E integration tests with real MCP protocol
11 Go integration tests that start an in-process server with in-memory
SQLite, register agents with API keys, and make real JSON-RPC 2.0 calls
to /mcp. Tests cover: direct messages, channels, search, threads,
agent discovery, inbox filters, claim/mark-done, tool listing, auth
enforcement, private channels, and read-state tracking.

Run with: make test-e2e

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 15:18:00 +02:00
Algis DumbrisandClaude Opus 4.6 b8beff8adf feat: @mentions in channel messages with inbox notifications
Parse @agentname patterns in channel message body. Mentioned agents
(who are channel members, excluding sender) get mention=true flag in
their inbox notification metadata. Channel message metadata includes
mentioned_agents list for all recipients.

- mentions.go: regex parser with email exclusion, dedup, 22 test cases
- BroadcastMessage: metadata now uses json.Marshal, includes mentions
- Tests verify mention flag, self-mention exclusion, non-member skip

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 15:15:53 +02:00
Algis DumbrisandClaude Opus 4.6 77ffea2d96 feat: improve MCP tool descriptions to guide agent behavior
Updated tool descriptions to teach agents the right workflow:
- read_inbox: "Call this first when connecting"
- list_channels: "Call this when connecting to see available channels"
- send_message: guides to discover_agents first, points to send_channel_message
- search_messages: clarifies it searches inbox + channels
- send_channel_message: documents @agentname mentions
- discover_agents: explains it lists all agents when no query given

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 15:12:52 +02:00
Algis DumbrisandClaude Opus 4.6 d3ff70f6d3 fix: add get_channel_messages MCP tool and fix search to include channel messages
Agents could send channel messages but had no MCP tool to read them.
Also, search_messages only searched DMs (to/from agent), missing channel
messages entirely. Now SearchMessages includes channel messages where
the agent is a member.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 14:48:26 +02:00
Algis DumbrisandClaude Opus 4.6 41b24c3584 feat: multi-client MCP setup UX with auth mode switcher
Agent registration success screen now shows tabbed client selector
(Claude Code, Gemini, Cursor, Windsurf, VS Code, Claude Desktop)
with per-client CLI commands, JSON config, and API Key/OAuth toggle.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 14:28:16 +02:00
Algis DumbrisandClaude Opus 4.6 91ba02b148 fix: OAuth agent identity, channel messaging, thread replies, and token exchange
- Fix OAuth agent identity: add GetAgentName/GetUserID methods to fositeSession
  so the introspection type assertion succeeds and MCP uses the selected agent
  (e.g., "Alice Bot") instead of the human username ("alice")
- Fix channel broadcast: create a proper channel message (with channel_id) so
  messages sent via MCP send_channel_message appear in the Web UI channel view
- Fix thread replies: pass conversation_id from thread panel so replies go into
  the same conversation instead of creating a new one
- Fix OAuth token exchange: normalize localhost→127.0.0.1 in redirect_uri to
  match what was stored during authorization (fixes Gemini CLI callback timeout)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 14:02:30 +02:00
Algis DumbrisandClaude Opus 4.6 2575ce2626 feat: OAuth 2.1 with PKCE, MCP auth, dead letters, channel management, and UX polish
- Add OAuth 2.1 identity provider with PKCE S256 (ory/fosite)
- Add RFC 7591 dynamic client registration for MCP clients
- Add RFC 8414 OAuth metadata discovery endpoint
- Add branded OAuth login/authorize pages with SynapBus design
- Add SYNAPBUS_BASE_URL env var for remote/LAN deployments
- Add OAuth bearer token authentication for MCP connections
- Add dead letter queue with Web UI management page
- Add channel leave, member list, and improved channel management
- Add agent auth middleware for MCP-authenticated requests
- Add console printer for structured server startup output
- Hide human accounts from agent management UI
- Fix SSE through middleware (Flush/Unwrap support)
- Fix graceful shutdown by closing SSE clients before server stop
- Fix localhost/127.0.0.1 redirect URI normalization for OAuth
- Remove agent self-registration MCP tools (manage via Web UI only)
- Update README with OAuth setup guide and MCP client config example

