Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 8 additions & 10 deletions README.de.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
> **Hinweis:** Diese Übersetzung wurde automatisch erstellt und kann Ungenauigkeiten enthalten.

<p align="center">
Missionskontrolle für Ihre Coding-Agenten: eine unendliche Arbeitsfläche für Terminals, Editoren, Browser und Dokumente.
Eine IDE auf unendlicher Arbeitsfläche für parallele Coding-Agenten.
</p>

<p align="center">
Expand Down Expand Up @@ -45,15 +45,13 @@ Laden Sie eine vorgefertigte Version herunter. Bauen Sie für den täglichen Geb

## Was drinsteckt

- **Agenten-bewusste Terminals:** Cate erkennt Coding-Agenten (Claude Code, Codex und andere), die in einem beliebigen Terminal laufen. Tabs zeigen den Agentenzustand live: läuft, fertig oder wartet auf Eingabe, mit einer Systembenachrichtigung, wenn ein Agent Sie braucht. Terminals überstehen Neustarts und Fensterwechsel mit intaktem Verlauf, Farben und Vollbild-TUIs.
- **Paralleles Arbeiten:** Beschreiben Sie, woran Sie arbeiten, und Cate erstellt einen Git-Worktree mit eigenem Branch, eigener Farbe und eigenem Territorium auf der Fläche. Checken Sie eine PR direkt in einen Worktree aus, und lassen Sie `.env` oder `node_modules` automatisch in jeden neuen verlinken.
- **Agenten-steuerbarer Browser:** eingebaute Browser-Panels, die Agenten über die `cate`-CLI aus der Shell steuern können: Seiten öffnen, Screenshots aufnehmen, Accessibility-Snapshots lesen, klicken und tippen.
- **Integrierter Agent-Chat:** ein eingebetteter Coding-Agent (Pi) mit Chat-Threads und Modellgedächtnis pro Thread. Verbinden Sie Anthropic, OpenAI Codex, GitHub Copilot, Gemini, OpenRouter, Groq, Mistral, DeepSeek und weitere per OAuth oder API-Key.
- **Arbeitsfläche & Layout:** unendliches Zoomen und Verschieben, Andocken als Tabs und Splits in vier Zonen, ablösbare Fenster, gespeicherte Layouts und Sitzungswiederherstellung über mehrere Projekte.
- **Editoren & Dokumente:** Monaco-Editoren mit Syntaxhervorhebung, Multi-Cursor, Diffs und Markdown-Vorschau; Dokument-Panels für PDFs, DOCX und Bilder.
- **Git:** git-bewusster Dateibaum mit Live-Überwachung, dazu eine Versionsverwaltungs-Seitenleiste für Staging, Branches, Worktrees, Verlauf und Inline-Diffs. Volltextsuche.
- **Remote-Arbeitsbereiche:** Verbinden Sie sich per SSH mit einer Maschine und arbeiten Sie wie in einem lokalen Ordner. Terminals, Agenten und Suche laufen remote über einen leichtgewichtigen Runtime-Daemon.
