Files
autofirmer-expanded/app/api/autobuyer/capture/route.ts
T
Brandon LiandClaude Opus 5 54221bbc0c Add autobuyer page capture, browser extension, and desktop clicker
Builds the pipeline the autobuyer needs: see the page, find an element,
click it.

extension/ — MV3 Chromium extension. Polls /api/autobuyer/status and,
while on, scrapes the target tab's HTML and posts it back. Also serves
locate requests: focuses the window, scrolls the element into view, and
reports its position. host_permissions is scoped to tradeify plus
localhost so it cannot read other sites — an empty target pattern would
otherwise capture whatever tab happened to be active, including banking
or mail.

app/api/autobuyer/ — status toggle, capture store, and the locate request
queue. CORS is open because the extension's origin changes every time an
unpacked extension is reloaded.

app/autobuyer/page.tsx — ON switch, source view (default) and a rendered
view. The render uses sandbox="allow-scripts" without allow-same-origin:
the page's own JS is needed because sites ship content at opacity:0 and
fade it in, but the frame must not reach the dashboard's same-origin API
routes, which serve firm credentials.

clicker/ — Python CLI. Asks the extension where a selector is, adds the
element rect to the window's screen position and the browser chrome
height to get desktop coordinates, then clicks with a human motion model
(curved path, eased velocity, occasional overshoot, dwell before press).
Raises the browser application first, since macOS consumes a click on an
unfocused window rather than delivering it.

Refuses to click when the element is covered by an overlay, when the
coordinates fall off-screen, or when the browser cannot be confirmed
frontmost.

Verified: API round-trips, capture pruning, locate claim-once semantics,
motion geometry and timing, and focus activation — the last two against
stubs, since pyautogui and pyobjc are not installed here. NOT verified
end to end: Chrome is still running a stale build of the extension, so a
locate request has never completed against a real page and no real click
has been sent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-27 16:15:18 -05:00

81 lines
2.6 KiB
TypeScript

import { NextRequest } from 'next/server';
import { saveCapture, getLatestCapture, clearCaptures } from '@/lib/db';
import { corsJson, corsPreflight } from '../cors';
/** Guard against a runaway page dumping tens of megabytes into SQLite every poll. */
const MAX_HTML_BYTES = 8 * 1024 * 1024;
interface CapturePayload {
url?: string;
title?: string;
html?: string;
viewport?: unknown;
elements?: unknown;
capturedAt?: number;
}
/** Written by the Chromium extension each time it scrapes the target tab. */
export async function POST(req: NextRequest) {
try {
const body = await req.json() as CapturePayload;
if (typeof body.html !== 'string' || typeof body.url !== 'string') {
return corsJson({ error: '`url` and `html` are required' }, { status: 400 });
}
if (body.html.length > MAX_HTML_BYTES) {
return corsJson({ error: `HTML exceeds ${MAX_HTML_BYTES} bytes` }, { status: 413 });
}
const capturedAt = typeof body.capturedAt === 'number' ? body.capturedAt : Date.now();
saveCapture({
url: body.url,
title: typeof body.title === 'string' ? body.title : '',
html: body.html,
viewport: JSON.stringify(body.viewport ?? {}),
elements: JSON.stringify(body.elements ?? []),
captured_at: capturedAt,
});
return corsJson({ ok: true, capturedAt, bytes: body.html.length });
} catch (err: any) {
return corsJson({ error: err?.message ?? 'Failed to save capture' }, { status: 500 });
}
}
/** Read by the AutoBuyer page. Pass `?since=<capturedAt>` to skip re-sending
* an unchanged capture — the HTML blob is megabytes and the page polls often. */
export async function GET(req: NextRequest) {
const row = getLatestCapture();
if (!row) return corsJson({ capture: null });
const since = Number(req.nextUrl.searchParams.get('since'));
if (Number.isFinite(since) && since > 0 && since >= row.captured_at) {
return corsJson({ unchanged: true });
}
return corsJson({
capture: {
url: row.url,
title: row.title,
html: row.html,
viewport: safeParse(row.viewport, {}),
elements: safeParse(row.elements, []),
capturedAt: row.captured_at,
},
});
}
export async function DELETE() {
clearCaptures();
return corsJson({ ok: true });
}
export async function OPTIONS() {
return corsPreflight();
}
function safeParse<T>(json: string, fallback: T): T {
try { return JSON.parse(json) as T; } catch { return fallback; }
}