feat(web): drive run/whitebox/greybox exploitation through a real REPL session

Root cause of "can't send prompts while a run streams": /api/exploit
spawned a plain `neurosploit run ...` subprocess, and that CLI path
(run_mode() in main.rs) never reads stdin - it only waits on the task or
Ctrl-C. The ONLY thing in the harness that keeps accepting input while an
engagement streams is the interactive REPL's background-run loop. So:

- New startJobViaRepl(): for mode run/whitebox/greybox, spawns a bare
  `neurosploit` REPL session and scripts it via stdin (/target or /repo,
  /model, /sub, /mcp, /votes, /chain, /recon, /focus, /objective,
  /scope-out, /creds, /only <agents> or /only clear, then /run) instead
  of building CLI args. Same underlying pipeline, same tagged output
  lines, so all existing parsing (findings/phase/progress/runId) works
  unchanged. host/aitest/skills modes stay on the old one-shot
  startJob() - they need onboarding's scope picker, an interactive
  arrow-key menu that silently skips itself over a piped stdin, so they
  can't be scripted this way.
- New POST /api/exploit/:id/input writes a line to the session's stdin -
  natural language, /status, /continue, anything the REPL accepts - and
  the live run view grows a "send prompt" box (in the Activity log tab)
  for it, shown only when the job reports interactive: true.
- Stop, for an interactive job, now sends the REPL's own graceful
  '/stop\n1\n' (validate what's found, then report) instead of SIGINT -
  the REPL's own input loop has no signal handler, so SIGINT there would
  just kill the process outright and skip the report step. Non-
  interactive jobs still get SIGINT (run_mode() does catch that).
- 'done' can no longer be process-exit only: an interactive session stays
  open after the engagement finishes (for /report, /continue, another
  /run), so ingestLine() now also flags done from the same "phase
  complete" content signal it already used for the phase field.

Verified end-to-end: started an interactive job, confirmed
`interactive: true` and a captured runId, sent /status and /agents mid-
and post-run over the new /input endpoint (both accepted, session stayed
alive and responsive after completion), and confirmed a non-interactive
run is unaffected.

Also: the missing "Activity log" tab a screenshot showed for a "running"
engagement was the sidebar's detail-view fallback (2 tabs, no log) for a
run whose Job object no longer exists in server memory - it happens when
the Node process gets restarted while a spawned neurosploit child is
still alive underneath it (an orphan from testing across many redeploys
this session, not a code bug); the live view itself always had the tab.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0129WdYHccPsH27k5GGuwijd
This commit is contained in:
CyberSecurityUP
2026-08-23 16:04:55 -03:00
co-authored by Claude Sonnet 5
parent 07bed42467
commit 4fbe608a7a
4 changed files with 150 additions and 5 deletions
+8 -1
View File
@@ -227,7 +227,14 @@
<div class="run-body">
<div class="run-tab-panel" data-tabpanel="findings"><table class="data-table" id="liveFindingsTable"><thead><tr><th>Severity</th><th>Title</th><th>Endpoint</th><th>CWE</th><th>Agent</th><th>Conf.</th></tr></thead><tbody></tbody></table><div class="empty-state" id="liveFindingsEmpty">No validated findings yet.</div></div>
<div class="run-tab-panel" data-tabpanel="attackpath" hidden><div id="liveAttackPath"></div></div>
<div class="run-tab-panel" data-tabpanel="log" hidden><div class="log-panel" id="logList" style="height: 100%;"></div></div>
<div class="run-tab-panel log-tab-panel" data-tabpanel="log" hidden>
<div class="log-panel" id="logList"></div>
<div class="send-prompt-row" id="sendPromptRow" hidden>
<span class="repl-prompt"></span>
<input id="sendPromptInput" type="text" autocomplete="off" spellcheck="false" placeholder="/status · /stop · /continue · or describe it in plain language" />
</div>
<div class="field-help" id="sendPromptHelp" hidden>This session stays interactive while the engagement runs — type a command or plain instruction and press Enter.</div>
</div>
</div>
</section>