Create standalone browser port of LTX Athena with authenticated native API transport

This commit is contained in:
Mikei386
2026-09-29 17:59:23 +02:00
commit 1333b0c36b
202 changed files with 63054 additions and 0 deletions
+55
View File
@@ -0,0 +1,55 @@
# Architecture
Browser (React, inherited Gen Space and timeline)
→ Node web service (session authentication, file I/O, streaming HTTP forwarding)
→ Athena Deck shared API port in Video mode
→ original LTX Desktop backend.
The backend address may alternatively point directly to the native LTX API.
The web service forwards `/ltx/api/...` to `/api/...`, preserving method, body,
query, response status and body. No model-specific request translation. A fixed,
operator-configured upstream prevents browser-controlled proxy targets. Tokens
are loaded from files at startup and never sent to the browser. Native streaming
HTTP responses and polling are supported; WebSocket forwarding is not implemented.
`frontend/lib/web-platform.ts` implements the inherited typed `electronAPI` boundary
in the browser. It is an OS/file integration replacement, not a model API adapter.
The application shell no longer calls Python installers, model setup, first-run
license acceptance, Electron updates or backend process start/stop. Unsupported
functions throw explicit errors; timeline rendering is visibly disabled.
Media: browsers cannot send server paths without first uploading. File dialogs
upload immediately; drag-and-drop uses temporary blob URLs until a generation or
asset import resolves the file. Server stores UUID filenames in a shared input
folder; its backend-visible path is returned. The web service and LTX must see the
SAME files (Docker bind mounts can expose different absolute paths). Existing LTX
outputs are mounted read-only. Only configured input/output roots are readable;
traversal and symlinks escaping those roots are rejected. ffmpeg/ffprobe create
thumbnails, dimensions and extracted frames on CPU; they are not inference runtimes.
Network protocols are disabled for media inspection. HTTP Range supports seeking.
Projects: initial preview retains the upstream browser-local project storage.
Projects are specific to this browser/origin, not multiuser or cross-device synced.
JSON backup and restore are provided. Media is persistent in the mounted input directory.
Deleting a project removes its index/metadata, not shared LTX files.
Security: single shared login, >=16-character operator-provided password, in-memory
12-hour sessions, HttpOnly SameSite=Strict cookie, Secure for configured HTTPS,
login throttling, same-origin requests, fixed upstream, no Docker socket or GPU
access. PUBLIC_ORIGIN must match the user's actual browser address. For remote
access use HTTPS or an SSH tunnel; no unencrypted public password login.
The existing native LTX API has operator-level functionality; authenticated web
users are trusted operators, not isolated tenants. The input directory must be
writable only by trusted service accounts. This is a preview, not a public SaaS.
## Current limitations
- No native timeline video rendering; FCPXML exports metadata only and references
backend media paths. A portable XML/media package needs a later export stage.
- No server-side project library, cross-browser synchronization or multiuser roles.
- No desktop Hugging Face OAuth, server-folder chooser or Electron updater.
- Exact feature support depends on the selected LTX backend/model. Browser porting
does not add Retake/Extend support to a model that lacks it.
- Another container stack needs access to the same media storage; an API URL alone
does not transport backend filesystem files. No SSH/SCP credentials are embedded.
- First release validated with a synthetic backend, not a real GPU generation.
+18
View File
@@ -0,0 +1,18 @@
# Source provenance
Initial import: local LTX-Athena working tree at commit
`68cd86c15e5fd25f56229ea63c0dbcb0338f7812` (version 1.2.7), 2026-09-29.
Source directory: LTX-Athena, sibling of this repository.
Upstream: https://github.com/Lightricks/LTX-Desktop (Apache-2.0).
The import includes the user's current frontend changes in use-generation,
use-extend, use-retake, GenSpace, generation-input and the shared IPC schema.
Only frontend, shared schemas, public assets, build configuration and license
notices were copied. No backend, Electron main process, credentials, application
state, backups, downloaded weights, or generated user media were imported.
The source working tree was not changed.
Modifications in this fork: browser platform implementation, web application shell,
authenticated HTTP transport, shared-directory media operations, Docker packaging,
web-specific labels and explicit unsupported desktop functions. This is an
independent derivative, not an official Lightricks distribution.
+23
View File
@@ -0,0 +1,23 @@
# Validation — initial web preview
2026-09-29:
- `npm run typecheck`: passed.
- `npm run build`: passed. Vite reports a large inherited editor bundle; splitting
the editor into a lazy-loaded chunk is a future performance improvement.
- `npm test`: 8 tests passed (7 HTTP/media integrations + 1 error-presentation test).
- Browser smoke test against `scripts/ui-fixture.mjs`, which never contacts Athena:
sign-in; new project; reload and reopen saved project; Gen Space renders backend
model options; synthetic native API failure shows a recoverable error dialog;
timeline editor opens; synthetic 1-second clip upload/import returns dimensions
and thumbnail in the asset library.
- Source LTX-Athena working-tree changes left untouched.
Not verified yet: Docker image build/run on Debian, real LTX generation through
Athena Deck's selected Video endpoint, remote file permissions/mount paths,
long-running job recovery/cancellation, all editor interactions and all LTX modes.
No Athena service was started, stopped or reconfigured during this port.
The synthetic fixture uses a fixed public test password and isolated temporary
media storage on loopback port 18118. Never deploy that fixture as the real service.
Production start (`server/index.mjs`) requires an operator-provided password file.