* feat(web): value-first /home reskin (CEO mock palette + pillars + first-session)
Restructures `/home` to lead with product value instead of install steps,
matching the CEO mock proposed for the homepage:
- New intro hero on top — eyebrow `Welcome, {{ display_name }}`, H1
`{{ instance_brand }} is your team's AI workspace`, lede framing the
product as an "AI Chief of Staff", two CTAs (`Set up in ~15 min →`
jumps to the wizard, `Just browse — no install needed` jumps to
`#look-around`), and a four-pillar row (Data packages · Plugins ·
Skills · Memory). Renders for both onboarded and not-onboarded users
so the value framing is consistent across visits.
- New `first-session` narrative — five-beat walkthrough (launch → pick
project → memory loads → ask → close) with mock terminal frames
carrying traffic-light dots, prompts, and dimmed system output.
- Setup wizard chrome — progress chip (`Step 1 of N · ~15 min ·
One-time · Reversible`), thin progress bar, and per-step number
badges on each `.install-block` so the wizard reads as bounded
instead of an open-ended scroll.
- Palette shift from blue to green/navy: `--hp-primary` aliases
`#2ea877` (mint), `--hp-hero-bg` is navy `#0f1b3a`, code panels stay
near-black `#0c1224` with warm-yellow `#ffd866` accents. The token
alias is reused so downstream rules pick up the new accent
automatically; instance theme overrides via
`config.theme_overrides()` still win.
- VS Code surface tile carries a `Recommended` pill; the existing
"Want to look around first?" section is renamed to `Explore your
workspace` and gets the `#look-around` anchor.
All test-pinned class names and IDs (`install-hero`, `install-block`,
`home-mock`, `self-mark-btn`, `setupClaudeBtn`, `offboard-strip`,
`home-getting-started`, `home-gs-item`, `home-overview`,
`home-usage`) preserved as structural anchors; new visual language
overlays via additional classes. Existing onboarded/not-onboarded
branching, `/api/me/onboarded` POST, status frame gating, post-CTA
modal, and OS-tab switching JS unchanged. Stray `~/FoundryAI`
comment swapped for `~/{{ workspace_dir }}` to honor the
vendor-agnostic OSS rule.
51 home tests pass without modification.
* fix(web): /home palette inversion — dark intro hero on top, light setup card below
Previous reskin commit kept the install-hero as a dark navy gradient and
rendered the new intro hero as a light surface — opposite of what the CEO
mock specifies. Playwright comparison vs `data/ceo_home.html` confirmed:
- CEO mock: dark navy hero at TOP (with white pillars on navy), LIGHT
white setup card BELOW with light step rows and dark code panels
inset.
- Previous: light intro hero on top, dark setup card below. Inverted.
This patch flips both:
- `.home-hero-intro` now: dark navy gradient `#0f1b3a → #1a2a5f`, green
radial glow in the corner, green eyebrow, white H1 (`accent` span
green), rgba-white lede, green pill primary CTA, translucent-white
secondary CTA, pillars row separated by hairline border-top with
green square-dot bullets in front of each pillar header.
- `.install-hero` and `.install-block` now: white surface card with
thin green accent strip across the top, light step rows split by
hairline borders, green-tinted step-number circles (`#e6f9f0` bg,
`#1f8a5e` ink), green progress chip + bar. Code panels
(`.install-cmd`) and terminal frames stay dark — they're the "type
this" surfaces.
- All previously-rgba-white descendants of `.install-hero`
(close button, eyebrow, h1, lead, links, code chips, OS tabs,
install notes, setup-CTA button, self-mark fallback, auto-detect
badge, terminal-howto disclosure) re-skinned for light surface.
All 12 home page tests still pass (no markup changes, only CSS).
* fix(web): /home parity polish — system font + mock sizes + blue info hint + gray step-num
After v2 palette flip, user comparison vs CEO mock surfaced three
remaining gaps in the wizard area:
- Font stack mismatch: Agnes inherits Inter via `style-custom.css`,
but the CEO mock uses the platform system stack (San Francisco on
macOS, Segoe UI on Windows). The rendered weight/letterforms read
noticeably different. `.home-mock` now declares
`-apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, sans-serif`
for itself and all descendants, with the monospace stack reserved
for `code`/`kbd`/`pre`, `.install-cmd`, and `.terminal-body`.
- Step number badges were green-tinted; mock uses neutral gray
(`#f0f2f6` bg, `#4a5168` ink) — green is reserved for the "done"
state. Switched to `--hp-surface-dim` + `--hp-text-secondary`.
- "Don't have a terminal open?" disclosure was an amber/yellow
variant left over from the old dark-hero palette. Mock uses a
blue info-hint vocabulary (`--info-bg: #eef3ff`,
`--info-line: #4f7cf2`, `--info-ink: #1c3994`) with white kbd
chips. Added the info-* tokens to the `:root` block and re-skinned
`details.terminal-howto` (incl. summary, body, kbd) to match.
Step-body type sizes also brought in line with the mock spec —
`.install-block .label` (step h3 equivalent) is now 17px / 700 with
6px gap; `.install-note` body type is 14px / 1.55.
`--hp-info-bg / --hp-info-ink / --hp-info-line / --hp-warn-bg /
--hp-warn-ink / --hp-warn-line / --hp-surface-dim` added as
first-class tokens so future hint/warn callouts pick the same colors
without a duplicate vocabulary.
12/12 home tests pass.
* feat(web): centralize design tokens + reword /home wizard to 6 steps (CEO mock parity)
Two intertwined changes that touch both global design + /home structure:
GLOBAL TOKEN SHIFT (app/web/static/style-custom.css)
- `--primary` flipped from blue `#0073D1` to green `#2ea877` — same brand
alias the rest of the app referenced, so every page picks up the new
accent automatically. Old `--primary-dark` / `--primary-light` recolored
to match.
- New tokens added: `--brand-accent`, `--hero-bg`, `--hero-ink`,
`--surface-dim`, `--info-bg/ink/line`, `--warn-bg/ink/line`. Brings
the global vocabulary in line with the CEO mock's `:root` block so
callouts and hero surfaces don't have to invent local tokens.
- `--font-primary` switched from Inter-led stack to the system stack
(`-apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Inter",
system-ui, sans-serif`) so weight/letterforms render identically on
macOS (San Francisco) and Windows (Segoe UI) — matches the mock and
avoids a font-loading flash for analysts without Inter installed.
- Shadow tints re-cast in navy `rgba(15,27,58,...)`; focus ring uses
the new green `rgba(46,168,119,0.25)`.
- `.app-nav-link` font-size 13px → 14px, padding 6px 12px → 8px 14px,
hover bg → `--primary-light` (mint), color → `--primary-dark`.
`.app-nav-menu-item.is-active` re-tinted to the same green system.
- Sweep across 26 templates (style-custom.css + 25 template files)
replacing every hardcoded `#0073D1` / `#005BA3` / `#E6F3FC` /
`rgba(0,115,209,…)` / `rgba(0,86,163,…)` with token references or
the new green hexes — 175 occurrences total. Pages that styled their
own buttons / borders / shadows pick up the new brand color without
per-page overrides.
/HOME WIZARD: 6 STEPS PER MOCK (app/web/templates/home_not_onboarded.html)
- Step 1 reworded `Install Claude Code on your computer` + `~3 min`
subhead (mock copy).
- Step 2 renamed `Pick a folder for {{ instance_brand }}` (was
`create your workspace folder`) — same `mkdir` command, mock-aligned
framing.
- NEW Step 3 `Open a terminal inside that folder` — no shell command,
just the "you are standing in the right directory" reassurance with
a Finder/PowerShell/file-manager howto disclosure. Mirrors the CEO
mock's Step 3.
- Step 4 (was Step 3, gated by `home_automode.show`) renamed
`Launch Claude with auto-approve on`. Body copy lightly updated so
it references "the next step" instead of "Step 4".
- Step 5 (was Step 4) renamed `Get the install script and paste it
into Claude`. The setup-cta-lead now explicitly says
"pasting the script into Claude Code will install {{ instance_brand
}}…" so existing test assertions pinning the `install Agnes`
substring still match.
- NEW Step 6 `Optional: create a one-word shortcut for next time` —
prints an `echo 'alias {{workspace_dir|lower}}=…' >> ~/.zshrc`
one-liner for Unix and an `Add-Content $PROFILE …` equivalent for
Windows. OS tabs + copy buttons reuse the existing wizard chrome.
- Progress chip dynamic: `Step 1 of 6` when home_automode is on,
`Step 1 of 5` when off. Progress bar fill `100 // total_steps` so
the bar sits at 16-20 % on first paint.
- `.step-lede` token added for the new short body copy beneath each
step label (14.5px / ink-soft).
- `macOS / Linux / WSL` tab labels changed to `macOS / Linux` per
user instruction. Terminal-howto `WSL:` paragraph dropped; the
paste-shortcut hint now reads `(Linux)` instead of `(Linux/WSL)`.
Functional WSL handling in `connector_prompts.py` (it's a Linux
detection fallback, not user-facing label) preserved.
- `setup_instructions.py` Claude Code install hint:
`npm (Linux / WSL)` → `npm (Linux)`.
SURFACES — 4 CARDS PER MOCK
- Replaced the 3-tile `.home-usage-grid` with a 4-card grid:
- VS Code (Recommended) — `.surface-card.feature`, green ring,
DAILY USE eyebrow + 5-step numbered list + `Open VS Code setup
guide →` link to `/setup-advanced#vscode`.
- Terminal — QUICK ACCESS eyebrow + 4-step list.
- Claude Code (Desktop app) — CONNECT IT eyebrow + 4-step list.
- Cowork (claude.ai) — `.surface-card.incomplete`, warn-tinted
border + `Instructions needed` badge + a TODO callout describing
the missing content. The card is intentionally honest about the
gap rather than hiding it.
TEST UPDATES
- `test_web_home_page.py` negative onboarded-state assertions
rebased on the new step labels (6 entries instead of 4).
- `test_home_route_resolution.py` `test_home_renders_automode_block_by_default`
+ its `_when_env_off` counterpart now check the new
`Step 4 — Launch Claude with auto-approve on` label.
* fix(web): /home section content + layout — verbatim mock match
User comparison flagged several remaining gaps; this patch rewrites
the three lower sections of /home to match the CEO mock spec exactly:
FIRST-SESSION (5 beats)
- h2 28px / 700 / -.5px tracking (was 19px / 600).
- lede 18px ink-soft (was 13.5px secondary).
- `.session-walk` wrapper, 36px gap between beats (mock spec).
- `.session-step` grid 48px / 1fr, gap 22px — number circle on
the left, content on the right.
- `.session-num` 40 × 40 circle with SOLID GREEN bg (`--primary`)
and WHITE text + soft green shadow (was 28px mint pill w/
dark-green text).
- `.session-content h3` 18px / 600 (was 14.5px / 600).
- `.session-content > p` 15px.
- `.session-content .annotation` 13.5px ink-muted body type with
`strong` for highlighting (replaces the upper-case "WHAT'S
HAPPENING" eyebrow pattern that didn't match the mock).
- `.session-intro` callout card (white surface + mint icon block)
framing the "five beats" tagline.
- `.session-tldr` summary box (brand-light bg + brand-dark left
border) wrapping up the loop.
- Terminal frames re-skinned: `#0c1224` body / `#182241` bar /
real macOS traffic-light colors `#ff5f57` / `#febc2e` / `#28c840`.
- Terminal body 13px / 1.65 line-height with mock-spec class
vocabulary: `.you` (yellow input), `.ai-name` (brand bold),
`.path` (light blue), `.dim` (translucent code-ink), `.caret`
(blinking cursor).
