Compare commits

..

33 Commits

Author SHA1 Message Date
Slavi Pantaleev
c2eb7e94bc Use conventional mxlink version requirement
Replace the unconventional wildcard lower-bound expression with a standard semver lower bound for readability and tooling consistency.
2026-03-07 10:25:01 +02:00
Slavi Pantaleev
952b75318e Add auth config unit tests
Move auth_config tests into a dedicated cfg test module file to keep production config code compact while preserving behavior coverage. The tests cover password/token mode selection, missing/both auth method rejection, missing device_id, and empty-value handling.
2026-03-07 10:15:16 +02:00
Slavi Pantaleev
ce42942343 Centralize and harden user auth config handling
Move authentication-mode resolution into typed config parsing with ConfigUserAuth,
so downstream login setup consumes validated credentials instead of re-checking raw optional fields.

Enforce explicit password-vs-token selection, validate token/device/user-id requirements in one place,
and normalize empty auth env overrides to unset values for consistent behavior across YAML and environment input.
2026-03-07 10:01:47 +02:00
Slavi Pantaleev
9a226af36f Harden auth credential selection in matrix link init
Use the same non-empty access-token criterion for auth mode selection and bind the token directly from the branch condition.
Return explicit configuration errors for missing or empty `device_id`/`password` instead of panicking, so invalid auth config fails gracefully.
2026-03-07 09:42:13 +02:00
Slavi Pantaleev
0048226dc4 Update dependencies 2026-03-07 08:50:03 +02:00
Taylor Southwick
0361f9a100 use 1.13.0 2026-03-05 23:21:27 +00:00
Taylor Southwick
1d8f2b6890 Add support for access tokens using MAS 2026-03-05 18:57:00 +00:00
renovate[bot]
afc5572d6a Update docker/login-action action to v4 2026-03-04 17:13:28 +02:00
renovate[bot]
73e13dcf2f Update docker.io/ollama/ollama Docker tag to v0.17.6 2026-03-04 07:36:04 +02:00
renovate[bot]
2bebd109b1 Update forgejo.ellis.link/continuwuation/continuwuity Docker tag to v0.5.6 2026-03-04 07:35:22 +02:00
renovate[bot]
7f7c58be1f Update Rust crate tokio to 1.50.* 2026-03-03 16:27:53 +02:00
renovate[bot]
47e5a464a0 Update docker.io/ollama/ollama Docker tag to v0.17.5 2026-03-01 08:09:47 +02:00
renovate[bot]
85f751e514 Update docker.io/ollama/ollama Docker tag to v0.17.4 2026-02-27 07:08:48 +02:00
renovate[bot]
95acad3558 Update docker.io/postgres Docker tag to v18.3 2026-02-27 06:36:26 +02:00
renovate[bot]
304056c59a Update docker.io/ollama/ollama Docker tag to v0.17.2 2026-02-27 06:36:19 +02:00
renovate[bot]
bedc0335f1 Update docker.io/ollama/ollama Docker tag to v0.17.1 2026-02-26 13:33:16 +02:00
renovate[bot]
a8be8c3c1e Update ghcr.io/element-hq/element-web Docker tag to v1.12.11 2026-02-24 16:54:27 +02:00
renovate[bot]
826fa728a9 Update ghcr.io/element-hq/synapse Docker tag to v1.148.0 2026-02-24 16:53:10 +02:00
renovate[bot]
5aef8e8b2f Update Rust crate tempfile to 3.26.* 2026-02-24 08:21:45 +02:00
renovate[bot]
f70f20181e Update Rust crate chrono to v0.4.44 2026-02-24 08:16:54 +02:00
renovate[bot]
fcdd4f39ee Update docker.io/ollama/ollama Docker tag to v0.17.0 2026-02-24 08:16:31 +02:00
renovate[bot]
891adfec49 Update Rust crate anyhow to v1.0.102 2026-02-20 08:49:48 +02:00
renovate[bot]
35ab79844b Update docker.io/ollama/ollama Docker tag to v0.16.3 2026-02-20 08:49:37 +02:00
Slavi Pantaleev
bbc122fbb1 Release 1.14.3
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 06:37:11 +02:00
renovate[bot]
2413c8b88b Update actions/checkout action to v6 2026-02-18 06:31:39 +02:00
renovate[bot]
10c3c64469 Update Rust crate async-openai to 0.33.0 2026-02-18 06:25:58 +02:00
renovate[bot]
b3307b404b Update docker.io/rust Docker tag to v1.93.1 2026-02-18 06:25:48 +02:00
Slavi Pantaleev
7a0d1e830d Add Renovate configuration for automated dependency updates
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 06:06:02 +02:00
Slavi Pantaleev
b3bd241823 Release 1.14.2
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 05:53:46 +02:00
Slavi Pantaleev
de3d8b054f Update dependencies 2026-02-18 05:44:41 +02:00
Slavi Pantaleev
0a55e276a2 Update dependencies 2026-02-18 05:40:25 +02:00
Slavi Pantaleev
1f2c65d2e6 Refactor dev services to support homeserver choice (Continuwuity or Synapse)
The dev environment previously hardcoded Synapse (bundled with Postgres
and Element Web) in a monolithic etc/services/core/ directory.

With Continuwuity now available as a lighter alternative (no external DB),
this refactors the service layout so developers choose their homeserver
once and everything derives from that choice. Continuwuity is the new
default for its smaller footprint.

