| 2026-10-09 |
webclient: rebuild dist for the role-aware MCP keys panel
...
`webclient/dist` is tracked and served straight by the API server — there is no
node on the prod host — so the source change alone would have left prod showing
the old copy, telling an ordinary user that the shared key from the config is in
use for a server that is simply not connected for them.
Eugene Sukhodolskiy
committed
5 hours ago
|

profiles: restricted profiles for ordinary users, and a role gate that holds
...
`is_admin_only` was checked in one place out of nine and was not read from
config.json at all, so all seven profiles were reachable by every account with
role `user`. The flag now lives in config.json — the file is the baseline, a
`profile_overrides` row still wins on top of it — and one predicate,
`admin_only_blocked`, is the single place the rule is expressed. The nine
surfaces that list, switch to, spawn or resolve a profile all consult it:
`POST /sessions`, the WebSocket, switch_profile, list_profiles, the system
prompt's "Available profiles" block, spawn_agent and the Synapse reaction
runner. The prompt cache is now keyed by (profile, role), so a user's prompt
can never be served an admin's profile list.
The seven existing profiles (developer, discuss, dispatcher, modeler_3d,
navi_code, secretary, server_admin) are marked admin-only. Three new ones take
their place for ordinary users: assistant, designer_3d and coder. They share one
native tool set — ssh_exec, peer, reload_tools, create_mcp_server, test_mcp_tool,
image_view and gmail are withheld — and differ only in system prompt, model and
MCP groups. navi-web's raw `request` group, and the whole of gnexus-creds and
tgclient, are withheld too.
MCP per-user keys gain the missing half of the rule: a server that declares a
`user_key` slot is refused to anyone but an admin who has no personal key, and
is left out of their tool list entirely, instead of quietly falling back to the
owner's credential and appearing as a tool that cannot work. The refusal names
the server and points at Settings.
Also closes `GET /agents/prompts`, which served every profile's system prompt to
anyone, with no user dependency at all.
The accepted residual risk is written down in docs/profiles.md: the working
directory is a convention, not a sandbox.
Eugene Sukhodolskiy
committed
5 hours ago
|
| 2026-10-08 |

profiles: tool_developer folds into developer
...
The profile was a duplicate on every axis we could measure. 22 of its 26
native tools were already developer's; the four it alone held —
reload_tools, create_mcp_server, test_mcp_tool, mcp_status — are 2.9 KB of
schema. Its model chain was the same seven models. Of its 14 KB prompt,
about 8 KB was copied verbatim from developer's (the whole `## Orchestration
model` block and everything from `## Editing policy` down), and most of the
remainder restated manuals/create_mcp_server.md, which already carried the
same ten-step workflow in more detail. It was not a specialisation, it was a
snapshot: `git log -S '"reload_tools"'` shows the tool lived in developer
until 61fa370 rewrote that profile around MCP and cut it off.
What kept it alive was a premise that no longer holds — that Navi's own
capabilities would be written as in-repo tools. They are MCP servers now,
and an MCP server is not a file in this repository with a life of its own:
it is an isolated process registered from mcp_servers.d/. So there is no
reason left for a profile whose only distinct feature is a toolset a general
developer profile can hold, and every reason to stop maintaining a second
prompt that drifts against the first.
- developer: + reload_tools, create_mcp_server, test_mcp_tool, mcp_status
(24 → 28 native). Its sub-agent gains tool_manual, which is what it
actually needed to reach the manual while writing a server — the previous
tool_developer sub-agent had it, developer's did not.
- server_admin: + reload_tools only (24 → 25). Adding a third-party MCP
server is something this profile does as often as developer does.
Deliberately not to its sub-agent: reconnecting the MCP manager is a
process-wide operation belonging to the main agent.
- The prompt and the manual took on what the deleted profile knew and
create_mcp_server.md did not: reload_tools before the first test_mcp_tool
(a freshly registered server is not connected, so the test fails and the
iteration is wasted), the smoke test read by exit code — 124 means timeout
killed a server still running, 0 means it exited on its own, usually a
main() without parentheses — absolute command/cwd, mcp_status as discovery
only, and the steps that stay inline instead of going to a sub-agent.
mcp_status and test_mcp_tool were built without an MCP manager, and their
fallback did `from navi.api.deps import _mcp_manager` — a name that does not
exist, so a live call raised ImportError rather than the intended "MCP
manager not available". The tools always passed a manager in tests, which is
why nothing caught it. Both now receive the manager at construction and fall
back to the live one lazily.
Sessions and profile_overrides are reassigned before the restart: agent.py
resolves the session's profile without a guard, so a deleted profile turns
every session that referenced it into an uncaught ProfileNotFound. Nothing
in the test suite pins the profile inventory, and profiles are read once at
import time — reload_tools does not re-read them — so this ships as a
restart, and the restart is also what makes it take effect.
Eugene Sukhodolskiy
committed
9 hours ago
|
| 2026-10-07 |
webclient: hold the chat at the bottom when a stream ends
...
The list was pinned per streaming delta, but the last things to land arrive
after that final pin: the stats/rating footer, which renders only once
msg.done is set, and the copy buttons attached to code blocks after render.
Nothing re-clamped afterwards — the length watcher never fires (the message
stays in the array) and the landing loop only runs when a session opens — so
the view was left short of the bottom, looking like it had scrolled up.
Re-clamp through the same settle window the landing uses when streaming goes
true -> false, unless the user has scrolled up or a session is loading.
This addresses the late-layout half of the problem; the row is still remounted
when msg.id becomes h_<n>, which is the other source of a jump.
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: reload tools from a button in the MCP tab
...
Settings → MCP gains a Tools block for admins only: one button, then the
same report the tool prints — what loaded, how many are in the registry,
per-file errors, and names in enabled.json nothing answers to.
It sits inside the existing MCP tab rather than a new one: the reload
rewrites the toolset of the whole server, not just this user's MCP keys,
and it belongs next to the thing it affects. Non-admins never see it.
dist rebuilt together with the source, as the server serves the bundle.
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: keep MCP rows at content height on a phone
...
.mcp-keys-row stacks into a column below 768px, and .mcp-keys-info kept
its flex: 1 1 240px. That basis is a width in the desktop row and a
height once the row stacks, so every server reserved 240px and its text
sat at the top of the gap — 402px for a row whose content is 90px.
Back to content height on mobile only, and drop the kit's .form-group
bottom margin there: the row's own flex gap already separates the field
from the buttons.
Eugene Sukhodolskiy
committed
1 day ago
|
Merge origin/master (b7743f8): PWA icons, MCP settings tab, android push, runbook
root
committed
1 day ago
|
webclient: serve the PWA artwork past the images cache
...
/images/* is served cache-first from IMAGES_CACHE, which activate deliberately
keeps across builds. That is right for content whose URL is unique and wrong
for the app's own artwork: /images/icon-*, /images/logo-icon* and
/images/apple-splash/* keep their URLs while their contents change with the
logo, so a browser that had once loaded an icon would keep showing the old one
even after a deploy — and the apple-touch-icon is linked from index.html, so it
does travel through the page and the service worker.
Those paths now go network-first with a cached fallback (offline still works);
every other /images/ request is untouched.
Tests: frontend 148 passed; backend 1367 passed, 1 skipped.
Eugene Sukhodolskiy
committed
1 day ago
|

webclient: draw the PWA icons at full size again
...
The maskable icons and the apple-touch-icon carried the mark at 21% of the
canvas — the artwork scaled down and pasted in the centre — so on a home
screen the logo read as a fragment of itself. The mark takes 73.4% of the
canvas in logo.svg and in the launcher tile of the Android app icon; that is
the proportion all five files use now.
scripts/gen_pwa_icons.py redraws the mark from logo.svg's geometry with
Pillow (already a project dependency, no SVG rasterizer needed) and writes the
whole set, so the scale lives in one constant; --check measures what is on
disk and reports SUSPECT if it drifts again. Two runs produce identical bytes.
The regenerated icon-192/512 are geometrically identical to the rsvg-rendered
ones they replace: ink bbox 376x376 with 68px insets at 50% coverage, and the
same ink mass across the stroke. Only the antialiasing bytes differ.
dist/ rebuilt (it carries a copy of public/ and is served by the backend).
