Create standalone browser port of LTX Athena with authenticated native API transport
This commit is contained in:
@@ -0,0 +1,55 @@
|
||||
# Architecture
|
||||
|
||||
Browser (React, inherited Gen Space and timeline)
|
||||
→ Node web service (session authentication, file I/O, streaming HTTP forwarding)
|
||||
→ Athena Deck shared API port in Video mode
|
||||
→ original LTX Desktop backend.
|
||||
|
||||
The backend address may alternatively point directly to the native LTX API.
|
||||
The web service forwards `/ltx/api/...` to `/api/...`, preserving method, body,
|
||||
query, response status and body. No model-specific request translation. A fixed,
|
||||
operator-configured upstream prevents browser-controlled proxy targets. Tokens
|
||||
are loaded from files at startup and never sent to the browser. Native streaming
|
||||
HTTP responses and polling are supported; WebSocket forwarding is not implemented.
|
||||
|
||||
`frontend/lib/web-platform.ts` implements the inherited typed `electronAPI` boundary
|
||||
in the browser. It is an OS/file integration replacement, not a model API adapter.
|
||||
The application shell no longer calls Python installers, model setup, first-run
|
||||
license acceptance, Electron updates or backend process start/stop. Unsupported
|
||||
functions throw explicit errors; timeline rendering is visibly disabled.
|
||||
|
||||
Media: browsers cannot send server paths without first uploading. File dialogs
|
||||
upload immediately; drag-and-drop uses temporary blob URLs until a generation or
|
||||
asset import resolves the file. Server stores UUID filenames in a shared input
|
||||
folder; its backend-visible path is returned. The web service and LTX must see the
|
||||
SAME files (Docker bind mounts can expose different absolute paths). Existing LTX
|
||||
outputs are mounted read-only. Only configured input/output roots are readable;
|
||||
traversal and symlinks escaping those roots are rejected. ffmpeg/ffprobe create
|
||||
thumbnails, dimensions and extracted frames on CPU; they are not inference runtimes.
|
||||
Network protocols are disabled for media inspection. HTTP Range supports seeking.
|
||||
|
||||
Projects: initial preview retains the upstream browser-local project storage.
|
||||
Projects are specific to this browser/origin, not multiuser or cross-device synced.
|
||||
JSON backup and restore are provided. Media is persistent in the mounted input directory.
|
||||
Deleting a project removes its index/metadata, not shared LTX files.
|
||||
|
||||
Security: single shared login, >=16-character operator-provided password, in-memory
|
||||
12-hour sessions, HttpOnly SameSite=Strict cookie, Secure for configured HTTPS,
|
||||
login throttling, same-origin requests, fixed upstream, no Docker socket or GPU
|
||||
access. PUBLIC_ORIGIN must match the user's actual browser address. For remote
|
||||
access use HTTPS or an SSH tunnel; no unencrypted public password login.
|
||||
The existing native LTX API has operator-level functionality; authenticated web
|
||||
users are trusted operators, not isolated tenants. The input directory must be
|
||||
writable only by trusted service accounts. This is a preview, not a public SaaS.
|
||||
|
||||
## Current limitations
|
||||
|
||||
- No native timeline video rendering; FCPXML exports metadata only and references
|
||||
backend media paths. A portable XML/media package needs a later export stage.
|
||||
- No server-side project library, cross-browser synchronization or multiuser roles.
|
||||
- No desktop Hugging Face OAuth, server-folder chooser or Electron updater.
|
||||
- Exact feature support depends on the selected LTX backend/model. Browser porting
|
||||
does not add Retake/Extend support to a model that lacks it.
|
||||
- Another container stack needs access to the same media storage; an API URL alone
|
||||
does not transport backend filesystem files. No SSH/SCP credentials are embedded.
|
||||
- First release validated with a synthetic backend, not a real GPU generation.
|
||||
@@ -0,0 +1,18 @@
|
||||
# Source provenance
|
||||
|
||||
Initial import: local LTX-Athena working tree at commit
|
||||
`68cd86c15e5fd25f56229ea63c0dbcb0338f7812` (version 1.2.7), 2026-09-29.
|
||||
Source directory: LTX-Athena, sibling of this repository.
|
||||
Upstream: https://github.com/Lightricks/LTX-Desktop (Apache-2.0).
|
||||
|
||||
The import includes the user's current frontend changes in use-generation,
|
||||
use-extend, use-retake, GenSpace, generation-input and the shared IPC schema.
|
||||
Only frontend, shared schemas, public assets, build configuration and license
|
||||
notices were copied. No backend, Electron main process, credentials, application
|
||||
state, backups, downloaded weights, or generated user media were imported.
|
||||
The source working tree was not changed.
|
||||
|
||||
Modifications in this fork: browser platform implementation, web application shell,
|
||||
authenticated HTTP transport, shared-directory media operations, Docker packaging,
|
||||
web-specific labels and explicit unsupported desktop functions. This is an
|
||||
independent derivative, not an official Lightricks distribution.
|
||||
@@ -0,0 +1,23 @@
|
||||
# Validation — initial web preview
|
||||
|
||||
2026-09-29:
|
||||
|
||||
- `npm run typecheck`: passed.
|
||||
- `npm run build`: passed. Vite reports a large inherited editor bundle; splitting
|
||||
the editor into a lazy-loaded chunk is a future performance improvement.
|
||||
- `npm test`: 8 tests passed (7 HTTP/media integrations + 1 error-presentation test).
|
||||
- Browser smoke test against `scripts/ui-fixture.mjs`, which never contacts Athena:
|
||||
sign-in; new project; reload and reopen saved project; Gen Space renders backend
|
||||
model options; synthetic native API failure shows a recoverable error dialog;
|
||||
timeline editor opens; synthetic 1-second clip upload/import returns dimensions
|
||||
and thumbnail in the asset library.
|
||||
- Source LTX-Athena working-tree changes left untouched.
|
||||
|
||||
Not verified yet: Docker image build/run on Debian, real LTX generation through
|
||||
Athena Deck's selected Video endpoint, remote file permissions/mount paths,
|
||||
long-running job recovery/cancellation, all editor interactions and all LTX modes.
|
||||
No Athena service was started, stopped or reconfigured during this port.
|
||||
|
||||
The synthetic fixture uses a fixed public test password and isolated temporary
|
||||
media storage on loopback port 18118. Never deploy that fixture as the real service.
|
||||
Production start (`server/index.mjs`) requires an operator-provided password file.
|
||||
Reference in New Issue
Block a user