- Five beats rewritten with mock's exact narrative flow (launch →
menu → pick → ask → close), vendor-agnostic project names
(`RevenueAnalysis`, `Onboarding`, etc.) replacing the customer-
specific `GRPN_*` examples in the mock. Templated `{{
instance_brand }}` / `{{ workspace_dir }}` / `{{ workspace_dir |
lower }}` (the shortcut alias) everywhere.
SURFACES (4 cards)
- The section is no longer wrapped in a white rectangle; the
`.home-usage` class loses its bg + border + padding (mock has the
cards directly on the page bg).
- h2 28px (was 22px). Eyebrow 12px / 1.5px tracking / brand-dark.
- `.surface-card.feature` (VS Code) now uses 2px green border +
vertical brand-light → white gradient (was 1px ring).
- `.surface-card.incomplete` (Cowork) uses 2px red border (`#e35e5e`)
+ vertical red-tint → white gradient (was yellow flat bg).
- `.surface-card .steps` panel: inner surface-dim bg + 8px radius
+ 13px font.
- `.surface-foot` top-border + ink-muted (mock spec).
- `.badge-warn` now a solid red box (`#e35e5e` bg + white ink + 4px
radius) instead of a yellow pill, matching the mock.
- Header layout fixed: the global absorbed `header { display: flex;
justify-content: space-between }` rule was making the h2 sit on
the right of the eyebrow; explicit `display: block` override on
`.home-mock section > header` puts the title on the LEFT under
the eyebrow as the mock has.
BROWSE — Explore your workspace
- Wrapped in `<section class="browse-section">` with proper
eyebrow + h2 + lede (was a bare `.section-label` div).
- `.browse-grid` 5-col grid (was responsive auto-fill, 4-card
layout). Skills tile added as a 5th card linking to
`/marketplace?type=skills`.
- `.browse-card` mock-spec: 22 20 padding, 28px icon, 15px title,
12.5px ink-muted desc, hover lifts -2px with brand border +
shadow-md.
Section wrappers (`.home-usage`, `.first-session`) no longer carry
the white card chrome — they sit directly on the page bg, matching
the mock. Only Getting Started + Overview keep their white cards.
GLOBAL eyebrow vocabulary (`.home-hero-intro .eyebrow`,
`.first-session > .eyebrow`, `.surfaces > header .eyebrow`,
`.browse-section .eyebrow`) all aligned to mock spec: 12px / 700 /
1.5px tracking / brand-dark color / 14px bottom margin.
Hero h1 bumped to 44px / 800 / -1px tracking (was 32px / 600).
51/51 home tests pass.
* fix(web): /home session-intro card + terminal-body verbatim mock match
User comparison flagged three remaining /home gaps; this patch
addresses each:
- `.session-intro` rule was missing — the "five beats" tagline
rendered as a bare line with no card chrome. Added the mock-
spec card: white surface, 14px radius, 20×24 padding, 1px
border + shadow-sm, with a 44×44 brand-light icon block on the
left.
- Beat 1 terminal-title was `~/{{ workspace_dir }} — zsh` (mock-
style shell-pwd format), but the user wants every terminal
frame across all 5 beats to read `claude — {{ instance_brand }}`.
Updated.
- Terminal-body line structure for beats 2-5 rewritten verbatim
from the CEO mock:
- `<span class="prompt">></span><span class="you">…</span>`
now has no space between the prompt and user input (mock
pattern: zero gap, the .prompt's `margin-right: 8px` provides
the visual separation).
- Beat 2 menu items use `<strong>[N]</strong>` numbering with
project entries on indented lines, each project name followed
by a `<span class="dim">(N ago)</span>` timestamp at a fixed
column — instead of my prior single-line concatenation.
- Beat 3 narrative split into 4 stanzas separated by blank lines
(matches mock): the "Switched to <strong>X</strong>" status,
then dim Loaded/Last-session lines, then a stand-alone "One
unprocessed input detected:" pair, then the "Want me to
process …" question. My prior version dim-wrapped the entire
block, which looked off.
- Beat 4 narrative split into headline summary + risks section
with <strong> heads + bullet lists separated by blank lines,
matching the mock's "Q1 close summary" / "Open risks" rhythm.
The Q1 question carries the mock's manual line-break + 2-
space continuation indent inside the `.you` span — without
that, terminal-body's `white-space: pre-wrap` would auto-wrap
awkwardly at a different column than the mock.
- Beat 5 exit narrative uses two separate dim lines + a
standalone `.ai-name` "See you next time." line, then prompt
+ caret. My prior version collapsed everything into one dim
block.
- Project names changed from customer-specific (`GRPN_*`) to
generic (RevenueAnalysis, WeeklyReview, Onboarding, OpsDb,
HRHandShake) so the OSS distribution stays vendor-agnostic
per CLAUDE.md.
- `Marketing plan` examples replaced with `Q1 close` so the
narrative stays plausible for an analyst audience.
12/12 home tests pass.
* fix(web): /home surfaces verbatim mock — VS Code thumb, Terminal expected-output, NEW badge
User comparison flagged three remaining surface-section gaps:
- VS Code surface card was rendering a generic "Screenshot pending"
placeholder; the mock has a labeled inline mockup
(`<a class="vscode-thumb">` w/ `.thumb-fallback`) showing the
recommended 4-pane layout (EXPLORER yellow, TERMINAL 1 purple,
TERMINAL 2 green, TERMINAL 3 orange) on a dark navy bg + a
"Recommended layout" caption pill. CSS `.vscode-thumb` block
added — uses gradient-strip backgrounds to draw the colored
panel bars without needing a base64 image.
- "Recommended" badge was a pill (999px radius) with
`--brand-accent` bg + navy text. Mock uses `.badge` instead of
`.recommend-pill` — solid `--primary` (brand-dark green) bg
with WHITE text and 4px radius. Replaced the class + CSS rule
so the badge reads as a tag, not a pill.
- Terminal surface card was missing the "What you should see"
subsection — mock has an `.expected-output` block showing a
sample of the welcome menu inside a dim dashed panel. Added the
block with the mock's exact rendered output (templated to
`{{ instance_brand }}` + generic project names instead of
customer-specific GRPN entries) plus the `.expected-output`
CSS (surface-dim bg + dashed border + `::before` "WHAT YOU
SHOULD SEE" eyebrow per mock spec).
Also addressed the explore-section feedback:
- Skills browse-card now carries the `new` class so it picks up
the `.browse-card.new::after` corner badge ("NEW", green bg,
white text, 10px / 700 / 0.5px tracking) per mock.
- Browse cards align same height via `align-self: stretch` (grid
default) + `flex-grow: 1` on `.browse-desc` so descriptions
fill remaining vertical space; previously the Skills tile sat
shorter because its desc text was longer than others'.
Structural HTML changes to all four surface cards: dropped the
inner `<div class="surface-card-head">` wrapper + `<p
class="surface-pitch">` class in favor of mock's flat layout
(`.what` + `.steps` + `.when-to-use`). `<ol class="surface-steps">`
replaced with `<div class="steps"><strong
class="steps-eyebrow">DAILY USE / QUICK ACCESS / CONNECT IT</strong>
<ol>...</ol></div>` so the eyebrow + numbered list share the
mock's tinted surface-dim panel.
12/12 home tests pass.
* fix(web): align /home setup walkthrough to design spec
- Setup-section header (eyebrow + heading + lede) floats above the
install hero; install card has no accent strip; step labels drop
`Step N —` prefix; closing strip is single flex row.
- VS Code surface card renders recommended-layout screenshot from
`/static/img/vscode-layout.png` with click-to-enlarge lightbox.
- Workspace install path cascades to `~/Desktop/{workspace_dir}` in
every step, surface card, first-session annotation, and shortcut.
- Step 1 verify text restores Enterprise — Finance and Legal option.
- Step 6 shortcut installs a shell function with arg forwarding
(`"$@"` unix / `@args` windows) and a user-facing Auto / YOLO
permission-mode toggle.
- Step 5 manual-fallback details inline on the CTA row; description
reads at step-lede size, not 13px chip.
- Setup-section heading no longer right-aligns (was inheriting
`header { display: flex; justify-content: space-between }` from
the legacy stylesheet; wrapper changed to `<div>`).
- Getting Started `<details>` block removed (duplicated links).
* test(web): align /home tests with restructured setup wizard
- Replace test_getting_started_card_renders_on_home with
test_setup_section_renders_for_not_onboarded — asserts the new
setup-section-header floats above the install hero and Getting
Started markup is absent (block removed in the prior commit).
- Update automode-block test to match labels without the
`Step N —` prefix.
- Update setup-CTA partial test to match the relabeled
"Copy install script to clipboard" button.
Drop orphaned CSS for `.home-getting-started`, `.home-gs-summary*`,
and `.home-gs-item` — selectors had no matching markup after the
Getting Started block was removed.
Also: Step 3 `pwd` expected-output uses an absolute path
(`/Users/yourname/Desktop/{workspace_dir}`) instead of the
tilde-prefixed form, matching what the command actually prints.
* fix(web): repaint home_onboarded + setup_advanced; align CTA label
- home_onboarded + setup_advanced still carried the retired blue
`#0056A3` as both `--hp-primary-dark` and the hero gradient
endpoint. Both reference `var(--primary-dark)` now so the green
palette cascades.
- setup_advanced YOLO snippet was the old `alias` form (no cd, no
arg forwarding). Replaced with the shell function variant from
/home Step 6 — drops into ~/Desktop/{workspace_dir} and forwards
"\$@" (unix) / @args (Windows).
- setup_advanced ~/{workspace_dir} path references cascaded to
~/Desktop/{workspace_dir} so install story matches /home.
- Dashboard's "Setup a new Claude Code" button label aligned to the
canonical "Copy install script to clipboard" — matches /home and
the new docstring in _claude_setup_cta.jinja, which now mandates
this label across consumers.
* fix(web): keep base brand blue; scope green palette to /home redesign
User noticed login + dashboard had turned green when the /home
redesign flipped --primary from blue (#0073D1) to green (#2ea877)
in commit 278f202e. The brand-wide flip went further than the
redesign needed — only /home, /home (onboarded), and /setup-advanced
intentionally use the green/navy spec; every other page (login,
dashboard, catalog, marketplace, admin, profile) was just inheriting
the green because --primary cascaded everywhere.
Revert the global brand colour to blue and lock the green into the
two outstanding redesign scopes:
- style-custom.css: --primary back to #0073D1, --primary-light back
to rgba(0,115,209,0.1), --primary-dark back to #005BA3,
--brand-accent back to a lighter blue.
- home_onboarded.html: .home-mock now sets --hp-primary,
--hp-primary-dark, --hp-primary-light to explicit green hex
(matching home_not_onboarded), so the hero stays green regardless
of the global brand.
- setup_advanced.html: same lock — .advanced-mock pins the green
palette in-scope.
Hero gradients on both pages now reference the local --hp-primary
chain (not the global --primary), so any future palette tweak inside
either scope cascades correctly without disturbing the rest of the app.
* refactor(web): hoist --hp-* into shared design-tokens.css (--ds-*)
PR 2 of the design-system extraction ladder. Pure mechanical rename
+ dedup; no visual diff on any rendered page (verified on /home,
/dashboard).
- New app/web/static/css/design-tokens.css declares the full token
set on :root: brand surface (green primary, primary-dark, mint
light, brand-accent), hero (navy bg + ink), code-panel (near-black
bg + cool ink + warm-yellow), light surfaces (bg/surface/border),
text (primary/secondary/muted), orange accent, info + warn
callout vocabularies, navy-tinted elevation shadows, system font
stack + mono.
- base.html loads it alongside style-custom.css so the tokens are
globally available.
