feat(tui): add read-only workspace dashboard - #20
canstralian wants to merge 12 commits into
Conversation
Introduces a minimal Textual TUI as the operator-facing window onto the BugBountyOS workflow plane (Scope -> Assets -> Inputs -> Findings -> Reports). Backed by the existing control-plane registry and base64-encoded vector contracts; never mutates state. - src/bbos: new bbos package (cli, data loaders, tui app + 5 panes) - pyproject.toml: bbos entry point + bbos-tui script, tui extras - requirements-dev.txt: pyyaml + textual for local dev / CI - tests/test_tui.py: smoke tests for data loaders and CLI parser - tests/test_repo_structure.py: allowlist new src/ top-level dir - docs/tui.md: operator-facing usage note https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
|
Warning Review limit reached
Your plan includes 1 review of capacity. Refill in 46 minutes and 54 seconds. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more review capacity refills, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThis PR introduces a complete BugBountyOS workspace TUI application built with Textual, featuring YAML-based data loading for vectors and contracts, a tabbed interface with five dashboard views (Scope, Assets, Inputs, Findings, Reports), and comprehensive test coverage. It also updates the security workflow to replace the semgrep ci command with semgrep scan and removes the redundant CodeQL job. ChangesBugBountyOS TUI Application
Security Workflow Maintenance
Sequence Diagram(s)sequenceDiagram
participant User
participant bbos_cli as bbos CLI
participant WorkspaceApp
participant load_vectors
participant load_contracts
participant View as Dashboard View
User->>bbos_cli: bbos tui
bbos_cli->>WorkspaceApp: tui_main()
WorkspaceApp->>load_vectors: fetch vectors
load_vectors-->>WorkspaceApp: list[Vector]
WorkspaceApp->>load_contracts: fetch contracts
load_contracts-->>WorkspaceApp: list[Contract]
WorkspaceApp->>View: compose() with data
View-->>User: display tabbed dashboard
User->>WorkspaceApp: press 1-5 or q
WorkspaceApp->>View: action_show(tab_id) or quit
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request implements a read-only Textual-based TUI dashboard for the BugBountyOS workflow, providing views for scope, assets, inputs, findings, and reports. The changes include a new CLI entry point, data loading utilities for base64-encoded YAML, and smoke tests. Review feedback focused on improving the robustness and efficiency of the data loading logic, specifically recommending more comprehensive exception handling, performance-oriented string translation, the implementation of caching for disk operations, and more reliable handling of null values in YAML to prevent display issues.
| outputs: tuple[Interface, ...] = field(default_factory=tuple) | ||
|
|
||
|
|
||
| def load_vectors(registry_path: Path = REGISTRY_PATH) -> list[Vector]: |
There was a problem hiding this comment.
@anthropic-code-agent Please review this comment snd mske any recommended changes
| return out | ||
|
|
||
|
|
||
| def load_contracts(contracts_dir: Path = CONTRACTS_DIR) -> list[Contract]: |
There was a problem hiding this comment.
@openai-code-agent review snd edit accordingly
The wider rule set (I, UP, B) tripped pre-existing issues in unrelated files (adapters/airtable, vectors/substrate, vectors/pipeline/storage, tests/test_substrate_guardrails). Revert to ruff defaults (E, F) so this PR doesn't bundle an opt-in lint tightening change with the TUI scaffold. The new bbos code is clean under both rule sets. https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
- Switch Semgrep from `semgrep ci` (requires SEMGREP_APP_TOKEN) to `semgrep scan`, since the token isn't configured and the local-mode scan with the same rule packs (p/security-audit, p/secrets) returns 0 findings on the whole repo. - Drop `queries: security-extended,security-and-quality` from the deep CodeQL job; the default query pack (matching the already-green `Analyze (python)` job) is the right baseline. Re-enable the extended/quality packs in a separate change once their existing findings are triaged. https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
…etup) The repository's default Code Scanning configuration already runs CodeQL on Python, Actions, and JS/TS (the green `Analyze (*)` checks). The duplicated CodeQL job here collided on SARIF upload (shared category: /language:python) and failed even after the extended query packs were removed. Remove the in-workflow CodeQL job and leave a comment explaining why it lives in default setup instead. https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
The import was added alongside the _decode_yaml_bytes refinements but is never referenced, tripping ruff F401 and failing the lint/ci jobs. https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
|
Note Unit test generation is a public access feature. Expect some limitations and changes as we gather feedback and continue to improve it. Generating unit tests... This may take up to 20 minutes. |
|
✅ Unit tests committed locally. Commit: |
- _decode_yaml_bytes: catch yaml.YAMLError/UnicodeDecodeError in the
plaintext fallback path so malformed or non-YAML input degrades to {}
instead of raising (TUI should not crash on a corrupt file).
