server.cjs 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657
  1. const crypto = require('crypto');
  2. const http = require('http');
  3. const fs = require('fs');
  4. const path = require('path');
  5. // ========== WebSocket Protocol (RFC 6455) ==========
  6. const OPCODES = { TEXT: 0x01, CLOSE: 0x08, PING: 0x09, PONG: 0x0A };
  7. const WS_MAGIC = '258EAFA5-E914-47DA-95CA-C5AB0DC85B11';
  8. const MAX_FRAME_PAYLOAD_BYTES = 10 * 1024 * 1024;
  9. function computeAcceptKey(clientKey) {
  10. return crypto.createHash('sha1').update(clientKey + WS_MAGIC).digest('base64');
  11. }
  12. function encodeFrame(opcode, payload) {
  13. const fin = 0x80;
  14. const len = payload.length;
  15. let header;
  16. if (len < 126) {
  17. header = Buffer.alloc(2);
  18. header[0] = fin | opcode;
  19. header[1] = len;
  20. } else if (len < 65536) {
  21. header = Buffer.alloc(4);
  22. header[0] = fin | opcode;
  23. header[1] = 126;
  24. header.writeUInt16BE(len, 2);
  25. } else {
  26. header = Buffer.alloc(10);
  27. header[0] = fin | opcode;
  28. header[1] = 127;
  29. header.writeBigUInt64BE(BigInt(len), 2);
  30. }
  31. return Buffer.concat([header, payload]);
  32. }
  33. function decodeFrame(buffer) {
  34. if (buffer.length < 2) return null;
  35. const secondByte = buffer[1];
  36. const opcode = buffer[0] & 0x0F;
  37. const masked = (secondByte & 0x80) !== 0;
  38. let payloadLen = secondByte & 0x7F;
  39. let offset = 2;
  40. if (!masked) throw new Error('Client frames must be masked');
  41. if (payloadLen === 126) {
  42. if (buffer.length < 4) return null;
  43. payloadLen = buffer.readUInt16BE(2);
  44. offset = 4;
  45. } else if (payloadLen === 127) {
  46. if (buffer.length < 10) return null;
  47. const extendedLen = buffer.readBigUInt64BE(2);
  48. if (extendedLen > BigInt(MAX_FRAME_PAYLOAD_BYTES)) {
  49. throw new Error('WebSocket frame payload exceeds maximum allowed size');
  50. }
  51. payloadLen = Number(extendedLen);
  52. offset = 10;
  53. }
  54. if (payloadLen > MAX_FRAME_PAYLOAD_BYTES) {
  55. throw new Error('WebSocket frame payload exceeds maximum allowed size');
  56. }
  57. const maskOffset = offset;
  58. const dataOffset = offset + 4;
  59. const totalLen = dataOffset + payloadLen;
  60. if (buffer.length < totalLen) return null;
  61. const mask = buffer.slice(maskOffset, dataOffset);
  62. const data = Buffer.alloc(payloadLen);
  63. for (let i = 0; i < payloadLen; i++) {
  64. data[i] = buffer[dataOffset + i] ^ mask[i % 4];
  65. }
  66. return { opcode, payload: data, bytesConsumed: totalLen };
  67. }
  68. // ========== Configuration ==========
  69. const PORT_FILE = process.env.BRAINSTORM_PORT_FILE || null;
  70. const randomPort = () => 49152 + Math.floor(Math.random() * 16383);
  71. // Prefer an explicit port, else the port this session last bound (so a restart
  72. // reuses it and an already-open browser tab reconnects), else a random high port.