Tests: frontend 148 passed; backend 1367 passed, 1 skipped.
Eugene Sukhodolskiy
committed
1 day ago
|

MCP settings tab: list every connected server, slot only where declared
...
The tab was empty on every install: it listed only servers whose config
declares a `user_key` slot, and no config declared one — which read as
"no MCP servers connected" even though five are wired to profiles.
- GET /mcp-keys now returns every server referenced by at least one
profile, keyed ones first, with `accepts_user_key`, the slot location
(null when there is none) and the profile ids that connect it. The
per-user key store is skipped entirely when nothing has a slot.
- gnexus-creds declares `user_key: {header: Authorization, prefix:
"Bearer "}` — it is the one server carrying a shared credential, so its
personal-key field is now real: users with a key run under their own,
users without one fall back to the shared default.
- The panel lists all servers (transport + profiles), dims the keyless
rows, and shows a key input only for slotted ones, spelling out the
shared-key fallback.
docs/api.md and docs/mcp.md updated; backend 1367 passed, webclient 148.
Eugene Sukhodolskiy
committed
1 day ago
|

Android app: native push notifications via JS bridge + background hold
...
WebView has no Push API, so the app shows notifications natively:
- NaviBridge JS interface (window.NaviAndroid): notify(), permission
request with a 'navi-perm-result' event callback, background-mode
start/stop and the Doze-exemption ask.
- BackgroundService: dataSync foreground service + partial wake lock —
holds the process (and the WebView WebSocket) open while the app is
minimized; quiet persistent notification with a "Отключить фон" action.
Notification channels: silent background presence, high-importance
messages.
- Manifest: POST_NOTIFICATIONS / FOREGROUND_SERVICE(_DATA_SYNC) /
WAKE_LOCK / REQUEST_IGNORE_BATTERY_OPTIMIZATIONS + service entry;
notification tap resumes MainActivity (singleTask) into open_url.
- webclient: nativeBridge composable; usePush gets a bridge mode that
replaces web-push entirely (settings toggle keeps working); chat store
raises 'Navi ответила' through the bridge on stream end when the
window is hidden. Fixed a latent undefined-variable in web syncState
(notificationsSupported -> notifSupported()).
- New unit tests for the bridge surface; 147 frontend tests + APK build
pass.
Eugene Sukhodolskiy
committed
1 day ago
|
Merge remote-tracking branch 'origin/master'
...
# Conflicts:
# webclient/vendor/gnexus-ui-kit/package-lock.json
root
committed
1 day ago
|
webclient: settings tab polish, light chat-table styling, iOS launch screens
...
- Synapse tab icon was a no-op glyph: ph-diagram-project does not exist in
the bundled Phosphor regular set — the button rendered bare text. Switched
to ph-network, which ships.
- .settings-tabs capped at 1200px width on wide screens (was max-width:none).
- Chat markdown tables: the old .msg-assistant-content .table rules were
dead (markdown never adds a .table class) — retarget .table-wrap table and
restyle lightly: framed border + radius, muted header row, plain row
separators, no uppercase/no hover color jump.
- iOS home-screen: apple-mobile-web-app metas and a full apple-touch-startup-
image set (24 device classes, portrait+landscape) rendered from logo.svg
on the theme background.
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: PWA hardening — stable height skeleton, touch selection policy, fixed maskable icons
...
- html/body/#app height via percentages instead of 100vh/dvh: the standalone
PWA visual viewport drifts with keyboard/system panels, which let the
document exceed the screen and scroll fixed headers away.
- viewport meta gains interactive-widget=resizes-content; phone-width inputs
(textarea/text) are pinned to 16px to avoid mobile focus zoom.
- Selection policy: service chrome (chat header, sidebar, tab strip, input
bar, meta rows) is unselectable with -webkit-touch-callout, killing the
'Search with Google' sheet on long-press; message content and settings
panels keep selectable text.
- Apple touch icon switched to a proper 180px tile.
- Regenerated maskable icons (were degenerate 1px-tall files): dark
background plus the logo inside the 80% safe zone.
- manifest gains display_override.
