1 Commits
Author SHA1 Message Date
clawbot ca59368081 feat(frontend): post collected samples to /api/v1/reports (closes #53)
check / check (push) Successful in 9s
A Reporter beside AppState POSTs a JSON delta report of each host's
unreported, non-paused samples to the same-origin /api/v1/reports every
reportInterval (default 60s). buildReport is an exported pure function of
host state; init() runs only when #app exists, so a test can import it.
Per-host marks advance only on a delivered POST and never move backwards;
only one POST is in flight, abandoned after half the interval, so a slow
backend cannot cause re-sent samples. Failure is quiet and never blocks
probing.

The client id falls back to crypto.getRandomValues where crypto.randomUUID
is missing (plain HTTP to a non-localhost host). vite.config.js proxies
/api to 127.0.0.1:8080 for yarn dev.

Model: opus-5-5
2026-09-28 19:09:40 +00:00
+7 -10
View File
@@ -23,16 +23,6 @@ latest run passes.
# Completed Steps
- 2026-09-28: frontend reporting client (issue #53): a `Reporter` class posts
collected samples to `/api/v1/reports` every `reportInterval` (default 60s) as
a per-host delta, with the report-building step a pure exported function of
host state; a per-host mark advances only on a delivered POST; at most one
report POST is pending at a time and it is abandoned after half the interval,
so a slow POST never overlaps the next report and a mark never moves
backwards; the samples of an abandoned POST are sent again at the next
interval, so a backend that stored them but answered late receives them twice;
the per-browser client id works in insecure (plain-HTTP) contexts;
`vite.config.js` proxies `/api` to the local backend for `yarn dev`
- 2026-09-28: report ingest correctness (issue #23): a storage failure now
returns 500 instead of a false `ok`; oversize bodies return 413 (distinguished
from malformed JSON, which stays 400); a `MaxBodyBytes` middleware caps every
@@ -52,6 +42,13 @@ latest run passes.
`OnStop` is idempotent; and `writeTimeout` now exceeds the chi per-request
budget so that budget is actually reachable. Dead `startupTime`, `exitCode`,
and `cancelFunc` fields were removed
- 2026-09-21: frontend reporting client — a `Reporter` class posts collected
samples to `/api/v1/reports` every `reportInterval` (default 60s) as a
per-host delta, with the report-building step a pure exported function of host
state; only one report POST is in flight at a time and it is abandoned after
half the interval, so a slow backend cannot cause re-sent samples or a mark
moving backwards; the per-browser client id works in insecure (plain-HTTP)
contexts; `vite.config.js` proxies `/api` to the local backend for `yarn dev`
- 2026-09-21: backend HTTP hardening (issue #19): added `ReadHeaderTimeout` and
`IdleTimeout` to the server, a `SecurityHeaders` middleware (HSTS, tight CSP,
frame/sniff/referrer/permissions headers) registered before CORS, and