  73. function preferredPort() {
  74. if (process.env.BRAINSTORM_PORT) return Number(process.env.BRAINSTORM_PORT);
  75. if (PORT_FILE) {
  76. try {
  77. const p = Number(fs.readFileSync(PORT_FILE, 'utf-8').trim());
  78. if (Number.isInteger(p) && p > 1023 && p < 65536) return p;
  79. } catch (e) { /* no prior port recorded */ }
  80. }
  81. return randomPort();
  82. }
  83. let PORT = preferredPort();
  84. const HOST = process.env.BRAINSTORM_HOST || '127.0.0.1';
  85. const URL_HOST = process.env.BRAINSTORM_URL_HOST || (HOST === '127.0.0.1' ? 'localhost' : HOST);
  86. const SESSION_DIR = process.env.BRAINSTORM_DIR || '/tmp/brainstorm';
  87. const CONTENT_DIR = path.join(SESSION_DIR, 'content');
  88. const STATE_DIR = path.join(SESSION_DIR, 'state');
  89. let ownerPid = process.env.BRAINSTORM_OWNER_PID ? Number(process.env.BRAINSTORM_OWNER_PID) : null;
  90. // Per-session secret key. The companion is reachable by any local browser tab
  91. // and, when bound to a non-loopback host, by any host that can route to it.
  92. // The key authenticates the real client uniformly across loopback, tunnel, and
  93. // remote binds — and defeats DNS rebinding — where a Host/Origin allowlist
  94. // cannot. It rides the served URL as ?key= and is mirrored into a cookie on
  95. // first load so same-origin subresources and the WebSocket carry it for free.
  96. // Persisted alongside the port (BRAINSTORM_TOKEN_FILE) so a restart keeps the
  97. // same key and an already-open tab's cookie still validates.
  98. const TOKEN_FILE = process.env.BRAINSTORM_TOKEN_FILE || null;
  99. function generateToken() {
  100. return crypto.randomBytes(32).toString('hex');
  101. }
  102. function chmodOwnerOnly(file) {
  103. try { fs.chmodSync(file, 0o600); } catch (e) { /* best effort */ }
  104. }
  105. function initialToken() {
  106. if (process.env.BRAINSTORM_TOKEN) {
  107. return { value: process.env.BRAINSTORM_TOKEN, source: 'env' };
  108. }
  109. if (TOKEN_FILE) {
  110. try {
  111. const t = fs.readFileSync(TOKEN_FILE, 'utf-8').trim();
  112. if (/^[0-9a-f]{32,}$/i.test(t)) {
  113. chmodOwnerOnly(TOKEN_FILE);
  114. return { value: t, source: 'file' };
  115. }
  116. } catch (e) { /* no prior token recorded */ }
  117. }
  118. return { value: generateToken(), source: 'generated' };
  119. }
  120. const tokenInfo = initialToken();
  121. let TOKEN = tokenInfo.value;
  122. let tokenSource = tokenInfo.source;
  123. let COOKIE_NAME = 'brainstorm-key-' + PORT; // refined to the actual bound port in onListen
  124. const MIME_TYPES = {
  125. '.html': 'text/html', '.css': 'text/css', '.js': 'application/javascript',
  126. '.json': 'application/json', '.png': 'image/png', '.jpg': 'image/jpeg',
  127. '.jpeg': 'image/jpeg', '.gif': 'image/gif', '.svg': 'image/svg+xml'
  128. };
  129. // ========== Templates and Constants ==========
  130. const WAITING_PAGE = `<!DOCTYPE html>
  131. <html>
  132. <head><meta charset="utf-8"><title>Brainstorm Companion</title>
  133. <style>body { font-family: system-ui, sans-serif; padding: 2rem; max-width: 800px; margin: 0 auto; }
  134. h1 { color: #333; } p { color: #666; }</style>
  135. </head>
  136. <body><h1>Brainstorm Companion</h1>
  137. <p>Waiting for the agent to push a screen...</p></body></html>`;
  138. const FORBIDDEN_PAGE = `<!DOCTYPE html>
  139. <html>
  140. <head><meta charset="utf-8"><title>Session key required</title>
  141. <style>body { font-family: system-ui, sans-serif; padding: 2rem; max-width: 800px; margin: 0 auto; }
  142. h1 { color: #333; } p { color: #666; } code { background: #f0f0f0; padding: 0.1em 0.3em; border-radius: 4px; }</style>
  143. </head>
  144. <body><h1>Session key required</h1>
  145. <p>This page needs the full URL your coding agent gave you, including the