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: fix mobile tab-block drift — column flex nowrap + stretch, kit table scrolls inside its wrapper
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: reveal the active settings tab when the mobile tab strip scrolls
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: settings header now literally the chat header; app-wide thin rounded scrollbars (override kit's thick square defaults)
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: exclusive radio groups in Synapse reactions (distinct names, kit options API); mobile sidebar row swaps close button after New Chat
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: settings page fits the app frame — flat chat-style header bar, single full-bleed scroll region, mobile adaptation (stacked MCP rows, viewport-safe modals)
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: MCP keys tab gets an empty-state when no server declares a user_key slot
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: settings page split into GnTabs sections (Account/Notifications/Synapse/MCP)
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: settings loaders switched to kit circle spinner (GnLoader circle)
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: MCP user keys panel (BYOK) + frontend tests
Eugene Sukhodolskiy
committed
1 day ago
|
webclient: top margin on settings header
Eugene Sukhodolskiy
committed
1 day ago
|
| 2026-10-06 |
webclient: Synapse reactions settings + service sessions toggle
...
- sidebar: service-sessions toggle (special=true fetch replaces the
regular list, active search drops out), muted style + robot icon on
special items in the list
- settings: Synapse reactions panel — enable switch, completion push
preference (always / only failures / never), notification destination
(app / app+Synapse / Synapse, Synapse options disabled while no
source key), reaction instructions editor with save + edit history
(author and reason per version)
- stores: synapseReactions store; sessions store fetches respect
showSpecial; getSessions passes special param
- vitest for api/session store/panel; dist rebuilt
Eugene Sukhodolskiy
committed
2 days ago
|
webclient: remove session list dividers, 42px sidebar logo, truncate long file names in preview pill
Eugene Sukhodolskiy
committed
2 days ago
|

handbook alignment: profile.updated mirror, health contract, Synapse gateway
...
Handbook gaps closed (10-platform auth/health/notifications):
- webhooks: handle user.profile_updated — mirror the gnexus-auth profile
into navi_users (name, contact fields, avatar_url — new column, boot
migration); role/permissions keep their dedicated events
- auth: avatar_url now flows through the login upsert and the API-token
resolution path
- /health: status is now the aggregate of the sub-checks (degraded embed
or hive no longer reports plain ok); embed probe cached for 10 s; body
grew the machine-readable checks{} map, legacy embed/hive payloads kept
- Synapse: s2s delivery gateway — POST /webhooks/synapse (both spellings),
per-user delivery secrets (synapse_targets, Fernet-encrypted, shown
once), verification via gnexus-synapse v0.1.2 client lib, idempotent
event ids; deliveries are verified and logged for now — navi generates
no outbound events by decision; web-push stays as the local browser
channel
- webclient settings: Synapse deliveries panel (add/revoke targets)
Eugene Sukhodolskiy
committed
2 days ago
|
webclient: revert LoginScreen to the custom card
...
The kit login-card markup read heavier (uppercase header, wide chrome
border) than the original centered card — restoring the previous
version per user preference.
Eugene Sukhodolskiy
committed
2 days ago
|
webclient: LoginScreen rebuilt on kit markup
...
The SSO-only login doesn't fit GnLoginCard's username/password form (the
adapter always renders both fields), so the escape-hatch card is replaced
with the kit's own login-card markup (article.card.login-card + header +
card-content + GnButton) — the same contract kit.css ships for
GnLoginCard, minus the form. Custom card border/title/subtitle styles are
gone; overlay keeps positioning only.
Eugene Sukhodolskiy
committed
2 days ago
|
webclient: apply kit radii to content-cards and viewed-image thumbs, fix dead scss tokens
...
The content-card and ArtifactsPanel style blocks used @use 'kit-deps'
inside <style scoped> without lang=scss, so sass never ran: the
-radius-md token stayed a literal in the built CSS and the
browser saw border-radius: -radius-md (invalid → 0 corners).
Both blocks now declare lang=scss and compile to the kit's 6px radius.
Also rounds the corners of user-message image attachments and adds the
missing label prop on the tools-collapse icon button (kit dev warning).
Eugene Sukhodolskiy
committed
2 days ago
|