Commit Graph
53 Commits
Author SHA1 Message Date
Algis DumbrisandClaude Opus 4.6 87f24afd58 feat: enterprise identity provider support — GitHub, Google, Azure AD login
Add external IdP authentication via OAuth (GitHub) and OIDC (Google, Azure AD).
Users can sign in with enterprise credentials; accounts are auto-provisioned
and linked on first login. Configured entirely via environment variables.

- schema/011_external_auth.sql: user_identities table + email column on users
- internal/auth/idp/: provider interface, GitHub OAuth, generic OIDC, store,
  handlers (list providers, login redirect, callback with auto-provisioning)
- internal/auth/user_store.go: GetUserByEmail + SetEmail for IdP linking
- cmd/synapbus/main.go: wire IdP routes + agent provisioner adapter
- web/src/routes/login/+page.svelte: IdP buttons above password form
- Tests: domain restriction, store CRUD, provider listing, user provisioning

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 20:37:27 +02:00
Algis DumbrisandClaude Opus 4.6 1dd332adf7 fix: OAuth token introspection "context canceled" on concurrent MCP connections
Decouple fosite token introspection from the HTTP request context using
context.WithoutCancel + 10s timeout. When claude.ai opens multiple
concurrent MCP connections and one disconnects, the token validation
for subsequent connections no longer fails with "context canceled".

Fixes Bug #6 from #bugs-synapbus.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 17:59:23 +02:00
Algis DumbrisandClaude Opus 4.6 18d8179061 fix: derive OAuth URLs dynamically from request headers for tunnel/proxy support
When SYNAPBUS_BASE_URL is empty or set to "auto", the OAuth metadata
handler now reads X-Forwarded-Proto and X-Forwarded-Host headers to
construct correct OAuth URLs. This allows SynapBus to serve correct
OAuth metadata for both LAN and Cloudflare Tunnel access simultaneously.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 17:50:06 +02:00
Algis DumbrisandClaude Opus 4.6 fef2705d08 fix: URL auto-linking truncated — extract URLs before HTML escaping
Release / Build darwin/amd64 (push) Canceled after 0s
Release / Build linux/amd64 (push) Canceled after 0s
Release / Build darwin/arm64 (push) Canceled after 0s
Release / Build linux/arm64 (push) Canceled after 0s
Release / Generate Homebrew Formula (push) Canceled after 0s
Release / GitHub Release (push) Canceled after 0s
Release / Docker Image (push) Canceled after 0s
The regex matched against HTML-escaped text where &amp; entity chars
broke URL patterns. Now URLs are extracted and replaced with placeholders
before escapeHtml runs, then restored after all other inline processing.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 08:08:18 +02:00
Algis DumbrisandClaude Opus 4.6 faad47f0cf fix: rebuild embedded dist with all UI changes integrated
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-15 20:54:00 +02:00
Algis DumbrisandClaude Opus 4.6 47ba1e9740 feat: rework Conversations page into search-only with Slack-style filters
Replace the Conversations page with a dedicated search page featuring:
- Large, prominent search input with autofocus
- Collapsible filter panel with time range presets (24h, week, month,
  3 months, custom date range), channel filter (comma-separated,
  - prefix to exclude), and agent filter (same syntax)
- Search-results-only display with helpful empty state when no search
  has been performed
- Remove duplicate "Conversations" heading, rename to "Search"
- Update sidebar nav label and icon to match

Backend changes:
- Add channel, agent, after, before query parameters to
  GET /api/messages/search endpoint
- Add Channels, ExcludeChannels, Agents, ExcludeAgents fields to
  SearchOptions with SQL filter generation in store.go
- Support include/exclude semantics via - prefix for both channel
  and agent filters

