Commit Graph
9 Commits
Author SHA1 Message Date
clawbot 2b2aeccf5b Merge branch 'next' into issue-7-webhook-delivery
check / check (push) Successful in 1m33s
Brings in the exact results past the range of a double. docs/TODO.md
conflicted: both Completed Steps lines are kept, the newer one first.

Model: opus-5-5
2026-09-29 07:58:01 +00:00
clawbot 0b9121a806 Answer exact results past the range of a double, such as 2^1200 (closes #16)
check / check (push) Successful in 1m18s
`2^1200` was refused although the calculator computed it exactly: writing a result went through a float64 and refused anything outside a double's range. An exact result under the 4096-bit limit is now written from its exact value, rounded to 17 significant digits past that range, and a fractional power of such a number is computed by first bringing its base into range with square roots taken from the exact value. Results computed in float64 must still be normal doubles; past the 4096-bit limit is still refused.

Disclosures: `1e-310` is answered again, reversing a call made in PR 11; a fractional power carries `math.Pow`'s rounding, which for a large base can reach the last digits shown.

Model: opus-5-5
2026-09-29 09:56:54 +02:00
clawbot 7170576a8e Webhooks: post each new incoming message (closes #7)
check / check (push) Successful in 1m45s
Each message a contact sends in a direct chat is posted to each webhook
on that chat, as JSON holding `chat_id` and the message record of the
messages endpoint. The event handler only queues it: `api.Deliveries`
serves a queue of 100 with four goroutines, reads the chat's webhooks
there, and makes one POST per webhook, with a 10-second timeout, no
retry and no redirect followed. A full queue or a failed post is logged
by ids, never by URL or text. `bot.Run` stops it last, once the chat
client has exited. Tests cover the payload and its routing, a full
queue, failures, and a webhook that never answers; the README documents
the payload and what delivery promises.

Model: opus-5-5
2026-09-29 07:19:56 +00:00
clawbot 397fc95149 HTTP API: register, list and remove webhooks, kept across restarts (closes #6)
check / check (push) Successful in 1m19s
An external app can register webhooks on a chat (`POST /api/v1/chats/{id}/webhooks` with a URL), list them, and remove one. Registering the same URL again returns the existing registration. Registrations are kept in `$DATA_DIR/webhooks.json`, rewritten whole on each change through a file created 0600, synced and renamed, so a crash leaves the old file or the new one; a file present but unreadable stops startup. Delivery of incoming messages is the next unit.

Disclosures: the JSON body reading is now one helper shared with the send endpoint; gosec G304 is suppressed on reading the webhooks file; the 0600-from-creation claim rests on `os.CreateTemp`'s source, not a system-call trace.

Model: opus-5-5
2026-09-29 08:38:13 +02:00
clawbot f53b666119 HTTP API: a chat's recent messages, and sending a message (closes #5)
check / check (push) Successful in 1m5s
`GET /api/v1/chats/{id}/messages?count=N` returns a chat's recent messages, oldest first (`count` 1 to 100, default 20), and `POST` to the same path sends a text message and returns it once the chat client has taken it. Both answer `404` for any id the chats list does not show, looked up in the same contact list. The message record is defined once, for the webhooks to reuse.

Disclosures: items are read five at a time, because one item can be many times its text and 100 at once could pass the 16 MiB read limit; text too long gets `413`, a contact who deleted the chat `409` (unverified for one still connecting); a query the server cannot read gets its own `400`.

Model: opus-5-5
2026-09-29 07:33:36 +02:00
clawbot 8f0906d677 README: clone from sneak/simplexcalc (closes #13)
check / check (push) Successful in 1m38s
The repository moved to `sneak/simplexcalc`; the Getting Started clone command still named `clawbot/simplexcalc`, which only redirects. It was the only mention of the old location.

Model: opus-5-5
2026-09-29 05:14:00 +02:00
clawbot f10d820ed4 HTTP API: server, credential and the list of chats (closes #4)
check / check (push) Successful in 1m13s
The bot now serves an HTTP API on `PORT` (default 8080) beside the chat client, whose WebSocket stays on 127.0.0.1 inside the container. Every request needs `Authorization: Bearer` with the credential from the file named by `API_TOKEN_FILE`, compared in constant time; with no credential configured every request is refused, `OPTIONS *` included. `GET /api/v1/chats` lists the bot's chats. Responses carry the security headers from the repository policies; bodies, requests and the server are time- and size-bounded. The chat client stops only after the API has finished its requests.

Disclosures: `contact_deleted` is an extra field; 404 and 405 answer in JSON; requests net/http cannot parse are refused by net/http without the security headers; three gosec findings are suppressed as false positives.

Model: opus-5-5
2026-09-29 04:55:49 +02:00
clawbot ac721390de Exponentiation and modulo in the calculator (closes #3)
check / check (push) Successful in 1m7s
The calculator now takes `^` (or `**`) for powers and `%` for modulo. Powers bind tighter than a sign on their left and group to the right, so `-2^2` is `-4` and `2^3^2` is `512`; `%` sits with `*` and `/` and takes the sign of the divisor. A small parser of our own replaces `go/parser`, which cannot express `^`; `go/constant` still computes.

A whole-number exponent is exact; a fractional one is computed in float64. Every number is held as a fraction under 4096 bits, and a float64 result must be a normal double, so one message cannot stall the bot; anything else gets "That needs a number too large or too small for me."

Disclosure: tiny values below about 2.2e-308, which `next` answered, are now refused.

Model: opus-5-5
2026-09-29 04:28:15 +02:00
clawbot 09a5caa8ab Move the command tree into internal/cli (closes #8)
check / check (push) Successful in 1m40s
`cmd/simplexcalc/` now holds only `main.go`, whose body is one call, `os.Exit(cli.Main(version))`, as the Go style guide requires. The command tree and the `run` and `version` commands moved unchanged into `internal/cli`, with tests for `version` and for an unknown command. Output streams, exit statuses and the `-X main.version` build flag are as before.

Disclosure: the comment in `execute` saying cobra has already printed the error is false, since the root command silences cobra's errors; it moved unchanged and is left for a follow-up.

Model: opus-5-5
2026-09-29 01:51:34 +02:00