  146. <code>?key=&hellip;</code> part. Copy the complete URL and open it again.</p></body></html>`;
  147. function bootstrapPage(key) {
  148. const jsonKey = JSON.stringify(String(key));
  149. return `<!DOCTYPE html>
  150. <html>
  151. <head><meta charset="utf-8"><title>Opening Brainstorm Companion</title></head>
  152. <body>
  153. <script>
  154. try { sessionStorage.setItem('brainstorm-session-key', ${jsonKey}); } catch (e) {}
  155. location.replace('/');
  156. </script>
  157. </body>
  158. </html>`;
  159. }
  160. const frameTemplate = fs.readFileSync(path.join(__dirname, 'frame-template.html'), 'utf-8');
  161. const helperScript = fs.readFileSync(path.join(__dirname, 'helper.js'), 'utf-8');
  162. const helperInjection = '<script>\n' + helperScript + '\n</script>';
  163. // ========== Helper Functions ==========
  164. function isFullDocument(html) {
  165. const trimmed = html.trimStart().toLowerCase();
  166. return trimmed.startsWith('<!doctype') || trimmed.startsWith('<html');
  167. }
  168. function wrapInFrame(content) {
  169. return frameTemplate.replace('<!-- CONTENT -->', content);
  170. }
  171. function getNewestScreen() {
  172. const files = fs.readdirSync(CONTENT_DIR)
  173. .filter(f => !f.startsWith('.') && f.endsWith('.html'))
  174. .map(f => {
  175. const fp = path.join(CONTENT_DIR, f);
  176. if (!isRegularFileInsideContentDir(fp)) return null;
  177. return { path: fp, mtime: fs.statSync(fp).mtime.getTime() };
  178. })
  179. .filter(Boolean)
  180. .sort((a, b) => b.mtime - a.mtime);
  181. return files.length > 0 ? files[0].path : null;
  182. }
  183. function urlHostForHttp(host) {
  184. const h = String(host);
  185. if (h.startsWith('[') && h.endsWith(']')) return h;
  186. return h.includes(':') ? '[' + h + ']' : h;
  187. }
  188. function companionUrl() {
  189. return 'http://' + urlHostForHttp(URL_HOST) + ':' + PORT + '/?key=' + TOKEN;
  190. }
  191. function browserLauncherForPlatform(url, {
  192. platform = process.platform,
  193. osRelease = require('os').release(),
  194. env = process.env
  195. } = {}) {
  196. const isWSL = platform === 'linux' && /microsoft/i.test(osRelease);
  197. if (platform === 'darwin') return { bin: 'open', args: [url] };
  198. if (platform === 'win32' || isWSL) {
  199. return { bin: 'rundll32.exe', args: ['url.dll,FileProtocolHandler', url] };
  200. }
  201. if (env.DISPLAY || env.WAYLAND_DISPLAY) return { bin: 'xdg-open', args: [url] };
  202. return null;
  203. }
  204. function isRegularFileInsideContentDir(filePath) {
  205. let stat, realContentDir, realFilePath;
  206. try {
  207. stat = fs.lstatSync(filePath);
  208. if (stat.isSymbolicLink()) return false;
  209. if (!stat.isFile()) return false;
  210. if (stat.nlink !== 1) return false;
  211. realContentDir = fs.realpathSync(CONTENT_DIR);
  212. realFilePath = fs.realpathSync(filePath);
  213. } catch (e) {
  214. return false;
  215. }
  216. return realFilePath.startsWith(realContentDir + path.sep);
  217. }
  218. // ========== Authentication ==========
  219. function timingSafeEqualStr(a, b) {
  220. const ab = Buffer.from(String(a));
  221. const bb = Buffer.from(String(b));
  222. if (ab.length !== bb.length) return false;
  223. return crypto.timingSafeEqual(ab, bb);
  224. }
  225. function parseCookies(header) {
  226. const out = {};
  227. if (!header) return out;
  228. for (const part of header.split(';')) {
  229. const eq = part.indexOf('=');
  230. if (eq < 0) continue;
  231. out[part.slice(0, eq).trim()] = part.slice(eq + 1).trim();
  232. }
  233. return out;
  234. }
  235. // A request is authorized if it carries the session key as ?key= or as the
  236. // session cookie. Both are compared in constant time.
  237. function isAuthorized(req) {
  238. const q = req.url.indexOf('?');
  239. if (q >= 0) {
  240. const params = new URLSearchParams(req.url.slice(q + 1));
  241. if (params.has('key')) {
  242. const key = params.get('key');
  243. return Boolean(key && timingSafeEqualStr(key, TOKEN));
  244. }
  245. }
  246. const cookie = parseCookies(req.headers['cookie'])[COOKIE_NAME];
  247. if (cookie && timingSafeEqualStr(cookie, TOKEN)) return true;
  248. return false;
  249. }
  250. function pathnameOf(url) {
  251. const q = url.indexOf('?');
  252. return q >= 0 ? url.slice(0, q) : url;
  253. }
  254. function queryKey(url) {
  255. const q = url.indexOf('?');
  256. if (q < 0) return null;
  257. return new URLSearchParams(url.slice(q + 1)).get('key');
  258. }
  259. function securityHeaders(headers = {}) {
  260. return {
  261. 'Referrer-Policy': 'no-referrer',
  262. 'Cache-Control': 'no-store',
  263. 'X-Frame-Options': 'DENY',
  264. 'Content-Security-Policy': "frame-ancestors 'none'",
  265. 'Cross-Origin-Resource-Policy': 'same-origin',
  266. ...headers
  267. };
  268. }
  269. function isAllowedWebSocketOrigin(req) {
  270. const origin = req.headers.origin;
  271. if (!origin) return true;
  272. const host = req.headers.host;
  273. if (!host) return false;
  274. return origin === 'http://' + host;
  275. }
  276. // ========== HTTP Request Handler ==========
  277. function handleRequest(req, res) {
  278. if (!isAuthorized(req)) {
  279. res.writeHead(403, securityHeaders({ 'Content-Type': 'text/html; charset=utf-8' }));
  280. res.end(FORBIDDEN_PAGE);
  281. return;
  282. }
  283. touchActivity(); // only authorized requests count as activity
  284. // Mirror the key into a cookie so same-origin subresources (/files/*) can
  285. // authenticate after bootstrap. HttpOnly keeps it away from page scripts; the
  286. // WebSocket Origin check below is what blocks cross-origin localhost injection.
  287. res.setHeader('Set-Cookie',
  288. COOKIE_NAME + '=' + TOKEN + '; HttpOnly; SameSite=Strict; Path=/');
  289. const pathname = pathnameOf(req.url);
  290. const keyFromQuery = queryKey(req.url);
  291. if (req.method === 'GET' && pathname === '/' && keyFromQuery && timingSafeEqualStr(keyFromQuery, TOKEN)) {
  292. res.writeHead(200, securityHeaders({ 'Content-Type': 'text/html; charset=utf-8' }));
  293. res.end(bootstrapPage(keyFromQuery));
  294. } else if (req.method === 'GET' && pathname === '/') {
  295. const screenFile = getNewestScreen();
  296. let html = screenFile
  297. ? (raw => isFullDocument(raw) ? raw : wrapInFrame(raw))(fs.readFileSync(screenFile, 'utf-8'))
  298. : WAITING_PAGE;
  299. if (html.includes('</body>')) {
  300. html = html.replace('</body>', helperInjection + '\n</body>');
  301. } else {
  302. html += helperInjection;
  303. }
  304. res.writeHead(200, securityHeaders({ 'Content-Type': 'text/html; charset=utf-8' }));
  305. res.end(html);
  306. } else if (req.method === 'GET' && pathname.startsWith('/files/')) {
  307. const fileName = path.basename(pathname.slice(7));
  308. const filePath = path.join(CONTENT_DIR, fileName);
  309. // Reject empty/dotfile names and anything that isn't a regular file —
  310. // `/files/` would otherwise resolve to CONTENT_DIR and crash readFileSync (EISDIR).