API client updated to pass new filter parameters.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-15 19:47:22 +02:00
Algis DumbrisandClaude Opus 4.6 6abd45eeff fix: remove API Keys management section from Settings page
API keys are managed via admin CLI, not the web UI. Remove the
Management section from Settings, delete the api-keys route, and
clean up the Header page-title mapping.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-15 19:42:36 +02:00
Algis DumbrisandClaude Opus 4.6 96d9fbd246 fix: unify favicon and OAuth logo with constellation icon
Replace generic cube favicon and OAuth layered-planes logo with the
same constellation icon used in the sidebar and login page.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-15 19:07:57 +02:00
Algis DumbrisandClaude Opus 4.6 5938fcd555 fix: bugs #1-3-5 from #bugs-synapbus + live SSE notifications
- Auto-join public channels on first send (bug #1)
- Channel broadcasts no longer create duplicate DM copies; inbox DMs
  only sent for @mentions (bug #2)
- Embedding pipeline auto-enqueues new messages via MessageListener
  callback instead of requiring pod restart (bug #3)
- Admin socket defaults to /tmp in containers to avoid PVC filesystem
  incompatibility with Unix sockets (bug #5)
- SSE events now fire for MCP-sent messages (not just REST API),
  enabling live notification badges without page reload
- Fixed frontend SSE field name mismatch (channel_name → channel)
- Fixed SSE client not connecting after login redirect

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-15 18:56:30 +02:00
Algis DumbrisandClaude Opus 4.6 9dd27c4b9b feat: admin CLI & Docker fixes — alpine base, channels create/join, absolute socket path
Switch Docker runtime from scratch to alpine:3.19 so kubectl exec works
for admin CLI operations. Add `synapbus channels create` and
`synapbus channels join` CLI commands with corresponding admin socket
handlers. Change default socket path to /data/synapbus.sock (absolute).
Also add Helm envFrom support and NodePort configuration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 14:54:13 +02:00
Algis DumbrisandClaude Opus 4.6 5143e32f83 fix: notification bugs — human-agent-only counts, Svelte 5 lifecycle, API response parsing
Release / Build darwin/amd64 (push) Canceled after 0s
Release / Build linux/amd64 (push) Canceled after 0s
Release / Build darwin/arm64 (push) Canceled after 0s
Release / Build linux/arm64 (push) Canceled after 0s
Release / Generate Homebrew Formula (push) Canceled after 0s
Release / GitHub Release (push) Canceled after 0s
Release / Docker Image (push) Canceled after 0s
- Use human agent's perspective only for unread counts (avoids system agent inflation)
- Replace onDestroy + get() with $effect cleanup in channel/DM pages (Svelte 5 compat)
- Fix notification store to parse array-of-objects API response format
- Add last_read_message_id to DM messages endpoint
- Fix test agent type seeding for GetHumanAgentForUser

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 09:56:29 +02:00
Algis DumbrisandClaude Opus 4.6 eec06f5b5f feat: web UI notifications — unread badges, new message line, auto mark-as-read
Backend:
- GET /api/notifications/unread returns channel + DM unread counts
- POST /api/notifications/mark-read updates inbox_state for channels/DMs
- SSE broadcaster wired into message send for real-time push
- last_read_message_id added to channel/DM message responses

Frontend:
- Notification store tracks unread counts per channel/DM
- SSE listener for new_message and unread_update events
- Red circular badges in sidebar (Slack-style)
- "New messages" separator line in channel/DM views
- Auto mark-as-read after 2 seconds of viewing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 09:18:36 +02:00
Algis DumbrisandClaude Opus 4.6 68b7d946b3 fix: scan SQLite text timestamps in channel summary query
sql.NullTime cannot scan SQLite's text-format timestamps from
modernc.org/sqlite. Switch to sql.NullString with manual time.Parse.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 08:43:18 +02:00
Algis DumbrisandClaude Opus 4.6 fe8928a7fc refactor: consolidate 30 MCP tools into 4 hybrid tools (my_status, search, execute, send_message)
- JS/TS execution engine (goja + esbuild) with sandboxed runtime and call() bridge
- BM25 action discovery index over 23 registered actions
- ServiceBridge mapping call() invocations to existing service methods
- Admin CLI subcommands for webhook/k8s/gc operations
- Pagination support (offset/limit) in read_inbox, search_messages, get_channel_messages
- Fixed test assertions for call() envelope structure {ok, result}

