Merge #9d6de783: Fix IndeeHub registration for managed stack installati…

Fix IndeeHub registration for managed stack installations

nostr:nevent1qqsf6m08s06sy2emsk0qk8e73q0r38dyfqkathg4lu56gz6wyhd0ewqpz3mhxue69uhhyetvv9ujumn8d96zuer9wc4mpaz6

PR-Author: Personal
nostr:npub1w3sqdkrhn0gyuvsex32effzgnfpyde6qrrc4u467flg5e9txh4wsfn5vjg

PR description:

Managed IndeeHub has one installed package record; its API runs as an internal stack component. Require the installed running parent and existing API identity pin, while retaining validation of legacy standalone API records. Includes regression coverage for parent-only state and records reopened identity/upload UAT. Focused isolated backend tests and production build are in progress.
This commit is contained in:
archipelago
2026-10-09 11:34:19 -04:00
4 changed files with 125 additions and 2 deletions
@@ -201,12 +201,12 @@ impl RpcHandler {
anyhow::ensure!( anyhow::ensure!(
state state
.package_data .package_data
.get("indeedhub-api") .get("indeedhub")
.is_some_and(|entry| matches!( .is_some_and(|entry| matches!(
entry.state, entry.state,
crate::data_model::PackageState::Running crate::data_model::PackageState::Running
)), )),
"The installed IndeeHub API must be running to register its media" "The installed IndeeHub app must be running to register its media"
); );
let identity = let identity =
crate::identity::NodeIdentity::load_existing(&self.config.data_dir.join("identity")) crate::identity::NodeIdentity::load_existing(&self.config.data_dir.join("identity"))
@@ -48,6 +48,12 @@ pub(crate) fn installed_context(
state: &crate::data_model::DataModel, state: &crate::data_model::DataModel,
) -> Result<InstalledAppContext> { ) -> Result<InstalledAppContext> {
for id in ["indeedhub", "indeedhub-api"] { for id in ["indeedhub", "indeedhub-api"] {
// Stack components are not separate package records on managed installs.
// Keep validating legacy standalone API records when they exist; the
// installed parent and its existing API identity pin are mandatory.
if id == "indeedhub-api" && !state.package_data.contains_key(id) {
continue;
}
let entry = state let entry = state
.package_data .package_data
.get(id) .get(id)
@@ -613,6 +619,12 @@ mod tests {
assert!(installed_context(root.path(), &identity, &state).is_err()); assert!(installed_context(root.path(), &identity, &state).is_err());
let pin = ensure_for_installation(root.path(), "indeedhub-api", &identity).unwrap(); let pin = ensure_for_installation(root.path(), "indeedhub-api", &identity).unwrap();
let first = installed_context(root.path(), &identity, &state).unwrap(); let first = installed_context(root.path(), &identity, &state).unwrap();
let api_entry = state.package_data.remove("indeedhub-api").unwrap();
assert_eq!(
installed_context(root.path(), &identity, &state).unwrap(),
first
);
state.package_data.insert("indeedhub-api".into(), api_entry);
assert_eq!(first.app_audience, pin.app_audience); assert_eq!(first.app_audience, pin.app_audience);
assert_eq!(first.app_origins, vec!["https://localhost:7778"]); assert_eq!(first.app_origins, vec!["https://localhost:7778"]);
state.package_data.get_mut("indeedhub-api").unwrap().state = state.package_data.get_mut("indeedhub-api").unwrap().state =
+73
View File
@@ -42,6 +42,79 @@ acceptance; this is a new paid-file incident.
## Current tasks ## Current tasks
- 2026-10-09 live repair checkpoint (supersedes the pending deployment notes
immediately below): Yaya now runs management backend SHA256
`938a90c7d9ecbdb179b1cf2886b5ed03e4d78c0d454f2cec42c0d9de3d447eb9`,
built from the registration correction in `424070d2`. Optimized build passed.
Management health, unchanged running container IDs, unchanged node identity key
and unchanged registration pin/marker checks passed. The old binary is retained
under `/var/lib/archipelago/support/indee-registration-424070d2/`.
The first context probe during inventory startup still failed; after inventory
recovery the authenticated `media.registration.context` probe succeeds and
returns all installation bindings. No catalog or app-data mutation was used.
The probe initially treated JSON-RPC `error: null` as failure; corrected it and
repeated the successful live request. Isolated backend regression compilation
remains pending after severe build-host swapping; do not claim its test passed.
A real native Home Serve login then exposed another defect: `UserDTO` omitted
`nostrPubkey`, so the strict frontend profile check correctly refused the
otherwise matching signed session. IndeeHub `08586e3` adds this public field;
two DTO regressions and backend production build pass. Deployed only the built
DTO module with its previous copy saved under the private
`indee-profile-08586e3` artifact directory, then restarted only `indeedhub-api`.
API health passes. A clean real browser selected native **Home Serve**, approved
only its kind-27235 authentication request, and verified that the native choice,
session subject and API profile key match. The signer closes normally. No
identity was created/replaced and no payment or publication was submitted.
Frontend `7b18912` and API DTO remain running-container patches; durable image/
managed deployment, complete video upload/publication and cached-account-switch
acceptance remain open. Preserve the operator's native identities throughout.
- 2026-10-09 UI checkpoint: IndeeHub commit `40b3798` is served on Yaya
(index SHA256 `d921a88448f89674809dbe623ec045849012b1fb0330e3abf1d2d6836e9b3c96`).
Publishing now appears only in its own editor tab; Assets remains mounted
across tab switches. Copy distinguishes computer upload from Cloud-backed
catalog publication; saved-registration recovery is under a details control.
Production build and 26 focused frontend tests pass. Browser checks verify
native signer availability, no automatic login, removal of local account
controls and clearing of legacy app-local accounts. Real selected-identity
sign-in and video upload/publication remain unverified. This is a running
container frontend patch, not a durable pinned-image/catalog deployment.
Backend correction `424070d2` has ngit proposal
`9d6de783f5022b3b859e0b1f3e881e389da4482dd5dd15ff29a40b4e25dafcb8`;
