feat(dashboard): bearer-token auth with browser persistence + MIT license
Pre-release polish. Two related changes bundled because they both land the project on public-release footing: Dashboard auth - fn dashboard now gates the HTTP API + terminal/badge WebSockets behind a bearer token by default. Token resolution order: --token flag, FUSION_DASHBOARD_TOKEN env, FUSION_DAEMON_TOKEN env (back-compat), or an auto-generated fn_<32 hex>. --no-auth disables. The startup banner prints a click-to-open URL with ?token=<token> embedded. - Auth middleware now also accepts fn_token=<token> as a query-string fallback so EventSource and WebSocket clients (which can't set custom headers) still authenticate. - setupTerminalWebSocket / setupBadgeWebSocket now refuse unauthenticated upgrades with a proper 401 + socket close. - Frontend: new auth.ts module captures ?token= off the URL into localStorage (key fn.authToken), strips it from the visible URL via replaceState, and installs a window.fetch wrapper that injects Authorization: Bearer <token> on every same-origin /api/* request. EventSource/WebSocket URL builders (api.ts, sse-bus.ts, useTerminal, useBadgeWebSocket) route through appendTokenQuery(). MIT license - LICENSE file at repo root. - license: "MIT" on root package.json and every packages/*/package.json, plus description/bugs metadata on the CLI package. Docs - docs/cli-reference.md documents --token / --no-auth / FUSION_DASHBOARD_TOKEN and the click-to-open auth flow. - docs/getting-started.md, docs/docker.md, README.md point at the new flow and the CLI reference section. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -72,12 +72,25 @@ fn dashboard --paused # start with automation paused
|
||||
fn dashboard --dev # run UI only (no engine)
|
||||
```
|
||||
|
||||
Open: `http://localhost:4040` (or your custom port).
|
||||
On startup, Fusion prints a click-to-open URL that includes a bearer token:
|
||||
|
||||
```
|
||||
→ http://localhost:4040
|
||||
Token: fn_8f3a...
|
||||
Open: http://localhost:4040/?token=fn_8f3a...
|
||||
```
|
||||
|
||||
Click the **Open** link. Your browser captures the token into `localStorage`,
|
||||
strips it from the visible URL, and reuses it automatically on later loads.
|
||||
See [CLI reference → fn dashboard → Authentication](./cli-reference.md#fn-dashboard)
|
||||
for details, including how to set a stable token via `FUSION_DASHBOARD_TOKEN`
|
||||
or disable auth with `--no-auth` for strictly-local setups.
|
||||
|
||||
Other launch modes:
|
||||
|
||||
```bash
|
||||
fn serve --port 5050 --host 0.0.0.0 # headless node (API + engine, no web UI)
|
||||
fn dashboard --host 0.0.0.0 # expose on LAN (auth stays on by default)
|
||||
fn serve --port 5050 --host 0.0.0.0 # headless node (API + engine, no web UI)
|
||||
fn daemon --port 5050 # daemon mode with token auth support
|
||||
fn desktop # launch Electron desktop app
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user