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 08:29:37 +02:00
Algis DumbrisandClaude Opus 4.6 fef84ed538 refactor: consolidate 30 MCP tools into 4 hybrid tools
Replace 5 separate tool registrars (messaging, channels, swarm,
attachments, webhooks) with a single HybridToolRegistrar exposing
4 tools: my_status, send_message, search, and execute.

New foundation packages:
- internal/actions: action registry (22 actions) + BM25 search index
- internal/jsruntime: lightweight call() expression parser with
  concurrency-limited execution pool

The `execute` tool dispatches call() expressions through a
ServiceBridge that maps action names to existing service methods,
preserving all original handler logic. The `search` tool enables
agents to discover available actions by keyword. The `send_message`
tool merges DM and channel sending with mutual exclusion.

All unit tests, integration tests, build, and vet pass.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 08:16:41 +02:00
Algis Dumbris 275a80326f merge: Task C - Pagination + advanced filtering 2026-03-15 08:00:15 +02:00
Algis Dumbris 8e62319166 merge: Task B - Action registry + BM25 search (internal/actions/) 2026-03-15 08:00:12 +02:00
Algis Dumbris b47070533b merge: Task A - JS/TS runtime engine (internal/jsruntime/) 2026-03-15 08:00:06 +02:00
Algis DumbrisandClaude Opus 4.6 b9d402c135 feat: add offset-based pagination and advanced filtering to service layer
Add Offset, After, Before date filters to ReadOptions and SearchOptions.
Add Channel name filter to SearchOptions. Introduce PaginatedMessages,
PaginatedChannels, and PaginatedTasks types with total counts. Update
ReadInbox, SearchMessages, and GetChannelMessages to return paginated
results. Add CountInboxMessages, CountSearchMessages, CountChannelMessages,
and CountTasks store methods. Update all callers in MCP tools, REST API
handlers, and search service. Add comprehensive tests for offset
pagination, date filtering, channel name filtering, and combined
filters with pagination.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:59:33 +02:00
Algis DumbrisandClaude Opus 4.6 7f74357437 feat: add action registry with BM25 search index for tool discovery
Register all 23 agent-callable operations (messaging, channels, swarm,
attachments) with full parameter metadata and usage examples. Provide
in-memory BM25 text search over action documentation for tool discovery,
with simple stemming and compound-token matching so exact action names
rank highest.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:54:13 +02:00
Algis DumbrisandClaude Opus 4.6 d5ca5b915f feat: add webhook, k8s, and attachments gc CLI subcommands
Add admin CLI subcommands for managing webhooks, K8s job handlers,
and running attachment garbage collection via the Unix admin socket.

Server-side:
- Add WebhookServiceProvider and K8sServiceProvider interfaces to admin pkg
- Add 7 new command handlers: webhook.{register,list,delete},
  k8s.{register,list,delete}, attachments.gc
- Wire webhook and k8s services into admin.Services struct in main.go

CLI-side:
- Add `synapbus webhook {register,list,delete}` commands
- Add `synapbus k8s {register,list,delete}` commands
- Add `synapbus attachments gc` command
- All commands follow existing patterns (adminRequest, printTable, printJSON)

Tests:
- Add cmd/synapbus/admin_test.go with 9 tests covering command
  registration, required flag validation, and existing command preservation

