hive-dashboard: remove the MATRIX credentials tab and its login route
The CR3D3NTIALS page's MATRIX tab was the only caller of `POST /api/matrix-account-login` (provision/log in an external matrix account through the hive) and `GET /api/matrix-accounts` (its account list). External matrix accounts are linked from the swarm UI now (`LinkMatrixAccountForm` -> swarm-controller), so the hive-side UI and both routes go. `priv_client::restart_matrix_daemon` had no other caller and goes with them. Already-provisioned credentials keep working: the `matrix-token-<name>` files and `matrix-account-<name>.json` sidecars the old route wrote are still discovered by hive-matrix-mcp (`accounts::configured` -> `discover_token_accounts`), the `matrix-token*` path unit still re-fires the daemon, and `WriteAgentMatrixToken` stays for the swarm credential worker. Removing that usage waits on moving the existing creds to swarm level. The GITHUB tab is the credentials page's default tab now. Refs #4348
This commit is contained in:
parent
93bbec015f
commit
6a1d85c24f
12 changed files with 35 additions and 972 deletions
|
|
@ -5,9 +5,8 @@ HTTPS, both authenticated by an operator-supplied personal access token
|
|||
(PAT) — so it can run GitHub API calls and push commits without any manual
|
||||
`gh auth login`.
|
||||
|
||||
Provisioning is UI-driven, mirroring the dashboard side of the
|
||||
[matrix account](matrix.md) flow: paste a PAT into the agent's credentials
|
||||
tab and it works. No per-agent nix declaration, no rebuild — hive-c0re
|
||||
Provisioning is UI-driven: paste a PAT into the agent's credentials tab
|
||||
and it works. No per-agent nix declaration, no rebuild — hive-c0re
|
||||
injects the token into the agent's state dir out of band.
|
||||
|
||||
## Enabling
|
||||
|
|
|
|||
|
|
@ -29,7 +29,7 @@ the whole swarm), **Logs** (`/logs.html`, per-agent and host
|
|||
journals), **Stats** (`/stats.html`, swarm-wide usage stats),
|
||||
**Builds** (`/builds.html`, the rebuild queue and build history),
|
||||
**Core** (`/core.html`, tombstones and container resource use), and
|
||||
**Credentials** (`/credentials.html`, provisioning matrix/GitHub/forge
|
||||
**Credentials** (`/credentials.html`, provisioning GitHub/forge
|
||||
accounts per agent). Your local browser preferences (notifications)
|
||||
live in the dashboard's Y3R C4LL tab now, not a separate page.
|
||||
|
||||
|
|
|
|||
|
|
@ -296,60 +296,9 @@ on the H0M3 hub, same minimal chrome as `/logs.html` (a `← home` back-link
|
|||
than `/core.html`'s plain title. Its own esbuild bundle
|
||||
(`credentials.js`); no SSE — it reads `/api/state` once for the (shared)
|
||||
agent picker and otherwise works off purpose-built endpoints per tab.
|
||||
Three sub-tabs:
|
||||
Two sub-tabs:
|
||||
|
||||
### MATRIX tab
|
||||
|
||||
<!-- vale write-good.Passive = NO -->
|
||||
Provision / log in a per-agent **external** matrix account and store its
|
||||
access token (this half is unchanged from the old `/matrix-accounts.html`
|
||||
page it replaces — only the URL and surrounding chrome moved).
|
||||
<!-- vale write-good.Passive = YES -->
|
||||
|
||||
An agent picker (populated from `state.containers`, the live roster) drives a list of that
|
||||
agent's accounts — name, homeserver, user id, and a status dot —
|
||||
read from `GET /api/matrix-accounts?agent=<name>` →
|
||||
`{ accounts: [ { name, homeserver, token_present, live, user_id } ], as_of_unix }`.
