Builds the pipeline the autobuyer needs: see the page, find an element, click it. extension/ — MV3 Chromium extension. Polls /api/autobuyer/status and, while on, scrapes the target tab's HTML and posts it back. Also serves locate requests: focuses the window, scrolls the element into view, and reports its position. host_permissions is scoped to tradeify plus localhost so it cannot read other sites — an empty target pattern would otherwise capture whatever tab happened to be active, including banking or mail. app/api/autobuyer/ — status toggle, capture store, and the locate request queue. CORS is open because the extension's origin changes every time an unpacked extension is reloaded. app/autobuyer/page.tsx — ON switch, source view (default) and a rendered view. The render uses sandbox="allow-scripts" without allow-same-origin: the page's own JS is needed because sites ship content at opacity:0 and fade it in, but the frame must not reach the dashboard's same-origin API routes, which serve firm credentials. clicker/ — Python CLI. Asks the extension where a selector is, adds the element rect to the window's screen position and the browser chrome height to get desktop coordinates, then clicks with a human motion model (curved path, eased velocity, occasional overshoot, dwell before press). Raises the browser application first, since macOS consumes a click on an unfocused window rather than delivering it. Refuses to click when the element is covered by an overlay, when the coordinates fall off-screen, or when the browser cannot be confirmed frontmost. Verified: API round-trips, capture pruning, locate claim-once semantics, motion geometry and timing, and focus activation — the last two against stubs, since pyautogui and pyobjc are not installed here. NOT verified end to end: Chrome is still running a stale build of the extension, so a locate request has never completed against a real page and no real click has been sent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
AutoFirmer
Automated futures trading dashboard for prop firm accounts via Tradovate.
VPS Setup (Windows Server 2019 / 2022)
All commands are run in PowerShell (run as Administrator).
1. Install Git
Download and install from https://git-scm.com/download/win, or via winget:
winget install --id Git.Git -e --source winget
Restart PowerShell after installing so git is on the PATH.
2. Install Node.js 22+
winget install --id OpenJS.NodeJS.LTS -e --source winget
Restart PowerShell, then verify:
node --version # should be v22.x or higher
npm --version
3. Install Windows Build Tools (required for better-sqlite3)
better-sqlite3 compiles a native C++ module and needs the Visual Studio build tools:
npm install -g windows-build-tools
If that fails on newer Node, install manually:
- Download Build Tools for Visual Studio from https://visualstudio.microsoft.com/downloads/#build-tools-for-visual-studio-2022
- During install, select "Desktop development with C++"
4. Clone the repo
git clone https://github.com/Senofy/autofirmer.git
cd autofirmer
5. Install dependencies
npm install
6. Build
npm run build
7. Run
Development (with hot reload):
npm run dev
Production:
npm start
The app runs on port 3000. Access it at http://<your-vps-ip>:3000.
First-time setup
On first run, the SQLite database (autotrader.sqlite) is created automatically in the project root. No migrations need to be run manually.
Open the app in your browser and add your firms through the UI:
- Click + Add Firm on the main page
- Enter the firm name, Tradovate username, and password
- Go to the firm's Settings page to configure account types (prefix, profit target, consistency %, etc.)
- Return to the main page — accounts will populate once the firm connects to Tradovate
Keeping it running (PM2)
Install PM2 globally:
npm install -g pm2
npm install -g pm2-windows-startup
Start the app and save the process list:
cd C:\path\to\autofirmer
pm2 start "npm start" --name autofirmer
pm2 save
pm2-startup install
To restart after pulling updates:
cd C:\path\to\autofirmer
git pull
npm install
npm run build
pm2 restart autofirmer
Firewall
To restrict port 3000 to a specific trusted IP only:
New-NetFirewallRule -DisplayName "AutoFirmer" -Direction Inbound -Protocol TCP -LocalPort 3000 -RemoteAddress <your-ip> -Action Allow
Or open it to all inbound (less secure):
New-NetFirewallRule -DisplayName "AutoFirmer" -Direction Inbound -Protocol TCP -LocalPort 3000 -Action Allow
Updating
cd C:\path\to\autofirmer
git pull
npm install # only needed if dependencies changed
npm run build
pm2 restart autofirmer