Skip to content

feat(ssh): build the local control window and terminal launcher #148

Description

@Tutitoos

Parent tracking issue: #141. Phase 8 of 11.

Objective

Provide the list-based Atenea SSH control window and installable atenea-ssh Terminal entry point.

Scope

Integrate the tested Wails v2 shell and independent per-user Go controller from #151 according to #142. Deliver the complete React/TypeScript feature UI and app packaging on macOS, Windows and Linux. Keep native IPC and lifecycle ownership in the foundation; full support still requires integrated vault, execution and rendered UI checks. Reuse project UI components where useful while keeping SSH actions and decrypted history off the published observability listener.

Define a real desktop window whose content reproduces SwiftUI-style sidebar, list/detail navigation, toolbar, typography, spacing, selection and status feedback through a shared design system. It does not run Apple SwiftUI on Windows or Linux. Keep the same content structure and behavior on all three platforms; document intentional OS-specific window chrome, shortcuts, dialogs and native vault prompts. Install/remove the atenea-ssh Terminal launcher with the appropriate app package; repeated opens activate the existing window/controller rather than starting duplicate services. The Go controller must survive window closure and reconcile durable work after restart.

Expose narrow, typed product commands for inventory, diagnostics, credentials, dispatch and history. Retain the framework-runtime enforcement established in #151 and re-test the complete reachable native surface; a small Go binding list alone does not restrict Wails runtime URL, clipboard or other native APIs. Authenticate app-to-controller IPC as the local OS user, validate every request and bound payload sizes. Restrict WebView navigation and remote content, apply CSP, render remote text safely, and ensure vault secrets never return to the UI after saving. Test hostile content, another OS user and stale/replayed app activation. Production assets are packaged locally with no browser control listener, remote CDN or remote privileged content. Audit any internal asset transport and origin checks. A development server uses synthetic data and is not a supported browser fallback. No security claim against a compromised same-user OS account.

Show a searchable list of this controller’s config aliases and last-checked time. Label history as local to this controller; a future #154 sync view must preserve the source controller and must not turn remote history into a locally authorized target. Selecting displays cached state; an explicit Check/Connect starts network diagnostics and optional bounded polling for that selected host. Show unknown/changed identity, unsupported platform, credentials required, connector absent/version error, Codex mode readiness, busy/offline/error independently. Provide fingerprint trust flow, secret add/change/delete controls, install/update, thread selection/new chat, permission and visible/hidden selector, prompt composer, progress, cancel, history/detail and sanitized logs. Remote titles/logs are untrusted text, never executable HTML. Do not decrypt/display credentials after saving.

Implement the reference visual states from #151 with shared tokens, redistributable font/icon assets, light/dark themes, high-DPI scaling, reduced motion and keyboard/screen-reader behavior. Compare equal-size reference fixtures on all three OS WebViews; allow documented rendering differences without changing layout or interaction semantics. SwiftUI provides patterns rather than one predefined screen. Use a separate desktop entry/build and narrow UI services; sharing presentational components must not publish SSH capabilities through the read-only dashboard.

Apply #145 to WebView profile/caches and form state. Clear decrypted views on controller/vault lock, controller IPC disconnect or account change; discard stale responses and bind submission to the visibly selected target. If a target changes while a prompt is composed, require an explicit send for the new target. Do not expose history keys to JavaScript.

Package app, launcher and controller with matched protocol versions; document per-OS runtime prerequisites and signed/trusted artifact verification, macOS notarization and Windows signing evidence separately from development builds. Manual versioned upgrades are sufficient: stop new admissions, coordinate the single state writer and schema migration, preserve active request receipts and reject incompatible rollback. Uninstall removes executable/startup integration while data/credentials require explicit deletion choice. Window close and Quit UI leave the independent controller recoverable; Stop controller is a distinct action and never implies remote cancellation.

Acceptance criteria

  • Installed atenea-ssh opens/focuses the Wails desktop window and does not probe all hosts; repeated launch and closing/reopening preserve work.
  • Selection, explicit diagnostics, trust handling, credentials, installation, new/existing chats and visibility are usable with loading/error states.
  • Authenticated local UI can read full encrypted history; published dashboard and arbitrary web/other-user clients cannot.
  • Unknown-key trust and inherited app permissions are accurately shown; no silent visibility downgrade.
  • macOS, Windows and Linux render the same SwiftUI-style sidebar, host list, detail, composer and history states from one shared UI; each claimed platform passes native build/IPC/vault/window, keyboard and accessibility checks. OS-specific differences are documented.

Validation and evidence level

Go/IPC and WebView bridge security tests, UI check/build and appropriate project tests; actual desktop rendering, visual parity and per-OS packaging checks. Test actual framework runtime calls, navigation and asset origins; browser-only snapshots cannot replace native WebView evidence.

Dependencies and risks

Depends on #143, #144, #145, #146, #147, #151.

Out of scope

Chat/MCP entry point (#149), native controller-owned notifications (#155), Apple SwiftUI runtime on Windows/Linux or broad remote dashboard access.

Delivery boundary

Parent #141 defines the shared product contract. This issue owns one reviewable change and its own validation; do not close the parent from its PR. Keep source implementation, automated checks, installation and observed client behavior distinct. No secrets, real prompts, account identifiers or unredacted device logs belong in GitHub evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions