You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(ssh): build the local control window and terminal launcher #148
Provide the list-based Atenea SSH control window and installable atenea-ssh Terminal entry point.
Scope
Integrate the tested Wails v2 shell and independent per-user Go controller from #151 according to #142. Deliver the complete React/TypeScript feature UI and app packaging on macOS, Windows and Linux. Keep native IPC and lifecycle ownership in the foundation; full support still requires integrated vault, execution and rendered UI checks. Reuse project UI components where useful while keeping SSH actions and decrypted history off the published observability listener.
Define a real desktop window whose content reproduces SwiftUI-style sidebar, list/detail navigation, toolbar, typography, spacing, selection and status feedback through a shared design system. It does not run Apple SwiftUI on Windows or Linux. Keep the same content structure and behavior on all three platforms; document intentional OS-specific window chrome, shortcuts, dialogs and native vault prompts. Install/remove the atenea-ssh Terminal launcher with the appropriate app package; repeated opens activate the existing window/controller rather than starting duplicate services. The Go controller must survive window closure and reconcile durable work after restart.
Expose narrow, typed product commands for inventory, diagnostics, credentials, dispatch and history. Retain the framework-runtime enforcement established in #151 and re-test the complete reachable native surface; a small Go binding list alone does not restrict Wails runtime URL, clipboard or other native APIs. Authenticate app-to-controller IPC as the local OS user, validate every request and bound payload sizes. Restrict WebView navigation and remote content, apply CSP, render remote text safely, and ensure vault secrets never return to the UI after saving. Test hostile content, another OS user and stale/replayed app activation. Production assets are packaged locally with no browser control listener, remote CDN or remote privileged content. Audit any internal asset transport and origin checks. A development server uses synthetic data and is not a supported browser fallback. No security claim against a compromised same-user OS account.
Show a searchable list of this controller’s config aliases and last-checked time. Label history as local to this controller; a future #154 sync view must preserve the source controller and must not turn remote history into a locally authorized target. Selecting displays cached state; an explicit Check/Connect starts network diagnostics and optional bounded polling for that selected host. Show unknown/changed identity, unsupported platform, credentials required, connector absent/version error, Codex mode readiness, busy/offline/error independently. Provide fingerprint trust flow, secret add/change/delete controls, install/update, thread selection/new chat, permission and visible/hidden selector, prompt composer, progress, cancel, history/detail and sanitized logs. Remote titles/logs are untrusted text, never executable HTML. Do not decrypt/display credentials after saving.
Implement the reference visual states from #151 with shared tokens, redistributable font/icon assets, light/dark themes, high-DPI scaling, reduced motion and keyboard/screen-reader behavior. Compare equal-size reference fixtures on all three OS WebViews; allow documented rendering differences without changing layout or interaction semantics. SwiftUI provides patterns rather than one predefined screen. Use a separate desktop entry/build and narrow UI services; sharing presentational components must not publish SSH capabilities through the read-only dashboard.
Apply #145 to WebView profile/caches and form state. Clear decrypted views on controller/vault lock, controller IPC disconnect or account change; discard stale responses and bind submission to the visibly selected target. If a target changes while a prompt is composed, require an explicit send for the new target. Do not expose history keys to JavaScript.
Package app, launcher and controller with matched protocol versions; document per-OS runtime prerequisites and signed/trusted artifact verification, macOS notarization and Windows signing evidence separately from development builds. Manual versioned upgrades are sufficient: stop new admissions, coordinate the single state writer and schema migration, preserve active request receipts and reject incompatible rollback. Uninstall removes executable/startup integration while data/credentials require explicit deletion choice. Window close and Quit UI leave the independent controller recoverable; Stop controller is a distinct action and never implies remote cancellation.
Acceptance criteria
Installed atenea-ssh opens/focuses the Wails desktop window and does not probe all hosts; repeated launch and closing/reopening preserve work.
Selection, explicit diagnostics, trust handling, credentials, installation, new/existing chats and visibility are usable with loading/error states.
Authenticated local UI can read full encrypted history; published dashboard and arbitrary web/other-user clients cannot.
Unknown-key trust and inherited app permissions are accurately shown; no silent visibility downgrade.
macOS, Windows and Linux render the same SwiftUI-style sidebar, host list, detail, composer and history states from one shared UI; each claimed platform passes native build/IPC/vault/window, keyboard and accessibility checks. OS-specific differences are documented.
Validation and evidence level
Go/IPC and WebView bridge security tests, UI check/build and appropriate project tests; actual desktop rendering, visual parity and per-OS packaging checks. Test actual framework runtime calls, navigation and asset origins; browser-only snapshots cannot replace native WebView evidence.
Chat/MCP entry point (#149), native controller-owned notifications (#155), Apple SwiftUI runtime on Windows/Linux or broad remote dashboard access.