isolated regression and optimized build are still running, not passed or
deployed. Preserve this distinction when resuming the backend work.
- 2026-10-09 follow-up: operator reports missing autosign and the same generic
registration error. `40b3798` disabled provider auto-authentication without
replacing it with app authentication on native selection; this was a regression.
IndeeHub `7b18912` adds a single shared automatic/manual login path driven by
the trusted provider's `onIdentitySelected`. It rejects mismatching signer keys
and changed selections, checks the backend profile, and never falls back to a
cached app identity. Twenty-one focused tests and the production build pass.
Yaya serves index SHA256
`1c7fee64430b0d993288408dbe493d0f4f55a49fe2422a3507c7204c12343632`;
the native provider bytes are unchanged. A disposable served-app browser test
verifies selection triggers exactly one kind-27235 signature request without
clicking login; it intentionally stops before signing with a stub. This is not
real-identity login acceptance. The first browser run raced deployment and
failed against the previous build; the post-deployment rerun passes.
Authenticated read-only registration RPC still reproduces the generic failure,
with server cause `IndeeHub is not installed`; backend build/test remain pending.
- [ ] **2026-10-09 IndeeHub UAT remains failed:** operator still reports wrong
Nostr identity, upload failure and confusing always-visible publishing UI.
Preserve native identities; remove only app-local generated/imported accounts.
Require explicit Archipelago selection and matching API profile. On Yaya,
`media.registration.context` logs `IndeeHub is not installed` while all seven
containers run. Authenticated state includes only the parent `indeedhub`
package; the registration code incorrectly requires a separate
`indeedhub-api` package record. Candidate correction retains parent running/
installed checks and the existing API installation pin; it checks a legacy
API package when present. Source tests/build and live registration acceptance
must complete before closing. Move publishing to its own editor tab, preserve
computer-upload state and existing pending registration requests.
- [x] Yaya App Store component/alias regression (reported 2026-10-02): one - [x] Yaya App Store component/alias regression (reported 2026-10-02): one
Cuprate entry (hide Cuprate UI companion), one BTCPay Server in Commerce Cuprate entry (hide Cuprate UI companion), one BTCPay Server in Commerce
with its icon (merge legacy btcpay pins), one NetBird entry (hide server with its icon (merge legacy btcpay pins), one NetBird entry (hide server
+38
View File
@@ -92,8 +92,46 @@ hardening rather than claiming every cache key was erased. The IndeeHub frontend
commits `0d6434e` and `71cf546a` remain local because that repository has no ngit commits `0d6434e` and `71cf546a` remain local because that repository has no ngit
coordinate; do not publish them Gitea-only under the mirror policy. coordinate; do not publish them Gitea-only under the mirror policy.
### IndeeHub selected-identity regression — UAT reopened 9 October 2026
Operator UAT disproved the earlier sign-out acceptance: choosing the homeserver
identity could continue with a previously active saved account and display a
different npub. `loginWithExtension` caught selection/provider failures without
rethrowing, after which the modal read `accountManager.active`; that pointer could
still name the old account. IndeeHub commits `a4d3946` and `86256ee` now clear the
active pointer before an explicit native switch, propagate failure, bind the
authentication call to the exact returned signer account, and retain the
Archipelago provider hook in the source index. A regression starts with a stale
saved account and proves a failed selection cannot fall back to it while the
saved key itself remains preserved.
All 155 frontend tests, type checking and the production build pass. A live Yaya
frontend-only correction is installed with rollback under the operator's private
artifact directory. The served index references the provider, provider SHA256 is
still `ad4c93b3b25545dca1b391c5add75e5bc618c865290805f7ac5d1ad0fd18b469`,
the service worker was regenerated to invalidate the brief provider-less cache,
and `/health` passes. Automated Chromium confirms the provider loads and no stale
active account is restored. Real homeserver selection and displayed-npub matching
remain pending operator UAT; the current live filesystem correction is not yet a
new signed catalog/image activation and must not be described as durable managed
deployment acceptance.
## Combined Yaya UAT candidate — 9 October 2026 ## Combined Yaya UAT candidate — 9 October 2026
Follow-up operator request: retain all node-native identities; remove IndeeHub's
Create Account/private-key import and reset only its old browser accounts.
IndeeHub commit `7fbdc74` removes generation/import handlers and screens, performs
a one-time removal of `indeedhub-accounts`, `indeedhub-active-account` and app
session credentials, and corrects the default API base from browser localhost
to `/api`. The previous live hotfix was built without explicit API settings,
explaining its network error; its earlier success claims were premature.
Twenty-one focused authentication/reset tests pass and the production build
passes with `/api`, `/storage`, `/relay`, mock off and publication enabled.
This updated static bundle is deployed to Yaya's existing frontend container;
its index SHA256 is `a14834acab5fc9b42f55a92c540b9b765334ac7d2d2628ddc82bc1c5725d53ad`.
Node identity storage was not modified. Signed-image recreation and real native
identity sign-in acceptance remain outstanding.
The combined source is published on ngit and mirrored byte-for-byte to Gitea at The combined source is published on ngit and mirrored byte-for-byte to Gitea at
main `bb933d409187a8181e284a5a91a81b4e036b3036`, based on accepted main main `bb933d409187a8181e284a5a91a81b4e036b3036`, based on accepted main
`aff408cc`. Its integration commits retain each proposal head as a parent: `aff408cc`. Its integration commits retain each proposal head as a parent: