feat(api): server-rendered Jinja2 Runtime console at /ui/

Replaces the separate Vue/Vite `console/` SPA with a same-origin,
server-rendered console built on a module-level Jinja2 Environment
with select_autoescape(["html","xml"]).

- Add api/console_web.py with /ui/ routes (dashboard, tasks, task
  detail/timeline, config) and a _status_fragment polled every 10s.
- Refactor api/console.py into a typed ConsoleService shared by the
  JSON and HTML routers so validation/persistence cannot drift.
- Remove RUNTIME_CONSOLE_STATIC_DIR, SpaStaticFiles, and the wildcard
  CORS middleware from api/rest.py; GET / now redirects to /ui/.
- Delete the top-level console/ project; add jinja2 and python-multipart
  as direct dependencies and ship templates/CSS/JS via package-data.
- Add 31 tests (XSS probes, PRG flows, fragment refresh, no-static-dir
  and no-CORS regressions, wheel-packaging smoke test).

/console/* JSON endpoints remain unchanged. The console keeps the
trusted-network-only boundary; auth/CSRF is intentionally deferred.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-07-15 08:03:13 +08:00
co-authored by Claude Opus 4.6
parent 56f3f96363
commit e00c50e703
39 changed files with 1890 additions and 2228 deletions
+6 -2
View File
@@ -54,8 +54,12 @@ uv build --package device-agent-runtime
uv build --package device-cloud-platform
```
The Vue/Vite application under `console/` remains an independent npm project;
uv does not install or modify its JavaScript dependencies.
The Runtime API ships a same-origin operator console at `/ui/`, rendered through
Jinja2 templates packaged with `device-agent-runtime`. Start the API
(`uvicorn api.rest:create_app --factory`) and open `/` (it redirects to `/ui/`).
The `/console/*` JSON endpoints remain available for programmatic clients. The
console assumes a trusted local network; it has no authentication, authorization,
or CSRF protection.
## Project Direction