feat: Pheby platform adapter/plugin for Hermes (protocol v1)
Third-party Hermes platform plugin serving the Pheby WebSocket+HTTPS protocol for the native Android client, behind Caddy: - Platform adapter (BasePlatformAdapter subclass) registered via the documented plugin system (plugins.platforms pattern, kind: platform) - Multiple conversations mapped to Hermes sessions (authoritative state) - Streaming chat via GatewayStreamConsumer edit path (message.delta) - Structured tool events (never fake tool text in chat), incl. post_tool_call hook relay with Hermes tool_call_ids - Native approval + clarification round-trips via tools.approval / tools.clarify_gateway primitives - Attachment delivery: adapter-owned copies, opaque IDs, persistent metadata, 7-day retention + safe cleanup, authenticated HTTPS download - Model + reasoning-effort query/change via Hermes picker data and session/global overrides - Shared-secret auth (constant-time, lockout), size limits, path- traversal-proof attachment resolution, minimal health endpoint - Protocol v1 spec with JSON examples (docs/PROTOCOL.md) - Install/config/Caddy/security docs + discovered Hermes limitations - 37 passing tests (auth, conversations, protocol, attachments incl. expiry/traversal, tool events, approvals, clarifications, cancel, reconnect re-sync, live WS smoke tests) — gateway-free fakes No Hermes core modifications required.
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
name: pheby
|
||||
label: Pheby
|
||||
kind: platform
|
||||
version: 1.0.0
|
||||
description: >
|
||||
Pheby platform adapter for Hermes Agent — serves a WebSocket + HTTPS
|
||||
protocol for the Pheby native Android client (Kotlin/Compose) behind a
|
||||
Caddy reverse proxy. Exposes multiple conversations (Hermes sessions),
|
||||
streamed chat, structured tool events, native approval/clarification
|
||||
round-trips, model + reasoning-effort selection, and agent-generated
|
||||
attachments with 7-day adapter-managed retention. Single-user, shared-secret
|
||||
auth (PHEBY_SECRET). No Hermes core modifications required.
|
||||
author: Pheby (for Chris)
|
||||
requires_env:
|
||||
- name: PHEBY_SECRET
|
||||
description: "Shared credential every WS connection and attachment download must present (generate with: openssl rand -hex 32)"
|
||||
prompt: "Pheby shared secret"
|
||||
password: true
|
||||
optional_env:
|
||||
- name: PHEBY_BIND_HOST
|
||||
description: "Bind address (default: 127.0.0.1 — safe behind a local Caddy)"
|
||||
prompt: "Bind host (or empty for 127.0.0.1)"
|
||||
password: false
|
||||
- name: PHEBY_PORT
|
||||
description: "Listen port (default: 8620)"
|
||||
prompt: "Listen port (or empty for 8620)"
|
||||
password: false
|
||||
- name: PHEBY_DEBUG
|
||||
description: "Verbose protocol logging (true/false, default false)"
|
||||
prompt: "Enable debug protocol logging? (true/false)"
|
||||
password: false
|
||||
- name: PHEBY_LOG_CHAT_CONTENT
|
||||
description: "Debug logs may include chat text and tool previews (default false)"
|
||||
prompt: "Log chat content in debug mode? (true/false)"
|
||||
password: false
|
||||
- name: PHEBY_HOME_CHANNEL
|
||||
description: "Conversation ID receiving cron/scheduled deliveries by default"
|
||||
prompt: "Home conversation ID (or empty)"
|
||||
password: false
|
||||
- name: PHEBY_ALLOWED_USERS
|
||||
description: "Comma-separated allowlist treated as user IDs by the gateway (optional)"
|
||||
prompt: "Allowed user IDs (or empty)"
|
||||
password: false
|
||||
- name: PHEBY_ALLOW_ALL_USERS
|
||||
description: "Allow any authenticated client (dev only)"
|
||||
prompt: "Allow all users? (true/false)"
|
||||
password: false
|
||||
Reference in New Issue
Block a user