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:53:53 +02:00
Algis DumbrisandClaude Opus 4.6 e8165511de feat: add sandboxed JS/TS runtime engine (internal/jsruntime)
Pure Go JavaScript/TypeScript execution engine using goja + esbuild.
Provides sandboxed code execution with a call() bridge for agent
actions, automatic TypeScript detection and transpilation, timeout
enforcement, max-calls limits, and a concurrent execution pool.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-15 07:53:25 +02:00
Algis DumbrisandClaude Opus 4.6 67783566d7 feat: embeddings management, message retention & agent inbox improvements
Release / Build darwin/amd64 (push) Canceled after 0s
Release / Build linux/amd64 (push) Canceled after 0s
Release / Build darwin/arm64 (push) Canceled after 0s
Release / Build linux/arm64 (push) Canceled after 0s
Release / Generate Homebrew Formula (push) Canceled after 0s
Release / GitHub Release (push) Canceled after 0s
Release / Docker Image (push) Canceled after 0s
- Add `my_status` MCP tool: single call returns agent identity, pending
  DMs, channel mentions, system notifications, channel summaries, and
  stats with truncation for large inboxes
- Add embeddings CLI: `synapbus embeddings status|reindex|clear` for
  managing vectors when switching embedding providers
- Add automatic message retention worker with configurable period
  (--message-retention, default 12m), warning notifications 1 month
  before deletion, cascade cleanup, and incremental vacuum
- Add manual purge: `synapbus messages purge --older-than --agent --channel`
  and `synapbus db vacuum` for on-demand cleanup
- Add `synapbus retention status` CLI for admin visibility
- Create system agent at startup for sending retention warnings
- Filter system agent from discover_agents results

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 19:20:07 +02:00
Algis DumbrisandClaude Opus 4.6 42775df65f feat: webhooks & Kubernetes Job runner for event-driven agents
- Webhook registration via MCP (register_webhook, list_webhooks, delete_webhook)
- HMAC-SHA256 payload signing, SSRF-safe HTTP client, loop detection (depth 5)
- 8-worker goroutine delivery pool with exponential backoff retry (1s/5s/30s)
- Dead letter queue with auto-purge, auto-disable after 50 consecutive failures
- Per-agent rate limiting (60 deliveries/min)
- K8s Job runner (register_k8s_handler, list_k8s_handlers, delete_k8s_handler)
- Auto-detect in-cluster via InClusterConfig, NoopRunner fallback
- REST API for webhook deliveries, dead letters, K8s job runs and logs
- Web UI: webhook management, K8s handler pages, dead letters view
- MultiDispatcher fan-out pattern for webhook + K8s event dispatch
- SQLite migration 009: webhooks, webhook_deliveries, k8s_handlers, k8s_job_runs
- 51 tests across 9 test packages, all passing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 18:14:04 +02:00
Algis DumbrisandClaude Opus 4.6 6b6285c014 chore: rebuild embedded web assets
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 16:26:53 +02:00
Algis DumbrisandClaude Opus 4.6 b8beff8adf feat: @mentions in channel messages with inbox notifications
Parse @agentname patterns in channel message body. Mentioned agents
(who are channel members, excluding sender) get mention=true flag in
their inbox notification metadata. Channel message metadata includes
mentioned_agents list for all recipients.

- mentions.go: regex parser with email exclusion, dedup, 22 test cases
- BroadcastMessage: metadata now uses json.Marshal, includes mentions
- Tests verify mention flag, self-mention exclusion, non-member skip

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 15:15:53 +02:00
Algis DumbrisandClaude Opus 4.6 77ffea2d96 feat: improve MCP tool descriptions to guide agent behavior
Updated tool descriptions to teach agents the right workflow:
- read_inbox: "Call this first when connecting"
- list_channels: "Call this when connecting to see available channels"
- send_message: guides to discover_agents first, points to send_channel_message
- search_messages: clarifies it searches inbox + channels
- send_channel_message: documents @agentname mentions
- discover_agents: explains it lists all agents when no query given

