From 3380c1915f224693dc6c231a12cb6a6bd0af06f8 Mon Sep 17 00:00:00 2001 From: atlas Date: Fri, 2 Oct 2026 20:02:03 +0200 Subject: [PATCH] swarm UI: show the accounts linked to each agent GET /api/hives/{hive}/agents/{agent}/linked-accounts returns one row per account linked to the agent, as kind, name and host: each matrix account under swarm/agents//matrix (with its homeserver, and the agent's own `main` marked reserved), each forge label under swarm/agents//forge (with its url), and github when swarm/agents//github-token exists (host github.com, which is not stored). No credential field is in the response type. Listing those two directories needs a new controller grant: `list` on secret/metadata/swarm/agents/+/matrix and .../+/forge only, pinned in bao-grants.nix as the only metadata stanzas under agents/ beside the queue revocation. Checked against a dev OpenBao 2.6.3: the grant lists those two directories and is refused on agents/, agents//, and a leaf. The swarm UI agent detail panel shows all rows under "accounts"; the table view's matrix column shows the matrix rows. The link badges stay. Refs #4855 --- docs/swarm/ui.md | 18 +- .../src/pages/LinkForgeAccountForm.tsx | 3 +- .../src/pages/LinkGithubAccountForm.tsx | 4 +- .../src/pages/LinkMatrixAccountForm.tsx | 7 +- .../swarm-ui/src/pages/agents/AgentsPage.tsx | 75 +++- .../src/pages/agents/LinkedAccounts.css | 18 + .../src/pages/agents/LinkedAccounts.tsx | 92 +++++ nix/host-modules/swarm-bao.nix | 8 + nix/module-eval/bao-grants.nix | 17 + swarm-controller/README.md | 3 +- swarm-controller/src/linked_accounts.rs | 353 ++++++++++++++++++ swarm-controller/src/main.rs | 2 + swarm-controller/src/matrix_account.rs | 7 +- 13 files changed, 577 insertions(+), 30 deletions(-) create mode 100644 frontend/packages/swarm-ui/src/pages/agents/LinkedAccounts.css create mode 100644 frontend/packages/swarm-ui/src/pages/agents/LinkedAccounts.tsx create mode 100644 swarm-controller/src/linked_accounts.rs diff --git a/docs/swarm/ui.md b/docs/swarm/ui.md index fe33f3cc..e4f96b36 100644 --- a/docs/swarm/ui.md +++ b/docs/swarm/ui.md @@ -23,7 +23,23 @@ An agent created here or with `swarmctl agent create` starts `paused`; set it Each agent on `/agents` opens three dialogs that write a credential for it into the swarm secret store through swarm-controller. All three are blind -set/update actions: no route lists linked accounts or hands a token back. +set/update actions: no route hands a token back. + +The agent's detail panel lists its linked accounts under **accounts**, one row +per account: kind, name and host. The table view's matrix column lists the +matrix rows. Both come from +`GET /api/hives/{hive}/agents/{agent}/linked-accounts`, which returns names +and hosts and never a credential. + +| kind | one row per | name | host | +| ------- | ------------------------------------------- | ----------- | ------------------------ | +| matrix | `swarm/agents//matrix/` | the account | its `homeserver`, if set | +| forgejo | `swarm/agents//forge/