q792602257andClaude Opus 4.6 8381b3068a
Tests / Test failed: 4, passed: 744
feat(host-agent): migrate local console to Jinja2 templates with autoescape
Replace hand-written f-string + html.escape() rendering in the Host Agent
local console with a module-level Jinja2 Environment configured with
select_autoescape(["html","xml"]). XSS safety now holds by mechanism
rather than per-call discipline — every operator-controlled field
(device name, connection_info, task summary, etc.) is escaped by the
engine uniformly.

Eight templates under host_agent/web/templates/ replace the former
_chrome(), _CSS, escape(), and per-page _xxx_body() helpers: base.html
(header/nav/CSS + {% block body %}), login, dashboard (with the polling
<script> preserved byte-identically inside {% raw %}), devices, account,
history, tasks_list, and task_detail. The task-list and task-detail
templates — added by the just-landed task-execution-progress-visibility
change — were also migrated here rather than left in f-string form,
since this change removes the shared helpers they depended on.

URLs, auth/session/CSRF semantics, redirects, and /api/status JSON are
unchanged. 15 new template tests cover render-smoke, XSS probing, script
byte-identity, and no-autoescape-bypass guards. Tasks 8.1-8.6 (manual
browser verification) remain.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-14 13:05:19 +08:00
2026-07-14 09:06:48 +08:00
2026-07-14 09:06:48 +08:00
2026-07-14 09:06:48 +08:00
2026-07-13 15:56:44 +08:00

Device Agent Runtime

Device Agent Runtime is a device-agnostic runtime for LLM-driven automation. It gives agents a stable way to observe, decide, and act against real devices through a small set of domain models, driver contracts, tools, perception providers, and runtime orchestration.

iPhone automation through WebDriverAgent/Appium is the first driver, not the platform boundary. Future drivers can target Android, browsers, desktop environments, or other device surfaces without changing the runtime's core contracts.

Current Shape

  • core/: shared domain models and runtime errors.
  • driver/: the Driver contract, concrete driver adapters, and driver-type registry.
  • device/: device lifecycle and active driver management.
  • tools/: device capabilities exposed to runtime and API layers.
  • perception/: screen-to-Scene perception behind PerceptionProvider.
  • runtime/: planning and execution orchestration.
  • api/: REST/MCP transport adapters.
  • storage/: timeline, task, and device configuration persistence.
  • packages/cloud-platform/: cloud scheduling, device pooling, plugins, and the Python cloud SDK as the device-cloud-platform workspace member.
  • apps/cloud-api/: deployable authenticated Cloud Control Plane with PostgreSQL/SQLite persistence, scheduling, leases, and health endpoints.
  • apps/device-host-agent/: outbound Host Agent that synchronizes configured devices and executes leased tasks through the existing Runtime/workflow.

Python Workspace

The repository uses a uv workspace with one committed lockfile. From the repository root, synchronize every Python member with:

uv sync --locked --all-packages

Run the complete local test suite in a workspace environment:

uv run --all-packages pytest -m "not integration"

Select one member when running package-specific commands:

uv run --package device-agent-runtime python -c "import runtime"
uv run --package device-cloud-platform python -c "import cloud"
uv run --package device-cloud-api device-cloud-api --help
uv run --package device-host-agent device-host-agent --help
uv build --package device-agent-runtime
uv build --package device-cloud-platform

The Vue/Vite application under console/ remains an independent npm project; uv does not install or modify its JavaScript dependencies.

Project Direction

The durable roadmap is in docs/ROADMAP.md. The architecture invariants future changes must preserve are in docs/CONSTITUTION.md.

Operator Guides

S
Description
No description provided
Readme
1.9 MiB
Languages
Python 92.5%
Vue 3.8%
HTML 1.7%
TypeScript 1.6%
CSS 0.3%
Other 0.1%