Files
Shade/packages/shade-observer
Sterister 8c606ad498
Some checks failed
Test / test (push) Has been cancelled
release(v4.8.2): per-from receive serialization + per-connection bridge dedup
Two interlocking robustness fixes for the duplicate-fan-out / first-contact
class of failures Prism reported.

1. `Shade.receive(from, env)` now queues its `manager.decrypt` step
   per `from` so concurrent dispatches can't race the SessionManager
   ratchet or the StorageProvider (sqlite "database is locked", IDB
   transaction conflicts). User message handlers run *outside* the
   queue so streams + file-RPC's nested `shade.receive` calls don't
   self-deadlock.

2. Bridge WS + SSE handlers now run a per-connection bounded msgId
   LRU as defense-in-depth against any flushTo re-entry (event-storm,
   future refactor). Pending-flush chains are wrapped in `.catch(() =>
   {})` so a transient `ws.send` rejection no longer poisons the
   connection's flush loop.

Tests: storming `inbox.blob_stored` 10× per PUT yields exactly one WS/
SSE frame; 8 concurrent `bob.receive('alice', envelope)` calls keep
the ratchet intact and never surface "database is locked".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-08 12:13:46 +02:00
..

@shade/observer

Live observability backend for Shade — exposes a snapshot endpoint, an SSE event stream, and serves the bundled dashboard SPA.

Install

bun add @shade/observer @shade/server @shade/core

Usage

import { createObserver } from '@shade/observer';
import { ShadeEventEmitter, ShadeSessionManager } from '@shade/core';
import { PrekeyServerEvents, createPrekeyServer } from '@shade/server';

// 1. Create event emitters
const clientEvents = new ShadeEventEmitter();
const serverEvents = new PrekeyServerEvents();

// 2. Wire them into your session manager and prekey server
const manager = new ShadeSessionManager(crypto, storage, { events: clientEvents });
const prekeyServer = createPrekeyServer({ crypto, events: serverEvents });

// 3. Create the observer
const observer = createObserver({
  token: process.env.SHADE_OBSERVER_TOKEN!,
  clientEvents,
  serverEvents,
});

// 4. Mount or serve standalone
import { Hono } from 'hono';
const app = new Hono();
app.route('/shade-observer', observer);

Bun.serve({ port: 3900, fetch: app.fetch });

After this, visit http://localhost:3900/shade-observer/dashboard/ and enter your bearer token to see the dashboard.

Endpoints

Method Path Auth Description
GET /api/state Bearer Current snapshot (identity, sessions, prekeys, server stats)
GET /api/events Bearer (or ?token=) SSE stream of live events
GET /dashboard/ None Bundled web UI
GET /health None Liveness check

Configuration

Env var Required Description
SHADE_OBSERVER_TOKEN Yes Bearer token (min 16 chars). Refuses to start if shorter.

The token is checked with constant-time comparison.

Security notes

  • Event payloads contain NO key material, plaintext, or signatures — only structural facts (counters, addresses, short hashes for display).
  • The observer is intended for internal/debugging use. Put it behind a reverse proxy and authenticate access.
  • The dashboard stores the bearer token in localStorage for convenience. Don't load the dashboard on shared computers.