Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
80 lines
2.8 KiB
TypeScript
80 lines
2.8 KiB
TypeScript
// Instance settings data layer (#79): admin-only, instance-wide configuration.
|
|
//
|
|
// The GET/PATCH return both the stored settings and a read-only "effective" view
|
|
// — what's actually in force after layering the DB over the environment — so the
|
|
// form can say "inheriting ollama-cloud/glm-5.2:cloud from the environment" and
|
|
// whether the API key is present, without the key ever crossing the wire.
|
|
|
|
import { queryOptions, useMutation, useQuery, useQueryClient } from '@tanstack/react-query'
|
|
import { z } from 'zod'
|
|
import { ApiError, api } from './api'
|
|
import { capabilitiesKey } from './agent'
|
|
|
|
export const instanceSettingsSchema = z.object({
|
|
// '' means "inherit the PANSY_AGENT_MODEL env var".
|
|
agentModel: z.string(),
|
|
// null means "inherit PANSY_AGENT_ENABLED"; true/false is an explicit override.
|
|
agentEnabled: z.boolean().nullable(),
|
|
version: z.number(),
|
|
updatedAt: z.string(),
|
|
})
|
|
export type InstanceSettings = z.infer<typeof instanceSettingsSchema>
|
|
|
|
export const effectiveAgentSchema = z.object({
|
|
model: z.string(),
|
|
enabled: z.boolean(),
|
|
hasApiKey: z.boolean(),
|
|
agentLive: z.boolean(),
|
|
})
|
|
export type EffectiveAgent = z.infer<typeof effectiveAgentSchema>
|
|
|
|
export const settingsResponseSchema = z.object({
|
|
settings: instanceSettingsSchema,
|
|
effective: effectiveAgentSchema,
|
|
})
|
|
export type SettingsResponse = z.infer<typeof settingsResponseSchema>
|
|
|
|
export const settingsKey = ['settings'] as const
|
|
|
|
export const settingsQueryOptions = queryOptions({
|
|
queryKey: settingsKey,
|
|
queryFn: async (): Promise<SettingsResponse> =>
|
|
settingsResponseSchema.parse(await api.get('/settings')),
|
|
})
|
|
|
|
export function useSettings() {
|
|
return useQuery(settingsQueryOptions)
|
|
}
|
|
|
|
export interface SettingsUpdate {
|
|
agentModel: string
|
|
agentEnabled: boolean | null
|
|
version: number
|
|
}
|
|
|
|
export function useUpdateSettings() {
|
|
const qc = useQueryClient()
|
|
return useMutation({
|
|
mutationFn: async (input: SettingsUpdate): Promise<SettingsResponse> =>
|
|
settingsResponseSchema.parse(await api.patch('/settings', input)),
|
|
onSuccess: (res) => {
|
|
qc.setQueryData(settingsKey, res)
|
|
// The save may have turned the assistant on or off; the editor keys its
|
|
// chat tab off /capabilities, so make it re-read rather than trust its
|
|
// cached answer.
|
|
qc.invalidateQueries({ queryKey: capabilitiesKey })
|
|
},
|
|
})
|
|
}
|
|
|
|
/** If err is a 409 version conflict, return the fresh settings it carries so a
|
|
* form can rebase; otherwise null. */
|
|
export function conflictSettings(err: unknown): InstanceSettings | null {
|
|
if (err instanceof ApiError && err.isConflict && err.body && typeof err.body === 'object') {
|
|
const current = (err.body as { current?: unknown }).current
|
|
const parsed = instanceSettingsSchema.safeParse(current)
|
|
if (parsed.success) return parsed.data
|
|
}
|
|
return null
|
|
}
|