# Diagnostic Access Improvements ## Goal Make it practical for an agent on a separate SSH machine to diagnose browser and production failures without granting broad production control or asking the user to paste console output. ## Browser Captures Diagnostic mode (`?diag=1`) offers **Capture diagnostic**. Upload and metadata remain authenticated. The PNG URL at `/api/debug/captures/{id}` is public by its 72-bit id, which is the explicit handoff capability a user shares with an agent. After inspecting a user-shared capture, the agent must immediately call: ``` DELETE /api/debug/captures/{id} ``` The 24-hour expiry and 50-capture cap remain a backstop. Do not inspect capture URLs that the user has not explicitly supplied. ## Production Diagnostics Do not grant an agent a general production shell or Docker-group membership. Docker access is effectively root access, and arbitrary shell access can expose environment variables, OAuth tokens, and mounted volumes. Instead create a dedicated `chart-debug` production account with a forced-command SSH wrapper. It accepts only a small, read-oriented command set: ``` logs --since status container-state recent-deploy capture-read capture-delete ``` The wrapper must reject arbitrary commands and paths. It should cap output, redact known secret patterns, and log every request. Use a dedicated SSH key that can be revoked without affecting deployment or normal administration. Expected agent usage: ``` ssh chart-debug@production logs --since 20m ``` ## Observability Keep browser performance telemetry separate from production access. A future frontend recorder should locally aggregate frame timing, long tasks, tick rate, visible bars, and rendered line/level counts, then periodically upload compact, authenticated summaries. Pair it with server timing for bar handling, level rebuilds, WebSocket serialization, and the existing loop-lag measure. This separates rendering, feed, transport, and backend pressure without logging prices, drawing text, cursor positions, screenshots, or per-tick event history.