Key changes:
- Break etc/services/core/ into etc/services/synapse/ and
  etc/services/element-web/, each with their own compose.yml
- Add `homeserver` variable in justfile (reads var/homeserver,
  defaults to continuwuity)
- Add `homeserver-init` recipe to persist the choice
- Use placeholders (__HOMESERVER_SERVER_NAME__, __HOMESERVER_URL__,
  __HOMESERVER_CLIENT_URL__) in config templates, resolved at
  prepare time based on the chosen homeserver
- Make services-start/stop/prepare/tail-logs delegate to the chosen
  homeserver's recipes + element-web
- Make users-prepare delegate to {homeserver}-users-prepare
- Update docs/development.md for the new homeserver choice flow

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 05:28:32 +02:00
Slavi Pantaleev
3b5e4745f2 Add optional Continuwuity homeserver service for development/testing
Adds Continuwuity as an alternative to Synapse for local development,
useful for testing baibot compatibility with different homeserver
implementations. Follows the same optional service pattern as localai/ollama.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 04:47:22 +02:00
27 changed files with 792 additions and 283 deletions

View File

@@ -16,7 +16,7 @@ jobs:
name: Unit testing and linting
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: dtolnay/rust-toolchain@stable
- name: Install SQLite3
run: sudo apt-get update && sudo apt-get install -y libsqlite3-dev
@@ -56,9 +56,9 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v6
- name: Log in to the GitHub Container registry
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}
@@ -95,7 +95,7 @@ jobs:
steps:
- name: Log in to the GitHub Container registry
uses: docker/login-action@v3
uses: docker/login-action@v4
with:
registry: ghcr.io
username: ${{ github.actor }}

View File

@@ -1,3 +1,17 @@
# (2026-02-18) Version 1.14.3
- (**Internal Improvement**) Add [Renovate](https://docs.renovatebot.com/) configuration for automated dependency updates
- (**Internal Improvement**) Dependency updates
# (2026-02-18) Version 1.14.2
- (**Internal Improvement**) Dependency updates
- (**Internal Improvement**) Reorganize the development environment to support [Continuwuity](https://continuwuity.org/) as a homeserver choice (in addition to [Synapse](https://github.com/element-hq/synapse)). Continuwuity is now the default for its lighter footprint (no external database required). See [development docs](./docs/development.md) for details.
# (2026-02-10) Version 1.14.1
- (**Security**) Dependency updates to fix security vulnerabilities ([time](https://crates.io/crates/time) stack exhaustion DoS, [bytes](https://crates.io/crates/bytes) integer overflow), via [mxlink](https://crates.io/crates/mxlink) 1.12.0

388
Cargo.lock generated

File diff suppressed because it is too large Load Diff

View File

@@ -7,7 +7,7 @@ license = "AGPL-3.0-or-later"
readme = "README.md"
keywords = ["matrix", "chat", "bot", "AI", "LLM"]
include = ["/etc/assets/baibot-torso-768.png", "/src", "/README.md", "/CHANGELOG.md", "/LICENSE"]
version = "1.14.1"
version = "1.14.3"
edition = "2024"
[lib]
@@ -17,7 +17,7 @@ path = "src/lib.rs"
[dependencies]
anthropic = { git = "https://github.com/etkecc/anthropic-rs.git", branch = "fix-content-block-image" }
anyhow = "1.0.*"
async-openai = { version = "0.32.4", features = ["audio", "chat-completion", "image", "responses"] }
async-openai = { version = "0.33.0", features = ["audio", "chat-completion", "image", "responses"] }
base64 = "0.22.*"
chrono = { version = "0.4.*", default-features = false, features = ["std", "now"] }
# We'd rather not depend on this, but we cannot use the ruma-events EventContent macro without it.
@@ -25,16 +25,16 @@ chrono = { version = "0.4.*", default-features = false, features = ["std", "now"
matrix-sdk = { version = "0.16.0", default-features = false, features = ["native-tls"] }
mime_guess = "2.0.*"
mxidwc = "1.0.*"
mxlink = ">=1.12.0"
mxlink = ">=1.13.0"
etke_openai_api_rust = "0.1.*"
quick_cache = "0.6.*"
regex = "1.12.*"
serde = { version = "1.0.*", features = ["derive"], default-features = false }
serde_json = "1.0.*"
serde_yaml_ng = "0.10.*"
tempfile = "3.25.*"
tempfile = "3.26.*"
tiktoken-rs = { version = "0.9.*", default-features = false }
tokio = { version = "1.49.*", features = ["rt", "rt-multi-thread", "macros"] }
tokio = { version = "1.50.*", features = ["rt", "rt-multi-thread", "macros"] }
tracing = "0.1.*"
tracing-subscriber = { version = "0.3.*", features = ["env-filter"] }
url = "2.5.*"

View File

@@ -4,7 +4,7 @@
# #
#######################################
FROM docker.io/rust:1.93.0-slim-trixie AS build
FROM docker.io/rust:1.93.1-slim-trixie AS build
RUN apt-get update && apt-get install -y build-essential pkg-config libssl-dev libsqlite3-dev

View File

@@ -4,7 +4,7 @@
# #
#######################################
FROM docker.io/rust:1.93.0-slim-trixie AS build
FROM docker.io/rust:1.93.1-slim-trixie AS build
RUN apt-get update && apt-get install -y build-essential pkg-config libssl-dev libsqlite3-dev

