feat: plan-approval overlay, auth-expiry handling, cert download, login reset

- Add a dedicated plan-approval bottom sheet (interactive-prompt) driven by
  ExitPlanMode's now-4-option layout (Claude Code v2.1.177), with
  approve/YOLO/reject/feedback wired through respondPlan(requestId).
- PermissionManager: stop auto-expiring AskUserQuestion/plan prompts and stop
  releasing pending prompts on client disconnect — they reflect real CLI
  state and must survive reconnects.
- Detect server-rejected tokens (401/403 or failed WS handshake) and bounce
  back to the login screen via a new AUTH_EXPIRED_EVENT.
- Add `/cert` endpoint + Settings entry so phones can download/trust the
  self-signed HTTPS cert directly; fix cert IP detection on non-macOS hosts.
- Add `clawtap reset-login` command and `/api/auth/reset-attempts` endpoint
  to clear login rate-limit lockouts.
- Codex adapter: only forward recognized keystrokes/option indices to tmux,
  never the synthetic "deny" dismissal signal.
- PWA: actively poll for service-worker updates (iOS standalone apps don't
  reliably check on navigation).
- update-service.sh: install tmux if missing, prompt to create the env file
  instead of failing, add --skip-firewall, and improve logging.
This commit is contained in:
2026-06-15 16:30:24 -04:00
parent 4e6dfb4726
commit 2ded310472
23 changed files with 656 additions and 97 deletions
+17 -1
View File
@@ -14,6 +14,14 @@ export function clearToken() {
localStorage.removeItem(STORAGE.TOKEN);
}
/** Fired when the server rejects the stored token (expired/invalid). */
export const AUTH_EXPIRED_EVENT = 'clawtap:auth-expired';
function handleAuthExpired() {
clearToken();
window.dispatchEvent(new Event(AUTH_EXPIRED_EVENT));
}
export function isAuthenticated(): boolean {
return !!getToken();
}
@@ -36,6 +44,9 @@ async function request<T>(path: string, options: RequestInit = {}): Promise<T> {
}
if (!res.ok) {
if ((res.status === 401 || res.status === 403) && token) {
handleAuthExpired();
}
const body = await res.json().catch(() => ({}));
throw new Error(body.error || `HTTP ${res.status}`);
}
@@ -72,7 +83,12 @@ export const api = {
headers: token ? { Authorization: `Bearer ${token}` } : {},
body: form,
});
if (!res.ok) throw new Error('Upload failed');
if (!res.ok) {
if ((res.status === 401 || res.status === 403) && token) {
handleAuthExpired();
}
throw new Error('Upload failed');
}
return res.json();
},