feat(m3.1): managed browser sessions for the tron CLI - #28
Conversation
Adds CDP-driven managed automation sessions (PRD M3.1) without a new binary or repo — everything routes through the existing `tron` CLI. New commands (via a `tron-session` engine shipped next to the shim): tron browser launch [--headless] [--profile <name|ephemeral>] tron browser status [--json] / tabs [--json] / use <id> / current / close tron open <url> # opens in the managed session, else legacy launch - packages/browser-core/src/automation: portable, unit-tested contract — SessionDescriptor schema, CDP endpoint URL builders, and the target→tab / current-tab mapping the shell engine mirrors (21 vitest cases). - apps/desktop/launcher/tron-session: the running engine. Drives the session over the DevTools HTTP endpoints (curl + python3, both already CLI deps); writes ~/.tronbrowser/automation/session.json recording the port, pid, profile and webSocketDebuggerUrl (the M3.2 attach point). - apps/desktop/launcher/tronbrowser: additive automation-mode flags (--remote-debugging-port, --headless=new) gated on env; the normal `tron <url>` launch path is unchanged. - install.sh dispatcher: `browser` case + `open` prefers a running session and falls back to the classic launch when none exists. - build-release.sh: ship tron-session in the launcher payload. - docs/managed-sessions.md. Launch uses --remote-debugging-port=0 so Chromium picks a free loopback port (read from DevToolsActivePort); the endpoint is 127.0.0.1-only. Headless defaults to an ephemeral profile removed on close. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
Regression coverage for the running shell implementation (previously only verified ad-hoc). Drives the real `tron-session` CLI against a Node CDP mock via child_process: launch + live descriptor (incl. webSocketDebuggerUrl), tabs/current, open-as-new-tab, use, already-running guard, headless→ephemeral profile cleanup, close, and the rc-3 no-session `open` fallback signal. Skips gracefully when curl/python3 are unavailable. 8 cases, wired into the existing `pnpm -r test` / vitest suite. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…#29) Adds CDP-driven page automation on the M3.1 managed session (PRD M3.2): tron snapshot [--json] [--include-hidden] tron click @e3 tron fill @E4 "hi@example.com" Runtime pivot: snapshots/actions need programmatic CDP over a WebSocket, which the PRD's TS package layout (browser-core/sdk) already assumes. So these subcommands are implemented in TypeScript/Node and the shell `tron` dispatcher delegates to them, attaching to the session via the descriptor's webSocketDebuggerUrl (the M3.1 attach point). packages/browser-core/src/automation: - cdp-client.ts CDP JSON-RPC over Node's global WebSocket (no dependency). - snapshot-script.ts / action-script.ts in-page scripts. Snapshot tags each element with data-tron-ref so a later `tron click @e3` (a separate process) resolves the ref by attribute selector; a vanished element -> STALE_REF. - page.ts evaluate + StaleRefError + compact text formatting. - page-target.ts pick the session's current page target to drive. packages/browser-core/src/automate-cli.ts + automate-bin.ts: the `tron-automate` Node entry (snapshot/click/fill), deps injectable. Packaging: build-release.sh ships browser-core's self-contained dist tree as `automate/` (with a {"type":"module"} marker); the dispatcher runs it via node. Tests (37 new): CDP client over a real WebSocket, the in-page scripts against a real DOM (happy-dom), orchestration + CLI with fakes, and an end-to-end run of the real fetch + CdpClient transport against a mock DevTools server. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Adds one-shot headless automation and structured extraction on the managed session (PRD M3.3), extending the M3.2 Node runtime: tron headless <url> --snapshot|--screenshot <p>|--pdf <p>|--extract <mode> [--json] tron extract <text|links|forms|tables|main|selector> [--field n=sel[@attr]] tron screenshot <path> [--full-page] tron pdf <path> - extract-script.ts: in-page extractors returning deterministic JSON; relative href/src resolve to absolute; password values omitted; hidden inputs skipped. - capture.ts: Page.captureScreenshot / Page.printToPDF -> bytes. - page.ts: goto() (navigate + wait for load) and extract(). - automate-cli.ts: extract/screenshot/pdf commands + a `headless` one-shot that runs in its own isolated temp TRONBROWSER_DATA (never touching an interactive session), launches/closes via the tron-session engine (TRON_SESSION_BIN), and always tears down (profile included), even on failure. - install.sh dispatcher routes the new subcommands to the Node runtime and passes TRON_SESSION_BIN so `tron headless` can manage its one-shot session. Tests (+20): extraction against a real DOM (happy-dom) for links/forms/tables/ custom fields, CLI for extract/screenshot/pdf/headless with injected fakes (incl. cleanup-on-failure), and extract + screenshot over the real HTTP+WS transport. 78 browser-core tests pass; dispatcher routing verified. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Implements M3.1 — managed browser sessions from the M3 PRD (#27). Makes TronBrowser programmable through the existing
tronCLI — no new binary, no new repo.Commands
Design
The repo's pattern is "shell is the running CLI, TS modules are the typed/tested spec" — this mirrors it:
packages/browser-core/src/automation/— portable, unit-tested contract:SessionDescriptorschema, CDP DevTools endpoint URL builders, and the target→tab / current-tab mapping. 21 vitest cases.apps/desktop/launcher/tron-session— the running engine. Drives the session through the DevTools HTTP endpoints (/json/version|list|new|activate|close) usingcurl+python3(both already launcher deps) — no WebSocket/dependency needed for M3.1. Writes~/.tronbrowser/automation/session.jsonrecording pid/port/profile and the browserwebSocketDebuggerUrl— the attach point for M3.2 tooling.apps/desktop/launcher/tronbrowser— additive automation-mode flags (--remote-debugging-port,--headless=new) gated on env. The normaltron <url>launch path is unchanged.install.shdispatcher — newbrowsercase;openprefers a running session and falls back to the classic window launch (rc 3 signal) so nothing regresses.build-release.sh— shipstron-sessionin the launcher payload (flows into the tarball, deb/rpm, and AppImage automatically).Launch uses
--remote-debugging-port=0so Chromium picks a free loopback port (read fromDevToolsActivePort); the endpoint is127.0.0.1-only. Headless defaults to an ephemeral profile that's removed on close.Acceptance criteria (PRD §22)
tron <url>behavior preserved (automation flags are additive/env-gated).open).Verification
curl | python - <<PYstdin-vs-heredoc bug, now fixed.install.shand validated forbrowserdelegation +opensession/legacy routing.install.sh/tronbrowser/tron-sessionpasssh -n.Notes / scope
curl+python3(already used by the launcher and Tor helper).tronbrowser.cmd).docs/managed-sessions.md.🤖 Generated with Claude Code