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 12:54:02 +02:00
Algis DumbrisandClaude Opus 4.6 69e926441e fix: UI polish — leave channel, thread panel lifecycle, agent form, and text fixes
- Fix leave channel: handle ErrOwnerCannotLeave with error display, remove
  all owned agents from channel
- Close thread panel when navigating between channels/DMs
- Remove Type dropdown from agent registration (agents are always AI;
  human accounts created via CLI)
- Fix dashboard showing "Untitled conversation" — now shows last agent name
- Fix "1 msgs" → "1 msg" singular form on dashboard
- Fix conversation detail "-- N messages" → "— N message(s)" with em-dash
- Hide "done" status badge in MessageList and conversation detail
  (consistent with DM view behavior)
- Add thread reply buttons and reply count to channel and DM messages
- Add agent selector for multi-agent users in channel and DM compose
- Add "Join Channel" prompt for non-members in channel compose area
- Show "(you)" indicator on channel member list for owned agents
- Add agent detail page with messages endpoint
- Improve release workflow and Dockerfile

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 08:16:54 +02:00
Algis DumbrisandClaude Opus 4.6 f12824cda9 feat: add Gemini embedding provider, agent registration UI, and UI polish
- Add Gemini embedding provider alongside OpenAI and Ollama
- Improve agent registration form with API key display and MCP config
- Polish dashboard, login page, and overall UI styling
- Update CLAUDE.md with embedding environment variables
- Add console command infrastructure

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 06:46:16 +02:00
Algis DumbrisandClaude Opus 4.6 f5ae132ef4 feat: add Slack-like channel and DM messaging UX
- Channel pages now show message feed with compose bar instead of
  just member lists. Messages display with agent avatars, names,
  and timestamps. Collapsible info panel shows channel details.
- New /dm/[name] route for direct message conversations between
  agents with from→to indicators and status badges.
- Sidebar DM links now navigate to /dm/{name} instead of agent
  edit forms.
- Backend: add GetChannelMessages and GetDMMessages store/service
  methods with corresponding API handlers and routes.
- Makefile: build target now depends on web target so binary
  always embeds latest UI assets.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 06:46:07 +02:00
Algis DumbrisandClaude Opus 4.6 cad0138337 chore: migrate to github.com/synapbus org and add logo assets
Move module path from github.com/smart-mcp-proxy/synapbus to
github.com/synapbus/synapbus across all Go imports (47 files).
Add constellation logo options generated via FLUX 1.1 Pro.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 05:46:46 +02:00
ff81f2f218 feat: production readiness - metrics, health, CI/CD, Docker, Helm (#1)
* docs: add specification for production readiness & website launch

Covers DevOps hooks, CI/CD, Prometheus observability, Docker/Helm
deployment, and synapbus.dev website with documentation and blog.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* docs: add implementation plan and research for production readiness

Covers 5 workstreams: git hooks, CI/CD, observability, deployment
artifacts, and website. All constitution gates pass.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add pre-commit and pre-push git hooks

Pre-commit runs go vet, golangci-lint (optional), and fast tests.
Pre-push runs full test suite and build verification.
Installable via `make hooks`.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci: add GitHub Actions for PR checks and releases

ci.yml: lint, test, build on PRs to main.
release.yml: multi-platform binaries + Docker image on version tags.
Targets: linux/amd64, linux/arm64, darwin/amd64, darwin/arm64, windows/amd64.
Docker pushed to ghcr.io/smart-mcp-proxy/synapbus.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add Dockerfile, docker-compose, and Helm chart

Multi-stage Docker build (node + golang + scratch), ~30MB image.
docker-compose.yml for local development with volume persistence.
Helm chart with configurable Deployment, Service, PVC, Ingress,
and Prometheus ServiceMonitor.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add Prometheus metrics and Kubernetes health endpoints

Add internal/metrics package with Prometheus collectors (HTTP requests,
duration, messages, agents, connections) and chi-compatible middleware.
Add internal/health package with /healthz (liveness) and /readyz
(readiness with DB ping) endpoints. Wire into main.go with promhttp
handler at /metrics.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: update Go version to 1.25, fix Docker build issues

- Update Dockerfile golang image from 1.23 to 1.25 (matches go.mod)
- Add tzdata package for timezone support in scratch image
- Use npm install --legacy-peer-deps for web frontend build
- Update CI/release workflows to use Go 1.25

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve CI failures - golangci-lint v2 and npm peer deps

- Upgrade golangci-lint-action to v7 with v2.1 (supports Go 1.25)
- Use npm install --legacy-peer-deps instead of npm ci for web builds

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: replace golangci-lint with go vet (golangci-lint doesn't support Go 1.25 yet)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 21:03:47 +02:00
Algis DumbrisandClaude Opus 4.6 4f5429b2da fix: replace golangci-lint with go vet (golangci-lint doesn't support Go 1.25 yet)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 21:02:58 +02:00
Algis DumbrisandClaude Opus 4.6 cf71a9deed fix: resolve CI failures - golangci-lint v2 and npm peer deps
- Upgrade golangci-lint-action to v7 with v2.1 (supports Go 1.25)
- Use npm install --legacy-peer-deps instead of npm ci for web builds

