picoclaw/web/frontend/src/hooks/use-credentials-page.ts
wenjie e55b3b7a8d
feat(web): migrate launcher to modular web frontend/backend and improve management UX (#1275)
* refactor: remove the legacy picoclaw-launcher

* feat: create initial web frontend and backend structure

* feat(packaging): add desktop entry for PicoClaw Launcher (#1062)

- Add .desktop file with Terminal=true, named "PicoClaw Launcher"
- Install to /usr/share/applications/ for app menu visibility
- Add 512x512 PNG icon to /usr/share/icons/hicolor/

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* `make dev`: If you haven't built it before, you need to run `build` first.

* feat(web): comprehensive web UI and backend refactoring
This commit introduces a major overhaul of both the frontend web UI and the Go backend API, transitioning to a highly modular architecture and integrating new core features.
Backend:
- Refactored monolithic API endpoints into domain-specific modules (config, gateway, log, models, pico, session).
- Cleaned up obsolete files (`server.go`, `status.go`, WebSocket handlers) and outdated tests.
- Implemented Gateway process lifecycle management (start/stop/restart) and real-time log streaming.
Frontend:
- Integrated Shadcn UI components to establish a modern, consistent design system.
- Introduced a new application layout featuring a responsive sidebar (`app-sidebar`) and header.
- Implemented internationalization (i18n) with initial support for English and Chinese.
- Restructured API clients, hooks, and Zustand stores into logical domains.
- Added new management pages for Settings, Logs, Models, Providers, and Credentials.
- Upgraded the Pico chat interface with session history management and dynamic model selection.
Build & Config:
- Updated frontend dependencies, Vite configuration, and lockfiles.
- Refined routing setup and overarching application stylesheets.

* feat(web): enhance model management, sorting, and deletion logic
- Implement model sorting in UI (default > configured > unconfigured)
- Prevent deletion of default models in the frontend
- Update backend to clear default settings when a model is deleted
- Add existence validation when setting a default model via API
- Group models in chat UI by type (API Key, OAuth, Local)
- Conditionally display model selector in chat based on configuration status

* refactor(web): refactor chat page into modular components/hooks and update i18n

- split chat route into dedicated chat components (page, composer, empty state, messages, history, model selector)
- extract model/session logic into use-chat-models and use-session-history hooks
- update chat locale keys in en/zh and add empty-state/history-related translations

* refactor(models): refactor models page into modular components and improve UX

- split /models route into dedicated components (page, provider section, card, add/edit sheets, delete dialog)
- add provider grouping/sorting, provider labels/icons, and a no-default hint in the models page
- add "Set as default model" toggle to add/edit flows with safer defaults
- introduce shared form helpers and new UI primitives (field, label, switch)
- update i18n strings (en/zh) for models and gateway header text usage
- apply minor UI polish (models nav icon, separator client directive)

* fix(web): add SPA index fallback for embedded frontend routes

Serve existing static assets as-is, keep /api/* and missing asset paths returning 404, and add tests for SPA fallback behavior on refresh.

* fix(frontend/chat): normalize message timestamp units to prevent invalid far-future dates

* chore: delete TestSPARouteFallsBackToIndex

* feat: update build for web-based launcher (#1186)

- Makefile: add build-launcher target (builds frontend + Go backend)
- GoReleaser: point picoclaw-launcher build to web/backend, add frontend
  build hook, restore winres hook with updated paths
- Restore icon.ico and winres config from main for Windows builds

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* feat(credentials): add multi-provider OAuth credential management

- add backend `/api/oauth/*` endpoints for provider status, browser/device-code/token login, flow query/polling, and logout
- extend API handler with OAuth flow/state tracking and route registration, plus OAuth unit tests
- implement frontend credentials page/components for OpenAI, Anthropic, and Google Antigravity login/logout
- add OAuth API client and `useCredentialsPage` hook, with new EN/ZH i18n strings

* chore: remove placeholder index.html from dist (#1188)

The .gitkeep is sufficient for go:embed to find the dist directory.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(frontend): polish model and credential UX; remove Providers nav

- remove the Providers item from sidebar navigation and locale keys
- simplify chat composer by dropping attach/voice action buttons
- support ReactNode titles in credential cards and add provider brand icons
- refine sheet header/footer styling and device-code footer button hierarchy
- disable “Set default” when a model is unconfigured or already default

* feat(web): Update  config page (#1173)

* feat(web): Update  config page

* fix(web): useEffect resets editorValue whenever config changes

* fix(web): react-hooks/set-state-in-effect error & pnpm lint #1173

* feat(web): add channel management page for web console (#1190)

* feat(web): add channel management page for web console

Add a complete channel management UI that allows users to configure
messaging channels (Telegram, Discord, Slack, Feishu, etc.) directly
from the web console instead of manually editing config.json.

Backend: GET/PUT/PATCH API endpoints for listing, updating, and
toggling channels with secret field masking.

Frontend: Channel cards grid with enable/disable toggles, per-channel
configuration sheets with dedicated forms for major platforms and a
generic fallback for others.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(web/channels): move channels to own sidebar group and fix sheet padding

- Channels now has its own navigation group instead of being under Services
- Fix edit sheet form content padding (px-1 -> px-4) to match header/footer
- Fix naked return lint error in extractChannelInfo

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>

* fix(web): harden channel config updates and resolve frontend lint issues

- validate channel PUT/PATCH updates before saving and return structured validation errors
- require `enabled` in toggle requests to avoid silent false defaults
- support editing `allow_origins` in the generic channel form and parse string/array inputs on backend
- replace channel form `any` usage with `ChannelConfig` (`Record<string, unknown>`) and add safe value helpers
- add i18n strings for allow-origins fields and apply related frontend formatting cleanups

* fix(frontend): prevent false "Invalid JSON" errors in config editor

* feat: add startup readiness checks and propagate start availability to UI

- add gateway precondition validation for default model and credentials
- auto-start gateway on backend boot when conditions are met
- include gateway_start_allowed and gateway_start_reason in status updates
- prevent frontend start actions when gateway cannot be started

* feat(web): revamp channel config UX with catalog-based routing

- replace legacy channel management endpoints with a backend channel catalog API
- switch frontend channel updates to PATCH /api/config and per-channel config pages
- add dynamic channel items in the sidebar with support for expand/collapse
- migrate /channels to nested routes (/channels/$name) and remove old card/sheet flow
- improve channel forms with clearer hints, required/error states, and reusable switch cards
- fix Discord mention-only toggle to read/write group_trigger.mention_only

* refactor(frontend): move shared-form to components and unify default-model switch with SwitchCardField

* fix(frontend): improve model form validation and unify secret placeholder handling

- block duplicate model aliases when adding a model (with localized error messages)
- share masked secret placeholder logic across model and channel forms
- refresh gateway state after setting the default model
- apply minor UI cleanup to provider icon rendering

* feat(web): add visual system config and launcher/autostart controls

- add launcher config model and persistence (`launcher-config.json`) for port/public/CIDR settings
- add system APIs for launch-at-login and launcher parameters
- apply CIDR-based access-control middleware to backend HTTP routes
- split config routing into visual config and raw JSON config pages
- add frontend system API client and visual config sections for runtime/devices/launcher
- expand i18n strings (en/zh) for new config UI
- improve sidebar active matching and session ID generation fallback

* refactor(frontend): remove i18n fallback strings and drop providers route

- Replace `t(key, defaultValue)` calls with key-only translations across UI pages
- Clean up locale files by pruning unused keys and adding missing shared keys
- Remove the obsolete `/providers` page and update generated route tree

* fix(backend): correct gateway status detection on Windows

* fix(repo): keep web backend dist placeholder tracked

---------

Co-authored-by: Guoguo <16666742+imguoguo@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Dihubopen <dihubcn@gmail.com>
Co-authored-by: Dihubopen <130813726+Dihubopen@users.noreply.github.com>
2026-03-09 19:42:03 +08:00