|
||||
`token_present` is whether a token is **stored**; the matrix daemon
|
||||
backfills `live`, `homeserver`, and `user_id` from its
|
||||
`matrix-accounts.json` snapshot — a host-visible file it
|
||||
**force-rewrites every ~30s** (a heartbeat), so `as_of_unix` (the
|
||||
snapshot mtime) advances while the daemon is alive and a *stalled* value
|
||||
genuinely means "stopped publishing," not just "old snapshot." An account
|
||||
with a token but absent from the snapshot reports `live: false`.
|
||||
|
||||
The status dot renders these states:
|
||||
|
||||
- **green** — `live` and the container is running: online.
|
||||
- **dim green** — `live` but `as_of_unix` hasn't advanced in > ~90s (3
|
||||
missed heartbeats) while the container is *not* down: the daemon stopped
|
||||
publishing, so the snapshot's `live` is no longer trustworthy (likely
|
||||
dead/wedged). Labelled "online · no heartbeat."
|
||||
- **amber** — `live` but the container is **down** (a stopped container
|
||||
⟹ a dead daemon, so the snapshot is stale); also the `token_present &&
|
||||
!live` "provisioned but offline" case.
|
||||
- **grey** — no token (not provisioned).
|
||||
|
||||
The container-down cross-reference (`/api/state`) takes precedence over
|
||||
the age check. The dashboard tooltips `as_of_unix` ("live as of N ago")
|
||||
throughout so freshness is always legible. When `live` is absent (an older hive-c0re
|
||||
without the snapshot) the dot falls back to a token-present rendering.
|
||||
|
||||
The provision form (account name, homeserver, login method) posts
|
||||
`POST /api/matrix-account-login` (`x-www-form-urlencoded`, operator-auth):
|
||||
fields `agent, account, homeserver, mode=password|token, user_id?,
|
||||
password?, token?` → `200 { ok, user_id }` on success. Failures come back
|
||||
as RFC 9457 `application/problem+json` (`{ type, title, status, detail }`)
|
||||
with the human-readable message in `detail` and the status code reflecting
|
||||
the cause (400 for a validation error, 500 for a login / `whoami` /
|
||||
internal failure); the page reads `detail` for display. The host coordinator performs the login
|
||||
(password) or validates the token (`whoami`) and writes the bearer to
|
||||
the agent's `matrixAccounts.<account>.tokenFile` via the same
|
||||
privileged write path as the hive-internal `matrix-token`; the token is
|
||||
**never** echoed back, and the page clears the secret inputs on submit
|
||||
regardless of outcome. The account list reflects what's *provisioned*
|
||||
(an account with a stored token), so a config-declared-but-unprovisioned
|
||||
account appears only once the operator provisions it through the form.
|
||||
Link an external matrix account from the swarm UI (`LinkMatrixAccountForm` → swarm-controller). Accounts already linked through the old MATRIX tab keep working until the operator moves them to swarm level.
|
||||
|
||||
### GITHUB tab
|
||||
|
||||
|
|
@ -363,10 +312,10 @@ minimally scoped token) and a link to
|
|||
Status reads `GET /api/github-account?agent=<name>` →
|
||||
`{ present: bool }` — whether the agent's `github-token` file exists.
|
||||
There's no live/heartbeat concept for a static PAT, so this is just a
|
||||
"token stored ✓" / "not set" line, unlike MATRIX's status-dot taxonomy.
|
||||
"token stored ✓" / "not set" line.
|
||||
Provisioning posts `POST /api/github-account` (form-encoded `agent`,
|
||||
`token`) → `200 { ok: true }` on success, or the same `error_response`
|
||||
shape `/api/matrix-account-login` uses on failure. The token is never
|
||||
`token`) → `200 { ok: true }` on success; failures come back as RFC 9457
|
||||
`application/problem+json` with the message in `detail`. The token is never
|
||||
echoed back in either direction.
|
||||
|
||||
### FORGES tab
|
||||
|
|
|
|||
Loading…
Reference in a new issue