- Rename --hp-* -> --ds-* in home_not_onboarded (313 refs),
home_onboarded (15), setup_advanced (39). 367 token references
pointed at one of three local blocks; now all point at the
global :root.
- Drop the three local token blocks. Each scope class
(.home-mock / .advanced-mock) only keeps its base ink + font-size
+ line-height rules.
The legacy --primary family stays canonical for the blue base
brand — login, dashboard, catalog, marketplace, admin still read
blue. The design system is opt-in via the scope class.
* refactor(web): extract shared components.css; migrate /home markup
PR 3 of the design-system extraction ladder. First batch of
reusable components lifted out of home_not_onboarded.html into a
new shared stylesheet; markup migrated to consume them.
- New app/web/static/css/components.css with five components, all
reusable on any page that loads design-tokens.css:
.callout-rec — amber lightbulb recommendation box
.callout-hint — blue info hint box
.code-output — "WHAT YOU SHOULD SEE" terminal output block
.lightbox — full-bleed image enlarge overlay
.setup-section-header — wizard header (eyebrow + h2 + lede)
- base.html loads components.css after design-tokens.css.
- home_not_onboarded.html markup renamed:
class="rec" -> class="callout-rec"
class="hint" -> class="callout-hint"
class="expected-output" -> class="code-output"
- Local CSS rules removed from home_not_onboarded.html for each of
the extracted components — ~150 lines down to 5-line "extracted to
components.css" comments. The bespoke wizard-specific styles
(.install-cmd, .os-tabs, .mode-tabs, .terminal-frame) stay
template-local for now since they only have one consumer.
Visual regression check: /home install hero renders the amber rec
callout, blue hint callout, dashed code-output block, green section
header, and click-to-enlarge VS Code thumb identically to the
pre-extraction render. 43 home tests pass.
* fix(web): unify page-headers — activity-center full-width, marketplace shares box
- /activity-center audit-log hero rendered as half-width because the
_page_hero include was inside <header class="obs-topbar">, a flex
row that pinned the time-range + auto-refresh controls next to it.
The hero is now a sibling rendered before the <header>, so it
spans the full container width like every other admin page; the
controls keep their flex row underneath.
- Marketplace hero unified with .page-header--hero. Markup is now
<section class="page-header page-header--hero mp-hero"> so the
shared box drives padding/radius/gradient/max-width/shadow; the
.mp-hero override block only carries the right-anchored cover
image and the rules for the search row + scope checkboxes (which
the canonical hero doesn't have). Inner text uses the canonical
.page-header__eyebrow / __title / __subtitle classes.
- .page-header--hero shadow tint now follows the brand blue
(rgba(0, 115, 209, 0.2)) instead of the leftover green from the
prior palette flip; same depth highlight everywhere the gradient
is blue.
* fix(web): unify remaining page heroes — admin, profile, install, store, stack
Sweep across pages that carried bespoke gradient hero markup so
every page-hero shares the canonical `.page-header--hero`
dimensions (padding 28/32/24, border-radius 14, max-width
var(--width-app), navy-tinted shadow, gradient with --primary →
--primary-dark). Inner text uses the .page-header__eyebrow /
__title / __subtitle classes so typography matches across the app.
- admin_tables: migrated to _page_hero.html include.
- admin_tokens: kept .tokens-hero wrapper for the counts-chip row
but added the canonical class on the same element; stripped
duplicate gradient + padding + typography rules.
- install: same pattern (kept hero-meta pill row).
- profile: migrated to _page_hero.html include.
- store_upload: kept .upload-hero wrapper for the .meta chip row;
composite class with the canonical hero.
- setup_advanced: .advanced-mock .ad-hero now matches canonical
dimensions; green palette retained via --ds-primary/dark.
- stack_card.css: .stack-hero (catalog + corporate-memory search
hero) uses canonical gradient + padding + max-width.
The detail-page heroes (marketplace_plugin_detail,
marketplace_item_detail, catalog_*_detail, store_edit,
admin_group_detail, admin_store_submission_detail) stay bespoke
for now — they're rich detail headers with photos, badges, install
actions; converting them would lose contract context. Same applies
to dashboard.html env-setup-cta (it's a CTA card, not a page hero).
* fix(web): canonicalise .container — single page shell every page inherits
Previously each admin page set its own `.container:has(.<page>)
{max-width: none}` + `.<page>-page {max-width: 1400px}` override,
and per-page hero markup either nested inside flex toolbars (which
pinned the hero next to filter controls and squeezed it half-width)
or self-constrained with a different max-width than the page. /home,
/dashboard, /marketplace, and /admin/* ended up at different widths
with different nav-to-hero gaps.
- style-custom.css `.container` now carries the canonical 1280px
max-width + `16px 32px 48px` padding so every page inherits the
same nav-to-hero gap and side gutters. `.container > main` is
margin/padding 0 so the container is the sole owner of gutters.
- `.page-header--hero` drops its self-constraining max-width and
auto-centering margin — the container provides the width, so the
hero sits flush with the table/toolbar below it.
- `.stack-hero` (catalog + corporate-memory) and `.advanced-mock
.ad-hero` (/setup-advanced) follow the same pattern: container
owns the width.
- Per-page max-width overrides stripped from admin_users,
admin_access, admin_groups, admin_marketplaces, admin_welcome,
admin_workspace_prompt.
- _page_hero include extracted from inside flex toolbars on
admin_users, admin_access, admin_groups, admin_marketplaces,
admin_server_config, admin_welcome, admin_workspace_prompt,
admin_sessions, admin_session_detail, admin_usage,
activity_center. The toolbar (`.users-toolbar`, `.gp-toolbar`,
etc.) keeps only the filter + action controls; hero renders
before it as a sibling.
- _page_chrome.html trimmed to just the page-background tint for
the redesign scopes; the duplicate `.container` rules it carried
are now redundant.
Verified: /home, /admin/marketplaces, /admin/users all render
container width 1280px with hero top at 88px (16px below the
72px-tall sticky nav). Same spacing as /home design spec.
* fix(web): admin_tables + admin_corporate_memory inherit canonical .container
Both pages were overriding `{% block layout %}` from base.html,
which bypasses the canonical `.container` wrapper. Result: hero
span the full viewport (1596px on a wide screen) while the inner
content sat at a narrower max-width — hero and content didn't
align, and the nav-to-hero gap differed from every other admin
page.
Switched both templates to `{% block content %}` so they render
inside the canonical `.container` from base.html — same path as
admin_groups, admin_users, admin_marketplaces, etc.
- admin_tables: dropped local `.page-title { max-width: 1600px }`
+ `.content { max-width: 1600px }` overrides (kept typography +
inner gutter rules) and the mobile padding overrides that paired
with them. Container now owns the gutters.
- admin_corporate_memory: only the block keyword needed changing;
the template already had a clean inner structure (no max-width
override on `.container-memory`).
Verified on /admin/tables and /admin/corporate-memory:
- .container width 1280, padding 16/32/48
- Hero top 88 (nav 72 + container padding-top 16)
- Hero + content both 1216px wide, both at left 190 — perfect
alignment with /admin/groups.
* fix(web): drop .page-shell padding override + admin_tables stale :root
Two regressions discovered after the canonical-container unification:
1. `.container:has(.page-shell)` still set `padding: 28px 32px 48px`
while the canonical `.container` had moved to `16px 32px 48px`.
Every page-shell consumer (/admin/sessions, /admin/sessions/<id>,
/admin/usage, /marketplace, /dashboard, marketplace detail pages,
/me/activity, /store/*, /admin/store-submissions) was rendering
with a 28px nav-to-hero gap while /admin/users + /admin/groups
rendered with 16px. Same width, mismatched vertical rhythm.
The opt-in rule is now a no-op marker: canonical container
already provides 1280px + 16/32/48 + main margin/padding 0.
2. admin_tables.html had a stale `<style>` block that re-declared
`:root { --primary: var(--primary); ... }`. The self-referential
token resolved to empty, collapsing the page-header hero's
`linear-gradient(135deg, var(--primary), var(--primary-dark))`
to no background — the hero appeared as a pale ghost without
colour. The entire shadow `:root` block was a stale copy of the
design tokens that style-custom.css already provides. Dropped
it; tokens now resolve from the global `:root`.
After both fixes /admin/sessions, /admin/tables, and every other
page-shell consumer match /admin/groups exactly: container 1280px,
container padding-top 16px, hero at top 88px / left 190px / width
1216px.
* fix(web): drop /admin/tokens .tokens-page width + padding override
`.tokens-page` carried its own `max-width: 1280px; margin: 0 auto;
padding: 28px 8px 48px` block — the canonical `.container` already
provides width + 16/32/48 padding, so the nested wrapper was
adding 28px on top of the container's 16px (= 44px nav-to-hero
gap, vs 16px on every other admin page) and shrinking the hero
sideways by 8px on each side (1200px vs the canonical 1216px).
After: container owns the layout; `.tokens-page` is just a
font-family scope. /admin/tokens hero now sits at top 88, left 190,
width 1216 — same numbers as /admin/groups / /admin/users.
* fix(web): hero links readable on blue; /admin/access Groups link href
- New `.page-header--hero a` rule in style-custom.css forces any
anchor inside a gradient hero to render white + underlined so
links stay readable on the blue background. Previously links
inherited the global `var(--primary)` blue, which disappeared
on top of the matching blue gradient. No per-page class needed —
drop a plain `<a>` in any hero subtitle and it just works.
- /admin/access hero subtitle was Jinja-passing the inline link
with HTML-entity-encoded quotes (`href="..."`). The
entities decoded to literal `"` characters inside the rendered
href, producing `/admin/%22/admin/groups%22` — a 404. Switched
the `set` to a block-set (`{% set page_hero_subtitle %}...{% endset %}`)
so the inline `<a href="/admin/groups">Groups</a>` survives
unescaped through `_page_hero.html`. Also stripped the now-redundant
inline `style="color:#fff;text-decoration:underline;"` — the new
shared rule handles it.
* fix(web): /dashboard top padding matches every other page
`.main` on /dashboard had `padding: 28px 32px 48px` while every
other page now uses `16px 32px 48px` via the canonical
`.container`. Dashboard bypasses `.container` (overrides
base.html's `layout` block to render a full-width `<main>`
directly), so the padding lives on `.main` itself — bumped the
top to 16px to match.
After: first child top = 88, left = 190, width = 1216 — same
numbers as /admin/groups / /admin/users / /admin/marketplaces.
* fix(web): green eyebrow + white title on .page-header--hero (matches /home)
`.page-header--hero .page-header__eyebrow` was faint white
(rgba(255,255,255,0.75)) — readable but unbranded against the blue
gradient. Changed to `var(--ds-brand-accent)` (mint green #54d3a0)
so every page hero pairs a green eyebrow with white title +
subtitle, echoing /home's setup-section header (green eyebrow,
dark heading combo). One CSS rule applies everywhere — no
per-page styling needed.
Also bumped the eyebrow to font-weight 700 / letter-spacing 1.2px
so the green stands out cleanly against the gradient.
* fix(web): page-header--hero + stack-hero use /home navy gradient
`.page-header--hero` and `.stack-hero` were on the brand-blue
gradient (`var(--primary)` → `var(--primary-dark)`) while
/home's hero (`.home-hero-intro`) sits on the deeper navy
gradient (`#0f1b3a` → `#1a2a5f`). Every other page-hero now
uses that same navy gradient so /home, /marketplace, /catalog,
/corporate-memory, /admin/*, /profile, /install, /dashboard,
/setup-advanced share one brand surface. Shadow tint adjusted
to the navy depth (rgba(15, 27, 58, 0.22)).
Brand blue stays the link/CTA colour everywhere else; only the
hero box itself is navy.
