mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-08-13 22:37:29 +00:00
Adds apps/pwa: an Express + libSQL/Turso app that is now the home of team credential sharing, with the moshcode-style auth stack ported and reskinned to match logicsrc.com (light theme, Inter, green accent). apps/pwa - auth: email/password (scrypt), passkeys (WebAuthn), CoinPay OAuth, cookie sessions, and lsk_ API keys for the CLI via a loopback OAuth-PKCE flow (/cli/authorize + /cli/token). Ported from the moshcode PWA. - credshare API (/api/credshare/*): teams, members, invites, vaults, sealed grants, ciphertext secrets, audit — authed by session OR Bearer lsk_ key. Zero-knowledge: only ciphertext + sealed vault keys + public keys stored. - teams dashboard, accept-invite, and settings (API keys) pages, server-rendered in the LogicSRC brand (lib/html.mjs). - migrations (libSQL) 001_auth + 002_credshare, migrate-on-boot; Turso via TURSO_DATABASE_URL / TURSO_AUTH_TOKEN, or a local file db for dev. - trimmed moshcode-specific approvals/credits/push/deliver. CLI - `logicsrc login` now does browser loopback OAuth-PKCE against the app and stores an lsk_ token (email-OTP removed); --token for CI. Client repointed. Distribution - install.sh (served at logicsrc.com/install.sh) installs the CLI from the GitHub repo: tarball -> npm install -> `npm run build:cli` -> logicsrc wrapper. - root build:cli builds only the CLI's workspace chain (skips web/api/next). Cleanup - removed the commandboard-api credshare backend (superseded by the PWA) and its Supabase/Turso stores + libsql dep; commandboard-api tests green (40). - removed the Next.js /teams page (the PWA is the web UI now). Verified end-to-end: two accounts register on the PWA, mint lsk_ keys, CLI login uploads identity keys, owner pushes an encrypted .env, teammate invited -> accepted -> granted -> pulls the exact file. Server stores ciphertext only. Full workspace build + tests green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
53 lines
1.9 KiB
JavaScript
53 lines
1.9 KiB
JavaScript
/* Passkey button: try to sign in with a discoverable passkey; if there's none,
|
|
register a new one. Uses the @simplewebauthn/browser UMD bundle (/vendor). */
|
|
(function () {
|
|
var btn = document.getElementById("passkey-btn");
|
|
var msg = document.getElementById("passkey-msg");
|
|
if (!btn) return;
|
|
|
|
function csrf() {
|
|
var m = document.cookie.match(/(?:^|; )mc_csrf=([^;]+)/);
|
|
return m ? decodeURIComponent(m[1]) : "";
|
|
}
|
|
function post(url, body) {
|
|
return fetch(url, {
|
|
method: "POST",
|
|
headers: { "content-type": "application/json", "x-csrf-token": csrf() },
|
|
body: JSON.stringify(body || {}),
|
|
});
|
|
}
|
|
function say(t) { if (msg) msg.textContent = t; }
|
|
|
|
async function register() {
|
|
say("creating a passkey…");
|
|
var opts = await (await post("/auth/passkey/register/options")).json();
|
|
var att = await SimpleWebAuthnBrowser.startRegistration({ optionsJSON: opts });
|
|
var r = await post("/auth/passkey/register/verify", att);
|
|
var out = await r.json();
|
|
if (out.ok) location.href = out.redirect || "/";
|
|
else say(out.error || "couldn't create passkey");
|
|
}
|
|
|
|
async function login() {
|
|
var opts = await (await post("/auth/passkey/login/options")).json();
|
|
var asr = await SimpleWebAuthnBrowser.startAuthentication({ optionsJSON: opts });
|
|
var r = await post("/auth/passkey/login/verify", asr);
|
|
var out = await r.json();
|
|
if (out.ok) { location.href = out.redirect || "/"; return true; }
|
|
throw new Error(out.error || "sign-in failed");
|
|
}
|
|
|
|
btn.addEventListener("click", async function () {
|
|
if (!window.PublicKeyCredential) { say("this device doesn't support passkeys"); return; }
|
|
btn.disabled = true;
|
|
try {
|
|
await login();
|
|
} catch (e) {
|
|
// no discoverable credential / user cancelled login → offer to register
|
|
try { await register(); }
|
|
catch (e2) { say(String(e2.message || e2)); }
|
|
} finally {
|
|
btn.disabled = false;
|
|
}
|
|
});
|
|
})();
|