feat(dashboard): bearer-token auth with browser persistence + MIT license

Pre-release polish. Two related changes bundled because they both land the
project on public-release footing:

Dashboard auth
- fn dashboard now gates the HTTP API + terminal/badge WebSockets behind a
  bearer token by default. Token resolution order: --token flag,
  FUSION_DASHBOARD_TOKEN env, FUSION_DAEMON_TOKEN env (back-compat), or an
  auto-generated fn_<32 hex>. --no-auth disables. The startup banner prints
  a click-to-open URL with ?token=<token> embedded.
- Auth middleware now also accepts fn_token=<token> as a query-string
  fallback so EventSource and WebSocket clients (which can't set custom
  headers) still authenticate.
- setupTerminalWebSocket / setupBadgeWebSocket now refuse unauthenticated
  upgrades with a proper 401 + socket close.
- Frontend: new auth.ts module captures ?token= off the URL into
  localStorage (key fn.authToken), strips it from the visible URL via
  replaceState, and installs a window.fetch wrapper that injects
  Authorization: Bearer <token> on every same-origin /api/* request.
  EventSource/WebSocket URL builders (api.ts, sse-bus.ts, useTerminal,
  useBadgeWebSocket) route through appendTokenQuery().

MIT license
- LICENSE file at repo root.
- license: "MIT" on root package.json and every packages/*/package.json,
  plus description/bugs metadata on the CLI package.

Docs
- docs/cli-reference.md documents --token / --no-auth / FUSION_DASHBOARD_TOKEN
  and the click-to-open auth flow.
- docs/getting-started.md, docs/docker.md, README.md point at the new flow
  and the CLI reference section.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
gsxdsm
2026-04-21 18:01:20 -07:00
parent 04f8457c03
commit 7e3c68249e
24 changed files with 496 additions and 68 deletions

View File

@@ -1,6 +1,12 @@
{
"name": "@gsxdsm/fusion",
"version": "0.4.0",
"license": "MIT",
"description": "Fusion CLI: HTTP API server, daemon, dashboard launcher, and task tooling for the Fusion AI coding agent.",
"homepage": "https://github.com/Runfusion/Fusion#readme",
"bugs": {
"url": "https://github.com/Runfusion/Fusion/issues"
},
"type": "module",
"keywords": [
"pi-package"

View File

@@ -269,6 +269,8 @@ Options:
--project, -P <name> Target a specific project (bypasses CWD detection)
--port, -p <port> Dashboard/serve port (default: 4040)
--host <host> Serve host (default: 127.0.0.1 — localhost only; pass 0.0.0.0 to expose)
--token <token> Dashboard/daemon bearer token. Default: $FUSION_DASHBOARD_TOKEN, $FUSION_DAEMON_TOKEN, or auto-generated.
--no-auth Disable dashboard bearer-token auth (local-only; not recommended on 0.0.0.0)
--interactive Interactive mode (port selection for dashboard, issue selection for import)
--paused Start with engine paused (automation disabled)
--dev Start dashboard only (no AI engine)
@@ -506,7 +508,10 @@ async function main() {
const interactive = args.includes("--interactive");
const dashHostIdx = args.indexOf("--host");
const host = dashHostIdx !== -1 && dashHostIdx + 1 < args.length ? args[dashHostIdx + 1] : undefined;
await runDashboard(port, { paused, dev, interactive, host });
const noAuth = args.includes("--no-auth");
const dashTokenIdx = args.indexOf("--token");
const token = dashTokenIdx !== -1 && dashTokenIdx + 1 < args.length ? args[dashTokenIdx + 1] : undefined;
await runDashboard(port, { paused, dev, interactive, host, noAuth, token });
break;
}