* fix(web): primary buttons green; marketplace tabs navy translucent
Two parity tweaks pulling the rest of the app toward /home's
visual language.
- `.btn-primary` (both rules in style-custom.css) now uses
`var(--ds-primary)` / `var(--ds-primary-dark)` green fill,
matching the "Copy install script to clipboard" button on
/home. Brand-blue `--primary` still drives link colour and the
accent surface; only the filled button background flipped to
green. Every page with a `.btn-primary` (admin "+Add user",
"+Add marketplace", catalog, marketplace actions, dashboard,
modals) now reads as the same "do it" affordance.
- `.mp-tabs` (Curated Marketplace / Flea Market / My Stack tab
group) now sits on the navy `--ds-hero-bg` with translucent
white pills (rgba(255,255,255,0.10) inactive, 0.18 active) —
same translucent-white-on-navy treatment as the "Just browse —
no install needed" pill on /home. Icons render as soft white;
per-tab colour-coding dropped in favour of the unified surface.
* fix(web): catalog/memory tabs + empty-state CTA + admin action buttons
Bring /catalog and /memory in line with /home + /marketplace:
- `.stack-tabs` (Browse / My Stack / Recipes on /catalog,
Browse / My Stack on /memory) now uses the navy `--ds-hero-bg`
container with translucent-white-on-navy pills, mirroring the
`.mp-tabs` treatment and /home's "Just browse — no install
needed" CTA pill. Per-tab icon colour-coding dropped — icons
render as soft white on the navy fill.
- `.stack-tabs-row__actions .btn` (right-slot "+New Recipe",
"+New Data Package" admin CTAs) now uses green primary fill
(`--ds-primary`), matching `.btn-primary` and /home's
"Copy install script to clipboard" button.
- `.stack-empty .cta a` (empty-state action button — the
"Open /admin/tables →" CTA on /catalog and equivalent on
/memory) flipped from blue `--primary` to green `--ds-primary`
so the colour aligns with every other primary button in the app.
* fix(web): marketplace Search button green (--ds-primary) matching other CTAs
* fix(web): unify Search button + admin-action button across browse pages
- Added Search button (`<button class="stack-hero__search-btn">`)
to /catalog and /memory heroes — same green pill as /marketplace.
Wired to the existing live-filter pipeline (button click runs
`applyFilters()` and refocuses the input). All three browse pages
now wear the identical search bar UI.
- `.stack-hero__search-btn` shares `--ds-primary` fill with
`.mp-hero .search-btn`.
- `.mp-actions .btn` ("Submit a skill or plugin" CTA on /marketplace)
flipped from the legacy blue-outline to the same green primary
fill + dimensions (`display: inline-flex; line-height: 1;
padding: 9px 16px; gap: 6px`) as `.stack-tabs-row__actions .btn`
on /catalog and /memory. All three right-slot action buttons
render at identical height now.
- `.stack-tabs-row__actions .btn` got `inline-flex` + `line-height: 1`
+ `gap: 6px` so a `<button class="btn">` and a `<a class="btn">`
both render at exactly 33px high — the embedded
`.admin-only-hint` chip no longer pushes one variant taller
than the other.
* fix(web): marketplace guide CTAs green (fastpath + primary); drop flea purple
* fix(web): dashboard CTA hero on navy; readable <code> chips in hero
- `.env-setup-cta` on /dashboard ("Set up a new Claude Code"
card) flipped from the brand-blue gradient + green-tinted shadow
to the canonical navy gradient (`--ds-hero-bg` → `#1a2a5f`) with
navy-tinted shadow + 14px radius + 28/32/24 padding, matching
`.page-header--hero` and /home's `.home-hero-intro`. Dashboard's
top CTA now sits on the same brand surface as every other hero.
- Added `.page-header--hero code` rule — translucent white pill +
warm-yellow ink (#ffd866) so `<code>` chips embedded in hero
subtitles read as code samples against the navy gradient. The
global `code` rule sets `color: var(--text-primary)` (dark),
which turned in-hero chips into invisible dark-on-white-on-navy
ghosts (e.g. the `-by-dev` suffix on /store/new).
- /store/new's `.page-header__subtitle code` dropped its inline
style override — the shared rule handles it now.
* feat(web): two-theme switching via data-theme + admin toggle
Introduces a theme system that flips the entire UI palette between
"navy" (current design, default) and "blue" (pre-redesign palette)
via a single `<html data-theme="...">` attribute. Page markup, class
names, and component styles don't change — only the `--ds-*` token
values flip.
Backend
- New `app/instance_config.py::get_instance_theme()` resolves the
active theme from `AGNES_INSTANCE_THEME` env > `instance.theme`
in instance.yaml > default "navy". Unrecognised values clamp to
"navy" so a typo doesn't break the page.
- `app/web/router.py::_build_context` injects `instance_theme`
alongside `instance_brand` etc. so every template inherits it.
- `app/web/templates/base.html` renders
`<html lang="en" data-theme="{{ instance_theme | default('navy') }}">`.
CSS
- `app/web/static/css/design-tokens.css` adds two new tokens to
the default `:root` set: `--ds-hero-shadow` (drop-shadow tint
on hero boxes) and `--ds-hero-eyebrow` (eyebrow accent colour).
Plus a `:root[data-theme="blue"]` override block that flips
seven tokens: `--ds-primary`, `--ds-primary-dark`,
`--ds-primary-light`, `--ds-brand-accent`, `--ds-hero-bg`,
`--ds-hero-bg-deep`, `--ds-hero-shadow`, `--ds-hero-eyebrow`.
The blue theme aliases the brand surface tokens back to the
legacy `--primary` family.
- `.page-header--hero`, `.stack-hero`, `.env-setup-cta`,
`.home-mock .home-hero-intro` now reference the new
`--ds-hero-shadow` and `--ds-hero-bg-deep` tokens instead of
hard-coding `rgba(15, 27, 58, 0.22)` and `#1a2a5f` — gradient +
shadow now flip with the theme.
- `.page-header--hero .page-header__eyebrow` uses
`var(--ds-hero-eyebrow)` so the eyebrow goes mint-green on
navy and translucent-white on blue (mint on blue reads poorly).
Admin
- `app/api/admin.py::_KNOWN_FIELDS["instance"]` now registers a
`theme` field of kind `select` with options `["navy", "blue"]`
and a `hint` explaining the trade-off. The existing
/admin/server-config UI auto-renders a select for this — no
template changes needed.
Defaults
- Default value is "navy" so existing instances see no visual
change. Admins flip to "blue" via /admin/server-config to
restore the pre-redesign look.
Restart note: uvicorn must reload to pick up the Python changes
(new getter, new template-context key, new known-field). CSS
changes hot-reload via browser refresh.
* fix(web): blue theme — home hero eyebrow + CTA contrast
`.home-hero-intro .eyebrow` and `.btn-intro-primary` referenced
`--ds-brand-accent` directly, which on the blue theme resolves to
the lighter brand-accent blue (#4F9DEB). Result: light-blue eyebrow
on the blue gradient ("WELCOME, ADMIN" barely readable) and a
light-blue button with darker-blue text ("Set up in ~15 min")
that all sat in the same hue range.
Introduces three new theme-aware tokens:
- `--ds-hero-eyebrow` already existed; blue theme bumped opacity
to 0.92 so the eyebrow reads as full white.
- `--ds-hero-cta-bg` + `--ds-hero-cta-fg` + `--ds-hero-cta-bg-hover`
flip the primary hero CTA: mint-green on navy (default), white-
on-blue under `data-theme="blue"`.
`.home-hero-intro .eyebrow` now uses `--ds-hero-eyebrow` (mint on
navy / white on blue) and `.btn-intro-primary` uses the CTA token
trio.
Recommended palette on blue theme:
- Eyebrow: white at 92% opacity (clear on the blue gradient).
- Primary CTA pill: white background, brand-blue dark text
(`--primary-dark` = #005BA3) for AAA-level contrast.
- Secondary CTA: translucent white pill (unchanged).
* fix(web): blue theme — callout-hint info bg/border/ink re-tinted to brand blue (was indigo, clashed with brand-blue hero)
1137 lines
42 KiB
HTML
1137 lines
42 KiB
HTML
{% extends "base.html" %}
|
|
{% block title %}Access tokens — {{ config.INSTANCE_NAME }}{% endblock %}
|
|
|
|
{% block content %}
|
|
<style>
|
|
/* ─────────────────────────────────────────────────────────────────────────
|
|
/admin/tokens — ALL tokens across users for incident response + offboarding.
|
|
Admin-only. Card-stack layout with owner column, stat chip strip, owner
|
|
search + sort-by-owner chip, confirm-with-owner revoke modal. No "new
|
|
token" button here — admins use /me/profile for their own.
