Skip to content

feat(ai-summary): add client-side AI activity summary page - #922

Merged
ErikBjare merged 10 commits into
ActivityWatch:masterfrom
TimeToBuildBob:feat/ai-activity-summary
Aug 3, 2026
Merged

ErikBjare merged 10 commits into
ActivityWatch:masterfrom
TimeToBuildBob:feat/ai-activity-summary

Conversation

@TimeToBuildBob

@TimeToBuildBob TimeToBuildBob commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds an experimental, dev-mode-only /analysis/activity page for trying a client-side LLM summary of ActivityWatch window data.

  • Fetches local window events through the configured ActivityWatch client
  • Aggregates events by application before any provider request
  • Supports fixed OpenAI and Anthropic endpoints
  • Keeps the API key in page memory only; it is cleared on reload and never sent to aw-server
  • Persists only non-secret provider/model preferences
  • Shows the exact compact activity text sent to the provider
  • Includes date-range selection, custom prompt, response display, and copy action
  • Hides the Tools entry unless dev mode is enabled
  • Links to the ActivityWatch querying guide for deeper agent-based analysis

Experimental/privacy scope

This is a prototype, not the recommended end-user path for ActivityWatch + AI. Clicking Generate sends the displayed application names and durations to the selected third-party provider. The UI says so before the request, and the feature is hidden from the default navigation.

The broader product direction—local or subscription-backed agent workflows plus proper documentation built around ActivityWatch exporting/analysis and the canonical query—is tracked in ActivityWatch/activitywatch#1388. Richer, privacy-bounded single-pass context is tracked in #925. Neither belongs in this prototype PR.

Test plan

  • CI unit tests, lint, builds, and CodeQL pass
  • Tools entry is visible in dev mode and hidden otherwise
  • Route uses the intent-based /analysis/activity namespace
  • API key is not persisted
  • Unsupported stale provider settings are discarded
  • Provider requests use only CSP-allowed fixed endpoints
  • Raw aggregated text can be inspected before/after generation
  • Page links to the current querying documentation

Prototype toward #883; does not close the broader issue.

Comment thread src/util/aiSummary.ts Fixed
@codecov

codecov Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 88.67925% with 6 lines in your changes missing coverage. Please review.
✅ Project coverage is 39.93%. Comparing base (009f484) to head (329fe5f).

Files with missing lines Patch % Lines
src/util/aiSummary.ts 88.46% 6 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master     #922      +/-   ##
==========================================
+ Coverage   38.80%   39.93%   +1.13%     
==========================================
  Files          43       44       +1     
  Lines        2278     2331      +53     
  Branches      461      477      +16     
==========================================
+ Hits          884      931      +47     
- Misses       1315     1321       +6     
  Partials       79       79              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@greptile-apps

greptile-apps Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

The PR adds a browser-based AI activity-summary page that loads window events through the configured ActivityWatch client and sends an aggregated top-application summary to OpenAI or Anthropic.

  • Adds the /ai-summary route and Tools navigation entry.
  • Adds event aggregation, prompt formatting, provider request, and configuration helpers with unit tests.
  • Adds fixed provider origins to the page’s CSP and removes the earlier arbitrary custom-provider path.
  • Keeps API keys in page memory while persisting non-secret provider and model settings.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failure remains; the configured-client, CSP, event-limit, and stale custom-configuration issues reported in earlier threads are addressed at the current head.

Important Files Changed

Filename Overview
src/views/AISummaryView.vue Adds the complete summary-generation UI and now retrieves uncapped events through the configured AWClient.
src/util/aiSummary.ts Implements aggregation, formatting, non-secret configuration persistence, stale custom-provider migration, and fixed OpenAI/Anthropic requests.
index.html Extends connect-src to authorize the two fixed provider origins while preserving existing ActivityWatch and GitHub sources.
test/unit/aiSummary.test.node.ts Covers aggregation, formatting, secret-free persistence, stale-provider migration, and fixed provider request URLs.
src/route.js Registers the lazily loaded AI Summary route.
src/components/Header.vue Adds the AI Summary page to the Tools menu.

Sequence Diagram

sequenceDiagram
  participant U as User
  participant V as AI Summary View
  participant C as Configured AWClient
  participant S as aw-server
  participant L as LLM Provider
  U->>V: Select host, range, provider, and model
  V->>C: "getEvents(bucket, start, end, limit=-1)"
  C->>S: Authenticated event request
  S-->>C: Window events
  C-->>V: Events
  V->>V: Aggregate duration by application
  V->>L: Send prompt and aggregated summary
  L-->>V: Generated activity summary
  V-->>U: Display response and raw-data toggle
Loading

Reviews (5): Last reviewed commit: "fix(ai-summary): reset stale custom mode..." | Re-trigger Greptile

Comment thread src/views/AISummaryView.vue Outdated
Comment thread src/util/aiSummary.ts Outdated
Comment thread src/views/AISummaryView.vue Outdated
Comment thread src/util/aiSummary.ts Fixed
@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

@greptileai review

Comment thread index.html
@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

@greptileai review

Comment thread src/views/AISummaryView.vue
@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

@greptileai review

Comment thread src/util/aiSummary.ts
@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

@greptileai review

@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

CI-green and mergeable (Greptile 5/5) — waiting only on a maintainer click.

