Files
EveFlow/electron/ipc/http.ts
T
Claude 5f0fa7a1e2 fix: full review pass (main process, voice pipeline, Hermes client, HUD) and e2e-validated local voice (v2.1.0.1)
Electron main
- utility-process channel: sherpa output copied into V8 buffers (Electron rejects external
  buffers), audio exchanged as base64; worker restart on timeout, identity-safe exit handling,
  deterministic native unload by restart
- webhook: loopback by default without secret, UTF-8-safe body assembly, clean restart, port validation
- files IPC: realpath-based root check, openPath allow-list (reveal-only outside document folders),
  Windows reserved names; store: debounced async atomic writes with backup of corrupt files;
  logger: streaming writes with rotation; log message size cap
- HTTP stream proxy: socket released on idle timeout / renderer destroyed, id validation
- model manager: inactivity timeout, retrying rm/rename (Windows locks), engine stopped before
  replacing a model; WAV decoder handles float/24-bit; IPC payload validation
- window: opaque rounded window on Windows, navigation lock-down, visibility events;
  Ctrl+Alt+Escape instead of the Task Manager shortcut; single-instance guard; EVEFLOW_USER_DATA

Voice pipeline
- abort semantics (SendHandle.aborted), abort before the stream opens, session id prefixes per transport
- hands-free re-arm after replies without speech, start/stop race, no chime on auto re-arm,
  no silence shipped to STT (400 ms pre-roll), no transcription of empty manual stops
- TTS: bounded prefetch, cancellable segments, non-interrupting notices, volume applied at play time
- SSE CRLF split, usage in chat completions, finish_reason length, phonetic regex hoisted

HUD
- core renderer: no canvas shadows, cached colours, reusable spectrum buffer, theme read on change,
  30 fps idle, stops when the window is hidden; ping flashes on send / tool / speech
- deltas coalesced per animation frame; stable auto-scroll; narrow selectors everywhere
- bundled fonts (offline), reduce-motion fix, error toasts, ops drawer below 1180 px,
  interim transcript and first-token latency in the core caption, Ctrl+K, dialog semantics,
  switch/aria roles, compact widget cleanup, Whisper small recommended for French
- docs/ROADMAP.md: audit results, e2e results and the plan towards a real JARVIS

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Wn5VX9HNbJ7N54hR24u9Y
2026-09-03 18:08:09 +00:00