|
|
───────────────────────────────────────────────────────────────────────── */
|
|
|
|
/* Width + gutters come from the canonical `.container` in
|
|
style-custom.css. `.tokens-page` is just a font-family scope. */
|
|
.tokens-page {
|
|
font-family: var(--font-primary, 'Inter', system-ui, -apple-system, BlinkMacSystemFont, sans-serif);
|
|
}
|
|
|
|
/* ── Hero ──────────────────────────────────────────────────────────────── */
|
|
/* Hero box (gradient, padding, radius, max-width, shadow) comes
|
|
from the canonical `.page-header--hero` rule in
|
|
style-custom.css. `.tokens-hero` is now just a marker — the
|
|
extras (token-counts chip row) sit inside it as a child below
|
|
the canonical hero text. */
|
|
.tokens-hero {
|
|
margin-bottom: 20px;
|
|
}
|
|
|
|
.tokens-counts {
|
|
display: grid;
|
|
grid-template-columns: repeat(4, minmax(0, 1fr));
|
|
gap: 12px;
|
|
margin-top: 20px;
|
|
}
|
|
.tokens-counts .count-chip {
|
|
background: rgba(255, 255, 255, 0.12);
|
|
border: 1px solid rgba(255, 255, 255, 0.18);
|
|
border-radius: 10px;
|
|
padding: 12px 14px;
|
|
display: flex;
|
|
align-items: center;
|
|
gap: 10px;
|
|
backdrop-filter: saturate(140%) blur(2px);
|
|
}
|
|
.tokens-counts .count-chip .dot {
|
|
width: 10px; height: 10px; border-radius: 50%;
|
|
flex-shrink: 0;
|
|
box-shadow: 0 0 0 2px rgba(255, 255, 255, 0.15);
|
|
}
|
|
.tokens-counts .count-chip.active .dot { background: #16a34a; }
|
|
.tokens-counts .count-chip.expiring .dot { background: #ea580c; }
|
|
.tokens-counts .count-chip.expired .dot { background: #dc2626; }
|
|
.tokens-counts .count-chip.revoked .dot { background: #6b7280; }
|
|
.tokens-counts .count-chip .count-value {
|
|
font-size: 24px;
|
|
font-weight: 600;
|
|
line-height: 1;
|
|
color: #fff;
|
|
letter-spacing: -0.01em;
|
|
}
|
|
.tokens-counts .count-chip .count-label {
|
|
font-size: 11px;
|
|
font-weight: 500;
|
|
text-transform: uppercase;
|
|
letter-spacing: 0.4px;
|
|
color: rgba(255, 255, 255, 0.85);
|
|
margin-top: 2px;
|
|
}
|
|
.tokens-counts .count-chip .count-text {
|
|
display: flex;
|
|
flex-direction: column;
|
|
}
|
|
|
|
/* ── Toolbar ───────────────────────────────────────────────────────────── */
|
|
.toolbar {
|
|
margin-bottom: 14px;
|
|
display: flex;
|
|
flex-direction: column;
|
|
gap: 10px;
|
|
}
|
|
|
|
.chip-row {
|
|
display: flex;
|
|
flex-wrap: wrap;
|
|
align-items: center;
|
|
gap: 10px;
|
|
}
|
|
.chip-row .chip-group-label {
|
|
font-size: 11px;
|
|
font-weight: 600;
|
|
text-transform: uppercase;
|
|
letter-spacing: 0.4px;
|
|
color: var(--text-secondary, #6b7280);
|
|
margin-right: 4px;
|
|
}
|
|
|
|
.chip-group {
|
|
display: inline-flex;
|
|
flex-wrap: wrap;
|
|
gap: 6px;
|
|
}
|
|
.chip-btn {
|
|
font-family: var(--font-primary, inherit);
|
|
font-size: 12px;
|
|
font-weight: 500;
|
|
height: 30px;
|
|
padding: 0 12px;
|
|
border-radius: 999px;
|
|
border: 1px solid var(--border, #e5e7eb);
|
|
background: var(--surface, #fff);
|
|
color: var(--text-secondary, #6b7280);
|
|
cursor: pointer;
|
|
display: inline-flex;
|
|
align-items: center;
|
|
gap: 6px;
|
|
transition: all 0.12s ease;
|
|
line-height: 1;
|
|
white-space: nowrap;
|
|
}
|
|
.chip-btn:hover {
|
|
border-color: #cbd5e1;
|
|
color: var(--text-primary, #111827);
|
|
}
|
|
.chip-btn[aria-pressed="true"] {
|
|
background: rgba(46, 168, 119, 0.10);
|
|
border-color: var(--primary);
|
|
color: var(--primary);
|
|
font-weight: 600;
|
|
}
|
|
.chip-btn:focus-visible {
|
|
outline: 2px solid var(--primary);
|
|
outline-offset: 2px;
|
|
}
|
|
.chip-btn .chip-dot {
|
|
width: 7px; height: 7px; border-radius: 50%;
|
|
flex-shrink: 0;
|
|
}
|
|
.chip-btn[data-val="active"] .chip-dot { background: #16a34a; }
|
|
.chip-btn[data-val="expiring"] .chip-dot { background: #ea580c; }
|
|
.chip-btn[data-val="expired"] .chip-dot { background: #dc2626; }
|
|
.chip-btn[data-val="revoked"] .chip-dot { background: #6b7280; }
|
|
.chip-btn .chip-arrow {
|
|
width: 10px; height: 10px;
|
|
opacity: 0;
|
|
}
|
|
.chip-btn[data-sort-dir="asc"] .chip-arrow,
|
|
.chip-btn[data-sort-dir="desc"] .chip-arrow { opacity: 1; }
|
|
.chip-btn[data-sort-dir="asc"] .chip-arrow { transform: rotate(180deg); }
|
|
|
|
.search-row {
|
|
display: flex;
|
|
flex-wrap: wrap;
|
|
gap: 10px;
|
|
align-items: center;
|
|
}
|
|
.search-wrap {
|
|
position: relative;
|
|
flex: 1 1 280px;
|
|
min-width: 220px;
|
|
}
|
|
.search-wrap svg {
|
|
position: absolute;
|
|
left: 12px;
|
|
top: 50%;
|
|
transform: translateY(-50%);
|
|
width: 14px; height: 14px;
|
|
color: var(--text-secondary, #9ca3af);
|
|
pointer-events: none;
|
|
}
|
|
.search-wrap input[type="search"] {
|
|
width: 100%;
|
|
height: 38px;
|
|
padding: 0 12px 0 36px;
|
|
border: 1px solid var(--border, #e5e7eb);
|
|
border-radius: 8px;
|
|
font-size: 13px;
|
|
font-family: var(--font-primary, inherit);
|
|
background: var(--surface, #fff);
|
|
color: var(--text-primary, #111827);
|
|
transition: border-color 0.15s ease, box-shadow 0.15s ease;
|
|
}
|
|
.search-wrap input[type="search"]::placeholder { color: #9ca3af; }
|
|
.search-wrap input[type="search"]:hover { border-color: #cbd5e1; }
|
|
.search-wrap input[type="search"]:focus {
|
|
outline: none;
|
|
border-color: var(--primary);
|
|
box-shadow: 0 0 0 3px rgba(46, 168, 119, 0.15);
|
|
}
|
|
|
|
.clear-link {
|
|
font-family: var(--font-primary, inherit);
|
|
background: none;
|
|
border: none;
|
|
padding: 8px 4px;
|
|
font-size: 13px;
|
|
font-weight: 500;
|
|
color: var(--text-secondary, #6b7280);
|
|
cursor: pointer;
|
|
text-decoration: none;
|
|
margin-left: auto;
|
|
}
|
|
.clear-link:hover { color: var(--primary); text-decoration: underline; }
|
|
.clear-link:focus-visible {
|
|
outline: 2px solid var(--primary);
|
|
outline-offset: 2px;
|
|
border-radius: 4px;
|
|
}
|
|
|
|
/* Hidden legacy select controls — kept for test backcompat. */
|
|
.sr-only {
|
|
position: absolute !important;
|
|
width: 1px; height: 1px;
|
|
padding: 0; margin: -1px;
|
|
overflow: hidden; clip: rect(0,0,0,0);
|
|
white-space: nowrap; border: 0;
|
|
}
|
|
|
|
/* ── Card list ─────────────────────────────────────────────────────────── */
|
|
.tokens-list {
|
|
list-style: none;
|
|
padding: 0;
|
|
margin: 0;
|
|
display: flex;
|
|
flex-direction: column;
|
|
gap: 10px;
|
|
}
|
|
.token-card {
|
|
background: var(--surface, #fff);
|
|
border: 1px solid var(--border, #e5e7eb);
|
|
border-radius: 12px;
|
|
padding: 16px 20px;
|
|
display: flex;
|
|
align-items: center;
|
|
gap: 20px;
|
|
transition: box-shadow 0.15s ease, border-color 0.15s ease, transform 0.15s ease;
|
|
}
|
|
.token-card:hover {
|
|
box-shadow: 0 4px 16px rgba(15, 23, 42, 0.06);
|
|
border-color: #cbd5e1;
|
|
}
|
|
.token-card.is-revoked,
|
|
.token-card.is-expired {
|
|
background: #fafbfc;
|
|
}
|
|
.token-card.is-revoked .token-name,
|
|
.token-card.is-revoked .owner-email {
|
|
text-decoration: line-through;
|
|
color: var(--text-secondary, #6b7280);
|
|
}
|
|
|
|
.token-main {
|
|
flex: 1 1 auto;
|
|
min-width: 0;
|
|
display: flex;
|
|
align-items: center;
|
|
gap: 12px;
|
|
}
|
|
.avatar-sm {
|
|
width: 32px; height: 32px;
|
|
border-radius: 50%;
|
|
background: var(--primary);
|
|
color: #fff;
|
|
font-size: 12px;
|
|
font-weight: 600;
|
|
letter-spacing: 0.3px;
|
|
display: inline-flex;
|
|
align-items: center;
|
|
justify-content: center;
|
|
flex-shrink: 0;
|
|
text-transform: uppercase;
|
|
}
|
|
.token-text { min-width: 0; }
|
|
.token-name {
|
|
display: block;
|
|
font-size: 15px;
|
|
font-weight: 600;
|
|
color: var(--text-primary, #1A253C);
|
|
line-height: 1.3;
|
|
white-space: nowrap;
|
|
overflow: hidden;
|
|
text-overflow: ellipsis;
|
|
max-width: 380px;
|
|
}
|
|
.token-meta {
|
|
display: block;
|
|
font-size: 13px;
|
|
color: var(--text-secondary, #6b7280);
|
|
line-height: 1.4;
|
|
margin-top: 2px;
|
|
white-space: nowrap;
|
|
overflow: hidden;
|
|
text-overflow: ellipsis;
|
|
max-width: 420px;
|
|
}
|
|
.owner-email { color: inherit; }
|
|
.chip-mono {
|
|
display: inline-block;
|
|
padding: 1px 6px;
|
|
background: var(--border-light, #f3f4f6);
|
|
border-radius: 4px;
|
|
font-family: var(--font-mono, ui-monospace, "SF Mono", Menlo, monospace);
|
|
font-size: 11.5px;
|
|
color: var(--text-secondary, #6b7280);
|
|
letter-spacing: 0.2px;
|
|
margin: 0 2px;
|
|
}
|
|
|
|
.token-usage {
|
|
flex: 0 0 200px;
|
|
min-width: 0;
|
|
display: flex;
|
|
flex-direction: column;
|
|
gap: 2px;
|
|
}
|
|
.token-usage .usage-main {
|
|
font-size: 13px;
|
|
font-weight: 500;
|
|
color: var(--text-primary, #1A253C);
|
|
white-space: nowrap;
|
|
overflow: hidden;
|
|
text-overflow: ellipsis;
|
|
}
|
|
.token-usage .usage-sub {
|
|
font-size: 11.5px;
|
|
color: var(--text-secondary, #6b7280);
|
|
white-space: nowrap;
|
|
overflow: hidden;
|
|
text-overflow: ellipsis;
|
|
}
|
|
.token-usage.soon .usage-main { color: #c2410c; }
|
|
.token-usage.expired .usage-main{ color: #b91c1c; }
|
|
.token-usage.strike .usage-main { text-decoration: line-through; color: #9ca3af; font-weight: 400; }
|
|
|
|
.token-aside {
|
|
display: flex;
|
|
align-items: center;
|
|
gap: 12px;
|
|
flex-shrink: 0;
|
|
}
|
|
|
|
/* ── Status pill ───────────────────────────────────────────────────────── */
|
|
.status-pill {
|
|
display: inline-flex;
|
|
align-items: center;
|
|
gap: 6px;
|
|
padding: 4px 10px;
|
|
border-radius: 999px;
|
|
font-size: 11px;
|
|
font-weight: 500;
|
|
text-transform: uppercase;
|
|
letter-spacing: 0.3px;
|
|
white-space: nowrap;
|
|
}
|
|
.status-pill .pill-dot {
|
|
width: 7px; height: 7px; border-radius: 50%;
|
|
flex-shrink: 0;
|
|
}
|
|
.status-pill.status-active { background: rgba(22, 163, 74, 0.12); color: #15803d; }
|
|
.status-pill.status-active .pill-dot { background: #16a34a; }
|
|
.status-pill.status-expiring { background: rgba(234, 88, 12, 0.12); color: #c2410c; }
|
|
.status-pill.status-expiring .pill-dot { background: #ea580c; }
|
|
.status-pill.status-expired { background: rgba(220, 38, 38, 0.12); color: #b91c1c; }
|
|
.status-pill.status-expired .pill-dot { background: #dc2626; }
|
|
.status-pill.status-revoked { background: rgba(107, 114, 128, 0.12); color: #4b5563; }
|
|
.status-pill.status-revoked .pill-dot { background: #6b7280; }
|
|
|
|
/* ── Revoke button ─────────────────────────────────────────────────────── */
|
|
.revoke-btn {
|
|
display: inline-flex;
|
|
align-items: center;
|
|
gap: 6px;
|
|
height: 32px;
|
|
padding: 0 14px;
|
|
border-radius: 8px;
|
|
font-family: var(--font-primary, inherit);
|
|
font-size: 13px;
|
|
font-weight: 500;
|
|
cursor: pointer;
|
|
background: transparent;
|
|
color: #dc2626;
|
|
border: 1px solid rgba(220, 38, 38, 0.35);
|
|
transition: all 0.12s ease;
|
|
line-height: 1;
|
|
}
|
|
.revoke-btn:hover:not([disabled]) {
|
|
background: #dc2626;
|
|
color: #fff;
|
|
border-color: #dc2626;
|
|
}
|
|
.revoke-btn:focus-visible {
|
|
outline: 2px solid var(--primary);
|
|
outline-offset: 2px;
|
|
}
|
|
.revoke-btn[disabled] {
|
|
opacity: 0.4;
|
|
cursor: not-allowed;
|
|
border-color: var(--border, #e5e7eb);
|
|
color: var(--text-secondary, #9ca3af);
|
|
}
|
|
.revoke-btn svg { display: block; }
|
|
.token-card:hover .revoke-btn:not([disabled]) {
|
|
border-color: #dc2626;
|
|
}
|
|
|
|
/* ── Empty / loading ───────────────────────────────────────────────────── */
|
|
.tokens-empty, .tokens-loading {
|
|
text-align: center;
|
|
padding: 48px 24px;
|
|
color: var(--text-secondary, #6b7280);
|
|
font-size: 14px;
|
|
background: var(--surface, #fff);
|
|
border: 1px solid var(--border, #e5e7eb);