View File

@@ -1,4 +1,5 @@
import type { AddressInfo } from "node:net";
import { randomBytes } from "node:crypto";
import { join } from "node:path";
import { TaskStore, AutomationStore, CentralCore, AgentStore, PluginStore, PluginLoader, getTaskMergeBlocker, getEnabledPiExtensionPaths } from "@fusion/core";
import { createServer, GitHubClient, createSkillsAdapter, getProjectSettingsPath, loadTlsCredentialsFromEnv } from "@fusion/dashboard";
@@ -193,10 +194,30 @@ async function resolveRuntimeProjectPath(): Promise<string> {
}
}
export async function runDashboard(port: number, opts: { paused?: boolean; dev?: boolean; interactive?: boolean; open?: boolean; host?: string } = {}) {
export async function runDashboard(port: number, opts: { paused?: boolean; dev?: boolean; interactive?: boolean; open?: boolean; host?: string; noAuth?: boolean; token?: string } = {}) {
// Default to localhost so the dashboard (and its shell-capable terminal API)
// is not exposed on the LAN. Pass --host 0.0.0.0 explicitly to opt-in.
const selectedHost = opts.host ?? "127.0.0.1";
// ── Bearer-token auth ────────────────────────────────────────────────
//
// By default the dashboard API is gated by a bearer token so that when the
// server is bound to a non-localhost interface (e.g. `pnpm dev dashboard`
// which injects --host 0.0.0.0 for LAN testing) nearby users can't hit the
// terminal or exec endpoints uninvited. Precedence:
// 1. `opts.token` — explicit override (mostly for tests)
// 2. `FUSION_DASHBOARD_TOKEN` — user-provided env
// 3. `FUSION_DAEMON_TOKEN` — back-compat with daemon mode
// 4. auto-generated random token (printed at startup so the user can auth)
// `--no-auth` skips the middleware entirely. The token is embedded in the
// launch URL (as `?token=...`) so the user can click once and the browser
// stores it to localStorage for subsequent loads.
const dashboardAuthToken: string | undefined = opts.noAuth
? undefined
: opts.token
?? process.env.FUSION_DASHBOARD_TOKEN
?? process.env.FUSION_DAEMON_TOKEN
?? `fn_${randomBytes(16).toString("hex")}`;
ensureProcessDiagnostics();
// Handle interactive port selection
@@ -606,6 +627,7 @@ export async function runDashboard(port: number, opts: { paused?: boolean; dev?:
onProjectFirstAccessed: (projectId: string) => engineManager.onProjectAccessed(projectId),
skillsAdapter,
https: loadTlsCredentialsFromEnv(),
daemon: dashboardAuthToken ? { token: dashboardAuthToken } : undefined,
});
const shutdown = async (signal: NodeJS.Signals) => {
@@ -787,6 +809,7 @@ export async function runDashboard(port: number, opts: { paused?: boolean; dev?:
pluginRunner: pluginLoader,
skillsAdapter,
https: loadTlsCredentialsFromEnv(),
daemon: dashboardAuthToken ? { token: dashboardAuthToken } : undefined,
});
}
@@ -918,10 +941,29 @@ export async function runDashboard(port: number, opts: { paused?: boolean; dev?:
}
}
// Compose the user-visible URL. When we're bound to a non-localhost
// interface (LAN testing), surface the actual host so the URL is
// usable from another device. Otherwise keep it as `localhost` for
// the nicer click-to-open experience.
const displayHost =
selectedHost === "0.0.0.0" || selectedHost === "::" ? selectedHost : "localhost";
const baseUrl = `http://${displayHost}:${actualPort}`;
const tokenizedUrl = dashboardAuthToken
? `${baseUrl}/?token=${encodeURIComponent(dashboardAuthToken)}`
: baseUrl;
console.log();
console.log(` fn board`);
console.log(` ────────────────────────`);
console.log(`http://localhost:${actualPort}`);
console.log(`${baseUrl}`);
if (dashboardAuthToken) {
console.log(` Auth: bearer token required`);
console.log(` Token: ${dashboardAuthToken}`);
console.log(` Open: ${tokenizedUrl}`);
console.log(` (the browser stores the token so you only need to click once)`);
} else {
console.log(` Auth: disabled (--no-auth)`);
}
console.log();
console.log(` Tasks stored in .fusion/tasks/`);
console.log(` Merge: AI-assisted (conflict resolution + commit messages)`);