dashboard: hide forge links instead of guessing <hostname>:3000

Adds services.hyperhive.forge.publicUrl (defaults to the gateway vhost
URL when behindGateway=true, null otherwise). HIVE_FORGE_PUBLIC_URL is
now sourced from it instead of hardcoding https://${forge.domain}
whenever behindGateway is on.

The 4 frontend call sites that built a forge link from
state.forge_public_url now hide the link when that's absent, rather
than guessing http://<browser-hostname>:3000 — a guess that's only
correct by accident once the operator isn't on plain localhost. Fixes
the dashboard H0M3 tile, per-agent-row forge links + agent menu, the
approval-queue PR link, and the per-agent page's own meta-nav forge
link (found during this pass, same defect, not in the original
3-site inventory).

Docs + doc-comments updated to match.
This commit is contained in:
iris 2026-08-03 00:30:22 +02:00 committed by mara
commit 3512e4b019
10 changed files with 96 additions and 42 deletions

View file

@ -35,7 +35,10 @@ through. Three flex columns:
Each `NavLink.kind` resolves
differently in the frontend: `Container` → same-origin path
(the agent page is itself container-local); `Forge`
`http://<host>:3000<url>`; `External` → already absolute.
`state.forge_public_url + url` (sourced from
`services.hyperhive.forge.publicUrl`), and the link is omitted
entirely when that's unset — never guessed from `<host>:3000`;
`External` → already absolute.
All anchors are built via `el()` — agent-declared icon /
label / url strings never reach `innerHTML` (XSS-safe by
construction).