This PR is ready to merge, but the bot has pull-only access to this repo and can't self-merge — surfacing it here so it isn't lost. The monitoring loop will stop re-flagging it now that this note is posted.

@ErikBjare

Copy link
Copy Markdown
Member

@TimeToBuildBob This is an interesting concept/idea to play with, but I don't think it should appear by default (hide under dev mode at the least) and might need a better approach and proper docs for "how to use ActivityWatch with agents/AI" as an extension to the exporting and analysis docs (using the "canonical query" etc).

I also don't like the idea that we are basically suggesting to users to send all their data to OpenAI/Anthropic API (feels iffy with private/personal data tbh) and use API key pricing (although request-volume is low, it's not the path we want to suggest) instead of existing subscriptions they may have.

Adding API key every time etc is also very annoying, I get that this is a first version, but definately needs better gating to now be widely shown in this early state.

Also, the /ai-summary path is bad, come up with a better path.

TimeToBuildBob and others added 9 commits August 3, 2026 08:06
Adds a new /ai-summary route that lets users generate an LLM-powered
summary of their activity data directly in the browser.

- Client-side only: queries AW's local REST API for window events,
  aggregates by app, and sends a compact summary to the user's
  configured LLM endpoint
- Supports OpenAI, Anthropic, and custom OpenAI-compatible providers
- API key stored in localStorage only — never sent to the AW server
- Date range selection: 7d / 30d / 90d
- Shows raw aggregated data used in prompt (toggle)
- Copy-to-clipboard for the LLM response
- Nav link added to Tools dropdown
- 11 unit tests for aggregation and formatting logic

Closes: ActivityWatch#883
CodeQL flagged cleartext storage of the API key in localStorage as a
high-severity vulnerability. API keys are sensitive credentials; storing
them in localStorage persists them on disk indefinitely and exposes them
to any same-origin JS across browser sessions.

Split storage: non-sensitive config (provider, model, baseUrl) stays in
localStorage for cross-session convenience; apiKey goes to sessionStorage,
which is scoped to the browser tab and never written to disk.
@TimeToBuildBob
TimeToBuildBob force-pushed the feat/ai-activity-summary branch from 0bd203b to 2e9b251 Compare August 3, 2026 08:12
@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

Agreed on the gating and privacy concerns. I pushed 2e9b251 to hide the entry behind dev mode and renamed the route from /ai-summary to /activity-analysis.

I’m deliberately not treating the current OpenAI/Anthropic API-key flow as a user-facing recommendation or expanding it further in this PR. The better product direction is local/subscription-backed agent workflows plus proper “ActivityWatch with agents/AI” docs built around exporting/analysis and the canonical query. That broader design needs a separate pass rather than getting smuggled into this prototype.

The API key remains memory-only (not stored), but yes, re-entering it is intentionally awkward and another signal that this is experimental rather than ready for default exposure.

@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

Monitoring follow-up: all required checks are green on 2e9b251, the PR is mergeable, and there are no unresolved review threads. I also corrected the stale PR description: this is now explicitly a dev-mode-only privacy-sensitive prototype at /activity-analysis; the API key is memory-only, and this PR no longer claims to close the broader #883 docs/product-direction work. Ready for maintainer review.

@ErikBjare

Copy link
Copy Markdown
Member

@TimeToBuildBob I would prefer /analysis/activity (i want some kind of intent/category-based namespace), or /tools/llm, or something like that. Also think further about which other/more descriptive statistics to include to the LLM context (since it's a single-pass without tools). And add a link to docs (TODO?) most relevant for using agents with ActivityWatch (when the user outgrows the basic analysis offered inside ActivityWatch itself). You should create those issues/tasks now (if they don't exist already, or update the existing ones), for the things that don't go in this PR.

@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

Addressed the in-PR pieces in 329fe5f: the prototype now lives at /analysis/activity, and the page links to the existing ActivityWatch querying guide as the current next step for deeper agent-based analysis.\n\nI searched for existing trackers and created the two distinct follow-ups you requested instead of expanding this prototype:\n\n- #925 — richer, bounded single-pass context (AFK-filtered active time, title counts, domains, categories, temporal/focus statistics, inspectable payload)\n- ActivityWatch/activitywatch#1388 — privacy-first “ActivityWatch with agents/AI” documentation built around querying/export, canonical AFK filtering, local aggregation, and local/subscription-backed workflows\n\nI am not adding those richer statistics or writing the full docs in this PR because both would materially expand its current dev-mode prototype scope. Targeted tests and lint pass locally; CI is now running on the new commit.

@TimeToBuildBob

Copy link
Copy Markdown
Contributor Author

CI is fully green on 329fe5f across lint, both builds, CodeQL, and all three server test matrices. The requested route namespace, temporary docs link, and separately scoped follow-up issues are now in place. Ready for your review.

@ErikBjare
ErikBjare merged commit 1be5633 into ActivityWatch:master Aug 3, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants