The backend logic lives in app/app.py. This file contains the Flask routes, path validation, AI provider adapters, terminal resolution logic, and local model probing.
The app uses resolve_workspace_path() and is_git_restricted() to restrict access to the project root and prevent .git access or directory escapes outside the workspace.
The /read-file and /save-file routes validate the path, reject invalid or out-of-workspace locations, then read or write the file using UTF-8 encoding. Path sanitization is applied before disk operations.
The /api/ai-chat route inspects the selected provider and API key state. If the provider is a custom gateway or an API key is present, it routes to call_external_ai_api(). Otherwise it falls back to call_local_ai_model().
Gateway endpoints often appear in shapes like localhost:1234/v1/, https://proxy.example.com/base/, or https://example.com/chat/completions. normalize_gateway_url() and build_openai_compatible_url() normalize these into a consistent base URL and final OpenAI-compatible path.
call_external_ai_api() sanitizes the provider name, restricts it to an allowlist, and collapses custom-like labels into a shared custom route. This prevents invalid provider strings from being used in outbound requests.
resolve_terminal_command() checks, in order: bash in PATH, common Git Bash install locations, Git Bash Start Menu shortcut, then Windows cmd.exe as a fallback.
The app probes common local AI gateway ports such as 11434, 1234, 8080, 8081, 8000, and 3000, and tries common OpenAI-compatible paths such as /api/generate, /v1/chat/completions, and /chat/completions.
/run-file supports only a specific set of safe script extensions and invokes subprocesses with shell=False and argument lists instead of a shell command string. The path is also validated before it is executed.
Run the project’s test suite with pytest -q from the repo root. The repo includes regression tests for gateway normalization, custom AI route routing, and terminal fallback logic. If you modify gateway or path handling, add or update tests before relying on the change.
- The workspace root is enforced using
WORKSPACE_ROOTand path containment checks. - API responses are structured as JSON with
statusandmessagefields for the frontend to consume consistently. sanitize_str()strips control characters and CR/LF sequences to prevent malformed HTTP payloads and unsafe render output.