Watch
0
0
Fork
You've already forked hyperhive
0

hive-dashboard: remove the MATRIX credentials tab and its login route

The CR3D3NTIALS page's MATRIX tab was the only caller of
`POST /api/matrix-account-login` (provision/log in an external matrix
account through the hive) and `GET /api/matrix-accounts` (its account
list). External matrix accounts are linked from the swarm UI now
(`LinkMatrixAccountForm` -> swarm-controller), so the hive-side UI and
both routes go. `priv_client::restart_matrix_daemon` had no other caller
and goes with them.

Already-provisioned credentials keep working: the `matrix-token-<name>`
files and `matrix-account-<name>.json` sidecars the old route wrote are
still discovered by hive-matrix-mcp (`accounts::configured` ->
`discover_token_accounts`), the `matrix-token*` path unit still re-fires
the daemon, and `WriteAgentMatrixToken` stays for the swarm credential
worker. Removing that usage waits on moving the existing creds to
swarm level.

The GITHUB tab is the credentials page's default tab now.

Refs #4348
This commit is contained in:
atlas 2026-09-29 10:40:40 +02:00 • committed by mara
commit 6a1d85c24f
12 changed files with 35 additions and 972 deletions

View file

@ -24,10 +24,9 @@
//! already has a bearer token) and `password` (this daemon performs
//! `m.login.password` against the caller-given homeserver itself and stores
//! the resulting token; the password is never stored, and is not sent to the
//! hive either — only the derived token is). Mirrors what hive-c0re's own
//! `/api/matrix-account-login` does for a *hive-local* account, done here
//! instead so the browser never has to hold the password long enough to call
//! an arbitrary homeserver directly.
//! hive either — only the derived token is). Done here so the browser never
//! has to hold the password long enough to call an arbitrary homeserver
//! directly.
use axum::Json;
use axum::extract::State;
@ -177,9 +176,8 @@ pub async fn put_matrix_account(
// module owns that `matrixAccounts` entry, which is why this route
// refuses to write one: an extra account literally named `main` would
// not overwrite the real one (it lands at a different token-file suffix)
// but would confuse anything that lists accounts by name. Same guard
// hive-c0re's own `/api/matrix-account-login` applies, checked before any
// mode-specific work (including a network login) runs.
// but would confuse anything that lists accounts by name. Checked
// before any mode-specific work (including a network login) runs.
if is_reserved_account(&account) {
return Err(error_problem(
StatusCode::BAD_REQUEST,