Skip to content

Commit 49d3c4b

Browse files
wgsimclaude
andcommitted
docs: Update README architecture and directory structure for v2.0.13
Major updates: - Expanded architecture section with high-level flow, session isolation, and security architecture details - Added detailed directory structure for both installation (~/.claude-glm-mcp) and runtime (~/.claude-glm) directories - Documented v2.0.0+ session isolation design - Explained security layers (PATH hardening, absolute paths, execution order) - Clarified symlink strategy (shared plugins/projects, isolated settings) - Removed 'external' qualifier from security review mention These updates reflect the current v2.0.13 production architecture with comprehensive session isolation and security hardening. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
1 parent 1be5ddf commit 49d3c4b

1 file changed

Lines changed: 75 additions & 18 deletions

File tree

‎README.md‎

Lines changed: 75 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111

1212
No more API keys in config files. No more credential leaks. Just secure, isolated sessions backed by your OS credential manager.
1313

14-
> **🔒 Security-First Design**: 10 rounds of external security review • Zero known vulnerabilities • PASS verdict from independent auditors
14+
> **🔒 Security-First Design**: Comprehensive security review • Zero known vulnerabilities • PASS verdict from security auditors
1515
>
1616
> **🚀 Production Ready**: Automated secret scanning • Pre-commit hooks • Comprehensive credential protection • Session isolation
1717
@@ -64,38 +64,95 @@ claude-by-glm --glm-version # GLM MCP Wrapper version
6464

6565
## Architecture
6666

67+
### High-Level Flow
68+
6769
```
68-
claude-by-glm
69-
↓ (sets GLM_MODE=1)
70+
User runs: claude-by-glm [arguments]
71+
↓
72+
1. Set CLAUDE_CONFIG_DIR=~/.claude-glm (session isolation)
73+
2. Fetch API key from platform credential storage
74+
(macOS Keychain / Linux libsecret / Windows ENV)
75+
3. Set GLM_MODE=1 (optional MCP activation)
76+
4. Launch Claude Code with isolated config
77+
↓
7078
Claude Code reads ~/.claude.json
79+
↓ (if GLM_MODE=1 and GLM_USE_MCP=1)
80+
glm-mcp-wrapper
7181
↓
72-
glm-mcp-wrapper (activated by GLM_MODE)
73-
↓ (fetches API key from keychain)
74-
Z.ai MCP Server
82+
Z.ai MCP Server (optional)
83+
```
84+
85+
### Session Isolation (v2.0.0+)
86+
87+
GLM sessions use separate config directory to prevent settings pollution:
88+
89+
```
90+
Official Claude: uses ~/.claude/
91+
GLM Sessions: uses ~/.claude-glm/
92+
↓
93+
Isolated settings, plugins, projects
94+
No interference with official Claude sessions
95+
```
96+
97+
### Security Architecture (v2.0.13)
98+
99+
```
100+
Security Layers:
101+
1. Trusted PATH (/usr/bin:/bin:/usr/sbin:/sbin)
102+
2. All external commands use absolute paths
103+
3. Session setup completes BEFORE credential fetch
104+
4. Credentials never exposed to user-modifiable PATH
105+
5. Platform credential storage (never in config files)
106+
6. Session cleanup on exit
75107
```
76108

77-
## Installation Directory
109+
## Directory Structure
110+
111+
### Installation Directory (~/.claude-glm-mcp/)
112+
113+
Where the wrapper is installed:
78114

79115
```
80116
~/.claude-glm-mcp/
81117
├── bin/
118+
│ ├── claude-by-glm # Main launcher (sets up environment)
82119
│ ├── glm-mcp-wrapper # MCP wrapper (GLM_MODE aware)
83-
│ ├── install-key.sh # API key registration
84-
│ └── claude-by-glm # Main launcher
120+
│ ├── install-key.sh # API key registration utility
121+
│ └── glm-cleanup-sessions # Session cleanup utility
85122
├── config/
86-
│ └── mcp.conf # MCP configuration (GLM_USE_MCP)
123+
│ └── mcp.conf # MCP configuration (GLM_USE_MCP=0/1)
87124
├── credentials/
88-
│ ├── common.sh # Credential abstraction layer
89-
│ ├── macos.sh # macOS Keychain
90-
│ ├── linux.sh # Linux libsecret
91-
│ ├── windows.sh # Windows env var
92-
│ └── security.conf # Centralized configuration
125+
│ ├── common.sh # Platform abstraction layer
126+
│ ├── macos.sh # macOS Keychain operations
127+
│ ├── linux.sh # Linux libsecret operations
128+
│ ├── windows.sh # Windows environment variable
129+
│ └── security.conf # Credential storage configuration
93130
├── scripts/
94-
│ ├── install.sh # Installer
95-
│ └── uninstall.sh # Uninstaller
131+
│ ├── common-utils.sh # Shared utility functions
132+
│ ├── install.sh # Installation script
133+
│ └── uninstall.sh # Uninstallation script
96134
└── backups/
97-
└── .claude.json.backup.*
135+
└── .claude.json.backup.* # Automatic backups
136+
```
137+
138+
### Runtime Directory (~/.claude-glm/)
139+
140+
Where GLM sessions run (v2.0.0+ session isolation):
141+
98142
```
143+
~/.claude-glm/
144+
├── settings.json # GLM session settings (isolated)
145+
├── settings.local.json # Local overrides (isolated)
146+
├── glm-sessions/ # Temporary session files
147+
│ └── glm-<timestamp>-<pid>.json
148+
├── plugins/ → symlink to ~/.claude/plugins/
149+
├── commands/ → symlink to ~/.claude/commands/
150+
├── projects/ → symlink to ~/.claude/projects/
151+
├── todos/ → symlink to ~/.claude/todos/
152+
└── CLAUDE.md → symlink to ~/.claude/CLAUDE.md
153+
```
154+
155+
**Key Design**: Settings are isolated, but plugins/projects are shared via symlinks.
99156

100157
## Requirements
101158

0 commit comments

Comments
 (0)