logicsrc/apps/pwa/public/sw.js
Anthony Ettinger 9ba044577f
Some checks failed
CI / build (push) Has been cancelled
test / test (push) Has been cancelled
feat(pwa): logicsrc credentials app — real auth + Turso, redesigned; retire commandboard-api credshare
Adds apps/pwa: an Express + libSQL/Turso app that is now the home of team
credential sharing, with the moshcode-style auth stack ported and reskinned to
match logicsrc.com (light theme, Inter, green accent).

apps/pwa
- auth: email/password (scrypt), passkeys (WebAuthn), CoinPay OAuth, cookie
  sessions, and lsk_ API keys for the CLI via a loopback OAuth-PKCE flow
  (/cli/authorize + /cli/token). Ported from the moshcode PWA.
- credshare API (/api/credshare/*): teams, members, invites, vaults, sealed
  grants, ciphertext secrets, audit — authed by session OR Bearer lsk_ key.
  Zero-knowledge: only ciphertext + sealed vault keys + public keys stored.
- teams dashboard, accept-invite, and settings (API keys) pages, server-rendered
  in the LogicSRC brand (lib/html.mjs).
- migrations (libSQL) 001_auth + 002_credshare, migrate-on-boot; Turso via
  TURSO_DATABASE_URL / TURSO_AUTH_TOKEN, or a local file db for dev.
- trimmed moshcode-specific approvals/credits/push/deliver.

CLI
- `logicsrc login` now does browser loopback OAuth-PKCE against the app and
  stores an lsk_ token (email-OTP removed); --token for CI. Client repointed.

Distribution
- install.sh (served at logicsrc.com/install.sh) installs the CLI from the
  GitHub repo: tarball -> npm install -> `npm run build:cli` -> logicsrc wrapper.
- root build:cli builds only the CLI's workspace chain (skips web/api/next).

Cleanup
- removed the commandboard-api credshare backend (superseded by the PWA) and its
  Supabase/Turso stores + libsql dep; commandboard-api tests green (40).
- removed the Next.js /teams page (the PWA is the web UI now).

Verified end-to-end: two accounts register on the PWA, mint lsk_ keys, CLI login
uploads identity keys, owner pushes an encrypted .env, teammate invited ->
accepted -> granted -> pulls the exact file. Server stores ciphertext only.
Full workspace build + tests green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 14:29:29 +00:00

55 lines
2 KiB
JavaScript

/* LogicSRC PWA service worker — offline app shell (network-first for docs). */
const CACHE = "logicsrc-v1";
const SHELL = ["/", "/icon.svg", "/manifest.webmanifest", "/passkey.js"];
self.addEventListener("install", (e) => {
e.waitUntil(caches.open(CACHE).then((c) => c.addAll(SHELL)).then(() => self.skipWaiting()));
});
self.addEventListener("activate", (e) => {
e.waitUntil(
caches.keys().then((keys) => Promise.all(keys.filter((k) => k !== CACHE).map((k) => caches.delete(k)))).then(() => self.clients.claim())
);
});
// approval push notifications
self.addEventListener("push", (e) => {
let d = {};
try { d = e.data ? e.data.json() : {}; } catch (_) {}
e.waitUntil(self.registration.showNotification(d.title || "LogicSRC", {
body: d.body || "You have an approval waiting.",
icon: "/icon.svg",
badge: "/icon.svg",
data: { url: d.url || "/" },
tag: "logicsrc",
}));
});
self.addEventListener("notificationclick", (e) => {
e.notification.close();
const url = (e.notification.data && e.notification.data.url) || "/";
e.waitUntil(clients.matchAll({ type: "window" }).then((cs) => {
for (const c of cs) if ("focus" in c) { c.navigate(url); return c.focus(); }
return clients.openWindow(url);
}));
});
self.addEventListener("fetch", (e) => {
const { request } = e;
if (request.method !== "GET") return; // never cache POSTs / API writes
const url = new URL(request.url);
if (url.pathname.startsWith("/api/") || url.pathname.startsWith("/auth/") || url.pathname.startsWith("/webhooks/")) return;
// network-first, fall back to cache (so approvals stay fresh, offline still loads a shell)
e.respondWith(
fetch(request)
.then((res) => {
if (res.ok && url.origin === location.origin) {
const copy = res.clone();
caches.open(CACHE).then((c) => c.put(request, copy));
}
return res;
})
.catch(() => caches.match(request).then((r) => r || caches.match("/")))
);
});