View File

@@ -18,6 +18,27 @@ For local development, we run all dependency services in [🐋 Docker](https://w
- (Optional) an API key for some Large Language Model [☁️ provider](./providers.md) (e.g. [OpenAI](./providers.md#openai)), though we recommend using [LocalAI](#localai) or [Ollama](#ollama) for local development
### Choosing a homeserver
The development environment supports two homeserver implementations:
- **[Continuwuity](https://continuwuity.org/)** (default) — lightweight, no external database required. Good for most development needs.
- **[Synapse](https://github.com/element-hq/synapse)** — the reference implementation, bundled with Postgres. Use this if you need Synapse-specific behavior.
To choose a homeserver (optional — defaults to Continuwuity if skipped):
```sh
just homeserver-init continuwuity # or: just homeserver-init synapse
```
The choice is stored in `var/homeserver` and affects all subsequent commands.
> **Note:** If you switch homeservers after initial setup, you will need to:
> - Delete `var/app/local/` and/or `var/app/container/` (app config and data)
> - Delete `var/services/element-web/` (to regenerate its config)
> - Re-run the prepare and user registration steps
### Getting started guide
Developing [locally](#running-locally) is possible, but requires a [Rust](https://www.rust-lang.org/) toolchain.
@@ -28,11 +49,12 @@ In any case, you will need [🐋 Docker](https://www.docker.com/) as [dependency
#### Running locally
1. Start the core dependency services (Postgres, Synapse, Element Web): `just services-start`
2. (Only the first time around) Prepare initial app configuration in `var/app/local/config.yml`: `just app-local-prepare`
3. (Only the first time around) [Prepare your configuration file](#prepare-your-configuration-file)
4. (Only the first time around) Prepare initial default Matrix user accounts (`admin` and `baibot`): `just users-prepare`
5. (Optional) Start additional services depending on which [agent provider you've chosen](#choosing-an-agent-provider):
1. (Optional) Choose a homeserver: `just homeserver-init continuwuity` (or `synapse`). Default is `continuwuity`.
2. Start the homeserver and Element Web: `just services-start`
3. (Only the first time around) Prepare initial app configuration in `var/app/local/config.yml`: `just app-local-prepare`
4. (Only the first time around) [Prepare your configuration file](#prepare-your-configuration-file)
5. (Only the first time around) Prepare initial default Matrix user accounts (`admin` and `baibot`): `just users-prepare`
6. (Optional) Start additional services depending on which [agent provider you've chosen](#choosing-an-agent-provider):
- for [LocalAI](#localai):
- Start services: `just localai-start`
- Wait a while for LocalAI to start up. It has a lot of models to download. Monitor progress using `just localai-tail-logs`
@@ -40,12 +62,12 @@ In any case, you will need [🐋 Docker](https://www.docker.com/) as [dependency
- for [Ollama](#ollama):
- Start services: `just ollama-start`
- (Only the first time around) Pull the model configured in `agents.static_definitions` in the configuration file: `just ollama-pull-model gemma2:2b`
6. Start the bot: `just run-locally`
7. Go to http://element.127.0.0.1.nip.io:42025/ and login with `admin` / `admin`
8. Create a new room and invite `@baibot:synapse.127.0.0.1.nip.io`
9. When done, stop the bot (`Ctrl` + `C`)
10. Stop the core dependency services: `just services-stop`
11. (Optional) Stop additional services:
7. Start the bot: `just run-locally`
8. Go to http://element.127.0.0.1.nip.io:42025/ and login with `admin` / `admin`
9. Create a new room and invite `@baibot:continuwuity.127.0.0.1.nip.io` (or `@baibot:synapse.127.0.0.1.nip.io` if using Synapse)
10. When done, stop the bot (`Ctrl` + `C`)
11. Stop the services: `just services-stop`
12. (Optional) Stop additional services:
- for [LocalAI](#localai): `just localai-stop`
- for [Ollama](#ollama): `just ollama-stop`
@@ -54,11 +76,12 @@ In any case, you will need [🐋 Docker](https://www.docker.com/) as [dependency
You can avoid having a [Rust](https://www.rust-lang.org/) toolchain installed locally and build/run this in a container.
1. Start the core dependency services (Postgres, Synapse, Element Web): `just services-start`
2. (Only the first time around) Prepare initial app configuration in `var/app/container/config.yml`: `just app-container-prepare`
3. (Only the first time around) [Prepare your configuration file](#prepare-your-configuration-file)
4. (Only the first time around) Prepare initial default Matrix user accounts (`admin` and `baibot`): `just users-prepare`
5. (Optional) Start additional services depending on which [agent provider you've chosen](#choosing-an-agent-provider):
1. (Optional) Choose a homeserver: `just homeserver-init continuwuity` (or `synapse`). Default is `continuwuity`.
2. Start the homeserver and Element Web: `just services-start`
3. (Only the first time around) Prepare initial app configuration in `var/app/container/config.yml`: `just app-container-prepare`
4. (Only the first time around) [Prepare your configuration file](#prepare-your-configuration-file)
5. (Only the first time around) Prepare initial default Matrix user accounts (`admin` and `baibot`): `just users-prepare`
6. (Optional) Start additional services depending on which [agent provider you've chosen](#choosing-an-agent-provider):
- for [LocalAI](#localai):
- Start services: `just localai-start`
- Wait a while for LocalAI to start up. It has a lot of models to download. Monitor progress using `just localai-tail-logs`
@@ -66,12 +89,12 @@ You can avoid having a [Rust](https://www.rust-lang.org/) toolchain installed lo
- for [Ollama](#ollama):
- Start services: `just ollama-start`
- (Only the first time around) Pull the model configured in `agents.static_definitions` in the configuration file: `just ollama-pull-model gemma2:2b`
6. Start the bot: `just run-in-container`
7. Go to http://element.127.0.0.1.nip.io:42025/ and login with `admin` / `admin`
8. Create a new room and invite `@baibot:synapse.127.0.0.1.nip.io`
9. When done, stop the bot (`Ctrl` + `C`)
10. Stop the dependency services: `just services-stop`
11. (Optional) Stop additional services:
7. Start the bot: `just run-in-container`
8. Go to http://element.127.0.0.1.nip.io:42025/ and login with `admin` / `admin`
9. Create a new room and invite `@baibot:continuwuity.127.0.0.1.nip.io` (or `@baibot:synapse.127.0.0.1.nip.io` if using Synapse)
10. When done, stop the bot (`Ctrl` + `C`)
11. Stop the services: `just services-stop`
12. (Optional) Stop additional services:
- for [LocalAI](#localai): `just localai-stop`
- for [Ollama](#ollama): `just ollama-stop`

View File

@@ -1,12 +1,21 @@
homeserver:
# The canonical homeserver domain name
server_name: synapse.127.0.0.1.nip.io
url: http://synapse.127.0.0.1.nip.io:42020
server_name: __HOMESERVER_SERVER_NAME__
url: __HOMESERVER_URL__
user:
mxid_localpart: baibot
# Authentication: set EITHER password OR access_token + device_id.
#
# Password-based login (traditional homeservers):
password: baibot
# Access token login (for MAS/OIDC-enabled homeservers):
# Generate a token via: mas-cli manage issue-compatibility-token <username> [device_id]
# access_token: null
# device_id: null
# The name the bot uses as a display name and when it refers to itself.
# Leave empty to use the default (baibot).
name: baibot
@@ -45,7 +54,7 @@ room:
access:
# Space-separated list of MXID patterns which specify who is an admin.
admin_patterns:
- "@admin:synapse.127.0.0.1.nip.io"
- "@admin:__HOMESERVER_SERVER_NAME__"
persistence:
# This is unset here, because we expect the configuration to come from an environment variable (BAIBOT_PERSISTENCE_DATA_DIR_PATH).
@@ -157,7 +166,7 @@ initial_global_config:
# Space-separated list of MXID patterns which specify who can use the bot.
# By default, we let anyone on the homeserver use the bot.
user_patterns:
- "@*:synapse.127.0.0.1.nip.io"
- "@*:__HOMESERVER_SERVER_NAME__"
# Controls logging.
#

