feat: plan-approval overlay, auth-expiry handling, cert download, login reset

- Add a dedicated plan-approval bottom sheet (interactive-prompt) driven by
  ExitPlanMode's now-4-option layout (Claude Code v2.1.177), with
  approve/YOLO/reject/feedback wired through respondPlan(requestId).
- PermissionManager: stop auto-expiring AskUserQuestion/plan prompts and stop
  releasing pending prompts on client disconnect — they reflect real CLI
  state and must survive reconnects.
- Detect server-rejected tokens (401/403 or failed WS handshake) and bounce
  back to the login screen via a new AUTH_EXPIRED_EVENT.
- Add `/cert` endpoint + Settings entry so phones can download/trust the
  self-signed HTTPS cert directly; fix cert IP detection on non-macOS hosts.
- Add `clawtap reset-login` command and `/api/auth/reset-attempts` endpoint
  to clear login rate-limit lockouts.
- Codex adapter: only forward recognized keystrokes/option indices to tmux,
  never the synthetic "deny" dismissal signal.
- PWA: actively poll for service-worker updates (iOS standalone apps don't
  reliably check on navigation).
- update-service.sh: install tmux if missing, prompt to create the env file
  instead of failing, add --skip-firewall, and improve logging.
This commit is contained in:
2026-06-15 16:30:24 -04:00
parent 4e6dfb4726
commit 2ded310472
23 changed files with 656 additions and 97 deletions
+10 -1
View File
@@ -75,6 +75,7 @@ Commands:
hooks install Install hooks (all adapters, or use --adapter)
hooks uninstall Remove hooks (all adapters, or use --adapter)
cert Generate self-signed HTTPS certificate
reset-login Clear too-many-login-attempts lockout
Options:
-v, --version Show version
@@ -152,7 +153,7 @@ HELP
-out "$CERT_FILE" \
-days 365 \
-subj "/CN=ClawTap" \
-addext "subjectAltName=IP:$(ipconfig getifaddr en0 2>/dev/null || echo '0.0.0.0')" \
-addext "subjectAltName=IP:$(hostname -I 2>/dev/null | awk '{print $1}' || ipconfig getifaddr en0 2>/dev/null || echo '0.0.0.0')" \
2>/dev/null
if [ $? -ne 0 ]; then
echo "Failed to generate certificate. Is openssl installed?"
@@ -254,6 +255,14 @@ require_auth() {
AUTH_TOKEN=""
}
# "reset-login" → clear login rate-limit lockout
if [ "$1" = "reset-login" ]; then
curl -s $CURL_OPTS -X POST "$PROTOCOL://localhost:$PORT/api/auth/reset-attempts" \
-H "Content-Type: application/json" -d '{}' >/dev/null
echo "Login rate limit reset."
exit 0
fi
# No args → just start server, print URLs, exit
if [ $# -eq 0 ]; then
LAN_IP=$(ipconfig getifaddr en0 2>/dev/null || echo "")