Commit Graph
4 Commits
Author SHA1 Message Date
clawbot 4824937c92 HTTP API: its own 400 for a query that cannot be read (closes #5)
check / check (push) Successful in 1m12s
GET /api/v1/chats/{id}/messages answered any query that does not
decode, such as one holding ; or %zz, with the sentence about count,
even when count was valid or absent. It now answers such a query with
"the query cannot be read", and keeps the count sentence for a count
that decodes but is not a whole number from 1 to 100. The README names
both cases.

Model: opus-5-5
2026-09-29 05:08:52 +00:00
clawbot 2ce8da766a HTTP API: 404 for a chat id the list of chats leaves out (closes #5)
check / check (push) Successful in 1m19s
The chat client keeps contact records that GET /api/v1/chats does not
list, such as the bot's own profile (1 on a new profile) and a contact
it creates itself (2), and reads or sends in them when asked. The
message endpoints now look the id up, through chatID in
internal/api/chats.go, in the same list the chats endpoint answers
with, and answer 404 for any id not in it. The webhook endpoints can
call chatID too.

Model: opus-5-5
2026-09-29 04:32:28 +00:00
clawbot 2ad0b68e35 HTTP API: a chat's recent messages, and sending a message (closes #5)
check / check (push) Successful in 1m21s
GET /api/v1/chats/{id}/messages returns the messages among a chat's
last count items (default 20, at most 100), oldest first. POST sends a
text, waits for the chat client's answer and returns 201 with the
message as sent. A chat the bot does not have is 404, a contact who
deleted the chat is 409, a text too long for one message is 413, and
any other failure is 500 with a chosen sentence.

The chat client spells out a message's formatting in its answer, up to
26 times the text's length, so 100 items in one answer can pass the
16 MiB read limit and end the connection. Items are read five at a
time.

Model: opus-5-5
2026-09-29 03:48:45 +00:00
clawbot f10d820ed4 HTTP API: server, credential and the list of chats (closes #4)
check / check (push) Successful in 1m13s
The bot now serves an HTTP API on `PORT` (default 8080) beside the chat client, whose WebSocket stays on 127.0.0.1 inside the container. Every request needs `Authorization: Bearer` with the credential from the file named by `API_TOKEN_FILE`, compared in constant time; with no credential configured every request is refused, `OPTIONS *` included. `GET /api/v1/chats` lists the bot's chats. Responses carry the security headers from the repository policies; bodies, requests and the server are time- and size-bounded. The chat client stops only after the API has finished its requests.

Disclosures: `contact_deleted` is an extra field; 404 and 405 answer in JSON; requests net/http cannot parse are refused by net/http without the security headers; three gosec findings are suppressed as false positives.

Model: opus-5-5
2026-09-29 04:55:49 +02:00