View File

@@ -0,0 +1,23 @@
services:
continuwuity:
image: forgejo.ellis.link/continuwuation/continuwuity:v0.5.6
user: "${UID}:${GID}"
restart: unless-stopped
cap_drop:
- ALL
read_only: true
environment:
CONDUWUIT_CONFIG: /etc/continuwuity/continuwuity.toml
CONDUWUIT_DATABASE_PATH: /var/lib/continuwuity
ports:
- "${SERVICE_CONTINUWUITY_BIND_PORT_CLIENT_API}:6167"
volumes:
- ../../etc/services/continuwuity/config:/etc/continuwuity:ro
- ./continuwuity/data:/var/lib/continuwuity
tmpfs:
- /tmp:rw,noexec,nosuid,size=500m
networks:
default:
name: ${NETWORK_NAME}
external: true

View File

@@ -0,0 +1,19 @@
[global]
server_name = "continuwuity.127.0.0.1.nip.io"
address = "0.0.0.0"
port = 6167
database_path = "/var/lib/continuwuity"
allow_registration = true
yes_i_am_very_very_sure_i_want_an_open_registration_server_prone_to_abuse = true
new_user_displayname_suffix = ""
max_request_size = 20_000_000
allow_federation = false
trusted_servers = ["matrix.org"]
log = "info,state_res=warn,rocket=off,_=off,sled=off"

View File

@@ -0,0 +1,48 @@
#!/bin/sh
set -eu
if [ $# -ne 3 ]; then
echo "Usage: $0 <env-file> <username> <password>"
exit 1
fi
ENV_FILE="$1"
USERNAME="$2"
PASSWORD="$3"
SERVER="http://$(grep '^SERVICE_CONTINUWUITY_BIND_PORT_CLIENT_API=' "${ENV_FILE}" | cut -d= -f2)"
REGISTER_URL="${SERVER}/_matrix/client/v3/register"
echo "Registering user '${USERNAME}' on ${SERVER}..."
SESSION_RESPONSE=$(curl -s -X POST "${REGISTER_URL}" \
-H 'Content-Type: application/json' \
-d "{\"username\": \"${USERNAME}\", \"password\": \"${PASSWORD}\"}")
SESSION_ID=$(echo "${SESSION_RESPONSE}" | grep -o '"session":"[^"]*"' | head -1 | cut -d'"' -f4)
if [ -z "${SESSION_ID}" ]; then
echo "Error: Could not get session ID. Response: ${SESSION_RESPONSE}"
exit 1
fi
# Determine the required auth flow from the server response.
# The first user requires m.login.registration_token (bootstrap token from logs).
# Subsequent users use m.login.dummy (open registration).
if echo "${SESSION_RESPONSE}" | grep -q 'm.login.registration_token'; then
CONTAINER_ID=$(docker ps -q --filter name=baibot-continuwuity-continuwuity)
REG_TOKEN=$(docker logs "${CONTAINER_ID}" 2>&1 | sed 's/\x1b\[[0-9;]*m//g' | grep 'using the registration token' | grep -oP 'registration token \K[A-Za-z0-9]+' | head -1)
AUTH_BODY="{\"type\": \"m.login.registration_token\", \"token\": \"${REG_TOKEN}\", \"session\": \"${SESSION_ID}\"}"
else
AUTH_BODY="{\"type\": \"m.login.dummy\", \"session\": \"${SESSION_ID}\"}"
fi
RESULT=$(curl -s -X POST "${REGISTER_URL}" \
-H 'Content-Type: application/json' \
-d "{\"username\": \"${USERNAME}\", \"password\": \"${PASSWORD}\", \"auth\": ${AUTH_BODY}}")
if echo "${RESULT}" | grep -q '"user_id"'; then
echo "Successfully registered user: $(echo "${RESULT}" | grep -o '"user_id":"[^"]*"' | cut -d'"' -f4)"
else
echo "Registration failed. Response: ${RESULT}"
exit 1
fi

View File

@@ -0,0 +1,21 @@
services:
element-web:
image: ghcr.io/element-hq/element-web:v1.12.11
user: "${UID}:${GID}"
restart: unless-stopped
environment:
ELEMENT_WEB_PORT: 8080
ports:
- "${SERVICE_ELEMENT_WEB_BIND_PORT_HTTP}:8080"
volumes:
- ./element-web/config.json:/app/config.json:ro
tmpfs:
- /var/cache/nginx:rw,mode=777
- /var/run:rw,mode=777
- /tmp/element-web-config:rw,mode=777
- /etc/nginx/conf.d:rw,mode=777
networks:
default:
name: ${NETWORK_NAME}
external: true

View File

@@ -1,5 +1,5 @@
{
"default_hs_url": "http://synapse.127.0.0.1.nip.io:42020",
"default_hs_url": "__HOMESERVER_CLIENT_URL__",
"default_is_url": "https://vector.im",
"integrations_ui_url": "https://scalar.vector.im/",
"integrations_rest_url": "https://scalar.vector.im/api",

View File

@@ -3,6 +3,8 @@ SERVICE_SYNAPSE_BIND_PORT_FEDERATION_API=127.0.0.1:42028
SERVICE_ELEMENT_WEB_BIND_PORT_HTTP=127.0.0.1:42025
SERVICE_CONTINUWUITY_BIND_PORT_CLIENT_API=127.0.0.1:42030
SERVICE_OLLAMA_BIND_PORT_HTTP=127.0.0.1:42026
# See https://localai.io/basics/container/#all-in-one-images for the list of available images

View File

@@ -1,6 +1,6 @@
services:
ollama:
image: docker.io/ollama/ollama:0.15.4
image: docker.io/ollama/ollama:0.17.6
restart: unless-stopped
ports:
- "${SERVICE_OLLAMA_BIND_PORT_HTTP}:11434"

