| Filename | Latest commit message | Latest commit date |
|---|---|---|
The login-in-progress screen's OAuth-code input was a plain text field — anyone shoulder-surfing or capturing a screenshot of the agent web UI would see the code in cleartext. Same risk applies to dashboard share-screens during live demos. Changes: - input switches to type='password' so the pasted code renders as bullets by default. Placeholder updated to '(hidden)' so the operator knows the masking is intentional, not a browser quirk. - new 'reveal' button (👁) next to the input flips the type back to text on press, so the operator can sanity-check the paste before submitting if she wants. aria-pressed reflects state. - CSS for the reveal button mirrors the existing .btn-login amber family — quiet by default, amber border/glow when pressed. - spellcheck='false' on the input so browsers don't try to underline the random-looking string as a typo. The on-screen OAuth URL stays visible (the operator needs to click it). The code is the secret leg — only the operator's browser holds it, the URL is what was posted publicly to claude's OAuth provider. |
||
| .. | ||
| packages | ||
| .gitignore | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
hyperhive frontend
npm workspaces project for the hyperhive browser-facing assets:
packages/shared/— shared modules used by both surfaces (terminal pane, Catppuccin palette + body typography).packages/dashboard/— the hive-c0re dashboard SPA.packages/agent/— the per-container web UI (default agent page, stats, screen).
Build
npm install # one-off; uses the checked-in package-lock.json
npm run build # builds every workspace into packages/*/dist/
The Rust binaries serve packages/dashboard/dist/ and
packages/agent/dist/ via tower_http::ServeDir at runtime; the
build derivation is wired up in nix/modules/frontend.nix. Per-agent
additions are layered on top of the default agent dist via the
hyperhive.frontend.extraFiles option in agent.nix.
Why npm + esbuild
- Hermetic: dependencies vendored via the checked-in lockfile;
buildNpmPackagein nix uses it as the source-of-truth so the output is reproducible without network access at build time. - esbuild: vanilla-JS bundler, no framework runtime overhead.
Each workspace's
build.mjsis ~30 lines. - Single-PR migration: see issue #273 for the design proposal and the four-commit shape (npm scaffold → nix derivations → container plumbing → Rust cutover).