HTTP API: server, credential and the list of chats #12

Merged
clawbot merged 7 commits from issue-4-api-chats into next 2026-09-29 04:55:50 +02:00
7 Commits
Author SHA1 Message Date
clawbot b56d8714a7 Name the API credential in the README's Backup (closes #4)
check / check (push) Successful in 1m15s
Getting Started writes the credential to api-token on the volume, so a
backup that copies only the SimpleX database leaves it out, and the
documented docker run aborts after a restore. The Backup paragraph now
names api-token as the other durable file and says it is secret.

Model: opus-5-5
2026-09-29 02:42:39 +00:00
clawbot 1ba65da071 Merge next into issue-4-api-chats (closes #4)
check / check (push) Successful in 1m10s
Brings in the calculator's powers and remainders. docs/TODO.md keeps
both Completed Steps lines, the API one first.

Model: opus-5-5
2026-09-29 02:42:02 +00:00
clawbot 0c5163e69e Refuse OPTIONS * like any other API request (closes #4)
check / check (push) Successful in 1m16s
net/http answered "OPTIONS *" itself, with 200, before the router, so
it skipped the credential check and the security headers. The server
now passes it to the router, which refuses it with 401 like any other
request without the credential. A test sends it to a running server,
since the handler alone never sees it.

Model: opus-5-5
2026-09-29 02:20:58 +00:00
clawbot 9ce902fb05 Take the chat client's port from Run's caller (closes #4)
check / check (push) Successful in 1m8s
The test that runs the whole bot started its stand-in chat client on
5225, the port a real simplex-chat uses, so on a machine where one
listens there the test would have sent it the bot's set-up commands.
Run now takes the chat client's port: the run command passes
bot.ChatPort (5225), and the test a port it found free.

Model: opus-5-5
2026-09-29 02:08:56 +00:00
clawbot 407eaf847a Stop the chat client only after the API has stopped (closes #4)
check / check (push) Successful in 1m14s
The chat client's context no longer follows the bot's, so a stop no
longer sends it SIGTERM while the API is still finishing its requests.
The deferred stop in Run, which runs after the API's, stops it instead,
so a request in progress at a stop gets its answer rather than a 500.
The README says so.

The new test runs the whole bot with the test binary itself standing in
for simplex-chat on PATH. The stand-in holds its answer to the contacts
request until the test has told the bot to stop.

Model: opus-5-5
2026-09-29 01:36:44 +00:00
clawbot b965e45454 Send Permissions-Policy on every API response (closes #4)
check / check (push) Successful in 1m8s
docs/REPO_POLICIES.md requires a Permissions-Policy header restricting
the browser features an application does not use. The API now denies
the camera, microphone and location on every response, TestHeaders
checks it, and the README's Design section names it.

Model: opus-5-5
2026-09-29 00:59:42 +00:00
clawbot 17d6be9fe1 HTTP API: server, credential and the list of chats (closes #4)
check / check (push) Successful in 1m1s
The bot now serves an HTTP API on PORT (default 8080) beside the chat
client. Every request needs the credential read at startup from the
file named by API_TOKEN_FILE, sent as a bearer token; without one,
every request is refused. Responses carry the security headers, bodies
are capped at 64 KiB and each request's work at 10 seconds.

GET /api/v1/chats lists the bot's contacts from the chat client's
/_contacts command, ordered by id, and marks the contacts who deleted
their chat with the bot, which the chat client keeps listing. bot.Run
starts the API after set-up and stops it within 5 seconds; a listener
failure ends the bot as a chat client failure does.

Model: opus-5-5
2026-09-29 00:37:57 +00:00