View File

@@ -1,6 +1,6 @@
services:
postgres:
image: docker.io/postgres:18.1-alpine
image: docker.io/postgres:18.3-alpine
user: ${UID}:${GID}
restart: unless-stopped
environment:
@@ -14,7 +14,7 @@ services:
- /etc/passwd:/etc/passwd:ro
synapse:
image: ghcr.io/element-hq/synapse:v1.146.0
image: ghcr.io/element-hq/synapse:v1.148.0
user: "${UID}:${GID}"
restart: unless-stopped
entrypoint: python
@@ -23,25 +23,9 @@ services:
- "${SERVICE_SYNAPSE_BIND_PORT_CLIENT_API}:8008"
- "${SERVICE_SYNAPSE_BIND_PORT_FEDERATION_API}:8008"
volumes:
- ../../etc/services/core/synapse/config:/config:ro
- ../../etc/services/synapse/config:/config:ro
- ./synapse/media-store:/media-store
element-web:
image: ghcr.io/element-hq/element-web:v1.12.9
user: "${UID}:${GID}"
restart: unless-stopped
environment:
ELEMENT_WEB_PORT: 8080
ports:
- "${SERVICE_ELEMENT_WEB_BIND_PORT_HTTP}:8080"
volumes:
- ../../etc/services/core/element-web/config.json:/app/config.json:ro
tmpfs:
- /var/cache/nginx:rw,mode=777
- /var/run:rw,mode=777
- /tmp/element-web-config:rw,mode=777
- /etc/nginx/conf.d:rw,mode=777
networks:
default:
name: ${NETWORK_NAME}