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 21:00:58 +02:00
Algis DumbrisandClaude Opus 4.6 8258e19abc fix: update Go version to 1.25, fix Docker build issues
- Update Dockerfile golang image from 1.23 to 1.25 (matches go.mod)
- Add tzdata package for timezone support in scratch image
- Use npm install --legacy-peer-deps for web frontend build
- Update CI/release workflows to use Go 1.25

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:25:52 +02:00
Algis DumbrisandClaude Opus 4.6 a9d4954a36 feat: add Prometheus metrics and Kubernetes health endpoints
Add internal/metrics package with Prometheus collectors (HTTP requests,
duration, messages, agents, connections) and chi-compatible middleware.
Add internal/health package with /healthz (liveness) and /readyz
(readiness with DB ping) endpoints. Wire into main.go with promhttp
handler at /metrics.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:19:58 +02:00
Algis DumbrisandClaude Opus 4.6 b8460dcfa4 feat: add Dockerfile, docker-compose, and Helm chart
Multi-stage Docker build (node + golang + scratch), ~30MB image.
docker-compose.yml for local development with volume persistence.
Helm chart with configurable Deployment, Service, PVC, Ingress,
and Prometheus ServiceMonitor.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:17:28 +02:00
Algis DumbrisandClaude Opus 4.6 a187cb86d1 ci: add GitHub Actions for PR checks and releases
ci.yml: lint, test, build on PRs to main.
release.yml: multi-platform binaries + Docker image on version tags.
Targets: linux/amd64, linux/arm64, darwin/amd64, darwin/arm64, windows/amd64.
Docker pushed to ghcr.io/smart-mcp-proxy/synapbus.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:17:21 +02:00
Algis DumbrisandClaude Opus 4.6 7de0114927 feat: add pre-commit and pre-push git hooks
Pre-commit runs go vet, golangci-lint (optional), and fast tests.
Pre-push runs full test suite and build verification.
Installable via `make hooks`.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:17:15 +02:00
Algis DumbrisandClaude Opus 4.6 fcb8da613c docs: add implementation plan and research for production readiness
Covers 5 workstreams: git hooks, CI/CD, observability, deployment
artifacts, and website. All constitution gates pass.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:13:58 +02:00
Algis DumbrisandClaude Opus 4.6 5248593e67 docs: add specification for production readiness & website launch
Covers DevOps hooks, CI/CD, Prometheus observability, Docker/Helm
deployment, and synapbus.dev website with documentation and blog.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 20:12:32 +02:00
Algis DumbrisandClaude Opus 4.6 1cabbae6b5 fix: allow channel messages without specifying recipient in send_message MCP tool
The `to` parameter was incorrectly marked as Required() in the MCP tool
schema, preventing channel-only messages. The service layer already
validates that either `to` or `channel_id` must be provided.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 19:51:42 +02:00
Algis DumbrisandClaude Opus 4.6 588f6a4ac4 chore: remove __pycache__ from tracking and add to .gitignore
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 16:11:18 +02:00
Algis DumbrisandClaude Opus 4.6 b88d52276a feat: add admin CLI, API keys, threads, and Slack-like UI redesign
Major feature additions across backend and frontend:

Backend:
- Unix domain socket admin server with JSON-RPC protocol
- CLI subcommands: user/agent management, audit, backup, messages, channels
- Managed API keys (sb_ prefix) with permissions, channel limits, expiry
- Thread/reply support in messaging core (reply_to column)
- Context-based trace owner_id propagation for proper audit filtering
- Two-step auth middleware supporting both agent keys and managed API keys

Frontend:
- Complete Slack-like dark theme redesign with custom CSS properties
- Sidebar with Channels, Direct Messages, and Admin sections
- Thread panel (slide-in) for viewing message replies
- API key management page with create form, key display, and
  ready-to-use MCP/Claude Code config snippets with copy-to-clipboard
- All pages restyled: login, dashboard, agents, conversations, settings

E2E Tests:
- Fixed test runner binary path resolution
- Added pyproject.toml for test dependencies

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 16:10:51 +02:00
Algis DumbrisandClaude Opus 4.6 56e3ab3b56 feat: E2E agent test with subscription token auth
Rewrite test to use 3-tier auth fallback (from dialog-engine pattern):
ANTHROPIC_API_KEY → CLAUDE_CODE_OAUTH_TOKEN → macOS Keychain.
No dedicated API key required — works with Claude subscription.

