Register-ScheduledTask failed with Access denied (0x80070005). Writing to the root task folder needs elevation, so the claim that this install needed no admin was simply wrong. Rather than demand UAC, use two mechanisms that need no privileges at all: - a Startup-folder entry (AutoFirmer.cmd) runs start-all.bat at logon - PM2's own --cron-restart with --no-autorestart drives the 5-minute update check, so PM2 owns the schedule it was already going to resurrect anyway Both still run in the logged-in interactive session, which is the requirement that ruled out a Windows service in the first place: the clicker sends real input and needs a desktop. pm2 save now runs after the updater is registered, so `pm2 resurrect` brings back all three processes rather than two. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
242 lines
7.2 KiB
Markdown
242 lines
7.2 KiB
Markdown
# AutoFirmer
|
|
|
|
Automated futures trading dashboard for prop firm accounts via Tradovate.
|
|
|
|
---
|
|
|
|
## VPS Setup (Windows Server 2019 / 2022)
|
|
|
|
All commands are run in **PowerShell** (run as Administrator).
|
|
|
|
### 1. Install Git
|
|
|
|
Download and install from https://git-scm.com/download/win, or via winget:
|
|
|
|
```powershell
|
|
winget install --id Git.Git -e --source winget
|
|
```
|
|
|
|
Restart PowerShell after installing so `git` is on the PATH.
|
|
|
|
### 2. Install Node.js 22+
|
|
|
|
```powershell
|
|
winget install --id OpenJS.NodeJS.LTS -e --source winget
|
|
```
|
|
|
|
Restart PowerShell, then verify:
|
|
|
|
```powershell
|
|
node --version # should be v22.x or higher
|
|
npm --version
|
|
```
|
|
|
|
### 3. Install Windows Build Tools (required for better-sqlite3)
|
|
|
|
`better-sqlite3` compiles a native C++ module and needs the Visual Studio build tools:
|
|
|
|
```powershell
|
|
npm install -g windows-build-tools
|
|
```
|
|
|
|
If that fails on newer Node, install manually:
|
|
- Download **Build Tools for Visual Studio** from https://visualstudio.microsoft.com/downloads/#build-tools-for-visual-studio-2022
|
|
- During install, select **"Desktop development with C++"**
|
|
|
|
### 4. Clone the repo
|
|
|
|
```powershell
|
|
git clone https://github.com/Senofy/autofirmer.git
|
|
cd autofirmer
|
|
```
|
|
|
|
### 5. Install dependencies
|
|
|
|
```powershell
|
|
npm install
|
|
```
|
|
|
|
### 6. Build
|
|
|
|
```powershell
|
|
npm run build
|
|
```
|
|
|
|
### 7. Run
|
|
|
|
**Development (with hot reload):**
|
|
```powershell
|
|
npm run dev
|
|
```
|
|
|
|
**Production:**
|
|
```powershell
|
|
npm start
|
|
```
|
|
|
|
The app runs on **port 3000**. Access it at `http://<your-vps-ip>:3000`.
|
|
|
|
---
|
|
|
|
## First-time setup
|
|
|
|
On first run, the SQLite database (`autotrader.sqlite`) is created automatically in the project root. No migrations need to be run manually.
|
|
|
|
Open the app in your browser and add your firms through the UI:
|
|
|
|
1. Click **+ Add Firm** on the main page
|
|
2. Enter the firm name, Tradovate username, and password
|
|
3. Go to the firm's **Settings** page to configure account types (prefix, profit target, consistency %, etc.)
|
|
4. Return to the main page — accounts will populate once the firm connects to Tradovate
|
|
|
|
---
|
|
|
|
## AutoBuyer (browser automation)
|
|
|
|
The AutoBuyer page drives a real browser to buy and reset prop-firm accounts. It
|
|
is three pieces, and all three must be running:
|
|
|
|
| Piece | What it does |
|
|
|---|---|
|
|
| the dashboard | Defines automations, queues runs, shows progress |
|
|
| `extension/` | A Chromium extension that reads the broker page and measures elements |
|
|
| `clicker/runner.py` | A desktop process that moves the real mouse and keyboard |
|
|
|
|
Automations are declared in `lib/automations.ts` — one entry per firm, with the
|
|
steps inside. Adding a button means editing that file; the page and the runner
|
|
pick it up from the server.
|
|
|
|
### 1. Load the extension
|
|
|
|
`chrome://extensions` → enable **Developer mode** → **Load unpacked** →
|
|
select the `extension` folder.
|
|
|
|
Chrome does **not** reload an unpacked extension when its files change. After
|
|
pulling updates, click the reload icon on its card — the dashboard shows the
|
|
version it sees, and a mismatch means the reload did not take.
|
|
|
|
Adding a new firm also means adding its host to `host_permissions` in
|
|
`extension/manifest.json` and reloading. Without it the extension cannot read
|
|
that site, and every step fails to locate.