- **Navigation:** flächenweite Suche über Dateien, Terminal-Verlauf und Panel-Titel; Befehlspalette; Tastaturnavigation von Panel zu Panel.
- **Agenten-bewusste Terminals:** Cate klinkt sich per Hooks in die unterstützten Agenten-CLIs ein (Claude Code, Codex, Cursor, OpenCode, Pi), sodass der Agent selbst Turn-Beginn, Turn-Ende und Berechtigungsabfragen meldet. Das steuert den Panel-Zustand (läuft, wartet, fertig) und die Benachrichtigung, wenn einer eine Antwort braucht. Ein Agent, der keine Hooks sendet, zeigt keinen Status.
- **Agenten-Sitzungen überstehen Neustarts:** Der Hook-Strom trägt die Sitzungs-ID jeder CLI. Öffnen Sie das Projekt erneut, kommen die Terminals mit ihrem Verlauf zurück und der Agent wird mit seinem eigenen Resume-Befehl wieder angehängt. Eine veraltete ID fällt auf eine einfache Shell zurück, statt die falsche Unterhaltung fortzusetzen.
- **Worktrees für parallele Branches:** Beschreiben Sie, woran Sie arbeiten, und Cate legt Worktree und Branch an, ausgehend von einem lokalen oder entfernten Branch oder einer offenen PR. Jeder bekommt eine Farbe, die ihn durch Seitenleiste und Dock-Tabs begleitet, samt Territorium hinter seinen Panels auf der Arbeitsfläche.
- **Panels auf der Fläche oder im Dock:** Terminals, Monaco-Editoren, Browser, PDF-/Bild-/DOCX-Anzeigen, Erweiterungs-Webviews, verschachtelte Flächen. Lassen Sie sie schweben, docken Sie sie als Tabs und Splits an oder ziehen Sie sie in ein eigenes Fenster. Das Layout bleibt pro Projekt erhalten.
- **Git und Suche:** Versionsverwaltungs-Seitenleiste für Staging, Commits, Branches, Stash und Verlauf über mehrere Repos; Git-Markierungen im Dateibaum; Diffs nebeneinander. Ripgrep-Suche über den Arbeitsbereich, und `Cmd+K` für Befehle, Panels und Dateien.
- **Eine CLI, die Agenten aufrufen können:** In einem Cate-Terminal steuert `cate` ein Browser-Panel (`open`, `screenshot`, `snapshot`, `click`, `type`), liest ein anderes Terminal, öffnet Dateien, verwaltet Panels. Einstellungen → CLI gibt jede Fläche getrennt für Lesen und Steuern frei.
- **Lokal und remote gehen denselben Weg:** Ein einziger Runtime-Daemon bedient jeden Arbeitsbereich. Zeigen Sie Cate per SSH oder WSL auf einen Host: Terminals, Git, Suche und Agenten laufen dort; Editoren, Browser und Fläche bleiben lokal.