  311. if (!fileName || fileName.startsWith('.') || !isRegularFileInsideContentDir(filePath)) {
  312. res.writeHead(404, securityHeaders());
  313. res.end('Not found');
  314. return;
  315. }
  316. const ext = path.extname(filePath).toLowerCase();
  317. const contentType = MIME_TYPES[ext] || 'application/octet-stream';
  318. res.writeHead(200, securityHeaders({ 'Content-Type': contentType }));
  319. res.end(fs.readFileSync(filePath));
  320. } else {
  321. res.writeHead(404, securityHeaders());
  322. res.end('Not found');
  323. }
  324. }
  325. // ========== WebSocket Connection Handling ==========
  326. const clients = new Set();
  327. function handleUpgrade(req, socket) {
  328. if (!isAuthorized(req) || !isAllowedWebSocketOrigin(req)) { socket.destroy(); return; }
  329. const key = req.headers['sec-websocket-key'];
  330. if (!key) { socket.destroy(); return; }
  331. const accept = computeAcceptKey(key);
  332. socket.write(
  333. 'HTTP/1.1 101 Switching Protocols\r\n' +
  334. 'Upgrade: websocket\r\n' +
  335. 'Connection: Upgrade\r\n' +
  336. 'Sec-WebSocket-Accept: ' + accept + '\r\n\r\n'
  337. );
  338. let buffer = Buffer.alloc(0);
  339. clients.add(socket);
  340. socket.on('data', (chunk) => {
  341. buffer = Buffer.concat([buffer, chunk]);
  342. while (buffer.length > 0) {
  343. let result;
  344. try {
  345. result = decodeFrame(buffer);
  346. } catch (e) {
  347. socket.end(encodeFrame(OPCODES.CLOSE, Buffer.alloc(0)));
  348. clients.delete(socket);
  349. return;
  350. }
  351. if (!result) break;
  352. buffer = buffer.slice(result.bytesConsumed);
  353. switch (result.opcode) {
  354. case OPCODES.TEXT:
  355. handleMessage(result.payload.toString());
  356. break;
  357. case OPCODES.CLOSE:
  358. socket.end(encodeFrame(OPCODES.CLOSE, Buffer.alloc(0)));
  359. clients.delete(socket);
  360. return;
  361. case OPCODES.PING:
  362. socket.write(encodeFrame(OPCODES.PONG, result.payload));
  363. break;
  364. case OPCODES.PONG:
  365. break;
  366. default: {
  367. const closeBuf = Buffer.alloc(2);
  368. closeBuf.writeUInt16BE(1003);
  369. socket.end(encodeFrame(OPCODES.CLOSE, closeBuf));
  370. clients.delete(socket);
  371. return;
  372. }
  373. }
  374. }
  375. });
  376. socket.on('close', () => clients.delete(socket));
  377. socket.on('error', () => clients.delete(socket));
  378. }
  379. function handleMessage(text) {
  380. let event;
  381. try {
  382. event = JSON.parse(text);
  383. } catch (e) {
  384. console.error('Failed to parse WebSocket message:', e.message);
  385. return;
  386. }
  387. touchActivity();
  388. console.log(JSON.stringify({ source: 'user-event', ...event }));
  389. if (event && event.choice) {
  390. const eventsFile = path.join(STATE_DIR, 'events');
  391. fs.appendFileSync(eventsFile, JSON.stringify(event) + '\n');
  392. }
  393. }
  394. function broadcast(msg) {
  395. const frame = encodeFrame(OPCODES.TEXT, Buffer.from(JSON.stringify(msg)));
  396. for (const socket of clients) {
  397. try { socket.write(frame); } catch (e) { clients.delete(socket); }
  398. }
  399. }
  400. // Best-effort: open the user's browser the first time a screen is actually ready
  401. // to show. Skips when disabled, on a non-loopback (remote) bind, or when a
  402. // browser is already connected. Override the launcher with BRAINSTORM_OPEN_CMD.
  403. let browserOpened = false;
  404. function maybeOpenBrowser() {
  405. if (browserOpened) return;
  406. browserOpened = true;
  407. if (!process.env.BRAINSTORM_OPEN) return; // opt-in: only after the user approves the companion
  408. if (HOST !== '127.0.0.1' && HOST !== 'localhost') return;
  409. if (clients.size > 0) return; // the user already opened it
  410. const url = companionUrl(); // must carry the key or the gate 403s it
  411. const cp = require('child_process');
  412. // Operator-provided launcher: run as given (this env var is trusted operator input).
  413. if (process.env.BRAINSTORM_OPEN_CMD) {
  414. try { cp.exec(process.env.BRAINSTORM_OPEN_CMD + ' ' + JSON.stringify(url), () => {}); } catch (e) { /* best effort */ }
  415. return;
  416. }
  417. // Platform launchers: pass the URL as an argv element via execFile (no shell),
  418. // so a url-host containing shell metacharacters can't inject a command.
