Files
Sterister 3243647aa1
Some checks failed
Test / test (push) Has been cancelled
Docker build and publish / docker (push) Has been cancelled
Publish / publish (push) Has been cancelled
release(v4.11.1): ship pre-built dist/ to npm registry
publish-all.ts now does a tsc → dist/ build per package before pack, then
rewrites package.json's main/types/exports to point at the built artefacts
and ensures `files: ["dist"]` so the tarball ships only the built code.
The in-repo package.json is restored in the finally block so dev/typecheck
keep working without a build pass.

Why: strict-mode consumers (Cyndr) were forced to recompile Shade source
under their own tsconfig and tripped on internal `process.env.X` accesses
and implicit-any parameters. Shipping pre-built `.js` + `.d.ts` makes the
strictness contract live entirely inside Shade.
2026-05-21 13:29:52 +02:00
..

@shade/observer

Live observability backend for Shade — exposes a snapshot endpoint, an SSE event stream, and serves the bundled dashboard SPA.

Install

bun add @shade/observer @shade/server @shade/core

Usage

import { createObserver } from '@shade/observer';
import { ShadeEventEmitter, ShadeSessionManager } from '@shade/core';
import { PrekeyServerEvents, createPrekeyServer } from '@shade/server';

// 1. Create event emitters
const clientEvents = new ShadeEventEmitter();
const serverEvents = new PrekeyServerEvents();

// 2. Wire them into your session manager and prekey server
const manager = new ShadeSessionManager(crypto, storage, { events: clientEvents });
const prekeyServer = createPrekeyServer({ crypto, events: serverEvents });

// 3. Create the observer
const observer = createObserver({
  token: process.env.SHADE_OBSERVER_TOKEN!,
  clientEvents,
  serverEvents,
});

// 4. Mount or serve standalone
import { Hono } from 'hono';
const app = new Hono();
app.route('/shade-observer', observer);

Bun.serve({ port: 3900, fetch: app.fetch });

After this, visit http://localhost:3900/shade-observer/dashboard/ and enter your bearer token to see the dashboard.

Endpoints

Method Path Auth Description
GET /api/state Bearer Current snapshot (identity, sessions, prekeys, server stats)
GET /api/events Bearer (or ?token=) SSE stream of live events
GET /dashboard/ None Bundled web UI
GET /health None Liveness check

Configuration

Env var Required Description
SHADE_OBSERVER_TOKEN Yes Bearer token (min 16 chars). Refuses to start if shorter.

The token is checked with constant-time comparison.

Security notes

  • Event payloads contain NO key material, plaintext, or signatures — only structural facts (counters, addresses, short hashes for display).
  • The observer is intended for internal/debugging use. Put it behind a reverse proxy and authenticate access.
  • The dashboard stores the bearer token in localStorage for convenience. Don't load the dashboard on shared computers.