Documentation
¶
Overview ¶
Package server exposes the daemon's HTTP control surface: sessions are created, listed and messaged through here. Like the gateway, every handler runs behind a panic-recovery middleware — a single bad request must never take the daemon down and orphan every session it owns.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Server ¶
type Server struct {
// contains filtered or unexported fields
}
Server holds the session and agent services and exposes them over HTTP.
func New ¶
func New(sessions *session.Service, agentSvc *agent.Service, logger *slog.Logger, authToken string) *Server
New builds a daemon Server. authToken is the per-process bearer token every route (except /health) requires — the daemon's HTTP surface drives real code execution (bash, edit_file, approving its own tool calls), so leaving it open would let any local process, or a browser tab via DNS rebinding, run code as the user. An empty authToken means "no auth" (only for tests / an explicitly-insecure standalone run) and logs a loud warning.