Pre-release polish. Two related changes bundled because they both land the project on public-release footing: Dashboard auth - fn dashboard now gates the HTTP API + terminal/badge WebSockets behind a bearer token by default. Token resolution order: --token flag, FUSION_DASHBOARD_TOKEN env, FUSION_DAEMON_TOKEN env (back-compat), or an auto-generated fn_<32 hex>. --no-auth disables. The startup banner prints a click-to-open URL with ?token=<token> embedded. - Auth middleware now also accepts fn_token=<token> as a query-string fallback so EventSource and WebSocket clients (which can't set custom headers) still authenticate. - setupTerminalWebSocket / setupBadgeWebSocket now refuse unauthenticated upgrades with a proper 401 + socket close. - Frontend: new auth.ts module captures ?token= off the URL into localStorage (key fn.authToken), strips it from the visible URL via replaceState, and installs a window.fetch wrapper that injects Authorization: Bearer <token> on every same-origin /api/* request. EventSource/WebSocket URL builders (api.ts, sse-bus.ts, useTerminal, useBadgeWebSocket) route through appendTokenQuery(). MIT license - LICENSE file at repo root. - license: "MIT" on root package.json and every packages/*/package.json, plus description/bugs metadata on the CLI package. Docs - docs/cli-reference.md documents --token / --no-auth / FUSION_DASHBOARD_TOKEN and the click-to-open auth flow. - docs/getting-started.md, docs/docker.md, README.md point at the new flow and the CLI reference section. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
32 lines
969 B
TypeScript
32 lines
969 B
TypeScript
import { StrictMode } from "react";
|
|
import { createRoot } from "react-dom/client";
|
|
import { RootErrorBoundary } from "./components/ErrorBoundary";
|
|
import { App } from "./App";
|
|
import { installAuthFetch } from "./auth";
|
|
import "./styles.css";
|
|
|
|
// Install the bearer-token fetch wrapper before React mounts so every API
|
|
// call (including ones fired synchronously during the first render) picks up
|
|
// the token that was either captured from `?token=` in the launch URL or
|
|
// stored from a previous session.
|
|
installAuthFetch();
|
|
|
|
createRoot(document.getElementById("root")!).render(
|
|
<StrictMode>
|
|
<RootErrorBoundary>
|
|
<App />
|
|
</RootErrorBoundary>
|
|
</StrictMode>,
|
|
);
|
|
|
|
if (import.meta.env.PROD && "serviceWorker" in navigator) {
|
|
navigator.serviceWorker
|
|
.register("/sw.js")
|
|
.then((registration) => {
|
|
console.log("SW registered:", registration.scope);
|
|
})
|
|
.catch((error) => {
|
|
console.log("SW registration failed:", error);
|
|
});
|
|
}
|