Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Feat/control panel login and access management - #903

Merged
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management
Mar 8, 2026
Merged

Feat/control panel login and access management#903
coodos merged 2 commits into
mainfrom
feat/control-panel-login-and-access-management

Conversation

@coodos

@coodoscoodos commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Description of change

Issue Number

closes#783

Type of change

  • Breaking (any change that would cause existing functionality to not work as expected)
  • New (a change which implements a new feature)
  • Update (a change which updates existing functionality)
  • Fix (a change which fixes an issue)
  • Docs (changes to the documentation)
  • Chore (refactoring, build scripts or anything else that isn't user-facing)

How the change has been tested

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Implemented W3DS/eID Wallet authentication with QR code-based login flow
    • Added admin access control with allowlist-based authorization
    • Implemented user logout functionality
    • Updated monitoring interface layout for improved content organization
  • Documentation

    • Added authentication setup and configuration documentation

@coderabbitai

coderabbitaiBot commented Mar 8, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

📝 Walkthrough

Walkthrough

This PR implements a complete W3DS-based authentication system for the control panel, including session management, JWT token generation, admin allowlist validation, and updated UI/layouts to support user authentication and logout functionality.

Changes

Cohort / File(s)Summary
Environment & Configuration
infrastructure/control-panel/.env.example, infrastructure/control-panel/config/admin-enames.json, infrastructure/control-panel/README.md, infrastructure/control-panel/package.json
Added three new environment variables (PUBLIC_CONTROL_PANEL_URL, CONTROL_PANEL_JWT_SECRET, CONTROL_PANEL_ADMIN_ENAMES_FILE), example admin ENames JSON config, authentication documentation, and dependencies (jose, qrcode, signature-validator, @types/qrcode).
Authentication Core
infrastructure/control-panel/src/lib/server/auth/token.ts, infrastructure/control-panel/src/lib/server/auth/sessions.ts, infrastructure/control-panel/src/lib/server/auth/allowlist.ts
Implemented JWT token management (sign/verify with HS256, 7-day expiry), in-memory TTL-based session store (5-minute expiry) with subscriber notifications, and file-based admin ENames allowlist with normalization and caching.
Server Middleware & Types
infrastructure/control-panel/src/hooks.server.ts, infrastructure/control-panel/src/app.d.ts
Added comprehensive server hook for authentication, CORS, and request routing; defined ambient App.Locals and App.PageData interfaces with user property.
Authentication Endpoints
infrastructure/control-panel/src/routes/api/auth/+server.ts, infrastructure/control-panel/src/routes/api/auth/offer/+server.ts, infrastructure/control-panel/src/routes/api/auth/complete/+server.ts, infrastructure/control-panel/src/routes/api/auth/logout/+server.ts, infrastructure/control-panel/src/routes/api/auth/sessions/[id]/+server.ts
Implemented POST handlers for login payload validation and token issuance, GET endpoint for generating auth offers with w3ds:// URIs, POST handler for completing auth and setting cookies, logout functionality, and SSE endpoint for streaming session status updates.
Layout & Page Components
infrastructure/control-panel/src/routes/+layout.server.ts, infrastructure/control-panel/src/routes/+layout.svelte, infrastructure/control-panel/src/routes/login/+page.svelte, infrastructure/control-panel/src/routes/monitoring/+page.svelte
Added server load function to pass user data, conditional login/dashboard layout rendering, logout button, user name display, new login page with QR code generation and SSE-based auth monitoring, and restructured monitoring page layout to two-column design with status tracking.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (Browser)
participant LayoutSvelte as Layout Component
participant AuthAPI as /api/auth Endpoint
participant Registry as Registry (Signature Verification)
participant SessionStore as Session Store
participant AllowList as Admin AllowList
participant CookieJar as Cookie Storage
Client->>LayoutSvelte: Navigate to /login (unauthenticated)
LayoutSvelte->>AuthAPI: GET /api/auth/offer
AuthAPI->>SessionStore: createAuthSession()
SessionStore-->>AuthAPI: sessionId
AuthAPI-->>LayoutSvelte: {uri, sessionId, expiresInMs}
LayoutSvelte->>LayoutSvelte: Generate QR code from uri
LayoutSvelte->>LayoutSvelte: Establish SSE to /api/auth/sessions/[id]
Client->>Client: Scan QR with W3DS wallet
Client->>AuthAPI: POST /api/auth with signature
AuthAPI->>SessionStore: consumeAuthSession(id)
SessionStore-->>AuthAPI: valid/invalid
AuthAPI->>Registry: Verify signature
Registry-->>AuthAPI: Valid/Invalid
AuthAPI->>AllowList: isAdminEName(ename)
AllowList-->>AuthAPI: true/false
AuthAPI->>SessionStore: publishAuthSessionResult(id, {status, ename})
SessionStore-->>LayoutSvelte: SSE data (success)
AuthAPI-->>Client: {ok, ename} or error
LayoutSvelte->>AuthAPI: POST /api/auth/complete with sessionId
AuthAPI->>SessionStore: getAuthSessionResult(sessionId)
SessionStore-->>AuthAPI: {status: 'success', ename}
AuthAPI->>AuthAPI: signAuthToken({ename})
AuthAPI->>CookieJar: Set auth cookie (HttpOnly, Secure)
AuthAPI-->>LayoutSvelte: {ok: true, ename}
LayoutSvelte->>LayoutSvelte: Redirect to /
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

Suggested reviewers

  • sosweetham

Poem

🐰 A rabbit hops through auth's great door,
With sessions, tokens, and JWT lore,
QR codes hopping, signatures dance,
Allowlists checked with a careful glance,
W3DS wallets bring users to stay,
The control panel's secured today! 🔐

🚥 Pre-merge checks | ✅ 1 | ❌ 2

❌ Failed checks (2 warnings)

Check nameStatusExplanationResolution
Description check⚠️ WarningThe description follows the template structure but is incomplete. While it includes the Issue Number (closes #783), the Type of change section is empty (no option selected), How the change has been tested is blank, and all checklist items are unchecked with no notes provided.Select the appropriate type of change (likely 'New' based on the implementation), describe testing methodology, and address or check the relevant items in the change checklist to provide complete context.
Docstring Coverage⚠️ WarningDocstring coverage is 0.00% which is insufficient. The required threshold is 80.00%.Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (1 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: implementing login and access management for the control panel, which matches the scope of the files added (authentication endpoints, session management, allowlist, JWT tokens, login page).

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/control-panel-login-and-access-management

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodos
coodos merged commit 1286539 into mainMar 8, 2026
3 of 4 checks passed
@coodos
coodos deleted the feat/control-panel-login-and-access-management branch March 8, 2026 10:10
@coderabbitaicoderabbitaiBot mentioned this pull request Mar 12, 2026
6 tasks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[feature] Allow for multiple users in the control panel

1 participant

@coodos