172
justfile
View File

@@ -2,6 +2,13 @@ project_name := "baibot"
container_image_name := "localhost/baibot"
project_container_network := "baibot"
admin_username := "admin"
admin_password := "admin"
bot_username := "baibot"
bot_password := "baibot"
homeserver := `cat var/homeserver 2>/dev/null || echo continuwuity`
mise_data_dir := env("MISE_DATA_DIR", justfile_directory() / "var/mise")
mise_trusted_config_paths := justfile_directory() / "mise.toml"
@@ -9,6 +16,19 @@ mise_trusted_config_paths := justfile_directory() / "mise.toml"
default:
@just --list --justfile {{ justfile() }}
# Selects which homeserver implementation to use (continuwuity or synapse)
homeserver-init value:
#!/bin/sh
mkdir -p {{ justfile_directory() }}/var
echo {{ value }} > {{ justfile_directory() }}/var/homeserver
echo ""
echo "⚠️ If you had already prepared your app configuration (var/app/local/config.yml or var/app/container/config.yml),"
echo " you will need to update it manually or delete it and re-run the prepare step."
echo " You should also delete var/app/local/data and/or var/app/container/data,"
echo " as old application state is not compatible across homeserver implementations."
echo ""
echo "⚠️ If Element Web was already prepared, delete var/services/element-web/ to regenerate its config."
# Builds and runs a development binary
run-locally *extra_args: app-local-prepare
RUST_BACKTRACE=1 \
@@ -68,9 +88,13 @@ docker-compose services_type *extra_args:
-p {{ project_name }}-{{ services_type }} \
{{ extra_args }}
# Runs a docker-compose command against the core services
docker-compose-core *extra_args:
just docker-compose core {{ extra_args }}
# Runs a docker-compose command against the synapse services
docker-compose-synapse *extra_args:
just docker-compose synapse {{ extra_args }}
# Runs a docker-compose command against the element-web services
docker-compose-element-web *extra_args:
just docker-compose element-web {{ extra_args }}
# Runs a docker-compose command against the localai services
docker-compose-localai *extra_args:
@@ -80,17 +104,52 @@ docker-compose-localai *extra_args:
docker-compose-ollama *extra_args:
just docker-compose ollama {{ extra_args }}
# Runs all core dependency components (in the background)
services-start: services-prepare (docker-compose-core "up" "-d")
# Runs a docker-compose command against the continuwuity services
docker-compose-continuwuity *extra_args:
just docker-compose continuwuity {{ extra_args }}
# Stops all core dependency components
services-stop: (docker-compose-core "down")
# Runs the homeserver and Element Web (in the background)
services-start: services-prepare
just -f {{ justfile_directory() }}/justfile {{ homeserver }}-start
just -f {{ justfile_directory() }}/justfile element-web-start
# Tails the logs for all running core services
services-tail-logs: (docker-compose-core "logs" "-f")
# Stops Element Web and the homeserver
services-stop:
just -f {{ justfile_directory() }}/justfile element-web-stop
just -f {{ justfile_directory() }}/justfile {{ homeserver }}-stop
# Prepares the core services for running
services-prepare: _prepare-var-services-env _prepare-var-services-postgres _prepare-var-services-synapse _prepare-container-network
# Tails the logs for the homeserver and Element Web
services-tail-logs:
just -f {{ justfile_directory() }}/justfile {{ homeserver }}-tail-logs
# Prepares the homeserver and Element Web for running
services-prepare:
just -f {{ justfile_directory() }}/justfile {{ homeserver }}-prepare
just -f {{ justfile_directory() }}/justfile element-web-prepare
# Runs Synapse (in the background)
synapse-start: synapse-prepare (docker-compose-synapse "up" "-d")
# Stops Synapse
synapse-stop: (docker-compose-synapse "down")
# Tails the logs for Synapse
synapse-tail-logs: (docker-compose-synapse "logs" "-f")
# Prepares Synapse for running
synapse-prepare: _prepare-var-services-env _prepare-var-services-postgres _prepare-var-services-synapse _prepare-container-network
# Runs Element Web (in the background)
element-web-start: element-web-prepare (docker-compose-element-web "up" "-d")
# Stops Element Web
element-web-stop: (docker-compose-element-web "down")
# Tails the logs for Element Web
element-web-tail-logs: (docker-compose-element-web "logs" "-f")
# Prepares Element Web for running
element-web-prepare: _prepare-var-services-env _prepare-var-services-element-web _prepare-container-network
# Runs LocalAI (in the background)
localai-start: localai-prepare (docker-compose-localai "up" "-d")
@@ -116,6 +175,27 @@ ollama-tail-logs: (docker-compose-ollama "logs" "-f")
# Prepares Ollama for running
ollama-prepare: _prepare-var-services-env _prepare-var-services-ollama _prepare-container-network
# Runs Continuwuity (in the background)
continuwuity-start: continuwuity-prepare (docker-compose-continuwuity "up" "-d")
# Stops Continuwuity
continuwuity-stop: (docker-compose-continuwuity "down")
# Tails the logs for Continuwuity
continuwuity-tail-logs: (docker-compose-continuwuity "logs" "-f")
# Prepares Continuwuity for running
continuwuity-prepare: _prepare-var-services-env _prepare-var-services-continuwuity _prepare-container-network
# Registers a user on Continuwuity via the Matrix Client-Server API
continuwuity-register-user username password:
{{ justfile_directory() }}/etc/services/continuwuity/register-user.sh {{ justfile_directory() }}/var/services/env {{ username }} {{ password }}
# Prepares the Continuwuity user accounts
continuwuity-users-prepare: continuwuity-prepare
just -f {{ justfile_directory() }}/justfile continuwuity-register-user "{{ admin_username }}" "{{ admin_password }}"
just -f {{ justfile_directory() }}/justfile continuwuity-register-user "{{ bot_username }}" "{{ bot_password }}"
# Pulls an Ollama model
ollama-pull-model model_id:
just -f {{ justfile_directory() }}/justfile docker-compose-ollama \
@@ -129,16 +209,20 @@ app-local-prepare: _prepare-var-app-local-config_yml _prepare-var-app-local-data
app-container-prepare: _prepare-var-app-container-config_yml _prepare-var-app-container-data
# Prepares the user accounts
users-prepare: services-prepare
just -f {{ justfile_directory() }}/justfile synapse-register-admin-user "admin" "admin"
just -f {{ justfile_directory() }}/justfile synapse-register-regular-user "baibot" "baibot"
users-prepare:
just -f {{ justfile_directory() }}/justfile {{ homeserver }}-users-prepare
# Prepares the Synapse user accounts
synapse-users-prepare: synapse-prepare
just -f {{ justfile_directory() }}/justfile synapse-register-admin-user "{{ admin_username }}" "{{ admin_password }}"
just -f {{ justfile_directory() }}/justfile synapse-register-regular-user "{{ bot_username }}" "{{ bot_password }}"
# Starts a Postgres CLI (psql)
postgres-cli: services-prepare (docker-compose-core "exec" "postgres" "/bin/sh" "-c" "'PGUSER=synapse PGPASSWORD=synapse-password PGDATABASE=homeserver psql -h postgres'")
postgres-cli: synapse-prepare (docker-compose-synapse "exec" "postgres" "/bin/sh" "-c" "'PGUSER=synapse PGPASSWORD=synapse-password PGDATABASE=homeserver psql -h postgres'")
# Creates an administrator user
synapse-register-admin-user username password: services-prepare
just -f {{ justfile_directory() }}/justfile docker-compose-core \
# Creates an administrator user on Synapse
synapse-register-admin-user username password: synapse-prepare
just -f {{ justfile_directory() }}/justfile docker-compose-synapse \
exec synapse \
register_new_matrix_user \
--admin \
@@ -147,9 +231,9 @@ synapse-register-admin-user username password: services-prepare
-c /config/homeserver.yaml \
http://localhost:8008
# Create a regular user
synapse-register-regular-user username password: services-prepare
just -f {{ justfile_directory() }}/justfile docker-compose-core \
# Creates a regular user on Synapse
synapse-register-regular-user username password: synapse-prepare
just -f {{ justfile_directory() }}/justfile docker-compose-synapse \
exec synapse \
register_new_matrix_user \
--no-admin \
@@ -229,6 +313,22 @@ _prepare-var-services-synapse:
mkdir -p var/services/synapse/media-store
fi
_prepare-var-services-element-web:
#!/bin/sh
cd {{ justfile_directory() }};
if [ ! -f var/services/element-web/config.json ]; then
mkdir -p var/services/element-web
cp {{ justfile_directory() }}/etc/services/element-web/config.json.dist var/services/element-web/config.json
homeserver="{{ homeserver }}"
if [ "$homeserver" = "continuwuity" ]; then
sed --in-place 's|__HOMESERVER_CLIENT_URL__|http://continuwuity.127.0.0.1.nip.io:42030|g' var/services/element-web/config.json
elif [ "$homeserver" = "synapse" ]; then
sed --in-place 's|__HOMESERVER_CLIENT_URL__|http://synapse.127.0.0.1.nip.io:42020|g' var/services/element-web/config.json
fi
fi
_prepare-var-services-ollama:
#!/bin/sh
cd {{ justfile_directory() }};
@@ -237,6 +337,14 @@ _prepare-var-services-ollama:
mkdir -p var/services/ollama
fi
_prepare-var-services-continuwuity:
#!/bin/sh
cd {{ justfile_directory() }};
if [ ! -f var/services/continuwuity ]; then
mkdir -p var/services/continuwuity/data
fi
_prepare-var-services-localai:
#!/bin/sh
cd {{ justfile_directory() }};
@@ -260,6 +368,15 @@ _prepare-var-app-local-config_yml:
if [ ! -f var/app/local/config.yml ]; then
mkdir -p var/app/local
cp {{ justfile_directory() }}/etc/app/config.yml.dist var/app/local/config.yml
homeserver="{{ homeserver }}"
if [ "$homeserver" = "continuwuity" ]; then
sed --in-place 's/__HOMESERVER_SERVER_NAME__/continuwuity.127.0.0.1.nip.io/g' var/app/local/config.yml
sed --in-place 's|__HOMESERVER_URL__|http://continuwuity.127.0.0.1.nip.io:42030|g' var/app/local/config.yml
elif [ "$homeserver" = "synapse" ]; then
sed --in-place 's/__HOMESERVER_SERVER_NAME__/synapse.127.0.0.1.nip.io/g' var/app/local/config.yml
sed --in-place 's|__HOMESERVER_URL__|http://synapse.127.0.0.1.nip.io:42020|g' var/app/local/config.yml
fi
fi
_prepare-var-app-local-data:
@@ -277,7 +394,18 @@ _prepare-var-app-container-config_yml:
if [ ! -f var/app/container/config.yml ]; then
mkdir -p var/app/container
cp {{ justfile_directory() }}/etc/app/config.yml.dist var/app/container/config.yml
sed --in-place 's/synapse.127.0.0.1.nip.io:42020/synapse:8008/g' var/app/container/config.yml
homeserver="{{ homeserver }}"
if [ "$homeserver" = "continuwuity" ]; then
sed --in-place 's/__HOMESERVER_SERVER_NAME__/continuwuity.127.0.0.1.nip.io/g' var/app/container/config.yml
sed --in-place 's|__HOMESERVER_URL__|http://continuwuity.127.0.0.1.nip.io:42030|g' var/app/container/config.yml
sed --in-place 's/continuwuity.127.0.0.1.nip.io:42030/continuwuity:6167/g' var/app/container/config.yml
elif [ "$homeserver" = "synapse" ]; then
sed --in-place 's/__HOMESERVER_SERVER_NAME__/synapse.127.0.0.1.nip.io/g' var/app/container/config.yml
sed --in-place 's|__HOMESERVER_URL__|http://synapse.127.0.0.1.nip.io:42020|g' var/app/container/config.yml
sed --in-place 's/synapse.127.0.0.1.nip.io:42020/synapse:8008/g' var/app/container/config.yml
fi
sed --in-place 's/127.0.0.1:42026/ollama:11434/g' var/app/container/config.yml
sed --in-place 's/127.0.0.1:42027/localai:8080/g' var/app/container/config.yml
fi

