Skip to content

Make the Nodes page clearer: public-URL commands, visible limits, old addresses - #157

Merged
SaladDay merged 10 commits into
mainfrom
codex/web-ux-nodes
Sep 26, 2026
Merged

SaladDay merged 10 commits into
mainfrom
codex/web-ux-nodes

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

UX quick wins for the Nodes area, from the Web UX review (~/.parsar/plans/new-user-install-20260925/03-web-ux-review.md). One commit per item.

  • BE-6: node commands no longer depend on the browser address. The Add node and Clean up the host commands download from the installation's public_url and pass it as --source-url, since the reverse proxy already serves /node-install/* there.
    • When public_url is loopback, missing or not HTTPS, Add node generates no command (as before) and the clean-up dialog says no uninstall command can be given.
    • The browser-origin warnings and sandboxSetupOrigin are removed.
  • UX-21: every node's limit is visible. Docker nodes now show "Active / limit" in the list and on the detail page.
    • Edit node shows the host's CPUs and memory, the sandbox size, and "at most N", computed from host resources and the deployment's size only when every input is known.
  • UX-23: a refused change doesn't lock the page. Only no answer, a 408 or a 5xx counts as uncertain.
    • Any other 4xx shows Core's reason in a toast and the page stays usable.
    • The "not configured" hint appears only for sandbox_admin_not_configured. Other 403s show Core's message.
    • "Ask the deployment administrator" is gone, since the reader is that administrator.
  • UX-24: nodes on an old Core address. When a node's core_url differs from the deployment's, its status shows Old address with "Remove and add again". It never shows "Available".
  • UX-07: the next step after a node is ready. While Getting started is open, a one-line next step appears (set a default model, or finish Getting started).

Maintenance UI and copy are untouched, because the maintenance flow is being redesigned. One maintenance e2e now injects a 503 instead of a 409, since a 409 is no longer treated as uncertain.

Tests

docs/web (for the backend session's review)

docs/web/protocol-coverage.md:120 (Installation row: public_url is the node commands' source), :146 (Old address status), :147 (Edit node reads host resources), :149 (Enrollment downloads from public_url).


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.

The install and uninstall commands downloaded the node installer from the
browser's own origin, so a console opened over an SSH tunnel or 127.0.0.1
produced commands that fail on every other host. The reverse proxy already
serves <public_url>/node-install/* from the console, so both commands now
use the installation's public_url as the download origin and --source-url.

Add node already issues no command for a loopback public URL; the clean-up
dialog now says no uninstall command can be given in that case. The
browser-origin loopback warnings, their strings and sandboxSetupOrigin go.
The Nodes list showed active / limit only for microsandbox, and a node's
page had no limit at all, so a Docker node's limit was invisible before
and after Edit node. Both now show active / max_active for every provider.
Edit node adds the host's CPUs and memory from the node detail read, each
sandbox's size and at most how many of those fit.
Every failed sandbox write was treated as an uncertain outcome: the node
list turned to Status unconfirmed and all writes stayed locked until a
refresh, even when Core had clearly refused the change. Only no answer, a
timeout or a 5xx is uncertain now; any other 4xx shows Core's reason in
an error toast and leaves the page as it was.

The sandbox administration hint appears only for
sandbox_admin_not_configured, other 403s show Core's message, and the
Nodes copy no longer tells the administrator to ask the deployment
administrator.
The Nodes page named nodes bound to an old Core address in a banner, but
their rows still read Available although Core places no new sandboxes on
them. Such a node's status on the list and on its page is now Old address,
with Remove and add again under it.
Add node ended at the node's Connected line with only Done, leaving a new
administrator to find the rest of Getting started. While the checklist is
open, the ready state now names the next step in one line: set a default
model while that step is to do, otherwise finish Getting started, each
with a link to System or the Overview.
Only a 403 showed Core's message; a 400 got generic text and every 409
sandbox_deployment_conflict read "already configured", although Core
uses that code for a stale expected_generation, a deployment not in
maintenance and resources still allocated. Any 4xx other than 401 now
shows Core's message, and only sandbox_admin_not_configured keeps the
console's own words.

Whether a write is uncertain now depends on the status alone, so an E2B
configuration refused with a 4xx, whose reason the client withholds, is
a refusal too: it reads "Core rejected the E2B configuration." and no
longer locks the page.
nodeSourceUrl normalized the public URL through URL.origin, which drops an
explicit port such as :443, and accepted plain HTTP on loopback names. It
now keeps the validated value as written, like the self-hosted executor
command, and requires an HTTPS origin.

Add node also takes --core-url from that same freshly read public URL
instead of the page's deployment read, so a public_url fixed on the Core
host shows on the next opening without a refresh.
A file-managed local node, which Core did not enroll, reports an empty
core_url. It read as Old address and was named in the banner. An empty
address is now unknown: such a node shows its health, stays out of the
banner, and its clean-up offers no --force form.

On a node's page, as in the list, an Old address status no longer shows
the offline or provider help tip beside it.
After Remove, the dialog opened only when the installation read was
already cached; after a failed read the host's uninstall command was
simply never offered. The dialog now always opens and reads the
installation itself if needed: it says it is checking, or that the read
failed with Try again, and gives the command once the public URL is read.

A loopback public URL now reads as unreachable from other machines rather
than missing.
runtime_node_in_use and runtime_node_unavailable each have one exact,
stable meaning, so a refused node removal again reads in the console's
language instead of Core's English message. Every other 4xx still shows
Core's message.
@SaladDay
SaladDay merged commit b108a76 into main Sep 26, 2026
2 checks passed
@SaladDay
SaladDay deleted the codex/web-ux-nodes branch October 7, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant