feat: add SSH ops panel, Git graph swimlane, LAN remote preview & IM push - #341
Closed
Jason880902 wants to merge 5 commits into
Closed
feat: add SSH ops panel, Git graph swimlane, LAN remote preview & IM push#341Jason880902 wants to merge 5 commits into
Jason880902 wants to merge 5 commits into
Conversation
added 5 commits
August 16, 2026 11:11
Extend the in-session terminal bridge to spawn commands directly
(e.g. ssh user@host), parse ~/.ssh/config for a host list, and add a
sidebar entry ('运维') that opens a multi-session SSH ops panel with
quick-connect input and xterm rendering.
Add a sidebar entry ('Git') that opens a swimlane git graph panel. The
Electron main process gains an ipollowork:git:graph IPC that builds a
commit DAG from rev-list --parents plus ref -> commit mapping from
for-each-ref; the renderer draws an SVG lane layout with branch badges,
commit selection, and a detail pane.
Add a default-off LAN read-only preview server so phones and tablets on the local network can view the workbench via a pairing flow. The main process gains a lan-preview-server with 6-digit single-use pair codes, challenge-based anti-CSRF, in-memory session tokens, per-IP fail lockout and rate limiting, and a hard 403 on /api/execute (read-only). A new settings tab (Remote Preview) toggles the server, shows the LAN address and pair code with countdown, and lists paired devices.
SSH ops + Git graph + LAN preview remediation pass: - Git graph: detect and surface truncation (rev-list total-count probe, truncated banner, dashed stub edges for parents outside the window); fix lane layout so sibling branches fork to distinct lanes instead of collapsing onto the parent lane. - LAN preview: raise pair-code entropy (8-char uppercase alphabet, ~39.6 bits) and add a global fail lockout with exponential backoff on top of per-IP limits. - Module layout: move ops-panel/git-panel out of domains/session/terminal into domain-owned dirs with pure-logic modules (graph-layout.ts, ops-utils.ts) instead of dodging the single-file-directory audit rule. - Main process: extract ssh-ops.mjs and git-graph.mjs factories from main.mjs; add preview-core.mjs shared read-only renderer bridge with sanitized public summary for LAN/IM channels. - Tests: node:test suites for ssh config parsing, git DAG building, and preview-core redaction; bun:test suites for swimlane layout and SSH target normalization.
Add an IM notification section to the Remote Preview settings tab: paste a DingTalk/Feishu MCP Streamable-HTTP endpoint and push a redacted workbench summary to the group. The main process gains im-bot.mjs, a minimal MCP client that discovers a send tool by name (send_message / sendMessage / send_text / messages_send) and calls it with the sanitized snapshot from preview-core. No lan-preview session tokens are ever sent. Includes node:test coverage for tool discovery, argument mapping, and summary redaction.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
概述
为 iPolloWork 客户端左侧功能菜单新增三个工具入口,并完成一轮规范性整改。所有改动已在真实运行的 Electron 应用中端到端验证。
新功能
1. SSH 运维面板
terminal:create支持command直接 spawn(如ssh user@host),新增~/.ssh/config主机解析(ipollowork:ssh:list-hosts)domains/session/ops/:主机列表 + 快速连接 + 多会话 tab + xterm 终端2. Git 图谱泳道
git-graph.mjs:rev-list --parents精确 DAG +for-each-ref分支映射,含截断检测domains/session/git/:泳道布局(父继承 + merge 分叉)+ SVG 渲染 + 分支徽章 + 提交详情3. LAN 远程只读预览(移动端)
lan-preview-server.mjs:0.0.0.0 可选端口(默认 39485)/api/snapshot、/api/actions只读,/api/execute硬拒 4034. IM 推送(钉钉 MCP 方式)
preview-core.mjs:只读 renderer 桥 + 脱敏公开摘要(LAN 与 IM 共用)im-bot.mjs:最小 MCP client,连接钉钉 Streamable HTTP 端点 → 发现 send 工具 → 推送脱敏摘要规范性整改
ssh-ops.mjs、git-graph.mjs、lan-preview-server.mjs、preview-core.mjs、im-bot.mjs验证
pnpm --filter @ipollowork/app typecheck✓pnpm --filter @ipollowork/desktop test— 132 pass / 0 failpnpm --filter @ipollowork/app test— 757 pass(4 个既有失败与本 PR 无关)pnpm --filter @ipollowork/app build✓说明
分支基于 fork 的旧 main(ahead 5 / behind 44)。如需要可与上游 main 对齐后再合并。