mirror of
https://github.com/dtzp555-max/ocp.git
synced 2026-07-19 09:44:07 +00:00
fix(server): wire CLAUDE_SYSTEM_PROMPT (dead since APPEND_SYSTEM_PROMPT retirement) (#175)
* fix(server): wire CLAUDE_SYSTEM_PROMPT into the composed system prompt (was dead since APPEND_SYSTEM_PROMPT retirement) The var was read (SYSTEM_PROMPT, server.mjs), documented in the file header as "appended to all requests", and echoed on /health.systemPrompt — but nothing on the request path consumed it: extractSystemPrompt() composed only the wrapper + client system messages. The wiring was lost when APPEND_SYSTEM_PROMPT was retired, leaving the header comment and the buildCliArgs comment describing behavior that did not exist (caught by the PR #170 independent reviewer). Wire, not delete, because: - the /health `systemPrompt` field is part of the grandfathered B.2 contract (ADR 0006, frozen at v3.16.4) — removal would need an ADR; wiring keeps the shape and makes the field honest; - fleet check: no deployment sets the var (Mac prod plist, Oracle systemd unit, PI231 /etc/ocp/ocp.env all clean), so wiring changes behavior for NOBODY today; - with the var unset, appendOperatorPrompt returns its input string unchanged — the default path is byte-for-byte identical. Mechanics: new pure lib/prompt.mjs `appendOperatorPrompt(base, operatorAppend)` (trimmed; whitespace-only treated as unset so a stray space in a service unit cannot inject "\n\n " into every request), applied as the LAST segment in both extractSystemPrompt branches — an operator-wide directive reads as the final instruction, after client system messages. TUI-mode is untouched (panes keep the interactive CLI's own system prompt); documented in the README row. ALIGNMENT.md Rule 2: no cli.js citation applies. No endpoint, header, or wire field is added or altered; the change affects only the CONTENT OCP passes to the already-established `--system-prompt` flag (file header § verified v2.1.104), i.e. OCP-owned prompt composition. /health shape unchanged. Tests: +3, doubly mutation-proven (unconditional-base revert → 2 failures; trim removal → 2 failures). Suite 341 passed / 0 failed. Co-Authored-By: Claude <claude-opus-4-8> <noreply@anthropic.com> * docs(readme): cache-staleness caveat on CLAUDE_SYSTEM_PROMPT row (reviewer advisory) --------- Co-authored-by: dtzp555 <dtzp555@gmail.com> Co-authored-by: Claude <claude-opus-4-8> <noreply@anthropic.com>
This commit is contained in:
@@ -228,6 +228,7 @@ The canonical list lives in [`models.json`](./models.json) — the single source
|
||||
| `CLAUDE_ALLOWED_TOOLS` | `Bash,Read,...,Agent` | Comma-separated tools to pre-approve |
|
||||
| `CLAUDE_SKIP_PERMISSIONS` | `false` | Bypass all permission checks |
|
||||
| `CLAUDE_MCP_CONFIG` | *(unset)* | Path to an MCP server config JSON, passed to the spawned `claude` as `--mcp-config` (both the `-p` path and TUI `OCP_TUI_FULL_TOOLS` panes) |
|
||||
| `CLAUDE_SYSTEM_PROMPT` | *(unset)* | Operator-wide system-prompt text appended (last) to every request's composed system prompt on the default `-p` path. TUI-mode panes are unaffected (they keep the interactive CLI's own system prompt). Echoed truncated on `/health.systemPrompt`. Note: the response cache key does not include server config — after changing this value, flush the cache (`ocp clear`) or let TTL expire. |
|
||||
| `CLAUDE_NO_CONTEXT` | `false` | Suppress CLAUDE.md and auto-memory injection (pure API mode) |
|
||||
| `PROXY_API_KEY` | *(unset)* | Bearer token for shared-mode authentication |
|
||||
| `PROXY_ANONYMOUS_KEY` | *(unset)* | Well-known anonymous key (multi mode) — this exact string bypasses `validateKey()` and grants public access. Exposed via `/health.anonymousKey` only to localhost, or to all callers when `PROXY_ADVERTISE_ANON_KEY=1`. Full setup + security notes: [docs/lan-mode.md § Anonymous Access](docs/lan-mode.md#anonymous-access-optional). |
|
||||
|
||||
Reference in New Issue
Block a user