Files
Kigi-CLI/crates/codegen/kigi-tui
ZacharyZhang-NY ad3840f9ec fix(web_fetch): block non-public targets by default and gate every hop
kigi allowed loopback unconditionally and missed several non-public
ranges, and the SSRF check ran only on the initial URL.

Policy (ssrf.rs):
- loopback is blocked unless `[toolset.web_fetch] allow_local` (or
  KIGI_WEB_FETCH_ALLOW_LOCAL) is on, AND the URL names it explicitly,
  so a public name resolving to loopback stays blocked (DNS rebinding)
- add 0.0.0.0/8, 100.64/10, 192.0.0.0/24, TEST-NET-1/2/3, 198.18/15,
  240/4, IPv6 site-local and documentation prefixes
- inherit the IPv4 verdict through mapped, compatible, NAT64 and 6to4
  wrappers; network-specific NAT64 prefixes remain uncovered (see doc)

Plumbing (client.rs), where the exploitable half lived:
- re-check every redirect hop, not just the first
- compare hosts exactly; a `www` sibling has its own A records, so it
  is a cross-host redirect rather than an auto-followed hop
- run the check before the fetch service, so a blocked URL is never
  posted to an endpoint that egresses elsewhere
- exempt explicit local hosts from the https upgrade and from the
  single-label filter, and re-upgrade each followed hop

Wiring: allow_local reaches WebFetchParams from both construction
paths; documented in the config guide and the README env table.
2026-07-27 11:44:20 -04:00
..

kigi-tui

Terminal UI (TUI) for Kigi. Provides the interactive full-screen interface including the scrollback view, prompt input, session management, and all modal dialogs.

Architecture

src/
├── app/                 # Application state and event handling
│   ├── app_view.rs      # Top-level state (welcome screen, agents, config)
│   ├── agent_view/      # Per-session agent view (struct in mod.rs + per-domain impl modules)
│   ├── dispatch/        # Action → Effect dispatcher (router + per-domain modules)
│   ├── effects.rs       # Async side effects (ACP calls, file I/O)
│   └── event_loop.rs    # Main event loop (input, ticks, ACP messages)
├── views/               # UI components
│   ├── prompt_widget.rs # Text editor with file search, slash, history
│   ├── welcome/         # Welcome screen (logo, menu, prompt)
│   ├── extensions_modal.rs   # Extensions modal (hooks, plugins, marketplace, skills, MCP servers)
│   ├── file_search/     # @-completion dropdown and line viewer
│   ├── slash_dropdown.rs# /command completion dropdown
│   └── ...              # Scrollback, status bar, panes, etc.
├── scrollback/          # Message history rendering
├── slash/               # Slash command registry and built-in commands
├── appearance/          # Theme and pager.toml config
├── acp/                 # Agent Communication Protocol client state
└── render/              # Low-level rendering helpers (color, wrapping, etc.)

Key Concepts

  • AppView — owns the welcome screen, agent sessions, and global config
  • AgentView — one per session; owns the prompt, scrollback, tool panes, and modals
  • PromptWidget — text editor component with file search (@), slash commands (/), history search, and paste elements
  • Action/Effect — Elm-style architecture: input → Action → dispatch → Effect → state update

Keyboard Shortcuts

Key Context Action
Ctrl+P or ? Agent screen Open command palette
Ctrl+L Any (nonVS Code family) Open plugins/hooks modal; on VS Code / Cursor / Windsurf / Zed use /plugins or /hooks (Ctrl+L is mid-turn interject)
Tab Prompt Switch to scrollback
Esc Turn running No-op (does not cancel; use Ctrl+C)
Esc Esc Idle, non-empty prompt Clear prompt (within 800ms; first press shows hint)
Esc Esc Idle, empty prompt + messages Open rewind picker (silent first press)
Ctrl+M Prompt Toggle multiline mode
Shift+Enter Prompt Insert newline
/ Prompt Start slash command
@ Prompt Start file search
! Prompt (empty) Enter bash mode
Ctrl+C Prompt (with text) Clear prompt (even while turn running)
Ctrl+C Prompt (empty) + turn running Cancel running turn

Docs