## Erweiterungen

Expand Down
18 changes: 8 additions & 10 deletions README.fr.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
> **Note :** Cette traduction a été générée automatiquement et peut contenir des inexactitudes.

<p align="center">
Le centre de contrôle de vos agents de code : un canevas infini pour vos terminaux, éditeurs, navigateurs et documents.
Un IDE à canevas infini pour agents de code en parallèle.
</p>

<p align="center">
Expand Down Expand Up @@ -45,15 +45,13 @@ Téléchargez une version précompilée. Ne compilez pas depuis les sources pour

## Ce qu'il contient

- **Terminaux conscients des agents :** Cate détecte les agents de code (Claude Code, Codex et d'autres) qui tournent dans n'importe quel terminal. Les onglets affichent l'état de l'agent en direct : en cours, terminé ou en attente d'une réponse, avec une notification système quand un agent a besoin de vous. Les terminaux survivent aux redémarrages et aux déplacements de fenêtre avec leur historique, leurs couleurs et leurs TUI plein écran intacts.
- **Travail parallèle :** décrivez ce sur quoi vous travaillez et Cate crée un worktree git avec sa propre branche, sa couleur et son territoire sur le canevas. Récupérez une PR directement dans un worktree, et liez automatiquement `.env` ou `node_modules` dans chaque nouveau worktree.
- **Navigateur pilotable par agent :** des panneaux navigateur intégrés que les agents peuvent contrôler depuis le shell via la CLI `cate` : ouvrir des pages, prendre des captures d'écran, lire des instantanés d'accessibilité, cliquer et saisir du texte.
- **Chat d'agent intégré :** un agent de code embarqué (Pi) avec fils de discussion et mémoire de modèle par fil. Connectez Anthropic, OpenAI Codex, GitHub Copilot, Gemini, OpenRouter, Groq, Mistral, DeepSeek et d'autres via OAuth ou clé API.
- **Canevas et disposition :** zoom et déplacement infinis, ancrage en onglets et divisions sur quatre zones, fenêtres détachables, dispositions enregistrées et restauration de session multi-projets.
- **Éditeurs et documents :** éditeurs Monaco avec coloration syntaxique, multi-curseur, diffs et aperçu Markdown ; panneaux de document pour PDF, DOCX et images.
- **Git :** arborescence de fichiers consciente de git avec suivi en direct, plus une barre latérale de contrôle de source pour l'index, les branches, les worktrees, l'historique et les diffs en ligne. Recherche plein texte.
- **Espaces de travail distants :** connectez-vous à une machine via SSH et travaillez comme sur un dossier local. Terminaux, agents et recherche s'exécutent à distance via un démon runtime léger.
- **Navigation :** recherche sur tout le canevas dans les fichiers, l'historique des terminaux et les titres de panneaux ; palette de commandes ; navigation clavier de panneau en panneau.
- **Terminaux conscients des agents :** Cate installe ses hooks dans les CLI d'agents prises en charge (Claude Code, Codex, Cursor, OpenCode, Pi) : l'agent signale lui-même le début et la fin d'un tour ainsi que les demandes d'autorisation. C'est ce qui alimente l'état du panneau (en cours, en attente, terminé) et la notification quand un agent attend votre réponse. Un agent qui n'envoie aucun hook n'affiche aucun état.
- **Les sessions d'agent survivent aux redémarrages :** le flux de hooks transporte l'identifiant de session de chaque CLI. Rouvrez le projet : les terminaux reviennent avec leur historique et l'agent est rattaché via sa propre commande de reprise. Un identifiant périmé retombe sur un simple shell plutôt que de reprendre la mauvaise conversation.
- **Worktrees pour branches parallèles :** décrivez ce sur quoi vous travaillez et Cate crée un worktree et une branche, à partir d'une branche locale ou distante ou d'une PR ouverte. Chacun reçoit une couleur qui le suit dans la barre latérale, les onglets du dock et un territoire dessiné derrière ses panneaux sur le canevas.
- **Des panneaux sur le canevas ou dans le dock :** terminaux, éditeurs Monaco, navigateurs, visionneuses PDF/image/DOCX, webviews d'extensions, canevas imbriqués. Faites-les flotter sur le canevas, ancrez-les en onglets et divisions, ou glissez-les dans leur propre fenêtre. La disposition est conservée par projet.
- **Git et recherche :** barre latérale de contrôle de source pour l'index, les commits, les branches, le stash et l'historique, sur plusieurs dépôts ; badges git dans l'arborescence ; diffs côte à côte. Recherche ripgrep sur l'espace de travail, et `Cmd+K` pour les commandes, les panneaux et les fichiers.
- **Une CLI que les agents peuvent appeler :** dans un terminal Cate, `cate` pilote un panneau navigateur (`open`, `screenshot`, `snapshot`, `click`, `type`), lit un autre terminal, ouvre des fichiers, gère les panneaux. Réglages → CLI autorise chaque surface séparément en lecture et en contrôle.
- **Local et distant suivent le même chemin :** un seul démon runtime sert tous les espaces de travail. Pointez Cate vers une machine en SSH ou WSL : terminaux, git, recherche et agents s'y exécutent ; éditeurs, navigateur et canevas restent en local.

## Extensions

Expand Down
18 changes: 8 additions & 10 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
> **注意:** 本翻译由机器自动生成,可能存在不准确之处。

<p align="center">
编码智能体的任务控制中心:一块容纳终端、编辑器、浏览器和文档的无限画布
为并行编码智能体打造的无限画布 IDE
</p>

<p align="center">
Expand Down Expand Up @@ -45,15 +45,13 @@ Cate 是一款基于无限画布的桌面 IDE,为同时运行大量终端和