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 15:12:52 +02:00
Algis DumbrisandClaude Opus 4.6 d3ff70f6d3 fix: add get_channel_messages MCP tool and fix search to include channel messages
Agents could send channel messages but had no MCP tool to read them.
Also, search_messages only searched DMs (to/from agent), missing channel
messages entirely. Now SearchMessages includes channel messages where
the agent is a member.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 14:48:26 +02:00
Algis DumbrisandClaude Opus 4.6 41b24c3584 feat: multi-client MCP setup UX with auth mode switcher
Agent registration success screen now shows tabbed client selector
(Claude Code, Gemini, Cursor, Windsurf, VS Code, Claude Desktop)
with per-client CLI commands, JSON config, and API Key/OAuth toggle.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 14:28:16 +02:00
Algis DumbrisandClaude Opus 4.6 91ba02b148 fix: OAuth agent identity, channel messaging, thread replies, and token exchange
- Fix OAuth agent identity: add GetAgentName/GetUserID methods to fositeSession
  so the introspection type assertion succeeds and MCP uses the selected agent
  (e.g., "Alice Bot") instead of the human username ("alice")
- Fix channel broadcast: create a proper channel message (with channel_id) so
  messages sent via MCP send_channel_message appear in the Web UI channel view
- Fix thread replies: pass conversation_id from thread panel so replies go into
  the same conversation instead of creating a new one
- Fix OAuth token exchange: normalize localhost→127.0.0.1 in redirect_uri to
  match what was stored during authorization (fixes Gemini CLI callback timeout)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 14:02:30 +02:00
Algis DumbrisandClaude Opus 4.6 2575ce2626 feat: OAuth 2.1 with PKCE, MCP auth, dead letters, channel management, and UX polish
- Add OAuth 2.1 identity provider with PKCE S256 (ory/fosite)
- Add RFC 7591 dynamic client registration for MCP clients
- Add RFC 8414 OAuth metadata discovery endpoint
- Add branded OAuth login/authorize pages with SynapBus design
- Add SYNAPBUS_BASE_URL env var for remote/LAN deployments
- Add OAuth bearer token authentication for MCP connections
- Add dead letter queue with Web UI management page
- Add channel leave, member list, and improved channel management
- Add agent auth middleware for MCP-authenticated requests
- Add console printer for structured server startup output
- Hide human accounts from agent management UI
- Fix SSE through middleware (Flush/Unwrap support)
- Fix graceful shutdown by closing SSE clients before server stop
- Fix localhost/127.0.0.1 redirect URI normalization for OAuth
- Remove agent self-registration MCP tools (manage via Web UI only)
- Update README with OAuth setup guide and MCP client config example

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 12:54:02 +02:00
Algis DumbrisandClaude Opus 4.6 69e926441e fix: UI polish — leave channel, thread panel lifecycle, agent form, and text fixes
- Fix leave channel: handle ErrOwnerCannotLeave with error display, remove
  all owned agents from channel
- Close thread panel when navigating between channels/DMs
- Remove Type dropdown from agent registration (agents are always AI;
  human accounts created via CLI)
- Fix dashboard showing "Untitled conversation" — now shows last agent name
- Fix "1 msgs" → "1 msg" singular form on dashboard
- Fix conversation detail "-- N messages" → "— N message(s)" with em-dash
- Hide "done" status badge in MessageList and conversation detail
  (consistent with DM view behavior)
- Add thread reply buttons and reply count to channel and DM messages
- Add agent selector for multi-agent users in channel and DM compose
- Add "Join Channel" prompt for non-members in channel compose area
- Show "(you)" indicator on channel member list for owned agents
- Add agent detail page with messages endpoint
- Improve release workflow and Dockerfile

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 08:16:54 +02:00
Algis DumbrisandClaude Opus 4.6 f12824cda9 feat: add Gemini embedding provider, agent registration UI, and UI polish
- Add Gemini embedding provider alongside OpenAI and Ollama
- Improve agent registration form with API key display and MCP config
- Polish dashboard, login page, and overall UI styling
- Update CLAUDE.md with embedding environment variables
- Add console command infrastructure

