This repository has no description
flarebot docs agent-settings.md
5.6 kB

Agent settings #

/settings uses Octane and the pinned public Kumo components. One mounted native owner connection serves model settings, custom instructions, memory, tool availability and installation details. Public SSR contains no saved owner data.

The provider and model choices come from getModelCatalog; getModelSettings returns only the selected configuration and Anthropic credential presence. Workers AI needs no provider key. Selecting Anthropic in the editor requires a saved key before the UI enables Save model. Saving changes future turns, including scheduled tasks; it does not change a turn already running.

The password field calls the existing setProviderKey callable to save, replace or remove the encrypted Anthropic key. The key exists only in the mounted input state and authenticated RPC request, never in URLs, browser storage, generic agent state, public HTML or readback responses. Inputs clear after successful or failed key mutations, connection loss, and navigation. Retrying a failed key update requires re-entry. Configured means stored, not validated; Settings does not contact a paid provider to test credentials. Removing the selected provider's key can stop future turns until the user adds a key or saves a Workers AI model.

A transient disconnection disables writes and offers Reconnect. Unsaved model, instruction and memory drafts survive that reconnect; current saved settings and memories reload without replacing those drafts. Memory edits retain their original version so stale writes still fail the existing concurrency check. Async replies from a retired connection or mount cannot update the current editor. Native session expiry (close code 4001) and denied authentication preflight remove all private Settings panels and drafts, including installation information.

getRuntimeInfo is an authenticated, explicitly constructed DTO containing only application version, installation ID, effective runtime/control-plane origins and curated tool descriptors. Application version is embedded from package.json when the Worker is built. It is not the release manifest's git revision, deployed release identity, update availability or a migration version. Those installation and upgrade workflows are tracked separately.

Memory, URL reading and scheduling are included. Browser-backed search/reading and shell report configuration presence only, not remote entitlement, service health or container startup. Settings performs no health probes. Reserved Worker Loader functionality is not advertised as an available tool.

Validation uses the packaged Worker and Chromium in pnpm test:settings: real model and key RPC saves/reloads, native validation failures, secret readback and SSR exclusions, descriptor allowlist, reconnect/draft and expiry behavior, stale replies after navigation, existing instructions/memory CRUD, and 375px layout and 14px content checks.

Diagnostics uses the Settings owner connection to download a bounded JSON support file for the runtime and optionally one existing conversation. The selector can show conversation names; the file excludes them and all conversation/tool content and secrets. Scope, retention, unavailable usage/cost and incomplete outcomes are visible before download. See Agent diagnostics.

Settings reads now use the app's in-memory TanStack Query cache. Each resource has a separate reusable hook in src/runtime/queries/: instructions, model catalog, model settings, memories, runtime info and domain info. The seventh hook, conversations, is shared with the shell and diagnostics; its RPC uses the shell connection. Diagnostics downloads remain explicit Settings RPC actions. The existing native model read immediately before sending a conversation turn is unchanged.

CustomerQueryProvider lives above the router. Keys include the runtime origin and a random, nonsecret owner-session scope established by authenticated native preflight. Scope survives navigation and ordinary reconnects. SSR creates a request-local empty client, runs no private queries and dehydrates nothing. There is no query persistence in browser storage. A denied preflight, native 4001 expiry or denied domain read retires connected owners, clears query and mutation caches, and remounts Settings editors with no private data. Old RPCs cannot update that new scope. Tasks participate in this auth notification while retaining their existing read/command controller.

Reads are fresh for 30 seconds (the model catalog for the session), with a five-minute inactive cache lifetime and no automatic read retries. Query owns stale window/tab focus refresh. Explicit Settings reconnect forces all Settings reads, including the catalog; native reconnection owns socket readiness. Returning within the freshness window shows cached panels while preflight is pending, with writes disabled, and does not repeat the five Settings read RPCs or the domain HTTP read. A stale return refreshes behind the existing content. Transient read failures preserve saved values and offer explicit retry.

Instruction, model and memory writes use mutations with no retries or offline replay, rechecking the current native connection before sending. Conflicting reads are cancelled and confirmed responses update their resource cache directly. Dirty drafts remain independent; memory edits retain the original version through refresh so concurrent edits still produce the native conflict. Provider keys stay on an explicit RPC action path outside Query variables and data. Their inputs still clear on every attempt, disconnect and navigation.