## 包含什么

- **感知智能体的终端:** Cate 能检测在任意终端中运行的编码智能体(Claude Code、Codex 等)。标签页实时显示智能体状态:运行中、已完成或等待输入,当智能体需要你时还会发出系统通知。终端在重启和跨窗口移动后保留回滚缓冲、颜色和全屏 TUI。
- **并行工作:** 描述你要做什么,Cate 就会创建一个 git worktree,带有自己的分支、颜色和画布领地。可以把 PR 直接检出到 worktree,还能自动把 `.env` 或 `node_modules` 符号链接到每个新 worktree。
- **智能体可驱动的浏览器:** 内置浏览器面板,智能体可通过 `cate` CLI 在 shell 中控制:打开页面、截图、读取无障碍快照、点击和输入。
- **内置智能体聊天:** 内嵌编码智能体(Pi),支持聊天线程和按线程记忆模型。通过 OAuth 或 API key 接入 Anthropic、OpenAI Codex、GitHub Copilot、Gemini、OpenRouter、Groq、Mistral、DeepSeek 等。
- **画布与布局:** 无限缩放和平移,四个区域的标签和分屏停靠,可拆分窗口,保存布局,多项目会话还原。
- **编辑器与文档:** Monaco 编辑器,支持语法高亮、多光标、差异对比和 Markdown 预览;文档面板可渲染 PDF、DOCX 和图片。
- **Git:** 感知 git 的文件树,带实时监听;外加版本控制侧边栏,处理暂存、分支、worktree、历史和行内差异。全文搜索。
- **远程工作区:** 通过 SSH 连接远程机器,像本地文件夹一样工作。终端、智能体和搜索通过轻量级运行时守护进程在远端执行。
- **导航:** 跨画布搜索文件、终端回滚和面板标题;命令面板;面板间键盘导航。
- **感知智能体的终端:** Cate 会为支持的智能体 CLI(Claude Code、Codex、Cursor、OpenCode、Pi)安装钩子,由智能体自己上报一轮对话的开始、结束以及权限询问。面板的运行中/等待/已完成状态,以及智能体需要你回应时的通知,都由此驱动。不发送钩子的智能体不会显示任何状态。
- **智能体会话在重启后延续:** 钩子流会带上每个 CLI 的会话 ID。重新打开项目,终端会带着回滚缓冲回来,并用智能体自己的恢复命令重新接上会话。ID 已失效时会退回普通 shell,而不是恢复错误的会话。
- **为并行分支准备的 worktree:** 描述你要做什么,Cate 就会基于本地分支、远程分支或一个开放的 PR 创建 worktree 和分支。每个 worktree 都有专属颜色,贯穿侧边栏、停靠标签,以及画布上绘制在其面板背后的领地。
- **画布上或停靠区里的面板:** 终端、Monaco 编辑器、浏览器、PDF/图片/DOCX 查看器、扩展 webview、嵌套画布。可以浮在画布上、停靠成标签和分屏,或拖进独立窗口。布局按项目保存。
- **Git 与搜索:** 版本控制侧边栏支持暂存、提交、分支、stash 和历史,可跨多个仓库;文件树带 git 状态标记;并排差异对比。工作区内使用 ripgrep 搜索,`Cmd+K` 查找命令、面板和文件。
- **智能体可调用的 CLI:** 在 Cate 终端里,`cate` 可以驱动浏览器面板(`open`、`screenshot`、`snapshot`、`click`、`type`)、读取其他终端、打开文件、管理面板。设置 → CLI 中可分别授予每个能力的读取与控制权限。
- **本地与远程走同一条路:** 同一个运行时守护进程服务所有工作区。通过 SSH 或 WSL 指向一台主机,终端、git、搜索和智能体都在那边运行;编辑器、浏览器和画布留在本地。

## 扩展

Expand Down
11 changes: 9 additions & 2 deletions docs/extensions.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,11 @@

## Overview

An extension adds panels to Cate by shipping a **web frontend**, and optionally a **local server process** for backend work. Each panel renders on the canvas like any built-in panel (zooms, clips, composites). Extensions come in two shapes:
An extension adds panels to Cate by shipping a **web frontend**, and optionally a **local server process** for backend work. Each panel renders on the canvas like any built-in panel (zooms, clips, composites). Extensions come in three shapes:

- **Frontend-only** (default) — just static web assets. Cate serves them and the panel talks to Cate solely through the `cateHost` bridge. No process, port, token, or lifecycle to manage. Best for tools that only need the Cate API (viewers, formatters, pickers, dashboards over `cate.storage`).
- **Server-backed** — also ships a local server for full OS access (filesystem, processes, sockets, network) without a capability broker. Cate spawns **one server per extension per workspace** and points every panel's webview at it. The relationship is always **n:1** — many panels, one server — and the server handles concurrent panels: routing state and events per panel id, isolating panel-local data, and tolerating panels opening and closing independently.
- **URL** — no assets and no process: the manifest names a remote `https://` page and the panel is pointed straight at it. The panel webview is a top-level browsing context, so pages that refuse to be framed (`X-Frame-Options` / `frame-ancestors`) still load, and each extension keeps its own persistent session partition so a login survives restarts. Best for wrapping a hosted web app (chat, CRM, dashboards) as a panel. A URL extension gets **no** `cateHost` bridge — see Security Hygiene.