436 lines
11 KiB
TypeScript

import { useCallback, useEffect, useMemo, useRef, useState } from "react"
import { useTranslation } from "react-i18next"
import {
type OAuthFlowState,
type OAuthProvider,
type OAuthProviderStatus,
getOAuthFlow,
getOAuthProviders,
loginOAuth,
logoutOAuth,
pollOAuthFlow,
} from "@/api/oauth"
type FlowWatchMode = "" | "status" | "poll"
function getProviderLabel(provider: OAuthProvider | ""): string {
if (provider === "openai") return "OpenAI"
if (provider === "anthropic") return "Anthropic"
if (provider === "google-antigravity") return "Google Antigravity"
return ""
}
export function useCredentialsPage() {
const { t } = useTranslation()
const [providers, setProviders] = useState<OAuthProviderStatus[]>([])
const [loading, setLoading] = useState(true)
const [error, setError] = useState("")
const [activeAction, setActiveAction] = useState("")
const [activeFlow, setActiveFlow] = useState<OAuthFlowState | null>(null)
const actionTokenRef = useRef(0)
const [watchFlowID, setWatchFlowID] = useState("")
const [watchMode, setWatchMode] = useState<FlowWatchMode>("")
const [pollIntervalMs, setPollIntervalMs] = useState(2000)
const [openAIToken, setOpenAIToken] = useState("")
const [anthropicToken, setAnthropicToken] = useState("")
const [logoutDialogOpen, setLogoutDialogOpen] = useState(false)
const [logoutConfirmProvider, setLogoutConfirmProvider] = useState<
OAuthProvider | ""
>("")
const [deviceSheetOpen, setDeviceSheetOpen] = useState(false)
const [deviceFlow, setDeviceFlow] = useState<OAuthFlowState | null>(null)
const loadProviders = useCallback(async () => {
try {
const data = await getOAuthProviders()
setProviders(data.providers)
setError("")
} catch (err) {
setError(
err instanceof Error ? err.message : t("credentials.errors.loadFailed"),
)
} finally {
setLoading(false)
}
}, [t])
useEffect(() => {
void loadProviders()
}, [loadProviders])
useEffect(() => {
if (!watchFlowID || !watchMode) {
return
}
let canceled = false
let timer: ReturnType<typeof setTimeout> | null = null
const step = async () => {
try {
const flow =
watchMode === "poll"
? await pollOAuthFlow(watchFlowID)
: await getOAuthFlow(watchFlowID)
if (canceled) {
return
}
setActiveFlow(flow)
setDeviceFlow((prev) =>
prev?.flow_id === flow.flow_id ? { ...prev, ...flow } : prev,
)
if (flow.status === "pending") {
timer = setTimeout(step, pollIntervalMs)
return
}
if (watchMode === "poll") {
setDeviceSheetOpen(false)
}
setWatchFlowID("")
setWatchMode("")
setActiveAction("")
await loadProviders()
} catch (err) {
if (canceled) {
return
}
setWatchFlowID("")
setWatchMode("")
setActiveAction("")
setError(
err instanceof Error
? err.message
: t("credentials.errors.flowFailed"),
)
}
}
void step()
return () => {
canceled = true
if (timer) {
clearTimeout(timer)
}
}
}, [loadProviders, pollIntervalMs, t, watchFlowID, watchMode])
useEffect(() => {
const params = new URLSearchParams(window.location.search)
const flowID = params.get("oauth_flow_id")
if (!flowID) {
return
}
setWatchFlowID(flowID)
setWatchMode("status")
setPollIntervalMs(700)
window.history.replaceState({}, "", window.location.pathname)
}, [])
useEffect(() => {
const onMessage = (event: MessageEvent) => {
const data = event.data as
| { type?: string; flowId?: string; status?: string }
| undefined
if (!data || data.type !== "picoclaw-oauth-result" || !data.flowId) {
return
}
setWatchFlowID(data.flowId)
setWatchMode("status")
setPollIntervalMs(700)
}
window.addEventListener("message", onMessage)
return () => window.removeEventListener("message", onMessage)
}, [])
const providersMap = useMemo(() => {
const map = new Map<OAuthProvider, OAuthProviderStatus>()
for (const item of providers) {
map.set(item.provider, item)
}
return map
}, [providers])
const openaiStatus = providersMap.get("openai")
const anthropicStatus = providersMap.get("anthropic")
const antigravityStatus = providersMap.get("google-antigravity")
const bumpActionToken = useCallback(() => {
actionTokenRef.current += 1
return actionTokenRef.current
}, [])
const isActionTokenCurrent = useCallback((token: number) => {
return actionTokenRef.current === token
}, [])
const startBrowserOAuth = useCallback(
async (provider: OAuthProvider) => {
const actionToken = bumpActionToken()
setActiveAction(`${provider}:browser`)
setError("")
const authTab = window.open("", "_blank")
if (!authTab) {
if (!isActionTokenCurrent(actionToken)) {
return
}
setActiveAction("")
setError(t("credentials.errors.popupBlocked"))
return
}
try {
const resp = await loginOAuth({ provider, method: "browser" })
if (!isActionTokenCurrent(actionToken)) {
