hive-dashboard: remove the MATRIX credentials tab and its login route
The CR3D3NTIALS page's MATRIX tab was the only caller of `POST /api/matrix-account-login` (provision/log in an external matrix account through the hive) and `GET /api/matrix-accounts` (its account list). External matrix accounts are linked from the swarm UI now (`LinkMatrixAccountForm` -> swarm-controller), so the hive-side UI and both routes go. `priv_client::restart_matrix_daemon` had no other caller and goes with them. Already-provisioned credentials keep working: the `matrix-token-<name>` files and `matrix-account-<name>.json` sidecars the old route wrote are still discovered by hive-matrix-mcp (`accounts::configured` -> `discover_token_accounts`), the `matrix-token*` path unit still re-fires the daemon, and `WriteAgentMatrixToken` stays for the swarm credential worker. Removing that usage waits on moving the existing creds to swarm level. The GITHUB tab is the credentials page's default tab now. Refs #4348
This commit is contained in:
parent
93bbec015f
commit
6a1d85c24f
12 changed files with 35 additions and 972 deletions
|
|
@ -12,7 +12,7 @@
|
|||
</head>
|
||||
<body class="cred-shell">
|
||||
<!-- Minimal chrome: back link + sub-tab strip, same pattern as
|
||||
logs.html (MATRIX / GITHUB instead of AGENT/INFRA/SYSTEM). Back
|
||||
logs.html (GITHUB / FORGES instead of AGENT/INFRA/SYSTEM). Back
|
||||
link points to the H0M3 hub (served at /). -->
|
||||
<header class="page-header">
|
||||
<a class="page-back" href="/">← home</a>
|
||||
|
|
@ -25,123 +25,14 @@
|
|||
</header>
|
||||
|
||||
<main class="cred-main">
|
||||
<!-- Agent picker: shared across both tabs (one agent selected at a
|
||||
time drives both the matrix account list and the github status). -->
|
||||
<!-- Agent picker: shared across the tabs (one agent selected at a
|
||||
time drives both the github status and the forge list). -->
|
||||
<h3>◇ agent</h3>
|
||||
<label class="ma-field">
|
||||
<span>agent</span>
|
||||
<select id="ma-agent"></select>
|
||||
</label>
|
||||
|
||||
<!-- MATRIX tab: unchanged from the old /matrix-accounts.html, just
|
||||
moved under a tab pane. -->
|
||||
<section
|
||||
class="cred-pane"
|
||||
id="cred-pane-matrix"
|
||||
data-tab-pane="matrix"
|
||||
role="tabpanel"
|
||||
aria-labelledby="cred-tab-matrix"
|
||||
>
|
||||
<p class="meta">
|
||||
provision or log in an <strong>external</strong> matrix account for an
|
||||
agent and store its access token. the token is written to the agent's
|
||||
<code>matrixAccounts.<account>.tokenFile</code> by the host
|
||||
coordinator — it is never displayed back on this page.
|
||||
</p>
|
||||
|
||||
<h3>◇ provisioned accounts</h3>
|
||||
<p class="meta">
|
||||
accounts that have a stored token (provision one below to add it
|
||||
here); a config-declared account that hasn't been provisioned yet
|
||||
won't appear until it has a token. status reflects whether a
|
||||
<em>token is stored</em>, not a live session — a true
|
||||
online/offline indicator is a follow-up that needs the daemon's
|
||||
account registry.
|
||||
</p>
|
||||
<div id="ma-list" class="ma-list">
|
||||
<p class="meta">select an agent to see its matrix accounts.</p>
|
||||
</div>
|
||||
|
||||
<h3>◇ provision / log in</h3>
|
||||
<form id="ma-form" class="ma-form" autocomplete="off">
|
||||
<label class="ma-field">
|
||||
<span>account name</span>
|
||||
<input
|
||||
type="text"
|
||||
name="account"
|
||||
placeholder="e.g. public"
|
||||
required
|
||||
/>
|
||||
</label>
|
||||
<label class="ma-field">
|
||||
<span>homeserver</span>
|
||||
<input
|
||||
type="text"
|
||||
name="homeserver"
|
||||
placeholder="https://matrix.org"
|
||||
required
|
||||
/>
|
||||
</label>
|
||||
|
||||
<fieldset class="ma-mode">
|
||||
<legend>login method</legend>
|
||||
<label
|
||||
><input type="radio" name="mode" value="password" checked />
|
||||
password</label
|
||||
>
|
||||
<label
|
||||
><input type="radio" name="mode" value="token" /> existing
|
||||
token</label
|
||||
>
|
||||
</fieldset>
|
||||
|
||||
<div id="ma-pw-fields" class="ma-modefields">
|
||||
<label class="ma-field">
|
||||
<span>user id</span>
|
||||
<input
|
||||
type="text"
|
||||
name="user_id"
|
||||
placeholder="@user:matrix.org"
|
||||
autocomplete="username"
|
||||
/>
|
||||
</label>
|
||||
<label class="ma-field">
|
||||
<span>password</span>
|
||||
<input
|
||||
type="password"
|
||||
name="password"
|
||||
autocomplete="new-password"
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
|
||||
<div id="ma-token-fields" class="ma-modefields" hidden>
|
||||
<label class="ma-field">
|
||||
<span>access token</span>
|
||||
<input type="password" name="token" autocomplete="off" />
|
||||
</label>
|
||||
<label class="ma-field">
|
||||
<span
|
||||
>user id
|
||||
<span class="meta"
|
||||
>(optional — derived via whoami)</span
|
||||
></span
|
||||
>
|
||||
<input
|
||||
type="text"
|
||||
name="user_id"
|
||||
placeholder="@user:matrix.org"
|
||||
/>
|
||||
</label>
|
||||
</div>
|
||||
|
||||
<button type="submit" class="btn btn-spawn">
|
||||
log in & store token
|
||||
</button>
|
||||
<p id="ma-result" class="ma-result" aria-live="polite"></p>
|
||||
</form>
|
||||
</section>
|
||||
|
||||
<!-- GITHUB tab: single-account PAT paste. No login flow — the
|
||||
operator pastes an existing PAT for a dedicated bot account.
|
||||
Security-warning banner + a link to generate a PAT. -->
|
||||
|
|
@ -151,7 +42,6 @@
|
|||
data-tab-pane="github"
|
||||
role="tabpanel"
|
||||
aria-labelledby="cred-tab-github"
|
||||
hidden
|
||||
>
|
||||
<hive-warn level="warning">
|
||||
⚠ use a <strong>dedicated bot account</strong>, not a human's —
|
||||
|
|
@ -194,7 +84,7 @@
|
|||
|
||||
<!-- FORGES tab: external Forgejo/Gitea/Codeberg-compatible forges.
|
||||
Entirely dashboard-provisioned, no host-side nix config — same
|
||||
shape as GITHUB plus a base-URL field (like MATRIX's homeserver).
|
||||
shape as GITHUB plus a base-URL field.
|
||||
The operator creates a token on the external forge themselves
|
||||
(however that forge lets them) and pastes label + URL + token
|
||||
below. No remote account minting/revoking — purely local. -->
|
||||
|
|
|
|||
Loading…
Reference in a new issue