Cate only standardizes how it serves/launches an extension and a small reverse API back into Cate. The built-in agent panel is server-backed and is the canonical reference.

Expand All @@ -29,11 +30,16 @@ Cate only standardizes how it serves/launches an extension and a small reverse A
],
"frontend": "dist/index.html",
"server": { "command": "node dist/server.js", "readyPath": "/health", "portEnv": "PORT" },
"url": "https://example.com/app",
"cateApi": ["workspace.read", "editor.write", "storage"]
}
```

`server` is **optional** — omit it for a frontend-only extension, where Cate serves the `frontend` entry statically and injects only the `cateHost` bridge. When `server` is present it serves the frontend itself at `PORT` and `frontend` is ignored.
`server`, `url` and `frontend` are all **optional**, and a manifest normally declares exactly one. Mode precedence when several are present is **`server` > `url` > `frontend`** (a mixed manifest still loads; the extra fields are simply ignored):

- frontend-only: Cate serves the `frontend` entry statically and injects the `cateHost` bridge.
- server-backed: the server serves the frontend itself at `PORT`; `frontend` is ignored.
- url: `url` must be an absolute **`https://`** URL. Anything else (`http:` including `localhost`, `file:`, `javascript:`, `data:`, garbage) is dropped at manifest validation and the extension falls back to its other modes. Use `server` for a local dev server; `url` is for hosted pages only.

## Lifecycle

Expand All @@ -50,6 +56,7 @@ Applies only to **server-backed** extensions. Frontend-only panels are plain web
- Servers bind `127.0.0.1` only. Cate injects `HOST=127.0.0.1` into the server's environment and the server is expected to bind that host; a server that ignores `HOST` and binds `0.0.0.0` would expose itself on the network, defeating the token gate. Honoring `HOST` (alongside `PORT`) is part of the server contract.
- Per-server random port + shared token (`CATE_TOKEN`); the server requires the token on every panel connection so other local processes/tabs can't drive it. Panels authenticate with the token and identify themselves by `cate.panel.id`.
- Tight CSP on the webview.
- **URL extensions get no Cate API.** A guest's identity (which extension, which workspace) is derived from the opaque route token in the local proxy's own origin, so a remote page can never prove one — handing it the `cateHost` preload would only create a bridge whose every call is rejected. Cate therefore attaches no preload to a `url` panel, and the main process independently strips the preload from any guest whose URL isn't the proxy origin. `cateApi` scopes in a url-mode manifest are inert. The page still runs in the extension's own persistent partition, so its cookies/logins are isolated from other extensions and from browser panels.

## Reverse API

Expand Down
17 changes: 17 additions & 0 deletions src/main/extensions/proxyServer.ts
Original file line number Diff line number Diff line change
Expand Up @@ -477,6 +477,23 @@ export async function getProxyUrlFor(args: {
const manifest = extensionManager.getManifest(extensionId)
if (!manifest) return null

// URL-BACKED (manifest.url, no server): the panel points straight at a remote
// https page — no proxy server, no route token, no spawned process. Mode
// precedence is server > url > frontend, so this is only taken when the
// manifest declares no server.
//
// Security: such a guest gets NO cate host API. Guest identity is derived from
// the proxy's own origin + opaque routeToken (identityForGuestUrl), which a
// remote origin can never satisfy; handing it the cateHost preload would only
// create a bridge whose every call is rejected, while widening the surface a
// third-party page can poke at. So we return an empty preloadPath (the panel
// then omits the attribute) — and webSecurity.ts independently strips the
// preload from any guest whose URL isn't the proxy origin, so this holds even
// if the renderer asked for one.
if (!manifest.server && manifest.url) {
return { url: manifest.url, preloadPath: '' }
}

const port = await ensureProxyServer()
const routeToken = registerRoute(extensionId, workspaceId)

Expand Down
Loading
Loading