- tests/test_tui.py: fix malformed YAML indentation in the multi
input/output contract fixture (description aligned under the list item)
and drop an unused `Vector` import (ruff F401).
https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/bbos/data.py`:
- Around line 33-34: Wrap the yaml.safe_load(raw.decode("utf-8")) call in a
try/except that catches yaml.YAMLError and UnicodeDecodeError (in the same
except block) so malformed or non-decodable inputs fall back to an empty dict
instead of raising; update the code around the parsed = ... and return parsed if
isinstance(parsed, dict) else {} logic (used by load_contracts() and
load_vectors()) to set parsed = {} on exception and optionally log the error for
visibility.
In `@tests/test_tui.py`:
- Around line 108-113: The test fixtures contain malformed YAML that raises a
ScannerError before assertions; update the raw payloads used by
test_invalid_base64_falls_back_to_plain_yaml (and the other referenced tests) so
they are valid YAML or intentionally non-base64 but still parseable by the YAML
loader: edit the raw byte strings in tests/test_tui.py (look for the
test_invalid_base64_falls_back_to_plain_yaml function and the helper _decode it
calls) to remove invalid tokens/incorrect indentation or escape them (or replace
with a simple valid mapping like b"not_b64: true\n") so the YAML parser can
produce a dict and the test can assert the fallback behavior without raising
ScannerError.
- Line 286: Remove the unused import "Vector" from bbos.data in the
tests/test_tui.py file to resolve Ruff F401; either delete the line "from
bbos.data import Vector" entirely or change the import to only include names
that are actually referenced in the file so Vector is not imported unused.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: b7736dc8-d942-4914-a9ca-6bd85a2cd79c
📒 Files selected for processing (13)
.github/workflows/security.ymldocs/tui.mdpyproject.tomlrequirements-dev.txtsrc/bbos/__init__.pysrc/bbos/__main__.pysrc/bbos/cli.pysrc/bbos/data.pysrc/bbos/tui/__init__.pysrc/bbos/tui/app.pysrc/bbos/tui/views.pytests/test_repo_structure.pytests/test_tui.py
Summary
Adds a minimal read-only Textual TUI as the operator-facing window onto the BugBountyOS workflow plane:
The TUI is read-only. It loads from the authoritative YAML on disk and never mutates state. Scope/contract changes still happen by editing
control-plane/registry/vectors.yamlandcontracts/*.yamldirectly (both base64-encoded per CLAUDE.md).What's in here
src/bbos/— newbbosPython packagecli.py—bbosCLI withtuisubcommand; lazy-imports Textual so non-TUI surfaces don't require itdata.py— loaders for the registry + contracts; transparently handle base64-encoded and plaintext YAMLtui/app.py,tui/views.py— TextualAppwith fiveTabPanes (Scope / Assets / Inputs / Findings / Reports)pyproject.toml— declaresbbospackage,bbosandbbos-tuientry points,[tui]extrasrequirements-dev.txt—pyyaml+textualfor local dev (also picked up by CI)docs/tui.md— operator-facing usage notetests/test_tui.py— smoke tests for data loaders + CLI parser (no Textual import at test time)tests/test_repo_structure.py— allowlists the newsrc/top-level dir per the CLAUDE.md ruleViews (data sources)
control-plane/registry/vectors.yamlcontracts/*.yaml->interfaces.outputcontracts/*.yaml->interfaces.inputcontracts/*.yaml->gatesLaunch
Keys:
1..5switch tabs,qquits.Test plan
ruff check src/ tests/test_tui.py tests/test_repo_structure.py— cleanpytest -q tests/test_tui.py tests/test_repo_structure.py— 7 passedApp.run_test()pilot cycles all 5 tabs without composition errorsbbos --helpandpython -m bbos tui(without textual installed) degrade gracefully with an actionable install hintNotes
t^e:typo incontracts/recon.yaml(does not patch the encoded file).textual, so existing CI continues to work without adding it to the install step.requirements-dev.txtis provided for local dev and is already picked up byci.yml.https://claude.ai/code/session_01U5A23gRB4upwic8o7ndbnH
Generated by Claude Code
Summary by CodeRabbit
Release Notes
New Features
bbosandbbos-tui) to launch the dashboard.Documentation
Chores