authTab.close()
return
}
if (!resp.auth_url || !resp.flow_id) {
throw new Error(t("credentials.errors.invalidBrowserResponse"))
}
authTab.location.href = resp.auth_url
setActiveFlow({
flow_id: resp.flow_id,
provider,
method: "browser",
status: "pending",
expires_at: resp.expires_at,
})
setWatchFlowID(resp.flow_id)
setWatchMode("status")
setPollIntervalMs(2000)
} catch (err) {
if (!isActionTokenCurrent(actionToken)) {
authTab.close()
return
}
authTab.close()
setActiveAction("")
setError(
err instanceof Error
? err.message
: t("credentials.errors.loginFailed"),
)
}
},
[bumpActionToken, isActionTokenCurrent, t],
)
const startOpenAIDeviceCode = useCallback(async () => {
const actionToken = bumpActionToken()
setActiveAction("openai:device")
setError("")
try {
const resp = await loginOAuth({
provider: "openai",
method: "device_code",
})
if (!isActionTokenCurrent(actionToken)) {
return
}
if (!resp.flow_id || !resp.user_code || !resp.verify_url) {
throw new Error(t("credentials.errors.invalidDeviceResponse"))
}
const flow: OAuthFlowState = {
flow_id: resp.flow_id,
provider: "openai",
method: "device_code",
status: "pending",
user_code: resp.user_code,
verify_url: resp.verify_url,
interval: resp.interval,
expires_at: resp.expires_at,
}
setDeviceFlow(flow)
setDeviceSheetOpen(true)
setActiveFlow(flow)
setWatchFlowID(resp.flow_id)
setWatchMode("poll")
setPollIntervalMs(Math.max(1000, (resp.interval ?? 5) * 1000))
} catch (err) {
if (!isActionTokenCurrent(actionToken)) {
return
}
setActiveAction("")
setError(
err instanceof Error
? err.message
: t("credentials.errors.loginFailed"),
)
}
}, [bumpActionToken, isActionTokenCurrent, t])
const saveToken = useCallback(
async (provider: OAuthProvider, token: string) => {
const actionID = `${provider}:token`
setActiveAction(actionID)
setError("")
try {
await loginOAuth({ provider, method: "token", token })
if (provider === "openai") {
setOpenAIToken("")
}
if (provider === "anthropic") {
setAnthropicToken("")
}
await loadProviders()
} catch (err) {
setError(
err instanceof Error
? err.message
: t("credentials.errors.loginFailed"),
)
} finally {
setActiveAction("")
}
},
[loadProviders, t],
)
const doLogout = useCallback(
async (provider: OAuthProvider) => {
const actionID = `${provider}:logout`
setActiveAction(actionID)
setError("")
try {
await logoutOAuth(provider)
await loadProviders()
} catch (err) {
setError(
err instanceof Error
? err.message
: t("credentials.errors.logoutFailed"),
)
} finally {
setActiveAction("")
}
},
[loadProviders, t],
)
const askLogout = useCallback((provider: OAuthProvider) => {
setLogoutConfirmProvider(provider)
setLogoutDialogOpen(true)
}, [])
const handleConfirmLogout = useCallback(async () => {
if (!logoutConfirmProvider) {
return
}
await doLogout(logoutConfirmProvider)
setLogoutDialogOpen(false)
setLogoutConfirmProvider("")
}, [doLogout, logoutConfirmProvider])
const handleLogoutDialogOpenChange = useCallback((open: boolean) => {
setLogoutDialogOpen(open)
if (!open) {
setLogoutConfirmProvider("")
}
}, [])
const handleDeviceSheetOpenChange = useCallback(
(open: boolean) => {
setDeviceSheetOpen(open)
if (open) {
return
}
if (watchMode === "poll") {
setWatchFlowID("")
setWatchMode("")
if (activeAction === "openai:device") {
setActiveAction("")
}
}
setDeviceFlow(null)
if (
activeFlow?.method === "device_code" &&
activeFlow.status === "pending"
) {
setActiveFlow(null)
}
},
[activeAction, activeFlow, watchMode],
)
const stopLoading = useCallback(() => {
bumpActionToken()
setWatchFlowID("")
setWatchMode("")
setActiveAction("")
setDeviceSheetOpen(false)
setDeviceFlow(null)
setActiveFlow((prev) => (prev?.status === "pending" ? null : prev))
}, [bumpActionToken])
const logoutProviderLabel = getProviderLabel(logoutConfirmProvider)
const flowHint = useMemo(() => {
if (!activeFlow) {
return ""
}
if (activeFlow.status === "pending") {
return t("credentials.flow.pending")
}
if (activeFlow.status === "success") {
return t("credentials.flow.success")
}
if (activeFlow.status === "expired") {
return t("credentials.flow.expired")
}
return activeFlow.error || t("credentials.flow.error")
}, [activeFlow, t])
return {
loading,
error,
activeAction,
activeFlow,
flowHint,
openAIToken,
anthropicToken,
openaiStatus,
anthropicStatus,
antigravityStatus,
logoutDialogOpen,
logoutConfirmProvider,
logoutProviderLabel,
deviceSheetOpen,
deviceFlow,
setOpenAIToken,
setAnthropicToken,
startBrowserOAuth,
startOpenAIDeviceCode,
stopLoading,
saveToken,
askLogout,
handleConfirmLogout,
handleLogoutDialogOpenChange,
handleDeviceSheetOpenChange,
}
}