- Auto-start/stop SynapBus server (--auto-server flag)
- Dialog-engine tool loop pattern (max rounds + forced text termination)
- Token usage and cost tracking
- Add spec for E2E agent testing framework (011)

Tested: two Claude agents (Alice, Bob) autonomously exchange messages
through SynapBus MCP Streamable HTTP. Cost: ~$0.07 per run.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 14:25:17 +02:00
Algis DumbrisandClaude Opus 4.6 9bc9a74177 feat: add E2E test for two Claude agents communicating via SynapBus
Python script using Anthropic SDK + SynapBus MCP Streamable HTTP.
Two AI agents (Alice, Bob) autonomously exchange messages through
SynapBus tools: discover_agents, send_message, read_inbox, mark_done.

Usage: ANTHROPIC_API_KEY=... python tests/e2e/test_two_agents.py

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 14:03:34 +02:00
Algis DumbrisandClaude Opus 4.6 83f555f1e3 feat: switch MCP transport from SSE to Streamable HTTP
Replace deprecated SSE transport with Streamable HTTP (MCP spec
2025-03-26). Add OptionalAuthMiddleware for agent Bearer token
auth on /mcp endpoint — authenticates when token present, passes
through for unauthenticated tools like register_agent.

Also fix .gitignore to only ignore root synapbus binary, not
cmd/synapbus source directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 14:01:18 +02:00
Algis DumbrisandClaude Opus 4.6 f585ff17e5 fix: use all:dist embed pattern to include _app directory
Go's embed excludes files/directories starting with '_' by default.
SvelteKit outputs JS bundles under _app/, which would be silently
excluded by the dist/* pattern. Use all:dist to ensure all SPA assets
are embedded in the binary.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:55:16 +02:00
Algis DumbrisandClaude Opus 4.6 a6266d128d chore: track web/package-lock.json for reproducible builds
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:54:39 +02:00
Algis DumbrisandClaude Opus 4.6 199bf02d0e fix: Svelte 5 runes mode compatibility — replace onMount with $effect
onMount callbacks never fire in Svelte 5 runes mode compiled output,
causing the SPA to show a loading spinner indefinitely. Replace all
onMount calls with $effect + _initialized guard pattern, and convert
$: reactive statements to $derived(). Rebuild embedded SPA.

- Replace onMount with $effect in +layout.svelte and all 7 page components
- Convert $: reactive assignments to $derived() (runes mode requirement)
- Rebuild SPA with fixes (internal/web/dist/index.html updated)
- Add synapbus binary to .gitignore

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:54:34 +02:00
Algis DumbrisandClaude Opus 4.6 78735bb8ee feat: implement Web UI with Svelte 5 SPA and REST API
Add complete Web UI infrastructure:

Go backend:
- REST API handlers for messages, agents, channels (internal/api/)
- SSE hub for real-time event streaming
- Session-to-owner middleware bridging auth sessions to API context
- SPA file server with go:embed for static assets
- GetMessageByID on MessagingService, RevokeKey on AgentService
- Updated router with RouterConfig for full service wiring

Svelte 5 SPA (web/):
- SvelteKit with static adapter for SPA mode
- Tailwind CSS with dark mode (class-based, localStorage persisted)
- API client with auto-redirect on 401
- SSE client with exponential backoff reconnect
- Pages: Login, Dashboard, Conversations, Channels, Agents, Settings
- Components: Sidebar, Header, MessageList, ComposeForm, AgentCard, TraceViewer
- Responsive layout with mobile sidebar toggle

Build:
- Placeholder index.html in internal/web/dist/ for go:embed compilation
- Updated Makefile web target to copy build output
- All existing Go tests pass, CGO_ENABLED=0

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:34:36 +02:00
Algis DumbrisandClaude Opus 4.6 29fe5c4275 feat: merge semantic search, attachments, swarm patterns (Round 3)
- Semantic Search: HNSW vector index, OpenAI/Ollama providers, FTS5 fallback
- Attachments: content-addressable storage, SHA-256 dedup, MCP tools
- Swarm Patterns: task auction, stigmergy, agent discovery, expiry worker