|
|
|
|
### 2. Install the clicker
|
|
|
|
```powershell
|
|
cd clicker
|
|
pip install -r requirements.txt
|
|
```
|
|
|
|
See `clicker/README.md` for the per-platform notes — display scaling and
|
|
foreground lock both matter on Windows — and for the verification sequence to
|
|
run before letting it click anything on a new machine.
|
|
|
|
### 3. Start the runner
|
|
|
|
```powershell
|
|
python clicker\runner.py
|
|
```
|
|
|
|
Leave it running. It reports in every two seconds, and the dashboard greys out
|
|
the automation buttons when it is not there. A running Python process does not
|
|
reload when the source changes, so restart it after pulling updates; the
|
|
dashboard warns when its version is behind.
|
|
|
|
### Running it
|
|
|
|
Turn **Page capture** on from the AutoBuyer page, then press an automation's
|
|
button. Progress appears per step, and **Stop** halts a run between steps.
|
|
|
|
The browser must be visible and frontmost while a run is in flight — the clicks
|
|
are real OS-level input, so the machine cannot be used for anything else, and a
|
|
dialog stealing focus fails the step. That makes an RDP session a poor host:
|
|
disconnecting can suspend the desktop and break clicks in ways that are hard to
|
|
diagnose.
|
|
|
|
## Keeping it running
|
|
|
|
`setup-windows.bat` offers to set this up for you at step 6. To enable it later,
|
|
or after declining:
|
|
|
|
```powershell
|
|
powershell -NoProfile -ExecutionPolicy Bypass -File scripts\install-autostart.ps1
|
|
```
|
|
|
|
That puts the dashboard, the clicker and an update checker under PM2, adds a
|
|
Startup-folder entry so PM2 comes back at logon, and lets PM2's cron restart run
|
|
the update check every 5 minutes. It needs no administrator rights, changes
|
|
nothing machine-wide, and is safe to re-run.
|
|
|
|
```powershell
|
|
pm2 list # what is running
|
|
pm2 logs autofirmer # dashboard output
|
|
pm2 logs clicker # runner output
|
|
```
|
|
|
|
**Why not a Windows service.** The clicker sends real mouse and keyboard input
|
|
and has to own a desktop. A service runs in session 0, which has none, so the
|
|
clicks would go nowhere. Everything therefore runs in your logged-in session —
|
|
which also means an unattended reboot leaves the instance down until somebody
|
|
logs in.
|
|
|
|
To stop it starting at logon, delete the `AutoFirmer.cmd` shortcut from your
|
|
Startup folder (`shell:startup` in the Run dialog).
|
|
|
|
To start everything by hand without waiting for a logon:
|
|
|
|
```powershell
|
|
node scripts\start-all.mjs
|
|
```
|
|
|
|
`start-autofirmer.bat` still runs the dashboard in a visible window without PM2,
|
|
which is the easier thing to watch when a build is misbehaving.
|
|
|
|
|
|
## Firewall
|
|
|
|
To restrict port 3000 to a specific trusted IP only:
|
|
|
|
```powershell
|
|
New-NetFirewallRule -DisplayName "AutoFirmer" -Direction Inbound -Protocol TCP -LocalPort 3000 -RemoteAddress <your-ip> -Action Allow
|
|
```
|
|
|
|
Or open it to all inbound (less secure):
|
|
|
|
```powershell
|
|
New-NetFirewallRule -DisplayName "AutoFirmer" -Direction Inbound -Protocol TCP -LocalPort 3000 -Action Allow
|
|
```
|
|
|
|
---
|
|
|
|
## Updating
|
|
|
|
Once auto-start is installed, nothing here is manual. Every 5 minutes the update
|
|
task fetches `master`, and when it has moved it pulls, reinstalls dependencies if
|
|
`package-lock.json` or `clicker/requirements.txt` changed, rebuilds, restarts
|
|
AutoFirmer, and restarts the clicker if anything under `clicker/` changed.
|
|
|
|
**A failed build is never deployed.** The build runs before anything restarts, so
|
|
a broken push leaves the previous build serving and logs the failure instead.
|
|
|
|
Everything it does is appended to `scripts/update.log`. To see what it would do
|
|
without touching anything:
|
|
|
|
```powershell
|
|
node scripts\update-check.mjs --dry-run
|
|
```
|
|
|
|
To apply an update immediately rather than waiting for the next check:
|
|
|
|
```powershell
|
|
node scripts\update-check.mjs
|
|
```
|
|
|
|
### The two things that still do not reload themselves
|
|
|
|
- **The extension** — click reload on its card in `chrome://extensions`.
|
|
- **The scheduler is fine now.** It persists to the settings table and resumes
|
|
after a restart, so an update no longer silently stops automated trading.
|
|
|
|
The dashboard reports the version it sees from the extension and the runner, and
|
|
warns when either is behind. Most AutoBuyer bugs that look mysterious are the
|
|
extension still running the previous code.
|