9
renovate.json Normal file
View File

@@ -0,0 +1,9 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
],
"labels": [
"dependencies"
]
}

View File

@@ -25,7 +25,7 @@ use crate::agent::Manager as AgentManager;
use crate::entity::catch_up_marker::{
CatchUpMarker, CatchUpMarkerManager, DelayedCatchUpMarkerManager,
};
use crate::entity::cfg::{Avatar, Config};
use crate::entity::cfg::{Avatar, Config, ConfigUserAuth};
use crate::entity::globalconfig::{GlobalConfig, GlobalConfigurationManager};
use crate::entity::roomconfig::{RoomConfig, RoomConfigurationManager};
@@ -395,10 +395,22 @@ async fn create_matrix_link(config: &Config) -> anyhow::Result<MatrixLink> {
let session_encryption_key = config.persistence.session_encryption_key()?;
let db_dir_path: std::path::PathBuf = config.persistence.db_dir_path()?;
let login_creds = LoginCredentials::UserPassword(
config.user.mxid_localpart.to_owned(),
config.user.password.to_owned(),
);
let user_auth = config.user.auth_config(&config.homeserver.server_name)?;
let login_creds = match user_auth {
ConfigUserAuth::UserPassword { username, password } => {
LoginCredentials::UserPassword(username, password)
}
ConfigUserAuth::AccessToken {
user_id,
device_id,
access_token,
} => LoginCredentials::AccessToken {
user_id,
device_id,
access_token,
},
};
let login_encryption = LoginEncryption::new(
config.user.encryption.recovery_passphrase.clone(),

View File

@@ -29,7 +29,15 @@ pub fn load() -> anyhow::Result<Config> {
cfg_env::BAIBOT_HOMESERVER_SERVER_NAME => config.homeserver.server_name = value,
cfg_env::BAIBOT_HOMESERVER_URL => config.homeserver.url = value,
cfg_env::BAIBOT_USER_MXID_LOCALPART => config.user.mxid_localpart = value,
cfg_env::BAIBOT_USER_PASSWORD => config.user.password = value,
cfg_env::BAIBOT_USER_PASSWORD => {
config.user.password = optional_non_empty(value);
}
cfg_env::BAIBOT_USER_ACCESS_TOKEN => {
config.user.access_token = optional_non_empty(value);
}
cfg_env::BAIBOT_USER_DEVICE_ID => {
config.user.device_id = optional_non_empty(value);
}
cfg_env::BAIBOT_USER_ENCRYPTION_RECOVERY_PASSPHRASE => {
config.user.encryption.recovery_passphrase = Some(value);
}
@@ -120,3 +128,7 @@ pub fn load() -> anyhow::Result<Config> {
Ok(config)
}
fn optional_non_empty(value: String) -> Option<String> {
if value.is_empty() { None } else { Some(value) }
}

View File

@@ -1,6 +1,7 @@
use std::path::PathBuf;
use mxlink::helpers::encryption::EncryptionKey;
use mxlink::matrix_sdk::ruma::{OwnedDeviceId, OwnedUserId};
use serde::{Deserialize, Deserializer, Serialize};
use crate::{
@@ -38,7 +39,7 @@ pub struct Config {
impl Config {
pub fn validate(&self) -> anyhow::Result<()> {
self.homeserver.validate()?;
self.user.validate()?;
self.user.validate(&self.homeserver.server_name)?;
self.persistence.validate()?;
self.room.validate()?;
self.access.validate()?;
@@ -57,6 +58,19 @@ impl Config {
}
}
#[derive(Debug)]
pub enum ConfigUserAuth {
UserPassword {
username: String,
password: String,
},
AccessToken {
user_id: OwnedUserId,
device_id: OwnedDeviceId,
access_token: String,
},
}
#[derive(Debug, Serialize, Deserialize)]
pub struct ConfigHomeserver {
pub server_name: String,
@@ -127,7 +141,15 @@ impl Avatar {
#[derive(Debug, Serialize, Deserialize)]
pub struct ConfigUser {
pub mxid_localpart: String,
pub password: String,
#[serde(default)]
pub password: Option<String>,
#[serde(default)]
pub access_token: Option<String>,
#[serde(default)]
pub device_id: Option<String>,
#[serde(default = "super::defaults::name")]
pub name: String,
@@ -140,7 +162,7 @@ pub struct ConfigUser {
}
impl ConfigUser {
pub fn validate(&self) -> anyhow::Result<()> {
pub fn validate(&self, homeserver_server_name: &str) -> anyhow::Result<()> {
if self.mxid_localpart.is_empty() {
return Err(anyhow::anyhow!(
"The user.mxid_localpart ({}) configuration must be set",
@@ -148,12 +170,7 @@ impl ConfigUser {
));
}
if self.password.is_empty() {
return Err(anyhow::anyhow!(
"The user.password ({}) configuration must be set",
super::env::BAIBOT_USER_PASSWORD
));
}
self.auth_config(homeserver_server_name)?;
if self.name.is_empty() {
return Err(anyhow::anyhow!(
@@ -166,6 +183,57 @@ impl ConfigUser {
Ok(())
}
pub fn auth_config(&self, homeserver_server_name: &str) -> anyhow::Result<ConfigUserAuth> {
let password = self.password.as_deref().filter(|value| !value.is_empty());
let access_token = self
.access_token
.as_deref()
.filter(|value| !value.is_empty());
match (password, access_token) {
(Some(_), Some(_)) => Err(anyhow::anyhow!(
"Set exactly one authentication method: either user.password ({}) OR user.access_token ({}) + user.device_id ({})",
super::env::BAIBOT_USER_PASSWORD,
super::env::BAIBOT_USER_ACCESS_TOKEN,
super::env::BAIBOT_USER_DEVICE_ID
)),
(None, None) => Err(anyhow::anyhow!(
"Set one authentication method: either user.password ({}) OR user.access_token ({}) + user.device_id ({})",
super::env::BAIBOT_USER_PASSWORD,
super::env::BAIBOT_USER_ACCESS_TOKEN,
super::env::BAIBOT_USER_DEVICE_ID
)),
(Some(password), None) => Ok(ConfigUserAuth::UserPassword {
username: self.mxid_localpart.to_owned(),
password: password.to_owned(),
}),
(None, Some(access_token)) => {
let device_id = self
.device_id
.as_deref()
.filter(|value| !value.is_empty())
.ok_or_else(|| {
anyhow::anyhow!(
"user.device_id ({}) must be set when using access token authentication",
super::env::BAIBOT_USER_DEVICE_ID
)
})?;
let user_id = OwnedUserId::try_from(format!(
"@{}:{}",
self.mxid_localpart, homeserver_server_name
))
.map_err(|e| anyhow::anyhow!("Invalid user ID: {e}"))?;
Ok(ConfigUserAuth::AccessToken {
user_id,
device_id: OwnedDeviceId::from(device_id),
access_token: access_token.to_owned(),
})
}
}
}
}
#[derive(Debug, Default, Serialize, Deserialize)]
@@ -468,3 +536,7 @@ impl TryInto<GlobalConfig> for ConfigInitialGlobalConfig {
Ok(entity)
}
}
#[cfg(test)]
#[path = "config_tests.rs"]
mod config_tests;