169 lines
5.8 KiB
TypeScript

/**
* HTTP proxy: the renderer never talks to the network directly (webSecurity stays ON).
* Every request to Hermes / STT / TTS endpoints flows through here, which also removes
* CORS and mixed-content restrictions for LAN services served over plain HTTP.
*/
import { ipcMain, type WebContents } from 'electron';
import {
IPC,
type HttpProxyRequest,
type HttpProxyResponse,
type HttpStreamStart,
type HttpStreamEvent
} from '../../shared/ipc';
import { log } from '../logger';
const activeStreams = new Map<string, AbortController>();
function assertUrl(url: string): URL {
let parsed: URL;
try {
parsed = new URL(url);
} catch {
throw new Error(`URL invalide : ${url}`);
}
if (parsed.protocol !== 'http:' && parsed.protocol !== 'https:') {
throw new Error(`Protocole non autorise : ${parsed.protocol}`);
}
return parsed;
}
function buildInit(req: HttpProxyRequest, signal: AbortSignal): RequestInit {
const headers: Record<string, string> = { ...(req.headers ?? {}) };
let body: RequestInit['body'];
if (req.multipart) {
const form = new FormData();
for (const [k, v] of Object.entries(req.multipart.fields)) form.append(k, v);
const file = req.multipart.file;
const bytes = new Uint8Array(file.data);
form.append(req.multipart.fileField ?? 'file', new Blob([bytes], { type: file.type }), file.name);
body = form;
for (const key of Object.keys(headers)) {
if (key.toLowerCase() === 'content-type') delete headers[key];
}
} else if (req.body !== undefined) {
body = req.body;
}
return { method: req.method ?? 'GET', headers, body, signal };
}
function headersToObject(headers: Headers): Record<string, string> {
const out: Record<string, string> = {};
headers.forEach((v, k) => {
out[k.toLowerCase()] = v;
});
return out;
}
export async function proxyFetch(req: HttpProxyRequest): Promise<HttpProxyResponse> {
assertUrl(req.url);
const controller = new AbortController();
const timeoutMs = req.timeoutMs ?? 60_000;
const timer = setTimeout(() => controller.abort(), timeoutMs);
try {
const response = await fetch(req.url, buildInit(req, controller.signal));
const base = {
ok: response.ok,
status: response.status,
statusText: response.statusText,
headers: headersToObject(response.headers)
};
if (req.responseType === 'binary') {
return { ...base, binary: new Uint8Array(await response.arrayBuffer()) };
}
return { ...base, text: await response.text() };
} catch (err) {
const e = err as Error;
if (e.name === 'AbortError') throw new Error(`Delai depasse (${Math.round(timeoutMs / 1000)}s) : ${req.url}`);
throw new Error(e.message || String(err));
} finally {
clearTimeout(timer);
}
}
async function startStream(sender: WebContents, id: string, req: HttpProxyRequest): Promise<HttpStreamStart> {
assertUrl(req.url);
const controller = new AbortController();
activeStreams.set(id, controller);
const send = (event: HttpStreamEvent) => {
if (!sender.isDestroyed()) sender.send(IPC.httpStreamEvent, event);
};
let response: Response;
try {
response = await fetch(req.url, buildInit(req, controller.signal));
} catch (err) {
activeStreams.delete(id);
throw new Error((err as Error).message || String(err));
}
const start: HttpStreamStart = {
id,
ok: response.ok,
status: response.status,
statusText: response.statusText,
headers: headersToObject(response.headers)
};
const onDestroyed = () => controller.abort();
sender.once('destroyed', onDestroyed);
const pump = async () => {
try {
if (!response.body) {
send({ id, type: 'end' });
return;
}
const reader = response.body.getReader();
const decoder = new TextDecoder();
// Hermes runs can be long, but a totally silent stream is abandoned after the idle timeout.
const idleMs = req.timeoutMs ?? 10 * 60_000;
for (;;) {
let idleTimer: ReturnType<typeof setTimeout> | undefined;
const idle = new Promise<never>((_, reject) => {
idleTimer = setTimeout(() => reject(new Error('Flux silencieux (timeout)')), idleMs);
});
const { done, value } = await Promise.race([reader.read(), idle]);
if (idleTimer) clearTimeout(idleTimer);
if (done) break;
send({ id, type: 'chunk', text: decoder.decode(value, { stream: true }) });
}
const tail = decoder.decode();
if (tail) send({ id, type: 'chunk', text: tail });
send({ id, type: 'end' });
} catch (err) {
const e = err as Error;
if (e.name === 'AbortError') send({ id, type: 'end' });
else send({ id, type: 'error', message: e.message || String(err) });
} finally {
// Releases the socket when we bailed out early (idle timeout, renderer gone).
controller.abort();
sender.removeListener('destroyed', onDestroyed);
if (activeStreams.get(id) === controller) activeStreams.delete(id);
}
};
void pump();
return start;
}
export function abortAllStreams(): void {
for (const controller of activeStreams.values()) controller.abort();
activeStreams.clear();
}
export function registerHttpIpc(): void {
ipcMain.handle(IPC.httpFetch, (_e, req: HttpProxyRequest) => proxyFetch(req));
ipcMain.handle(IPC.httpStreamStart, (event, id: unknown, req: HttpProxyRequest) => {
if (typeof id !== 'string' || !id || id.length > 64 || activeStreams.has(id)) throw new Error('Identifiant de flux invalide');
if (!req || typeof req.url !== 'string') throw new Error('Requête invalide');
return startStream(event.sender, id, req);
});
ipcMain.on(IPC.httpStreamAbort, (_e, id: string) => {
const controller = activeStreams.get(id);
if (controller) {
controller.abort();
activeStreams.delete(id);
log('DEBUG', 'http', `stream ${id} aborted by renderer`);
}
});
}