An operator now links an agent's external forge account (label, base URL, token) in the swarm UI. swarm-controller stores it at swarm/agents/<agent>/forge/<label>. There is no index: the store's listing of the agent's forge/ directory is the set of accounts. In the agent, hive-agent-forge-accounts (oneshot + 2-minute timer, as the agent user, under its own store certificate) lists swarm/agents/<agent>/forge/ with the `list` #4866 grants an agent on its own metadata subtree, reads each account, and writes <state>/forge-<label>-token and forge-<label>.json in the names and shape hive-forge -f already reads. An empty listing (a 404, which `bao kv list -format=json` answers with `{}` and an empty stderr) is zero accounts; a denial or an unreachable store fails the unit. It never deletes: files for labels not listed, including ones the hive wrote, stay as they are. Removed: the dashboard FORGES tab (credentials.js/html section and its CSS), hive-c0re's extra_forges.rs and its routes, priv_client's extra-forge calls, and hive-priv's WriteAgentExtraForgeAccount / DeleteAgentExtraForgeAccount with their helpers. The GITHUB tab and WriteAgentGithubToken stay. Also: persistence.md's matrix avatar note names the exit-75 restart on a changed account listing, not the dashboard, as what brings a linked account up. Refs #4348
87 lines
3.2 KiB
HTML
87 lines
3.2 KiB
HTML
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
|
<title>hyperhive // CR3D3NTIALS</title>
|
|
<link rel="icon" type="image/svg+xml" href="/favicon.svg" />
|
|
<link rel="stylesheet" href="/static/colors.css" />
|
|
<link rel="stylesheet" href="/static/theme.css" />
|
|
<link rel="stylesheet" href="/static/common.css" />
|
|
<link rel="stylesheet" href="/static/credentials.css" />
|
|
</head>
|
|
<body class="cred-shell">
|
|
<!-- Minimal chrome: back link + sub-tab strip, same pattern as
|
|
logs.html (GITHUB instead of AGENT/INFRA/SYSTEM). Back
|
|
link points to the H0M3 hub (served at /). -->
|
|
<header class="page-header">
|
|
<a class="page-back" href="/">← home</a>
|
|
<hive-tab-strip
|
|
class="hive-tabbar cred-tabbar"
|
|
id="cred-tabbar"
|
|
prefix="cred"
|
|
role="tablist"
|
|
></hive-tab-strip>
|
|
</header>
|
|
|
|
<main class="cred-main">
|
|
<!-- Agent picker: the selected agent drives the github status. -->
|
|
<h3>◇ agent</h3>
|
|
<label class="ma-field">
|
|
<span>agent</span>
|
|
<select id="ma-agent"></select>
|
|
</label>
|
|
|
|
<!-- GITHUB tab: single-account PAT paste. No login flow — the
|
|
operator pastes an existing PAT for a dedicated bot account.
|
|
Security-warning banner + a link to generate a PAT. -->
|
|
<section
|
|
class="cred-pane"
|
|
id="cred-pane-github"
|
|
data-tab-pane="github"
|
|
role="tabpanel"
|
|
aria-labelledby="cred-tab-github"
|
|
>
|
|
<hive-warn level="warning">
|
|
⚠ use a <strong>dedicated bot account</strong>, not a human's —
|
|
and a <strong>minimally-scoped</strong> personal access token (only
|
|
the repos/scopes the agent actually needs, e.g. <code>repo</code> +
|
|
<code>workflow</code>). the container boundary is the enforcement:
|
|
anything within the token's scopes is reachable if the agent is ever
|
|
compromised. the token is injected into the agent's state dir and is
|
|
<strong>never displayed back</strong> on this page.
|
|
</hive-warn>
|
|
|
|
<h3>◇ status</h3>
|
|
<div id="gh-status" class="gh-status">
|
|
<p class="meta">
|
|
select an agent to see its github credential status.
|
|
</p>
|
|
</div>
|
|
|
|
<h3>◇ provision</h3>
|
|
<p class="meta">
|
|
generate a token at
|
|
<a
|
|
href="https://github.com/settings/tokens"
|
|
target="_blank"
|
|
rel="noopener"
|
|
>github.com/settings/tokens</a
|
|
>
|
|
and paste it below. one account per agent — pasting a new token
|
|
replaces the stored one.
|
|
</p>
|
|
<form id="gh-form" class="ma-form" autocomplete="off">
|
|
<label class="ma-field">
|
|
<span>personal access token</span>
|
|
<input type="password" name="token" autocomplete="off" required />
|
|
</label>
|
|
<button type="submit" class="btn btn-spawn">store token</button>
|
|
<p id="gh-result" class="ma-result" aria-live="polite"></p>
|
|
</form>
|
|
</section>
|
|
</main>
|
|
|
|
<script type="module" src="/static/credentials.js" defer></script>
|
|
</body>
|
|
</html>
|