Delivery boundary
Parent #141 defines the shared product contract. This issue owns one reviewable change and its own validation; do not close the parent from its PR. Keep source implementation, automated checks, installation and observed client behavior distinct. No secrets, real prompts, account identifiers or unredacted device logs belong in GitHub evidence.
Parent tracking issue: #141. Phase 8 of 11.
Objective
Provide the list-based Atenea SSH control window and installable atenea-ssh Terminal entry point.
Scope
Integrate the tested Wails v2 shell and independent per-user Go controller from #151 according to #142. Deliver the complete React/TypeScript feature UI and app packaging on macOS, Windows and Linux. Keep native IPC and lifecycle ownership in the foundation; full support still requires integrated vault, execution and rendered UI checks. Reuse project UI components where useful while keeping SSH actions and decrypted history off the published observability listener.
Define a real desktop window whose content reproduces SwiftUI-style sidebar, list/detail navigation, toolbar, typography, spacing, selection and status feedback through a shared design system. It does not run Apple SwiftUI on Windows or Linux. Keep the same content structure and behavior on all three platforms; document intentional OS-specific window chrome, shortcuts, dialogs and native vault prompts. Install/remove the
atenea-sshTerminal launcher with the appropriate app package; repeated opens activate the existing window/controller rather than starting duplicate services. The Go controller must survive window closure and reconcile durable work after restart.Expose narrow, typed product commands for inventory, diagnostics, credentials, dispatch and history. Retain the framework-runtime enforcement established in #151 and re-test the complete reachable native surface; a small Go binding list alone does not restrict Wails runtime URL, clipboard or other native APIs. Authenticate app-to-controller IPC as the local OS user, validate every request and bound payload sizes. Restrict WebView navigation and remote content, apply CSP, render remote text safely, and ensure vault secrets never return to the UI after saving. Test hostile content, another OS user and stale/replayed app activation. Production assets are packaged locally with no browser control listener, remote CDN or remote privileged content. Audit any internal asset transport and origin checks. A development server uses synthetic data and is not a supported browser fallback. No security claim against a compromised same-user OS account.
Show a searchable list of this controller’s config aliases and last-checked time. Label history as local to this controller; a future #154 sync view must preserve the source controller and must not turn remote history into a locally authorized target. Selecting displays cached state; an explicit Check/Connect starts network diagnostics and optional bounded polling for that selected host. Show unknown/changed identity, unsupported platform, credentials required, connector absent/version error, Codex mode readiness, busy/offline/error independently. Provide fingerprint trust flow, secret add/change/delete controls, install/update, thread selection/new chat, permission and visible/hidden selector, prompt composer, progress, cancel, history/detail and sanitized logs. Remote titles/logs are untrusted text, never executable HTML. Do not decrypt/display credentials after saving.
Implement the reference visual states from #151 with shared tokens, redistributable font/icon assets, light/dark themes, high-DPI scaling, reduced motion and keyboard/screen-reader behavior. Compare equal-size reference fixtures on all three OS WebViews; allow documented rendering differences without changing layout or interaction semantics. SwiftUI provides patterns rather than one predefined screen. Use a separate desktop entry/build and narrow UI services; sharing presentational components must not publish SSH capabilities through the read-only dashboard.
Apply #145 to WebView profile/caches and form state. Clear decrypted views on controller/vault lock, controller IPC disconnect or account change; discard stale responses and bind submission to the visibly selected target. If a target changes while a prompt is composed, require an explicit send for the new target. Do not expose history keys to JavaScript.
Package app, launcher and controller with matched protocol versions; document per-OS runtime prerequisites and signed/trusted artifact verification, macOS notarization and Windows signing evidence separately from development builds. Manual versioned upgrades are sufficient: stop new admissions, coordinate the single state writer and schema migration, preserve active request receipts and reject incompatible rollback. Uninstall removes executable/startup integration while data/credentials require explicit deletion choice. Window close and Quit UI leave the independent controller recoverable; Stop controller is a distinct action and never implies remote cancellation.
Acceptance criteria
Validation and evidence level
Go/IPC and WebView bridge security tests, UI check/build and appropriate project tests; actual desktop rendering, visual parity and per-OS packaging checks. Test actual framework runtime calls, navigation and asset origins; browser-only snapshots cannot replace native WebView evidence.
Dependencies and risks
Depends on #143, #144, #145, #146, #147, #151.
Out of scope
Chat/MCP entry point (#149), native controller-owned notifications (#155), Apple SwiftUI runtime on Windows/Linux or broad remote dashboard access.
Delivery boundary
Parent #141 defines the shared product contract. This issue owns one reviewable change and its own validation; do not close the parent from its PR. Keep source implementation, automated checks, installation and observed client behavior distinct. No secrets, real prompts, account identifiers or unredacted device logs belong in GitHub evidence.