Ken 5ba367af2f fix: code review fixes — auth gap, path traversal, dead code, health-check timeout
- backend/app.py: add Depends(_require_auth) to /api/copilotkit endpoint (critical
  security fix — endpoint was fully unprotected; now requires valid session cookie)
- backend/app.py: move 'from ag_ui.core import RunStartedEvent' from inline function
  body to top-level imports (style consistency)
- backend/auth.py: remove dead AUTH_PASS_HASH module-level constant (verify_password
  already reads from os.environ at call time; the cached binding was unused dead code)
- backend/artifacts.py: add path traversal guards to list_artifacts, get_artifact,
  and save_artifact — resolve paths and verify they stay within ARTIFACTS_DIR
- entrypoint.sh: health-check loop now sets READY flag and exits 1 if amplifierd
  fails to start within 30s (previously fell through silently, causing 502s)
- tests/test_app.py: add TestCopilotKitAuth — verifies unauthenticated requests to
  /api/copilotkit return 401; includes note explaining why streaming is not tested here
- tests/test_structure.sh: update to reflect that Dockerfile and entrypoint.sh now
  exist (created in Tasks 7+8); convert absent-checks to presence-checks

Co-authored-by: Amplifier <amplifier@anthropic.com>
2026-05-26 18:52:12 +00:00

Research Workbench

AI-powered research tool: chat + live browser + artifacts. Backed by amplifierd.

See DESIGN.md for the full architecture.

Quick Start

# Build
docker build -t research-workbench .

# Run
docker run -d --name research-workbench \
  -p 8080:8080 \
  -p 6080:6080 \
  -e ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY" \
  research-workbench

research.ampbox.io -- the app vnc.ampbox.io -- the live browser

S
Description
Research Workbench
Readme 406 KiB
Languages
TypeScript 51.6%
Python 24.2%
Shell 17.8%
HTML 2.7%
CSS 2%
Other 1.7%