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 06:46:16 +02:00
Algis DumbrisandClaude Opus 4.6 f5ae132ef4 feat: add Slack-like channel and DM messaging UX
- Channel pages now show message feed with compose bar instead of
  just member lists. Messages display with agent avatars, names,
  and timestamps. Collapsible info panel shows channel details.
- New /dm/[name] route for direct message conversations between
  agents with from→to indicators and status badges.
- Sidebar DM links now navigate to /dm/{name} instead of agent
  edit forms.
- Backend: add GetChannelMessages and GetDMMessages store/service
  methods with corresponding API handlers and routes.
- Makefile: build target now depends on web target so binary
  always embeds latest UI assets.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 06:46:07 +02:00
Algis DumbrisandClaude Opus 4.6 cad0138337 chore: migrate to github.com/synapbus org and add logo assets
Move module path from github.com/smart-mcp-proxy/synapbus to
github.com/synapbus/synapbus across all Go imports (47 files).
Add constellation logo options generated via FLUX 1.1 Pro.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 05:46:46 +02:00
ff81f2f218 feat: production readiness - metrics, health, CI/CD, Docker, Helm (#1)
* docs: add specification for production readiness & website launch

Covers DevOps hooks, CI/CD, Prometheus observability, Docker/Helm
deployment, and synapbus.dev website with documentation and blog.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* docs: add implementation plan and research for production readiness

Covers 5 workstreams: git hooks, CI/CD, observability, deployment
artifacts, and website. All constitution gates pass.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add pre-commit and pre-push git hooks

Pre-commit runs go vet, golangci-lint (optional), and fast tests.
Pre-push runs full test suite and build verification.
Installable via `make hooks`.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci: add GitHub Actions for PR checks and releases

ci.yml: lint, test, build on PRs to main.
release.yml: multi-platform binaries + Docker image on version tags.
Targets: linux/amd64, linux/arm64, darwin/amd64, darwin/arm64, windows/amd64.
Docker pushed to ghcr.io/smart-mcp-proxy/synapbus.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add Dockerfile, docker-compose, and Helm chart

Multi-stage Docker build (node + golang + scratch), ~30MB image.
docker-compose.yml for local development with volume persistence.
Helm chart with configurable Deployment, Service, PVC, Ingress,
and Prometheus ServiceMonitor.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add Prometheus metrics and Kubernetes health endpoints

Add internal/metrics package with Prometheus collectors (HTTP requests,
duration, messages, agents, connections) and chi-compatible middleware.
Add internal/health package with /healthz (liveness) and /readyz
(readiness with DB ping) endpoints. Wire into main.go with promhttp
handler at /metrics.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: update Go version to 1.25, fix Docker build issues

- Update Dockerfile golang image from 1.23 to 1.25 (matches go.mod)
- Add tzdata package for timezone support in scratch image
- Use npm install --legacy-peer-deps for web frontend build
- Update CI/release workflows to use Go 1.25

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve CI failures - golangci-lint v2 and npm peer deps

- Upgrade golangci-lint-action to v7 with v2.1 (supports Go 1.25)
- Use npm install --legacy-peer-deps instead of npm ci for web builds

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: replace golangci-lint with go vet (golangci-lint doesn't support Go 1.25 yet)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 21:03:47 +02:00
Algis DumbrisandClaude Opus 4.6 1cabbae6b5 fix: allow channel messages without specifying recipient in send_message MCP tool
The `to` parameter was incorrectly marked as Required() in the MCP tool
schema, preventing channel-only messages. The service layer already
validates that either `to` or `channel_id` must be provided.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 19:51:42 +02:00
Algis DumbrisandClaude Opus 4.6 b88d52276a feat: add admin CLI, API keys, threads, and Slack-like UI redesign
Major feature additions across backend and frontend:

Backend:
- Unix domain socket admin server with JSON-RPC protocol
- CLI subcommands: user/agent management, audit, backup, messages, channels
- Managed API keys (sb_ prefix) with permissions, channel limits, expiry
- Thread/reply support in messaging core (reply_to column)
- Context-based trace owner_id propagation for proper audit filtering
- Two-step auth middleware supporting both agent keys and managed API keys

