Skip to content

fix: make website install copy reliable - #31

Merged
arcabotai merged 1 commit into
mainfrom
fix/web-install-copy-20260802
Aug 2, 2026
Merged

arcabotai merged 1 commit into
mainfrom
fix/web-install-copy-20260802

Conversation

@arcabotai

@arcabotai arcabotai commented Aug 2, 2026 •

Copy link
Copy Markdown
Owner

Problem reproduced

The live landing page had two separate failures:

  1. The Copy button used an inline onclick, but production sends script-src-attr 'none', so the browser blocked the handler.
  2. The displayed command only downloaded install.sh; it did not execute it.

The clipboard path also failed silently when navigator.clipboard was unavailable or denied. During clean-install verification, the installer could report an older clawfix already on PATH instead of checking the launcher it had just written.

Changed contract

  • Bind the Copy button with addEventListener, compatible with the existing CSP.
  • Copy a download-then-run command without using curl | bash.
  • Fall back to a hidden textarea copy path and show explicit success/failure feedback.
  • Verify the exact launcher written by the installer and fail closed if it cannot start.
  • Show an immediately runnable absolute launcher path when ~/.local/bin is not on PATH.
  • Add regressions for the rendered command, CSP-safe event binding, clipboard fallback, and stale-PATH installer verification.

Verification

  • npm test: 523/523 passed
  • npm run prove:remediation: 7/7 passed
  • npm run validate:repairs: 50 scripts, 0 blockers
  • npm audit --omit=dev: 0 vulnerabilities
  • npm run capabilities:check: passed
  • bash -n scripts/install.sh: passed
  • shellcheck scripts/install.sh: passed
  • git diff --check: passed
  • Real headless Chrome trusted click with Clipboard API disabled: LOCAL_BROWSER_COPY_INSTALL=PASS
  • Real headless Chrome Clipboard API write/read round trip: LOCAL_BROWSER_MODERN_CLIPBOARD=PASS
  • Clean temporary-home install through the served installer: clawfix v0.12.0
  • Stale clawfix earlier on PATH was ignored for verification and command guidance
  • Installer test server teardown is awaited from finally, including assertion failures
  • Independent review findings for PATH precedence and missing negative clipboard coverage were reproduced and fixed

Deployment verification

  • Merged as a603bf4b0178ee5300b1a6b31961478234159a08.
  • Exact merge-head CI passed all four jobs: Node 22, Node 24, TUI tests/typecheck, and production container.
  • Railway production deployment 5711628465 completed successfully.
  • Live browser trusted click copied the exact command and showed Copied!.
  • Live browser fallback passed with Clipboard API rejection and unavailability.
  • The exact live command installed clawfix v0.12.0 in a fresh temporary home while ignoring a stale binary earlier on PATH.
  • Read-only production verification passed root, health, stats, installer, and served SHA-256 checks.

Signed-off-by: Cad from Arca <cad@arcabot.ai>
@arcabotai
arcabotai requested a review from felirami as a code owner August 2, 2026 06:57
@arcabotai
arcabotai merged commit a603bf4 into main Aug 2, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant