2026-03-06 18:35:58 +00:00
|
|
|
package recipe
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"bytes"
|
|
|
|
|
"fmt"
|
|
|
|
|
"os"
|
|
|
|
|
"regexp"
|
|
|
|
|
"strings"
|
|
|
|
|
"text/template"
|
|
|
|
|
|
|
|
|
|
"gopkg.in/yaml.v3"
|
|
|
|
|
)
|
|
|
|
|
|
2026-03-07 17:11:13 +00:00
|
|
|
// Global safe read-only whitelist
|
|
|
|
|
var safeReadOnlyCommands = map[string]bool{
|
|
|
|
|
"ls": true,
|
|
|
|
|
"pwd": true,
|
|
|
|
|
"cat": true,
|
|
|
|
|
"tree": true,
|
|
|
|
|
"git status": true,
|
|
|
|
|
"git log": true,
|
|
|
|
|
"find": true,
|
|
|
|
|
"grep": true,
|
|
|
|
|
"cndump -s": true,
|
|
|
|
|
"tea repos list -o csv -lm 100": true,
|
|
|
|
|
"tea repos search -o csv": true,
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-06 18:35:58 +00:00
|
|
|
var (
|
2026-03-06 21:48:35 +00:00
|
|
|
// stepRe still finds the headings (this one is solid)
|
2026-03-06 18:35:58 +00:00
|
|
|
stepRe = regexp.MustCompile(`(?m)^### Step (\d+): (.+)$`)
|
|
|
|
|
)
|
|
|
|
|
|
2026-03-06 20:32:04 +00:00
|
|
|
func Load(path string, userParams map[string]any) (*Recipe, error) {
|
2026-03-06 18:35:58 +00:00
|
|
|
b, err := os.ReadFile(path)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
parts := bytes.SplitN(b, []byte("---"), 3)
|
|
|
|
|
if len(parts) < 3 {
|
|
|
|
|
return nil, fmt.Errorf("missing YAML frontmatter")
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
var r Recipe
|
|
|
|
|
if err := yaml.Unmarshal(parts[1], &r); err != nil {
|
|
|
|
|
return nil, fmt.Errorf("yaml parse: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-07 17:11:13 +00:00
|
|
|
// === SAFETY CHECK: reject dangerous allowed_shell_commands ===
|
|
|
|
|
for _, cmd := range r.AllowedShellCommands {
|
|
|
|
|
trimmed := strings.TrimSpace(strings.ToLower(cmd))
|
|
|
|
|
if !safeReadOnlyCommands[trimmed] && !strings.HasPrefix(trimmed, "git status") && !strings.HasPrefix(trimmed, "git log") {
|
|
|
|
|
return nil, fmt.Errorf("\033[31mERROR: Recipe contains unsafe shell command: %q\033[0m\n\nOnly the following read-only commands are allowed:\n ls, pwd, cat, tree, git status, git log, find, grep\n\nRemove or replace the dangerous command and try again.", cmd)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-07 00:07:21 +00:00
|
|
|
// Apply defaults + user --param overrides
|
2026-03-06 20:32:04 +00:00
|
|
|
if r.Parameters == nil {
|
|
|
|
|
r.Parameters = make(map[string]Parameter)
|
|
|
|
|
}
|
2026-03-07 00:07:21 +00:00
|
|
|
r.ResolvedParams = make(map[string]any)
|
2026-03-06 20:32:04 +00:00
|
|
|
for name, p := range r.Parameters {
|
|
|
|
|
if v, ok := userParams[name]; ok {
|
2026-03-07 00:07:21 +00:00
|
|
|
r.ResolvedParams[name] = v
|
2026-03-06 20:32:04 +00:00
|
|
|
} else if p.Default != nil {
|
2026-03-07 00:07:21 +00:00
|
|
|
r.ResolvedParams[name] = p.Default
|
2026-03-06 20:32:04 +00:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-07 00:07:21 +00:00
|
|
|
// Render templates with resolved values
|
2026-03-06 18:35:58 +00:00
|
|
|
tpl, err := template.New("recipe").Parse(string(parts[2]))
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
var rendered bytes.Buffer
|
2026-03-07 00:07:21 +00:00
|
|
|
if err := tpl.Execute(&rendered, r.ResolvedParams); err != nil {
|
2026-03-06 18:35:58 +00:00
|
|
|
return nil, err
|
|
|
|
|
}
|
2026-03-06 20:46:30 +00:00
|
|
|
body := rendered.String()
|
2026-03-06 18:35:58 +00:00
|
|
|
|
2026-03-06 20:46:30 +00:00
|
|
|
// Extract Overview
|
|
|
|
|
if idx := strings.Index(body, "## Execution Steps"); idx != -1 {
|
|
|
|
|
r.Overview = strings.TrimSpace(body[:idx])
|
2026-03-06 20:32:04 +00:00
|
|
|
}
|
|
|
|
|
|
2026-03-06 21:48:35 +00:00
|
|
|
// Extract steps with robust multi-line parsing
|
2026-03-06 18:35:58 +00:00
|
|
|
matches := stepRe.FindAllStringSubmatch(body, -1)
|
|
|
|
|
for i, m := range matches {
|
|
|
|
|
stepNum := i + 1
|
|
|
|
|
title := m[2]
|
|
|
|
|
|
|
|
|
|
start := strings.Index(body, m[0])
|
|
|
|
|
end := len(body)
|
|
|
|
|
if i+1 < len(matches) {
|
2026-03-06 20:46:30 +00:00
|
|
|
nextStart := strings.Index(body[start:], matches[i+1][0])
|
|
|
|
|
end = start + nextStart
|
2026-03-06 18:35:58 +00:00
|
|
|
}
|
2026-03-06 20:46:30 +00:00
|
|
|
|
2026-03-06 18:35:58 +00:00
|
|
|
section := body[start:end]
|
|
|
|
|
|
|
|
|
|
step := Step{Number: stepNum, Title: title}
|
2026-03-06 21:48:35 +00:00
|
|
|
|
|
|
|
|
// Simple, reliable label-based parsing (handles multi-line + blank lines)
|
|
|
|
|
labels := []string{"**Objective:**", "**Instructions:**", "**Expected output:**"}
|
|
|
|
|
for _, label := range labels {
|
|
|
|
|
labelStart := strings.Index(section, label)
|
|
|
|
|
if labelStart == -1 {
|
|
|
|
|
continue
|
|
|
|
|
}
|
|
|
|
|
contentStart := labelStart + len(label)
|
|
|
|
|
contentEnd := len(section)
|
|
|
|
|
|
|
|
|
|
// Find next label or end of section
|
|
|
|
|
for _, nextLabel := range labels {
|
|
|
|
|
next := strings.Index(section[contentStart:], nextLabel)
|
|
|
|
|
if next != -1 {
|
|
|
|
|
contentEnd = contentStart + next
|
|
|
|
|
break
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
content := strings.TrimSpace(section[contentStart:contentEnd])
|
|
|
|
|
|
|
|
|
|
switch label {
|
2026-03-06 18:35:58 +00:00
|
|
|
case "**Objective:**":
|
2026-03-06 21:48:35 +00:00
|
|
|
step.Objective = content
|
2026-03-06 18:35:58 +00:00
|
|
|
case "**Instructions:**":
|
2026-03-06 21:48:35 +00:00
|
|
|
step.Instructions = content
|
2026-03-06 18:35:58 +00:00
|
|
|
case "**Expected output:**":
|
2026-03-06 21:48:35 +00:00
|
|
|
step.Expected = content
|
2026-03-06 18:35:58 +00:00
|
|
|
}
|
|
|
|
|
}
|
2026-03-06 21:48:35 +00:00
|
|
|
|
2026-03-06 18:35:58 +00:00
|
|
|
r.Steps = append(r.Steps, step)
|
|
|
|
|
}
|
|
|
|
|
|
2026-03-06 21:48:35 +00:00
|
|
|
// Final summary (everything after last step)
|
2026-03-06 20:46:30 +00:00
|
|
|
if len(matches) > 0 {
|
|
|
|
|
lastMatch := matches[len(matches)-1][0]
|
|
|
|
|
lastIdx := strings.LastIndex(body, lastMatch)
|
|
|
|
|
r.FinalSummaryPrompt = strings.TrimSpace(body[lastIdx+len(lastMatch):])
|
|
|
|
|
}
|
2026-03-06 18:35:58 +00:00
|
|
|
|
|
|
|
|
return &r, nil
|
|
|
|
|
}
|