Frontend:
- Complete Slack-like dark theme redesign with custom CSS properties
- Sidebar with Channels, Direct Messages, and Admin sections
- Thread panel (slide-in) for viewing message replies
- API key management page with create form, key display, and
  ready-to-use MCP/Claude Code config snippets with copy-to-clipboard
- All pages restyled: login, dashboard, agents, conversations, settings

E2E Tests:
- Fixed test runner binary path resolution
- Added pyproject.toml for test dependencies

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 16:10:51 +02:00
Algis DumbrisandClaude Opus 4.6 83f555f1e3 feat: switch MCP transport from SSE to Streamable HTTP
Replace deprecated SSE transport with Streamable HTTP (MCP spec
2025-03-26). Add OptionalAuthMiddleware for agent Bearer token
auth on /mcp endpoint — authenticates when token present, passes
through for unauthenticated tools like register_agent.

Also fix .gitignore to only ignore root synapbus binary, not
cmd/synapbus source directory.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 14:01:18 +02:00
Algis DumbrisandClaude Opus 4.6 f585ff17e5 fix: use all:dist embed pattern to include _app directory
Go's embed excludes files/directories starting with '_' by default.
SvelteKit outputs JS bundles under _app/, which would be silently
excluded by the dist/* pattern. Use all:dist to ensure all SPA assets
are embedded in the binary.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:55:16 +02:00
Algis DumbrisandClaude Opus 4.6 199bf02d0e fix: Svelte 5 runes mode compatibility — replace onMount with $effect
onMount callbacks never fire in Svelte 5 runes mode compiled output,
causing the SPA to show a loading spinner indefinitely. Replace all
onMount calls with $effect + _initialized guard pattern, and convert
$: reactive statements to $derived(). Rebuild embedded SPA.

- Replace onMount with $effect in +layout.svelte and all 7 page components
- Convert $: reactive assignments to $derived() (runes mode requirement)
- Rebuild SPA with fixes (internal/web/dist/index.html updated)
- Add synapbus binary to .gitignore

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:54:34 +02:00
Algis DumbrisandClaude Opus 4.6 78735bb8ee feat: implement Web UI with Svelte 5 SPA and REST API
Add complete Web UI infrastructure:

Go backend:
- REST API handlers for messages, agents, channels (internal/api/)
- SSE hub for real-time event streaming
- Session-to-owner middleware bridging auth sessions to API context
- SPA file server with go:embed for static assets
- GetMessageByID on MessagingService, RevokeKey on AgentService
- Updated router with RouterConfig for full service wiring

Svelte 5 SPA (web/):
- SvelteKit with static adapter for SPA mode
- Tailwind CSS with dark mode (class-based, localStorage persisted)
- API client with auto-redirect on 401
- SSE client with exponential backoff reconnect
- Pages: Login, Dashboard, Conversations, Channels, Agents, Settings
- Components: Sidebar, Header, MessageList, ComposeForm, AgentCard, TraceViewer
- Responsive layout with mobile sidebar toggle

Build:
- Placeholder index.html in internal/web/dist/ for go:embed compilation
- Updated Makefile web target to copy build output
- All existing Go tests pass, CGO_ENABLED=0

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:34:36 +02:00
Algis DumbrisandClaude Opus 4.6 29fe5c4275 feat: merge semantic search, attachments, swarm patterns (Round 3)
- Semantic Search: HNSW vector index, OpenAI/Ollama providers, FTS5 fallback
- Attachments: content-addressable storage, SHA-256 dedup, MCP tools
- Swarm Patterns: task auction, stigmergy, agent discovery, expiry worker

