feat: show the agent's artifacts — live, sandboxed, never on TeamWork's origin - #81
Merged
Merged
Conversation
…'s origin A line '[artifact:<id>]' in a message or note renders the agent's page as a live card (polls for new versions, full-screen view). The page comes from the agent through /api/artifacts (behind TeamWork's login) and runs as srcdoc in an iframe with sandbox='allow-scripts' and no allow-same-origin, under an injected CSP with no network. Verified in headless Chromium: parent, cookies and storage throw SecurityError, origin is null, fetch is refused. Idea credit: Telepath's Television.
…t private An agent shows its work in TeamWork without asking (Prax: TeamWork is trusted, a public link needs a person's decision). That holds only if TeamWork is deployed privately — login on, private reach — and no agent can check it from the inside.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TeamWork's half of artifacts: the viewer. The agent makes and stores the pages; Prax's half is praxagent/prax (feat/artifacts).
What
[artifact:<id>]renders the agent's page as a live card. It polls for new versions every 5 s and has a full-screen view (Esc closes it).GET /api/artifacts[/<id>][?meta=1]proxies to{PRAX_URL}/teamwork/artifacts….Why it's safe to render agent-written pages
TeamWork's origin holds your session, and an artifact may have been written while the agent was reading untrusted content. So the page never runs on TeamWork's origin:
srcdocin an iframe withsandbox="allow-scripts"and noallow-same-origin, so it gets an opaque origin, andreferrerpolicy=no-referrer.<head>: no network, no forms, no base changes. The page's own tags can't loosen it, because every policy applies and the strictest wins.Verified in real headless Chromium (the prax-sandbox image), with the exact attribute and CSP: from inside the frame,
parent.document,document.cookieandlocalStorage→ SecurityError;self.origin→ "null";fetch('https://example.com/')→ blocked byconnect-src 'none'; Chromium logged the CSP violation.Tests
make cigreen: 500 passed.tscclean,vite buildOK.Docs:
docs/artifacts.md. Idea credit: Telepath's Television (see #80).