|
|
border-radius: 12px;
|
|
}
|
|
.tokens-empty .empty-icon {
|
|
margin: 0 auto 14px;
|
|
width: 56px; height: 56px;
|
|
color: #d1d5db;
|
|
}
|
|
.tokens-empty .empty-title {
|
|
font-size: 15px;
|
|
font-weight: 600;
|
|
color: var(--text-primary, #1A253C);
|
|
margin: 0 0 4px;
|
|
}
|
|
.tokens-empty .empty-body {
|
|
font-size: 13px;
|
|
margin: 0 0 16px;
|
|
}
|
|
.tokens-empty .empty-clear {
|
|
padding: 8px 16px;
|
|
border-radius: 8px;
|
|
font-size: 13px;
|
|
font-weight: 500;
|
|
font-family: var(--font-primary, inherit);
|
|
border: 1px solid var(--border, #e5e7eb);
|
|
background: var(--surface, #fff);
|
|
color: var(--text-primary, #1A253C);
|
|
cursor: pointer;
|
|
transition: all 0.15s ease;
|
|
}
|
|
.tokens-empty .empty-clear:hover {
|
|
border-color: var(--primary);
|
|
color: var(--primary);
|
|
background: rgba(46, 168, 119, 0.04);
|
|
}
|
|
|
|
/* ── Modal ─────────────────────────────────────────────────────────────── */
|
|
.modal-backdrop {
|
|
position: fixed; inset: 0;
|
|
background: rgba(15, 23, 42, 0.55);
|
|
backdrop-filter: blur(2px);
|
|
display: none;
|
|
align-items: center;
|
|
justify-content: center;
|
|
z-index: 1000;
|
|
padding: 16px;
|
|
}
|
|
.modal-backdrop.is-open { display: flex; }
|
|
.modal-card {
|
|
background: var(--surface, #fff);
|
|
border-radius: 16px;
|
|
padding: 32px;
|
|
width: 100%;
|
|
max-width: 480px;
|
|
box-shadow: 0 24px 64px rgba(0, 0, 0, 0.28);
|
|
animation: modal-in 0.18s ease-out;
|
|
}
|
|
@keyframes modal-in {
|
|
from { opacity: 0; transform: translateY(8px) scale(0.98); }
|
|
to { opacity: 1; transform: translateY(0) scale(1); }
|
|
}
|
|
.modal-card h3 {
|
|
margin: 0 0 10px;
|
|
font-size: 20px;
|
|
font-weight: 700;
|
|
color: var(--text-primary, #1A253C);
|
|
letter-spacing: -0.01em;
|
|
}
|
|
.modal-card p.sub {
|
|
margin: 0 0 18px;
|
|
font-size: 13.5px;
|
|
color: var(--text-secondary, #6b7280);
|
|
line-height: 1.55;
|
|
}
|
|
.modal-meta {
|
|
margin: 14px 0 4px;
|
|
padding: 14px 16px;
|
|
background: var(--background, #F5F7FA);
|
|
border: 1px solid var(--border-light, #f3f4f6);
|
|
border-radius: 10px;
|
|
display: grid;
|
|
grid-template-columns: max-content 1fr;
|
|
gap: 6px 14px;
|
|
font-size: 13px;
|
|
}
|
|
.modal-meta .mk {
|
|
color: var(--text-secondary, #6b7280);
|
|
font-size: 11px;
|
|
text-transform: uppercase;
|
|
letter-spacing: 0.4px;
|
|
font-weight: 600;
|
|
align-self: center;
|
|
}
|
|
.modal-meta .mv {
|
|
color: var(--text-primary, #1A253C);
|
|
font-weight: 500;
|
|
word-break: break-all;
|
|
}
|
|
.modal-meta .mv.mono {
|
|
font-family: var(--font-mono, ui-monospace, monospace);
|
|
font-size: 12px;
|
|
font-weight: 400;
|
|
}
|
|
.modal-actions {
|
|
display: flex;
|
|
gap: 10px;
|
|
justify-content: flex-end;
|
|
margin-top: 24px;
|
|
}
|
|
|
|
/* ── Toast ─────────────────────────────────────────────────────────────── */
|
|
.toast-stack {
|
|
position: fixed; bottom: 24px; right: 24px; z-index: 2000;
|
|
display: flex; flex-direction: column; gap: 8px; pointer-events: none;
|
|
}
|
|
.toast {
|
|
background: #111827;
|
|
color: #fff;
|
|
padding: 11px 18px;
|
|
border-radius: 10px;
|
|
font-size: 13px;
|
|
font-weight: 500;
|
|
box-shadow: 0 12px 36px rgba(0, 0, 0, 0.28);
|
|
opacity: 0;
|
|
transform: translateY(8px);
|
|
transition: opacity 0.2s, transform 0.2s;
|
|
pointer-events: auto;
|
|
max-width: 400px;
|
|
}
|
|
.toast.show { opacity: 1; transform: translateY(0); }
|
|
.toast.success { background: #047857; }
|
|
.toast.error { background: #b91c1c; }
|
|
|
|
/* ── Responsive ────────────────────────────────────────────────────────── */
|
|
@media (max-width: 720px) {
|
|
.tokens-hero { padding: 24px 20px 20px; }
|
|
.tokens-hero .tokens-title { font-size: 22px; }
|
|
.tokens-hero .hero-top { flex-direction: column; align-items: stretch; }
|
|
|
|
.token-card {
|
|
flex-direction: column;
|
|
align-items: stretch;
|
|
gap: 14px;
|
|
}
|
|
.token-main { width: 100%; }
|
|
.token-name { max-width: none; white-space: normal; }
|
|
.token-meta { max-width: none; white-space: normal; }
|
|
.token-usage {
|
|
flex: 1 1 auto;
|
|
width: 100%;
|
|
padding-left: 44px; /* align under avatar */
|
|
}
|
|
.token-aside {
|
|
width: 100%;
|
|
justify-content: space-between;
|
|
padding-left: 44px;
|
|
}
|
|
}
|
|
@media (max-width: 480px) {
|
|
.tokens-counts { grid-template-columns: repeat(2, minmax(0, 1fr)); }
|
|
}
|
|
</style>
|
|
|
|
<div class="tokens-page" data-is-admin="true" data-view="admin">
|
|
<!-- ═════════ HERO ═════════ -->
|
|
{# Canonical page-hero box + bespoke `tokens-counts` chip row on the
|
|
gradient. `.page-header__title` etc. drive the typography from the
|
|
shared rule in style-custom.css, matching every other admin page. #}
|
|
<section class="page-header page-header--hero tokens-hero" aria-labelledby="tokens-title">
|
|
<div class="page-header__main">
|
|
<div class="page-header__eyebrow">Administration</div>
|
|
<h1 class="page-header__title" id="tokens-title">Access tokens</h1>
|
|
<p class="page-header__subtitle">
|
|
Personal access tokens across all users — for incident response and offboarding.
|
|
</p>
|
|
</div>
|
|
|
|
<div class="tokens-counts" id="tokens-counts" aria-live="polite" aria-label="Token counts summary">
|
|
<div class="count-chip active">
|
|
<span class="dot" aria-hidden="true"></span>
|
|
<div class="count-text">
|
|
<span class="count-value" id="count-active">0</span>
|
|
<span class="count-label">Active</span>
|
|
</div>
|
|
</div>
|
|
<div class="count-chip expiring" title="Active tokens expiring in the next 7 days">
|
|
<span class="dot" aria-hidden="true"></span>
|
|
<div class="count-text">
|
|
<span class="count-value" id="count-expiring">0</span>
|
|
<span class="count-label">Expiring soon</span>
|
|
</div>
|
|
</div>
|
|
<div class="count-chip expired">
|
|
<span class="dot" aria-hidden="true"></span>
|
|
<div class="count-text">
|
|
<span class="count-value" id="count-expired">0</span>
|
|
<span class="count-label">Expired</span>
|
|
</div>
|
|
</div>
|
|
<div class="count-chip revoked">
|
|
<span class="dot" aria-hidden="true"></span>
|
|
<div class="count-text">
|
|
<span class="count-value" id="count-revoked">0</span>
|
|
<span class="count-label">Revoked</span>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<!-- ═════════ TOOLBAR ═════════ -->
|
|
<section class="toolbar" aria-label="Filter and sort tokens">
|
|
<div class="chip-row">
|
|
<span class="chip-group-label" id="status-group-label">Status</span>
|
|
<div class="chip-group" role="radiogroup" aria-labelledby="status-group-label" id="flt-status-group">
|
|
<button type="button" class="chip-btn" role="radio" data-val="all" aria-pressed="true" aria-checked="true">All</button>
|
|
<button type="button" class="chip-btn" role="radio" data-val="active" aria-pressed="false" aria-checked="false"><span class="chip-dot" aria-hidden="true"></span>Active</button>
|
|
<button type="button" class="chip-btn" role="radio" data-val="expiring" aria-pressed="false" aria-checked="false"><span class="chip-dot" aria-hidden="true"></span>Expiring</button>
|
|
<button type="button" class="chip-btn" role="radio" data-val="expired" aria-pressed="false" aria-checked="false"><span class="chip-dot" aria-hidden="true"></span>Expired</button>
|
|
<button type="button" class="chip-btn" role="radio" data-val="revoked" aria-pressed="false" aria-checked="false"><span class="chip-dot" aria-hidden="true"></span>Revoked</button>
|
|
</div>
|
|
<!-- Hidden legacy select — kept so test assertion id="flt-status" stays valid -->
|
|
<select id="flt-status" class="sr-only" tabindex="-1" aria-hidden="true">
|
|
<option value="all" selected>All</option>
|
|
<option value="active">Active</option>
|
|
<option value="expiring">Expiring</option>
|
|
<option value="expired">Expired</option>
|
|
<option value="revoked">Revoked</option>
|
|
</select>
|
|
</div>
|
|
|
|
<div class="chip-row">
|
|
<span class="chip-group-label" id="sort-group-label">Sort by</span>
|
|
<div class="chip-group" role="group" aria-labelledby="sort-group-label" id="sort-group">
|
|
<button type="button" class="chip-btn" data-sort-key="created_at" data-sort-dir="desc" aria-pressed="true">
|
|
Created<svg class="chip-arrow" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="3" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><polyline points="6 9 12 15 18 9"></polyline></svg>
|
|
</button>
|
|
<button type="button" class="chip-btn" data-sort-key="last_used_at" aria-pressed="false">
|
|
Last used<svg class="chip-arrow" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="3" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><polyline points="6 9 12 15 18 9"></polyline></svg>
|
|
</button>
|
|
<button type="button" class="chip-btn" data-sort-key="expires_at" aria-pressed="false">
|
|
Expires<svg class="chip-arrow" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="3" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><polyline points="6 9 12 15 18 9"></polyline></svg>
|
|
</button>
|
|
<button type="button" class="chip-btn" data-sort-key="user_email" aria-pressed="false">
|
|
Owner<svg class="chip-arrow" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="3" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><polyline points="6 9 12 15 18 9"></polyline></svg>
|
|
</button>
|
|
</div>
|
|
<!-- Hidden legacy select — kept so test assertion id="flt-last-used" stays valid -->
|
|
<select id="flt-last-used" class="sr-only" tabindex="-1" aria-hidden="true">
|
|
<option value="any" selected>Any time</option>
|
|
<option value="never">Never used</option>
|
|
<option value="7d">< 7 days ago</option>
|
|
<option value="30d">< 30 days ago</option>
|
|
<option value="gt30d">> 30 days ago</option>
|
|
<option value="gt90d">> 90 days ago</option>
|
|
</select>
|
|
</div>
|
|
|
|
<div class="search-row">
|
|
<div class="search-wrap">
|
|
<svg viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
|
|
<circle cx="11" cy="11" r="7"></circle>
|
|
<path d="m21 21-4.3-4.3"></path>
|
|
</svg>
|
|
<input id="flt-user" type="search" placeholder="Search by owner email…" autocomplete="off" aria-label="Filter by user email">
|
|
</div>
|
|
<button type="button" class="clear-link" id="clear-filters-toolbar">Clear filters</button>
|
|
</div>
|
|
</section>
|
|
|
|
<!-- ═════════ LIST ═════════ -->
|
|
<div id="tokens-loading" class="tokens-loading">Loading tokens…</div>
|
|
<ul class="tokens-list" id="tokens-list" role="list" aria-labelledby="tokens-title"></ul>
|
|
<div id="tokens-empty" class="tokens-empty" style="display:none;">
|
|
<svg class="empty-icon" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true">
|
|
<circle cx="8" cy="15" r="4"></circle>
|
|
<line x1="10.85" y1="12.15" x2="19" y2="4"></line>
|
|
<line x1="18" y1="5" x2="20" y2="7"></line>
|
|
<line x1="15" y1="8" x2="17" y2="10"></line>
|
|
</svg>
|
|
<p class="empty-title">No tokens match these filters.</p>
|
|
<p class="empty-body">Adjust the filters or clear them to see everything.</p>
|
|
<button type="button" class="empty-clear" id="clear-filters-btn">Clear filters</button>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- ═════════ REVOKE MODAL ═════════ -->
|
|
<div class="modal-backdrop" id="confirm-modal" role="dialog" aria-modal="true" aria-labelledby="confirm-title">
|
|
<div class="modal-card">
|
|
<h3 id="confirm-title">Revoke this token?</h3>
|
|
<p class="sub" id="confirm-text">
|
|
This cannot be undone and will immediately sign out any session using this token.
|
|
</p>
|
|
<div class="modal-meta" id="confirm-meta" aria-hidden="true"></div>
|
|
<div class="modal-actions">
|
|
<button class="btn btn-secondary" id="confirm-cancel-btn" data-close-modal="confirm-modal">Cancel</button>
|
|
<button class="btn btn-danger" id="confirm-ok-btn">Revoke token</button>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="toast-stack" id="toast-stack" aria-live="polite"></div>
|
|
|
|
<script>
|
|
// Admin tokens — list of ALL tokens for incident response / offboarding.
|
|
const API_LIST = "/auth/admin/tokens";
|
|
const API_REVOKE = (id) => `/auth/admin/tokens/${encodeURIComponent(id)}`;
|
|
const SEVEN_DAYS = 7 * 86_400_000;
|
|
|
|
// ── Helpers ────────────────────────────────────────────────────────────────
|
|
function esc(s) {
|
|
const d = document.createElement("div");
|
|
d.textContent = s == null ? "" : String(s);
|
|
return d.innerHTML;
|
|
}
|
|
function fmtAbs(s) { return s ? String(s).replace("T", " ").slice(0, 19) : "—"; }
|
|
function parseDate(s) {
|
|
if (!s) return null;
|
|
const str = String(s).replace(" ", "T");
|
|
const d = new Date(str);
|
|
return isNaN(d.getTime()) ? null : d;
|
|
}
|
|
function relTime(s) {
|
|
const d = parseDate(s);
|
|
if (!d) return "—";
|
|
const diff = Date.now() - d.getTime();
|
|
const abs = Math.abs(diff);
|
|
const sign = diff < 0 ? "in " : "";
|
|
const suf = diff >= 0 ? " ago" : "";
|
|
const min = 60_000, hr = 3_600_000, day = 86_400_000;
|
|
if (abs < min) return sign + "just now";
|
|
if (abs < hr) return sign + Math.floor(abs / min) + "m" + suf;
|
|
if (abs < day) return sign + Math.floor(abs / hr) + "h" + suf;
|
|
const days = Math.floor(abs / day);
|
|
if (days === 1) return sign + "1 day" + suf;
|
|
if (days < 60) return sign + days + " days" + suf;
|
|
const months = Math.floor(days / 30);
|
|
if (months < 24) return sign + months + "mo" + suf;
|
|
return sign + Math.floor(days / 365) + "y" + suf;
|
|
}
|
|
function initialsFor(email) {
|
|
if (!email) return "??";
|
|
const clean = String(email).trim();
|
|
if (clean.includes("@")) {
|
|
const local = clean.split("@")[0];
|
|
if (local.includes(".")) {
|
|
const parts = local.split(".").filter(Boolean);
|
|
return (parts[0][0] + (parts[1] ? parts[1][0] : parts[0][1] || "")).toUpperCase();
|
|
}
|
|
return (local[0] + (local[1] || "")).toUpperCase();
|
|
}
|
|
return clean.slice(0, 2).toUpperCase();
|
|
}
|
|
|
|
function computeStatus(t, now) {
|
|
if (t.revoked_at) return "revoked";
|
|
const exp = parseDate(t.expires_at);
|
|
if (exp && exp.getTime() < now) return "expired";
|
|
if (exp && (exp.getTime() - now) < SEVEN_DAYS) return "expiring";
|
|
return "active";
|
|
}
|
|
function statusPill(status) {
|
|
const map = {
|
|
active: { cls: "status-active", label: "active", aria: "active token" },
|
|
expiring: { cls: "status-expiring", label: "expiring", aria: "token expiring soon" },
|
|
expired: { cls: "status-expired", label: "expired", aria: "expired token" },
|
|
revoked: { cls: "status-revoked", label: "revoked", aria: "revoked token" },
|
|
};
|
|
const info = map[status] || map.revoked;
|
|
return `<span class="status-pill ${info.cls}" aria-label="${info.aria}"><span class="pill-dot" aria-hidden="true"></span>${info.label}</span>`;
|
|
}
|
|
function statusTooltip(t, status) {
|
|
if (status === "revoked") return t.revoked_at ? "Revoked " + relTime(t.revoked_at) : "Revoked";
|
|
if (status === "expired") return t.expires_at ? "Expired " + relTime(t.expires_at) : "Expired";
|
|
if (status === "expiring") return t.expires_at ? "Expires " + relTime(t.expires_at) : "Expiring soon";
|
|
return t.expires_at ? "Active, expires " + relTime(t.expires_at) : "Active";
|
|
}
|
|
|
|
// ── Toast ──────────────────────────────────────────────────────────────────
|
|
function toast(msg, kind = "") {
|
|
const el = document.createElement("div");
|
|
el.className = "toast " + kind;
|
|
el.textContent = msg;
|
|
document.getElementById("toast-stack").appendChild(el);
|
|
requestAnimationFrame(() => el.classList.add("show"));
|
|
setTimeout(() => { el.classList.remove("show"); setTimeout(() => el.remove(), 250); }, 3500);
|
|
}
|
|
|
|
// ── Modal ──────────────────────────────────────────────────────────────────
|
|
let _modalPrevFocus = null;
|
|
function openModal(id) {
|
|
const m = document.getElementById(id);
|
|
_modalPrevFocus = document.activeElement;
|
|
m.classList.add("is-open");
|
|
const cancel = m.querySelector("#confirm-cancel-btn");
|
|
if (cancel) setTimeout(() => cancel.focus(), 10);
|
|
}
|
|
function closeModal(id) {
|
|
const m = document.getElementById(id);
|
|
m.classList.remove("is-open");
|
|
if (_modalPrevFocus && typeof _modalPrevFocus.focus === "function") {
|
|
try { _modalPrevFocus.focus(); } catch (_) {}
|
|
}
|
|
_modalPrevFocus = null;
|
|
}
|
|
document.querySelectorAll("[data-close-modal]").forEach(el =>
|
|
el.addEventListener("click", () => closeModal(el.dataset.closeModal)));
|
|
document.querySelectorAll(".modal-backdrop").forEach(el => {
|
|
el.addEventListener("click", e => { if (e.target === el) closeModal(el.id); });
|
|
});
|
|
document.addEventListener("keydown", e => {
|
|
if (e.key === "Escape") {
|
|
document.querySelectorAll(".modal-backdrop.is-open").forEach(m => closeModal(m.id));
|
|
}
|
|
if (e.key === "Tab") {
|
|
const open = document.querySelector(".modal-backdrop.is-open");
|
|
if (!open) return;
|
|
const focusables = open.querySelectorAll('button, [href], input, select, textarea, [tabindex]:not([tabindex="-1"])');
|
|
if (!focusables.length) return;
|
|
const first = focusables[0];
|
|
const last = focusables[focusables.length - 1];
|
|
if (e.shiftKey && document.activeElement === first) {
|
|
e.preventDefault(); last.focus();
|
|
} else if (!e.shiftKey && document.activeElement === last) {
|
|
e.preventDefault(); first.focus();
|
|
}
|
|
}
|
|
});
|
|
|
|
function confirmModal({ title, sub, meta, okLabel = "Revoke token" }) {
|
|
document.getElementById("confirm-title").textContent = title;
|
|
document.getElementById("confirm-text").textContent = sub;
|
|
const metaEl = document.getElementById("confirm-meta");
|
|
if (meta && Object.keys(meta).length) {
|
|
let html = "";
|
|
for (const [k, v] of Object.entries(meta)) {
|
|
const isMono = k === "Prefix";
|
|
html += `<span class="mk">${esc(k)}</span><span class="mv${isMono ? " mono" : ""}">${esc(v)}</span>`;
|
|
}
|
|
metaEl.innerHTML = html;
|
|
metaEl.style.display = "grid";
|
|
} else {
|
|
metaEl.style.display = "none";
|
|
}
|
|
const okBtn = document.getElementById("confirm-ok-btn");
|
|
okBtn.textContent = okLabel;
|
|
return new Promise(resolve => {
|
|
const ok = () => { closeModal("confirm-modal"); cleanup(); resolve(true); };
|
|
const cancel = () => { cleanup(); resolve(false); };
|
|
const onCancelClick = () => cancel();
|
|
const cancelBtn = document.getElementById("confirm-cancel-btn");
|
|
function cleanup() {
|
|
okBtn.removeEventListener("click", ok);
|
|
cancelBtn.removeEventListener("click", onCancelClick);
|
|
}
|
|
okBtn.addEventListener("click", ok, { once: true });
|
|
cancelBtn.addEventListener("click", onCancelClick, { once: true });
|
|
openModal("confirm-modal");
|
|
});
|
|
}
|
|
|
|
// ── State ──────────────────────────────────────────────────────────────────
|
|
let allTokens = [];
|
|
let filters = { status: "all", user: "" };
|
|
let sort = { key: "created_at", dir: "desc" };
|
|
|
|
function applyFilters(items) {
|
|
const now = Date.now();
|
|
return items.filter(t => {
|
|
const s = computeStatus(t, now);
|
|
if (filters.status !== "all" && s !== filters.status) return false;
|
|
if (filters.user) {
|
|
const q = filters.user.toLowerCase();
|
|
if (!(t.user_email || "").toLowerCase().includes(q)) return false;
|
|
}
|
|
return true;
|
|
});
|
|
}
|
|
|
|
function sortItems(items) {
|
|
const now = Date.now();
|
|
const { key, dir } = sort;
|
|
const mul = dir === "asc" ? 1 : -1;
|
|
return [...items].sort((a, b) => {
|
|
let va, vb;
|
|
if (key === "status") { va = computeStatus(a, now); vb = computeStatus(b, now); }
|
|
else { va = a[key] || ""; vb = b[key] || ""; }
|
|
if (va < vb) return -1 * mul;
|
|
if (va > vb) return 1 * mul;
|
|
return 0;
|
|
});
|
|
}
|
|
|
|
function updateCounts() {
|
|
const now = Date.now();
|
|
let active = 0, revoked = 0, expired = 0, expiring = 0;
|
|
for (const t of allTokens) {
|
|
const s = computeStatus(t, now);
|
|
if (s === "active") active++;
|
|
else if (s === "expiring") expiring++;
|
|
else if (s === "revoked") revoked++;
|
|
else if (s === "expired") expired++;
|
|
}
|
|
const byId = (id) => document.getElementById(id);
|
|
if (byId("count-active")) byId("count-active").textContent = active;
|
|
if (byId("count-revoked")) byId("count-revoked").textContent = revoked;
|
|
if (byId("count-expired")) byId("count-expired").textContent = expired;
|
|
if (byId("count-expiring")) byId("count-expiring").textContent = expiring;
|
|
}
|
|
|
|
// ── Card render ────────────────────────────────────────────────────────────
|
|
const TRASH_SVG = `<svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" aria-hidden="true"><polyline points="3 6 5 6 21 6"></polyline><path d="M19 6l-1 14a2 2 0 0 1-2 2H8a2 2 0 0 1-2-2L5 6"></path><path d="M10 11v6"></path><path d="M14 11v6"></path><path d="M9 6V4a2 2 0 0 1 2-2h2a2 2 0 0 1 2 2v2"></path></svg>`;
|
|
|
|
function renderCard(t, now) {
|
|
const status = computeStatus(t, now);
|
|
const ownerEmail = t.user_email || t.user_id || "—";
|
|
const initials = initialsFor(ownerEmail);
|
|
const exp = parseDate(t.expires_at);
|
|
|
|
const lastUsedRel = t.last_used_at ? relTime(t.last_used_at) : "—";
|
|
const lastUsedIp = t.last_used_ip ? `from ${esc(t.last_used_ip)}` : (t.last_used_at ? "" : "never used");
|
|
const lastUsedTitle = t.last_used_at
|
|
? `${fmtAbs(t.last_used_at)}${t.last_used_ip ? " from " + t.last_used_ip : ""}`
|
|
: "never used";
|
|
|
|
let usageCls = "";
|
|
if (status === "revoked") usageCls = "";
|
|
|
|
const createdRel = relTime(t.created_at);
|
|
let expPart = "";
|
|
if (t.revoked_at) {
|
|
expPart = `<span style="color:#6b7280;">Revoked ${esc(relTime(t.revoked_at))}</span>`;
|
|
} else if (exp) {
|
|
const delta = exp.getTime() - now;
|
|
if (delta < 0) {
|
|
expPart = `<span style="color:#b91c1c;font-weight:500;">Expired ${esc(relTime(t.expires_at))}</span>`;
|
|
} else if (delta < SEVEN_DAYS) {
|
|
expPart = `<span style="color:#c2410c;font-weight:500;">Expires ${esc(relTime(t.expires_at))}</span>`;
|
|
} else {
|
|
expPart = `Expires ${esc(relTime(t.expires_at))}`;
|
|
}
|
|
} else {
|
|
expPart = "No expiry";
|
|
}
|
|
|
|
const card = document.createElement("li");
|
|
card.className = "token-card" + (status === "revoked" ? " is-revoked" : "") + (status === "expired" ? " is-expired" : "");
|
|
card.setAttribute("role", "listitem");
|
|
card.setAttribute("data-token-card", t.id);
|
|
card.setAttribute("data-status", status);
|
|
|
|
card.innerHTML = `
|
|
<div class="token-main">
|
|
<span class="avatar-sm" aria-hidden="true">${esc(initials)}</span>
|
|
<div class="token-text">
|
|
<span class="token-name" title="${esc(t.name)}">${esc(t.name)}</span>
|
|
<span class="token-meta">
|
|
<span class="owner-email">${esc(ownerEmail)}</span>
|
|
<span aria-hidden="true"> · </span>
|
|
<span class="chip-mono">${esc(t.prefix)}…</span>
|
|
<span aria-hidden="true"> · </span>
|
|
<span>Created ${esc(createdRel)}</span>
|
|
<span aria-hidden="true"> · </span>
|
|
${expPart}
|
|
</span>
|
|
</div>
|
|
</div>
|
|
<div class="token-usage ${usageCls}" title="${esc(lastUsedTitle)}">
|
|
<span class="usage-main">Last used ${esc(lastUsedRel)}</span>
|
|
${lastUsedIp ? `<span class="usage-sub">${lastUsedIp}</span>` : ""}
|
|
</div>
|
|
<div class="token-aside">
|
|
<span title="${esc(statusTooltip(t, status))}">${statusPill(status)}</span>
|
|
<button type="button" class="revoke-btn" data-revoke
|
|
data-token-id="${esc(t.id)}"
|
|
data-token-name="${esc(t.name)}"
|
|
data-token-owner="${esc(ownerEmail)}"
|
|
data-token-prefix="${esc(t.prefix)}"
|
|
aria-label="Revoke token ${esc(t.name)} owned by ${esc(ownerEmail)}"
|
|
title="Revoke token"
|
|
${t.revoked_at ? "disabled" : ""}>
|
|
${TRASH_SVG}
|
|
<span>Revoke</span>
|
|
</button>
|
|
</div>`;
|
|
return card;
|
|
}
|
|
|
|
function renderList() {
|
|
const list = document.getElementById("tokens-list");
|
|
const loading = document.getElementById("tokens-loading");
|
|
const empty = document.getElementById("tokens-empty");
|
|
loading.style.display = "none";
|
|
|
|
const filtered = sortItems(applyFilters(allTokens));
|
|
list.innerHTML = "";
|
|
|
|
if (filtered.length === 0) {
|
|
empty.style.display = "block";
|
|
list.style.display = "none";
|
|
return;
|
|
}
|
|
empty.style.display = "none";
|
|
list.style.display = "flex";
|
|
|
|
const now = Date.now();
|
|
for (const t of filtered) list.appendChild(renderCard(t, now));
|
|
|
|
list.querySelectorAll("[data-revoke]").forEach(el => {
|
|
el.addEventListener("click", () => revokeToken({
|
|
id: el.dataset.tokenId,
|
|
name: el.dataset.tokenName,
|
|
owner: el.dataset.tokenOwner,
|
|
prefix: el.dataset.tokenPrefix,
|
|
}));
|
|
});
|
|
}
|
|
|
|
async function loadTokens() {
|
|
try {
|
|
const r = await fetch(API_LIST, { credentials: "include" });
|
|
if (!r.ok) throw new Error("HTTP " + r.status);
|
|
allTokens = await r.json();
|
|
updateCounts();
|
|
renderList();
|
|
} catch (e) {
|
|
document.getElementById("tokens-loading").textContent = "Failed to load tokens: " + e.message;
|
|
toast("Failed to load tokens", "error");
|
|
}
|
|
}
|
|
|
|
async function revokeToken({ id, name, owner, prefix }) {
|
|
const meta = {
|
|
"Name": name,
|
|
"Owner": owner,
|
|
"Prefix": (prefix || "") + "…",
|
|
};
|
|
const confirmed = await confirmModal({
|
|
title: "Revoke this token?",
|
|
sub: "This cannot be undone and will immediately sign out any session using this token.",
|
|
meta,
|
|
okLabel: "Revoke token",
|
|
});
|
|
if (!confirmed) return;
|
|
const r = await fetch(API_REVOKE(id), { method: "DELETE", credentials: "include" });
|
|
if (!r.ok) { toast("Failed: " + (await r.text()), "error"); return; }
|
|
toast("Token revoked", "success");
|
|
await loadTokens();
|
|
}
|
|
|
|
// ── Filter chips (status) ──────────────────────────────────────────────────
|
|
function setStatusFilter(val) {
|
|
filters.status = val;
|
|
document.querySelectorAll("#flt-status-group .chip-btn").forEach(b => {
|
|
const on = b.dataset.val === val;
|
|
b.setAttribute("aria-pressed", on ? "true" : "false");
|
|
b.setAttribute("aria-checked", on ? "true" : "false");
|
|
});
|
|
const sel = document.getElementById("flt-status");
|
|
if (sel) sel.value = val;
|
|
renderList();
|
|
}
|
|
document.querySelectorAll("#flt-status-group .chip-btn").forEach(btn => {
|
|
btn.addEventListener("click", () => setStatusFilter(btn.dataset.val));
|
|
});
|
|
document.getElementById("flt-status").addEventListener("change", e => setStatusFilter(e.target.value));
|
|
|
|
// ── Sort chips ─────────────────────────────────────────────────────────────
|
|
function setSort(key) {
|
|
if (sort.key === key) {
|
|
sort.dir = sort.dir === "asc" ? "desc" : "asc";
|
|
} else {
|
|
sort.key = key;
|
|
sort.dir = key === "user_email" ? "asc" : "desc";
|
|
}
|
|
document.querySelectorAll("#sort-group .chip-btn").forEach(b => {
|
|
if (b.dataset.sortKey === sort.key) {
|
|
b.setAttribute("aria-pressed", "true");
|
|
b.setAttribute("data-sort-dir", sort.dir);
|
|
} else {
|
|
b.setAttribute("aria-pressed", "false");
|
|
b.removeAttribute("data-sort-dir");
|
|
}
|
|
});
|
|
renderList();
|
|
}
|
|
document.querySelectorAll("#sort-group .chip-btn").forEach(btn => {
|
|
btn.addEventListener("click", () => setSort(btn.dataset.sortKey));
|
|
});
|
|
|
|
// ── Owner email search ─────────────────────────────────────────────────────
|
|
(function bindUserFilter() {
|
|
const el = document.getElementById("flt-user");
|
|
if (!el) return;
|
|
el.addEventListener("input", e => {
|
|
filters.user = e.target.value.trim(); renderList();
|
|
});
|
|
})();
|
|
|
|
function clearFilters() {
|
|
filters = { status: "all", user: "" };
|
|
setStatusFilter("all");
|
|
const uf = document.getElementById("flt-user");
|
|
if (uf) uf.value = "";
|
|
const lu = document.getElementById("flt-last-used");
|
|
if (lu) lu.value = "any";
|
|
renderList();
|
|
}
|
|
document.getElementById("clear-filters-btn").addEventListener("click", clearFilters);
|
|
document.getElementById("clear-filters-toolbar").addEventListener("click", clearFilters);
|
|
|
|
// Pre-fill user filter from ?user=... (deep-link from /admin/users)
|
|
(function initFromQuery() {
|
|
try {
|
|
const q = new URLSearchParams(window.location.search);
|
|
const u = q.get("user");
|
|
if (u) {
|
|
filters.user = u;
|
|
const el = document.getElementById("flt-user");
|
|
if (el) el.value = u;
|
|
}
|
|
} catch (_) {}
|
|
})();
|
|
|
|
loadTokens();
|
|
</script>
|
|
{% endblock %}
|