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:19:10 +02:00
Algis Dumbris e55a7f2b9b merge: attachments into main (resolve conflicts) 2026-03-13 12:17:16 +02:00
Algis DumbrisandClaude Opus 4.6 5dcb9e6149 feat: implement semantic search with embedding pipeline
Add HNSW-based vector search with configurable embedding providers
(OpenAI, Ollama) and automatic FTS5 fallback when no provider is
configured. Background pipeline embeds messages asynchronously on
ingest, stores vectors in a pure-Go HNSW index, and retries on
failure with exponential backoff. The search_messages MCP tool now
supports search_mode (auto/semantic/fulltext) and returns ranked
results with similarity scores. All existing tests continue to pass,
CGO_ENABLED=0 cross-compilation verified.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:14:36 +02:00
Algis DumbrisandClaude Opus 4.6 7909450473 feat: implement swarm patterns (task auction, stigmergy, discovery)
Add task auction lifecycle with full permission enforcement:
- TaskStore (SQLite) for tasks and bids CRUD, expiry, channel cancellation
- SwarmService with PostTask, BidOnTask, AcceptBid, CompleteTask
- MCP tools: post_task, bid_task, accept_bid, complete_task, list_tasks
- ExpiryWorker background goroutine for deadline-based task cancellation
- Channel type enforcement (auction ops only on auction channels)
- Agent cannot bid on own task, only poster accepts bids, only assignee completes
- Wired into main.go with graceful shutdown

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:12:33 +02:00
Algis DumbrisandClaude Opus 4.6 8e2294e19d feat: implement attachments with content-addressable storage
Add file attachment support with SHA-256 content-addressable storage,
automatic deduplication, MIME detection, and garbage collection for
orphaned files. Includes MCP tools (upload_attachment, download_attachment,
gc_attachments), REST API endpoints for Web UI, and comprehensive tests.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:12:27 +02:00
Algis DumbrisandClaude Opus 4.6 1cb0bb7a8f feat: merge auth, channels, and trace logging (Round 2)
- Human Auth: OAuth 2.1 with fosite, user registration, sessions, PKCE
- Channels: public/private channels, membership, broadcast, MCP tools
- Trace Logging: enhanced traces, REST API, metrics, retention cleanup
- Fixed migration numbering: channels=002, trace=003, auth=004

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 12:02:47 +02:00
Algis Dumbris 6ad78d58e0 fix: resolve migration version conflict (channels=002, trace=003) 2026-03-13 12:01:26 +02:00
Algis DumbrisandClaude Opus 4.6 8a1c096355 feat: implement human auth with OAuth 2.1 (fosite)
Add complete auth subsystem with OAuth 2.1 authorization server using
ory/fosite, local user accounts with bcrypt password hashing, session
management, and HTTP handlers for the Web UI.

Components:
- User store with bcrypt hashing (configurable cost, default 12), CRUD,
  validation (username 3-64 chars alphanumeric+underscore, password 8-72 bytes)
- Session store with secure random IDs, configurable lifetime (default 24h),
  expiration cleanup, and per-user invalidation
- OAuth client store with client_id/secret generation and bcrypt verification
- Fosite storage adapter implementing CoreStorage, TokenRevocationStorage,
  and PKCERequestStorage backed by SQLite
- OAuth provider configured with authorization code (PKCE S256 mandatory),
  client credentials, refresh token rotation, and token introspection
- HTTP handlers: POST /auth/register, POST /auth/login, POST /auth/logout,
  GET /auth/me, PUT /auth/password, GET /oauth/authorize, POST /oauth/token,
  POST /oauth/introspect
- Middleware: RequireSession (cookie), RequireBearer (access token),
  RequireAuth (either), RequireAdmin (role check)
- Structured auth event logging (login, token issuance, session lifecycle)
- Schema migration 002_auth.sql extending users, oauth_clients, oauth_tokens
  tables and adding sessions, oauth_authorization_codes tables
- Initial admin user auto-created on first run with random password printed
  to stdout
- All tests pass with CGO_ENABLED=0, zero external runtime dependencies

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-13 11:59:37 +02:00