extra-forges: fully dashboard-provisioned, no host config
Per mara's feedback on PR #2407 ("better: you can also provide url in dashboard, same as with matrix, no host config"), drops services.hyperhive.extraForges and the admin-API mint/revoke flow entirely. The operator now creates a token on the external forge themselves and pastes a label + base URL + access token into the dashboard's FORGES tab, the same shape as the GitHub PAT flow plus the base-URL field from the matrix extra-account flow. hive-c0re only ever writes/deletes two local files per account (forge-<label>-token, forge-<label>.json sidecar for the URL) via hive-priv — no remote account creation, no admin token, no revoke-on-the-remote-side, no nix config to enumerate. - nix/host-modules/hive-forge/default.nix: removed the extraForges option, its label-format assertion, and the HYPERHIVE_EXTRA_FORGES env forwarding. - hive-c0re/src/forge/extra.rs: deleted (REST admin-API provisioning, no longer needed). - hive-c0re/src/dashboard/extra_forges.rs: GET /api/extra-forges? agent= lists an agent's stored forges by scanning its state dir (mirrors matrix_accounts.rs's filename-scan listing), POST /api/extra-forge-account (agent/label/base_url/token/ action=add|remove) stores or removes an account. - hive-sh4re/priv_proto.rs + hive-priv/main.rs: new WriteAgentExtraForgeAccount/DeleteAgentExtraForgeAccount priv requests (adds base_url, writes/deletes a JSON sidecar alongside the token). - hive-c0re/src/priv_client.rs: matching wrapper functions. - frontend/packages/dashboard/src/credentials.{html,js}: FORGES tab is a per-agent list + add-account paste form (label/base_url/token), no grant/revoke-from-catalog UI. - docs/web-ui/dashboard.md: FORGES tab section rewritten. Supersedes the design in PR #2407 (already approved+green on the old admin-API model) — opening as a fresh PR against the same issues rather than force-pushing over the approved one.
This commit is contained in:
parent
f025f32ccb
commit
dbf880ac66
10 changed files with 558 additions and 2 deletions
|
|
@ -31,7 +31,10 @@ use crate::paths::FORGE_CORE_TOKEN as CORE_TOKEN_PATH;
|
|||
// build.
|
||||
/// Per-agent token scopes (broad-but-not-admin). See
|
||||
/// `docs/forge.md::Token scopes` for the per-scope rationale.
|
||||
const TOKEN_SCOPES: &str = "read:user,write:user,read:notification,write:notification,write:repository,write:issue,write:organization,write:misc";
|
||||
/// `pub(super)` — also reused by `extra.rs`'s external-forge
|
||||
/// provisioning so a granted agent gets the same scope set on an
|
||||
/// extra forge as on the internal one.
|
||||
pub(super) const TOKEN_SCOPES: &str = "read:user,write:user,read:notification,write:notification,write:repository,write:issue,write:organization,write:misc";
|
||||
|
||||
/// Bootstrap `core` token scopes — adds `read:admin,write:admin` on
|
||||
/// top of `TOKEN_SCOPES` so the host daemon can drive
|
||||
|
|
|
|||
Loading…
Reference in a new issue