  419. const launcher = browserLauncherForPlatform(url);
  420. if (!launcher) return; // headless: nothing to open
  421. try { cp.execFile(launcher.bin, launcher.args, () => {}); } catch (e) { /* best effort */ }
  422. }
  423. // ========== Activity Tracking ==========
  424. // Idle timeout: shut down after this long with no activity. Default 4 hours;
  425. // override with BRAINSTORM_IDLE_TIMEOUT_MS (start-server.sh: --idle-timeout-minutes).
  426. const IDLE_TIMEOUT_MS = (() => {
  427. const ms = Number(process.env.BRAINSTORM_IDLE_TIMEOUT_MS);
  428. return Number.isFinite(ms) && ms > 0 ? ms : 4 * 60 * 60 * 1000;
  429. })();
  430. // How often the watchdog checks for owner-death / idleness. Configurable mainly
  431. // so tests can run fast; production default is 60s.
  432. const LIFECYCLE_CHECK_MS = (() => {
  433. const ms = Number(process.env.BRAINSTORM_LIFECYCLE_CHECK_MS);
  434. return Number.isFinite(ms) && ms > 0 ? ms : 60 * 1000;
  435. })();
  436. let lastActivity = Date.now();
  437. function touchActivity() {
  438. lastActivity = Date.now();
  439. }
  440. // ========== File Watching ==========
  441. const debounceTimers = new Map();
  442. // ========== Server Startup ==========
  443. function startServer() {
  444. if (!fs.existsSync(CONTENT_DIR)) fs.mkdirSync(CONTENT_DIR, { recursive: true });
  445. if (!fs.existsSync(STATE_DIR)) fs.mkdirSync(STATE_DIR, { recursive: true });
  446. // Track known files to distinguish new screens from updates.
  447. // macOS fs.watch reports 'rename' for both new files and overwrites,
  448. // so we can't rely on eventType alone.
  449. const knownFiles = new Set(
  450. fs.readdirSync(CONTENT_DIR).filter(f => !f.startsWith('.') && f.endsWith('.html'))
  451. );
  452. const server = http.createServer(handleRequest);
  453. server.on('upgrade', handleUpgrade);
  454. const watcher = fs.watch(CONTENT_DIR, (eventType, filename) => {
  455. if (!filename || filename.startsWith('.') || !filename.endsWith('.html')) return;
  456. if (debounceTimers.has(filename)) clearTimeout(debounceTimers.get(filename));
  457. debounceTimers.set(filename, setTimeout(() => {
  458. debounceTimers.delete(filename);
  459. const filePath = path.join(CONTENT_DIR, filename);
  460. if (!fs.existsSync(filePath)) return; // file was deleted
  461. touchActivity();
  462. if (!knownFiles.has(filename)) {
  463. knownFiles.add(filename);
  464. const eventsFile = path.join(STATE_DIR, 'events');
  465. if (fs.existsSync(eventsFile)) fs.unlinkSync(eventsFile);
  466. console.log(JSON.stringify({ type: 'screen-added', file: filePath }));
  467. maybeOpenBrowser();
  468. } else {
  469. console.log(JSON.stringify({ type: 'screen-updated', file: filePath }));
  470. }
  471. broadcast({ type: 'reload' });
  472. }, 100));
  473. });
  474. watcher.on('error', (err) => console.error('fs.watch error:', err.message));
  475. function shutdown(reason) {
  476. console.log(JSON.stringify({ type: 'server-stopped', reason }));
  477. const infoFile = path.join(STATE_DIR, 'server-info');
  478. if (fs.existsSync(infoFile)) fs.unlinkSync(infoFile);
  479. fs.writeFileSync(
  480. path.join(STATE_DIR, 'server-stopped'),
  481. JSON.stringify({ reason, timestamp: Date.now() }) + '\n'
  482. );
  483. watcher.close();
  484. clearInterval(lifecycleCheck);
  485. // Close any upgraded WebSocket sockets so server.close() can complete and
  486. // the process actually exits instead of lingering on an open connection.
