61 lines
2.1 KiB
Markdown
61 lines
2.1 KiB
Markdown
# Diagnostic Access Improvements
|
|
|
|
## Goal
|
|
|
|
Make it practical for an agent on a separate SSH machine to diagnose browser and
|
|
production failures without granting broad production control or asking the user
|
|
to paste console output.
|
|
|
|
## Browser Captures
|
|
|
|
Diagnostic mode (`?diag=1`) offers **Capture diagnostic**. Upload and metadata
|
|
remain authenticated. The PNG URL at `/api/debug/captures/{id}` is public by its
|
|
72-bit id, which is the explicit handoff capability a user shares with an agent.
|
|
|
|
After inspecting a user-shared capture, the agent must immediately call:
|
|
|
|
```
|
|
DELETE /api/debug/captures/{id}
|
|
```
|
|
|
|
The 24-hour expiry and 50-capture cap remain a backstop. Do not inspect capture
|
|
URLs that the user has not explicitly supplied.
|
|
|
|
## Production Diagnostics
|
|
|
|
Do not grant an agent a general production shell or Docker-group membership.
|
|
Docker access is effectively root access, and arbitrary shell access can expose
|
|
environment variables, OAuth tokens, and mounted volumes.
|
|
|
|
Instead create a dedicated `chart-debug` production account with a forced-command
|
|
SSH wrapper. It accepts only a small, read-oriented command set:
|
|
|
|
```
|
|
logs --since <duration>
|
|
status
|
|
container-state
|
|
recent-deploy
|
|
capture-read <capture-id>
|
|
capture-delete <capture-id>
|
|
```
|
|
|
|
The wrapper must reject arbitrary commands and paths. It should cap output,
|
|
redact known secret patterns, and log every request. Use a dedicated SSH key that
|
|
can be revoked without affecting deployment or normal administration.
|
|
|
|
Expected agent usage:
|
|
|
|
```
|
|
ssh chart-debug@production logs --since 20m
|
|
```
|
|
|
|
## Observability
|
|
|
|
Keep browser performance telemetry separate from production access. A future
|
|
frontend recorder should locally aggregate frame timing, long tasks, tick rate,
|
|
visible bars, and rendered line/level counts, then periodically upload compact,
|
|
authenticated summaries. Pair it with server timing for bar handling, level
|
|
rebuilds, WebSocket serialization, and the existing loop-lag measure.
|
|
|
|
This separates rendering, feed, transport, and backend pressure without logging
|
|
prices, drawing text, cursor positions, screenshots, or per-tick event history.
|