* feat(ui): add symbolic math support to JS sandbox via nerdamer Preload nerdamer (with decimal.js) in the sandboxed worker, exposing the `nerdamer` global for symbolic computation: simplify, expand, factor, diff, integrate, solve, laplace, ilt, limit, partfrac, gcd/lcm, roots, coefficients, and more. Mirrors the math.js integration pattern from the feature/sandbox-symbolic-math branch, but uses nerdamer for a lighter, more focused symbolic math engine. * Update sandbox-harness.ts * docs(ui): update sandbox tool description with detailed nerdamer usage guide * Clarify nerdamer usage in sandbox tool description Updated the description of the sandbox tool to clarify usage of nerdamer. * ui: build nerdamer sandbox prelude from vendored source Replace the vendored all.min.js with the readable nerdamer-prime source and its two bundled deps (big-integer, decimal.js), licenses included. A vite plugin bundles and minifies them at build time with the upstream esbuild flags, exposed as virtual:nerdamer and imported lazily on first sandbox use. The vendors package.json pins commonjs so the project level type: module does not break esbuild format detection. The harness gains a CSP removing network egress from the worker, and browser tests cover the prelude, exact arithmetic, the fetch block and the timeout. Upstream snapshot: together-science/nerdamer-prime@1936145 * feat(ui): make symbolic math (nerdamer) a user-toggleable setting - Add SYMBOLIC_MATH_ENABLED setting key and registry entry (checkbox, default false) - Convert SANDBOX_TOOL_DEFINITION to buildSandboxToolDefinition(includeSymbolicMath) so the tool description includes/excludes nerdamer API docs dynamically - Cache sandbox harness per variant ('nerdamer' / 'plain') for instant toggle - Deprecate SANDBOX_TOOL_DEFINITION constant alias for backward compatibility - Update tools store to pass symbolic math config into tool definition * docs(ui): tell LLM to list nerdamer functions first, do not guess * test(ui): enable symbolic math in sandbox tests via settingsStore config * style(ui): fix formatting for tools.svelte.ts --------- Co-authored-by: Pascal <admin@serveurperso.com>
38 lines
1.7 KiB
TypeScript
38 lines
1.7 KiB
TypeScript
import { NEWLINE } from '$lib/constants';
|
|
import WORKER_SHIM from './sandbox-worker.js?raw';
|
|
|
|
/**
|
|
* CSP for the harness document, inherited by the blob worker. connect-src
|
|
* falls back to default-src, removing network egress for model and vendored
|
|
* code. 'unsafe-eval' is required by the worker's AsyncFunction constructor,
|
|
* 'unsafe-inline' by the inline script below, worker-src by the blob worker.
|
|
*/
|
|
const HARNESS_CSP = `default-src 'none'; script-src 'unsafe-inline' 'unsafe-eval'; worker-src blob:`;
|
|
|
|
/**
|
|
* Harness loaded as srcdoc into a sandboxed iframe (allow-scripts only).
|
|
* The opaque origin is the security boundary: no access to the app origin,
|
|
* its storage or its API. The harness spawns a worker so model code never
|
|
* runs on a main thread, which makes the parent timeout enforceable by
|
|
* removing the iframe. The prelude runs in the worker before the shim,
|
|
* exposing globals such as `nerdamer` to model code.
|
|
*/
|
|
export function buildSandboxHarness(preludeJs: string): string {
|
|
return `<!doctype html><meta http-equiv="Content-Security-Policy" content="${HARNESS_CSP}"><script>
|
|
const SHIM = ${JSON.stringify(preludeJs + NEWLINE + WORKER_SHIM)};
|
|
addEventListener('message', (event) => {
|
|
const respond = (payload) => parent.postMessage(payload, '*');
|
|
let worker;
|
|
try {
|
|
worker = new Worker(URL.createObjectURL(new Blob([SHIM], { type: 'text/javascript' })));
|
|
} catch (err) {
|
|
respond({ logs: [], result: null, error: 'Worker creation failed: ' + err });
|
|
return;
|
|
}
|
|
worker.onmessage = (msg) => respond(msg.data);
|
|
worker.onerror = (err) => respond({ logs: [], result: null, error: String(err.message || err) });
|
|
worker.postMessage({ code: event.data.code });
|
|
});
|
|
</script>`;
|
|
}
|