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:19:10 +02:00
Algis Dumbris e55a7f2b9b merge: attachments into main (resolve conflicts) 2026-03-13 12:17:16 +02:00
Algis DumbrisandClaude Opus 4.6 5dcb9e6149 feat: implement semantic search with embedding pipeline
Add HNSW-based vector search with configurable embedding providers
(OpenAI, Ollama) and automatic FTS5 fallback when no provider is
configured. Background pipeline embeds messages asynchronously on
ingest, stores vectors in a pure-Go HNSW index, and retries on
failure with exponential backoff. The search_messages MCP tool now
supports search_mode (auto/semantic/fulltext) and returns ranked
results with similarity scores. All existing tests continue to pass,
CGO_ENABLED=0 cross-compilation verified.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:14:36 +02:00
Algis DumbrisandClaude Opus 4.6 7909450473 feat: implement swarm patterns (task auction, stigmergy, discovery)
Add task auction lifecycle with full permission enforcement:
- TaskStore (SQLite) for tasks and bids CRUD, expiry, channel cancellation
- SwarmService with PostTask, BidOnTask, AcceptBid, CompleteTask
- MCP tools: post_task, bid_task, accept_bid, complete_task, list_tasks
- ExpiryWorker background goroutine for deadline-based task cancellation
- Channel type enforcement (auction ops only on auction channels)
- Agent cannot bid on own task, only poster accepts bids, only assignee completes
- Wired into main.go with graceful shutdown

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:12:33 +02:00
Algis DumbrisandClaude Opus 4.6 8e2294e19d feat: implement attachments with content-addressable storage
Add file attachment support with SHA-256 content-addressable storage,
automatic deduplication, MIME detection, and garbage collection for
orphaned files. Includes MCP tools (upload_attachment, download_attachment,
gc_attachments), REST API endpoints for Web UI, and comprehensive tests.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:12:27 +02:00
Algis DumbrisandClaude Opus 4.6 1cb0bb7a8f feat: merge auth, channels, and trace logging (Round 2)
- Human Auth: OAuth 2.1 with fosite, user registration, sessions, PKCE
- Channels: public/private channels, membership, broadcast, MCP tools
- Trace Logging: enhanced traces, REST API, metrics, retention cleanup
- Fixed migration numbering: channels=002, trace=003, auth=004

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:02:47 +02:00
Algis Dumbris 7c1e48efd8 chore: exclude worktrees from git tracking 2026-03-13 12:01:30 +02:00
Algis Dumbris 6ad78d58e0 fix: resolve migration version conflict (channels=002, trace=003) 2026-03-13 12:01:26 +02:00
Algis DumbrisandClaude Opus 4.6 8a1c096355 feat: implement human auth with OAuth 2.1 (fosite)
Add complete auth subsystem with OAuth 2.1 authorization server using
ory/fosite, local user accounts with bcrypt password hashing, session
management, and HTTP handlers for the Web UI.

Components:
- User store with bcrypt hashing (configurable cost, default 12), CRUD,
  validation (username 3-64 chars alphanumeric+underscore, password 8-72 bytes)
- Session store with secure random IDs, configurable lifetime (default 24h),
  expiration cleanup, and per-user invalidation
- OAuth client store with client_id/secret generation and bcrypt verification
- Fosite storage adapter implementing CoreStorage, TokenRevocationStorage,
  and PKCERequestStorage backed by SQLite
- OAuth provider configured with authorization code (PKCE S256 mandatory),
  client credentials, refresh token rotation, and token introspection
- HTTP handlers: POST /auth/register, POST /auth/login, POST /auth/logout,
  GET /auth/me, PUT /auth/password, GET /oauth/authorize, POST /oauth/token,
  POST /oauth/introspect
- Middleware: RequireSession (cookie), RequireBearer (access token),
  RequireAuth (either), RequireAdmin (role check)
- Structured auth event logging (login, token issuance, session lifecycle)
- Schema migration 002_auth.sql extending users, oauth_clients, oauth_tokens
  tables and adding sessions, oauth_authorization_codes tables
- Initial admin user auto-created on first run with random password printed
  to stdout
- All tests pass with CGO_ENABLED=0, zero external runtime dependencies

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 11:59:37 +02:00
Algis DumbrisandClaude Opus 4.6 be098081b4 feat: implement trace logging, REST API, and observability
Add comprehensive trace logging and observability features:

- Enhanced trace store with owner-scoped queries, filtering (agent, action,
  time range), pagination, streaming export, and retention cleanup
- REST API endpoints: GET /api/traces (list with filters), GET /api/traces/export
  (streaming JSON/CSV), GET /api/traces/stats (action counts)
- Owner isolation enforced at every layer (store, API, tests)
- Hand-rolled Prometheus metrics (pure Go, zero CGO): traces_total,
  traces_by_action, errors_total, active_agents at GET /metrics
- Configurable slog JSON handler with --log-level flag
- Request ID middleware for cross-referencing logs and traces
- Batch trace writing (64 entries or 100ms flush interval)
- Background retention cleanup via --trace-retention flag
- SQL migration 002 adds owner_id column and composite indexes

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 11:57:05 +02:00