  487. for (const socket of clients) {
  488. try { socket.destroy(); } catch (e) { /* already gone */ }
  489. }
  490. server.close(() => process.exit(0));
  491. }
  492. function ownerAlive() {
  493. if (!ownerPid) return true;
  494. try { process.kill(ownerPid, 0); return true; } catch (e) { return e.code === 'EPERM'; }
  495. }
  496. // Periodically exit if the owner process died or we've been idle too long.
  497. const lifecycleCheck = setInterval(() => {
  498. if (!ownerAlive()) shutdown('owner process exited');
  499. else if (Date.now() - lastActivity > IDLE_TIMEOUT_MS) shutdown('idle timeout');
  500. }, LIFECYCLE_CHECK_MS);
  501. lifecycleCheck.unref();
  502. // Validate owner PID at startup. If it's already dead, the PID resolution
  503. // was wrong (common on WSL, Tailscale SSH, and cross-user scenarios).
  504. // Disable monitoring and rely on the idle timeout instead.
  505. if (ownerPid) {
  506. try { process.kill(ownerPid, 0); }
  507. catch (e) {
  508. if (e.code !== 'EPERM') {
  509. console.log(JSON.stringify({ type: 'owner-pid-invalid', pid: ownerPid, reason: 'dead at startup' }));
  510. ownerPid = null;
  511. }
  512. }
  513. }
  514. // If the preferred port is already taken (e.g. a previous server is still
  515. // alive), fall back to a random port once instead of failing.
  516. let triedFallback = false;
  517. function onListen() {
  518. // Cookie name keys on the ACTUAL bound port (may differ from the preferred
  519. // one after an EADDRINUSE fallback) so it can't collide with another server's
  520. // cookie in the shared localhost jar.
  521. COOKIE_NAME = 'brainstorm-key-' + PORT;
  522. // Record the bound port AND token so the next restart of this session reuses
  523. // them — but ONLY when we got our preferred port. On a fallback we bound a
  524. // *different* port because someone else holds the preferred one; persisting
  525. // would overwrite the shared files and strand that other session's open tab.
  526. if (PORT_FILE && !triedFallback) {
  527. try { fs.writeFileSync(PORT_FILE, String(PORT)); } catch (e) { /* best effort */ }
  528. if (TOKEN_FILE) {
  529. try {
  530. fs.writeFileSync(TOKEN_FILE, TOKEN, { mode: 0o600 });
  531. chmodOwnerOnly(TOKEN_FILE);
  532. } catch (e) { /* best effort */ }
  533. }
  534. }
  535. const info = JSON.stringify({
  536. type: 'server-started', port: Number(PORT), host: HOST,
  537. url_host: URL_HOST, url: companionUrl(),
  538. screen_dir: CONTENT_DIR, state_dir: STATE_DIR, idle_timeout_ms: IDLE_TIMEOUT_MS
  539. });
  540. console.log(info);
  541. // server-info embeds the key — keep it owner-only.
  542. fs.writeFileSync(path.join(STATE_DIR, 'server-info'), info + '\n', { mode: 0o600 });
  543. }
  544. server.on('error', (err) => {
  545. if (err.code === 'EADDRINUSE' && !triedFallback) {
  546. if (tokenSource === 'env') {
  547. console.error('Server failed to bind: preferred port is in use and BRAINSTORM_TOKEN is set; refusing fallback with explicit token');
  548. process.exit(1);
  549. }
  550. triedFallback = true;
  551. PORT = randomPort();
  552. if (tokenSource === 'file') {
  553. TOKEN = generateToken();
  554. tokenSource = 'generated-fallback';
  555. }
  556. server.listen(PORT, HOST, onListen);
  557. } else {
  558. console.error('Server failed to bind:', err.message);
  559. process.exit(1);
  560. }
  561. });
  562. server.listen(PORT, HOST, onListen);
  563. }
  564. if (require.main === module) {
  565. startServer();
  566. }
  567. module.exports = {
  568. computeAcceptKey,
  569. encodeFrame,
  570. decodeFrame,
  571. browserLauncherForPlatform,
  572. OPCODES,
  573. MAX_FRAME_PAYLOAD_BYTES
  574. };