View File

@@ -0,0 +1,117 @@
use super::{Avatar, ConfigUser, ConfigUserAuth, ConfigUserEncryption};
use crate::entity::cfg::env;
fn base_user() -> ConfigUser {
ConfigUser {
mxid_localpart: "baibot".to_owned(),
password: None,
access_token: None,
device_id: None,
name: "baibot".to_owned(),
encryption: ConfigUserEncryption {
recovery_passphrase: None,
recovery_reset_allowed: false,
},
avatar: Avatar::Default,
}
}
#[test]
fn auth_config_uses_password_mode() {
let mut user = base_user();
user.password = Some("secret".to_owned());
let auth = user
.auth_config("example.com")
.expect("password auth should be valid");
match auth {
ConfigUserAuth::UserPassword { username, password } => {
assert_eq!(username, "baibot");
assert_eq!(password, "secret");
}
ConfigUserAuth::AccessToken { .. } => {
panic!("expected password auth mode");
}
}
}
#[test]
fn auth_config_uses_access_token_mode() {
let mut user = base_user();
user.access_token = Some("token123".to_owned());
user.device_id = Some("DEVICE1".to_owned());
let auth = user
.auth_config("example.com")
.expect("access token auth should be valid");
match auth {
ConfigUserAuth::AccessToken {
user_id,
device_id,
access_token,
} => {
assert_eq!(user_id.as_str(), "@baibot:example.com");
assert_eq!(device_id.as_str(), "DEVICE1");
assert_eq!(access_token, "token123");
}
ConfigUserAuth::UserPassword { .. } => {
panic!("expected access token auth mode");
}
}
}
#[test]
fn auth_config_rejects_both_auth_methods() {
let mut user = base_user();
user.password = Some("secret".to_owned());
user.access_token = Some("token123".to_owned());
user.device_id = Some("DEVICE1".to_owned());
let err = user
.auth_config("example.com")
.expect_err("both auth methods should be rejected");
assert!(
err.to_string()
.contains("exactly one authentication method")
);
}
#[test]
fn auth_config_rejects_missing_auth() {
let user = base_user();
let err = user
.auth_config("example.com")
.expect_err("missing auth should be rejected");
assert!(err.to_string().contains("Set one authentication method"));
}
#[test]
fn auth_config_rejects_access_token_without_device_id() {
let mut user = base_user();
user.access_token = Some("token123".to_owned());
let err = user
.auth_config("example.com")
.expect_err("access token mode without device_id should be rejected");
assert!(err.to_string().contains(env::BAIBOT_USER_DEVICE_ID));
}
#[test]
fn auth_config_treats_empty_strings_as_unset() {
let mut user = base_user();
user.password = Some(String::new());
user.access_token = Some(String::new());
user.device_id = Some(String::new());
let err = user
.auth_config("example.com")
.expect_err("empty auth values should be treated as unset");
assert!(err.to_string().contains("Set one authentication method"));
}

View File

@@ -5,6 +5,8 @@ pub const BAIBOT_HOMESERVER_URL: &str = "BAIBOT_HOMESERVER_URL";
pub const BAIBOT_USER_MXID_LOCALPART: &str = "BAIBOT_USER_MXID_LOCALPART";
pub const BAIBOT_USER_PASSWORD: &str = "BAIBOT_USER_PASSWORD";
pub const BAIBOT_USER_ACCESS_TOKEN: &str = "BAIBOT_USER_ACCESS_TOKEN";
pub const BAIBOT_USER_DEVICE_ID: &str = "BAIBOT_USER_DEVICE_ID";
pub const BAIBOT_USER_NAME: &str = "BAIBOT_USER_NAME";
pub const BAIBOT_USER_AVATAR: &str = "BAIBOT_USER_AVATAR";
pub const BAIBOT_USER_ENCRYPTION_RECOVERY_PASSPHRASE: &str =

View File

@@ -2,4 +2,4 @@ mod config;
pub mod defaults;
pub mod env;
pub use config::{Avatar, Config};
pub use config::{Avatar, Config, ConfigUserAuth};