From 99f1006669185f35aab338b6f693b3d09ccb8772 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Padez?= Date: Tue, 4 Aug 2026 13:31:30 +0000 Subject: [PATCH] auth: drop the user environment provisioning MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit provisionUserEnvironment seeded a managed home under DATA_PATH/ — shell configs from a template dir, plus a generated CLAUDE.md and settings.json — and bootstrap called it fire-and-forget when the owner account was created. It is outdated: the managed home is not where anything runs. Task runs, terminals and chats all execute in getOwnerHomeDir (the real login home, HOME_DIR), not the getHomeDir tree this was populating. Removed the function, its four template files, and the call in bootstrap. No setup script referenced it — checked all of scripts/*.sh — and bootstrap was its only caller anywhere in the tree. getHomeDir and toShellUsername stay in data-path.ts: pipeline-executor and pipeline-job-manager still use them. This leaves src/servers/generate-container-context.ts with zero consumers, since provision was the only thing importing it. Left in place rather than deleted in the same commit — it is 173 lines that build a CLAUDE.md and a settings.json for an agent, which is plausibly wanted somewhere else, and that is a call for the owner rather than a side effect of this cleanup. Co-Authored-By: Claude Opus 5 (1M context) --- src/servers/api/auth/bootstrap.ts | 8 -- src/servers/api/users/provision.ts | 85 --------------- src/servers/api/users/templates/.tmux.conf | 100 ------------------ src/servers/api/users/templates/.zshenv | 1 - src/servers/api/users/templates/.zshrc | 75 ------------- .../api/users/templates/starship-officer.toml | 19 ---- 6 files changed, 288 deletions(-) delete mode 100644 src/servers/api/users/provision.ts delete mode 100644 src/servers/api/users/templates/.tmux.conf delete mode 100644 src/servers/api/users/templates/.zshenv delete mode 100644 src/servers/api/users/templates/.zshrc delete mode 100644 src/servers/api/users/templates/starship-officer.toml diff --git a/src/servers/api/auth/bootstrap.ts b/src/servers/api/auth/bootstrap.ts index aff50bb3..c576f1cb 100644 --- a/src/servers/api/auth/bootstrap.ts +++ b/src/servers/api/auth/bootstrap.ts @@ -4,7 +4,6 @@ import argon2 from 'argon2'; import * as errors from '@@/custom-errors'; import { validatePassword } from './validate-password'; import { validateUsername } from './validate-username'; -import { provisionUserEnvironment } from '../users/provision'; // Single-step bootstrap for the one account Officer supports: the server owner is created directly as // active, with no email-verification round-trip. Gated to an empty user table. @@ -38,12 +37,5 @@ export const bootstrapHandler: Handler = async function (ctx) { status: 'Active', }); - // Provision the super admin's environment (DATA_PATH/ + configs) on creation. This is the only - // account-creation flow for a single-user platform, and nothing else provisions the first user. - // Fire-and-forget, mirroring verifyHandler. - provisionUserEnvironment(user.email, user.username ?? validUsername).catch((err) => { - console.error('[bootstrap] failed to provision super admin environment:', err); - }); - return ctx.json({ ok: true }); }; diff --git a/src/servers/api/users/provision.ts b/src/servers/api/users/provision.ts deleted file mode 100644 index 9cdcebcf..00000000 --- a/src/servers/api/users/provision.ts +++ /dev/null @@ -1,85 +0,0 @@ -import { existsSync, mkdirSync } from 'node:fs'; -import { join } from 'node:path'; -import { DATA_PATH, getHomeDir, toShellUsername } from '@@/data-path'; -import { generateContainerContext, generateClaudeSettings } from '@@/generate-container-context'; - -const TEMPLATE_DIR = join(import.meta.dir, 'templates'); - -const copyTemplate = async (src: string, dest: string) => { - if (existsSync(dest)) return; - const content = await Bun.file(src).text(); - await Bun.write(dest, content); -}; - -export async function provisionUserEnvironment(email: string, username: string): Promise { - const shellUsername = toShellUsername(username, email); - const homeDir = getHomeDir(email); - const userRoot = join(DATA_PATH, email); - - console.log(`[provision] provisioning environment for ${email}`); - - // Ensure data directories exist - mkdirSync(userRoot, { recursive: true }); - mkdirSync(homeDir, { recursive: true }); - - // Seed shell config files - await seedShellConfigs(homeDir); - - // Generate and write CLAUDE.md + settings.json - const contextFile = generateContainerContext(email); - const claudeDir = join(homeDir, '.claude'); - mkdirSync(claudeDir, { recursive: true }); - - const contextContent = await Bun.file(contextFile).text(); - await Bun.write(join(claudeDir, 'CLAUDE.md'), contextContent); - - const settingsFile = generateClaudeSettings(email, shellUsername); - const settingsContent = await Bun.file(settingsFile).text(); - await Bun.write(join(claudeDir, 'settings.json'), settingsContent); - - console.log(`[provision] provisioning complete for ${email}`); - return true; -} - -async function seedShellConfigs(homeDir: string): Promise { - // .zshenv (must be first — prevents system compinit before oh-my-zsh) - await copyTemplate(join(TEMPLATE_DIR, '.zshenv'), join(homeDir, '.zshenv')); - - // .zshrc - await copyTemplate(join(TEMPLATE_DIR, '.zshrc'), join(homeDir, '.zshrc')); - - // .tmux.conf - await copyTemplate(join(TEMPLATE_DIR, '.tmux.conf'), join(homeDir, '.tmux.conf')); - - // starship config - const configDir = join(homeDir, '.config'); - mkdirSync(configDir, { recursive: true }); - await copyTemplate(join(TEMPLATE_DIR, 'starship-officer.toml'), join(configDir, 'starship-officer.toml')); - - // Oh My Zsh — copy from host install - const ohMyZshDest = join(homeDir, '.oh-my-zsh'); - if (!existsSync(ohMyZshDest)) { - const hostOhMyZsh = join(process.env.HOME ?? '', '.oh-my-zsh'); - if (existsSync(hostOhMyZsh)) { - Bun.spawnSync({ cmd: ['cp', '-r', hostOhMyZsh, ohMyZshDest], stdout: 'ignore', stderr: 'ignore' }); - } else { - Bun.spawnSync({ - cmd: ['git', 'clone', '--depth=1', 'https://github.com/ohmyzsh/ohmyzsh.git', ohMyZshDest], - stdout: 'ignore', - stderr: 'ignore', - }); - } - } - - // LazyVim config - const nvimDir = join(homeDir, '.config', 'nvim'); - if (!existsSync(nvimDir)) { - const hostNvim = join(process.env.HOME ?? '', '.config', 'nvim'); - if (existsSync(hostNvim)) { - Bun.spawnSync({ cmd: ['cp', '-r', hostNvim, nvimDir], stdout: 'ignore', stderr: 'ignore' }); - } - } - - // Ensure .local/bin exists - mkdirSync(join(homeDir, '.local', 'bin'), { recursive: true }); -} diff --git a/src/servers/api/users/templates/.tmux.conf b/src/servers/api/users/templates/.tmux.conf deleted file mode 100644 index ccf66cbe..00000000 --- a/src/servers/api/users/templates/.tmux.conf +++ /dev/null @@ -1,100 +0,0 @@ -########## TPM AUTO-INSTALL + SESSION PERSISTENCE ########## - -# Auto-install TPM if missing -if-shell '[ ! -d ~/.tmux/plugins/tpm ]' \ - 'run-shell "git clone https://github.com/tmux-plugins/tpm ~/.tmux/plugins/tpm"' - -# Plugin list -set -g @plugin 'tmux-plugins/tpm' - -# remap prefix from 'C-b' to 'C-a' -unbind C-b -set-option -g prefix C-a -bind-key C-a send-prefix - -set -g base-index 1 - -# split panes using | and - -unbind '"' -unbind % -bind | split-window -h -bind - split-window -v - -# reload config file (change file location to your the tmux.conf you want to use) -unbind r -bind r source-file ~/.tmux.conf \; display-message "Config reloaded!" \; refresh-client -S - -# switch panes using Alt-arrow without prefix -bind -n M-Left select-pane -L -bind -n M-Right select-pane -R -bind -n M-Up select-pane -U -bind -n M-Down select-pane -D -# switch panes using Alt-HJKL without prefix -bind -n M-h select-pane -L -bind -n M-l select-pane -R -bind -n M-k select-pane -U -bind -n M-j select-pane -D - -# Enable mouse control (clickable windows, panes, resizable panes) - -# don't rename windows automatically -set-option -g allow-rename off - -###################### -### DESIGN CHANGES ### -###################### - -# loud or quiet? -set -g visual-activity off -set -g visual-bell off -set -g visual-silence off -setw -g monitor-activity off -set -g bell-action none - -# modes -setw -g clock-mode-colour colour12 -setw -g mode-style 'fg=colour1 bg=colour18 bold' - -# panes -set -g pane-border-style 'fg=colour19 bg=colour0' -set -g pane-active-border-style 'bg=colour0 fg=colour9' - -# statusbar -set -g status-position bottom -set -g status-justify left -set -g status-style 'bg=colour2 fg=colour23' -# set -g status-left '#[fg=white,bg=black,bold] pastilhas #[default]' -set -g status-left '#[fg=#ffffff,bg=#000000,bold] #{USER}@#H #[default]' -# set -g status-left-length 20 -set -g status-right '#[fg=#ffffff,bg=colour1] %d/%m #[fg=#ffffff,bg=colour8] %H:%M:%S ' -set -g status-right-length 50 -set -g status-left-length 20 - -setw -g window-status-current-style 'fg=colour1 bg=colour19 bold' -setw -g window-status-current-format ' #I#[fg=colour249]:#[fg=colour255]#W#[fg=colour249]#F ' - -setw -g window-status-style 'fg=colour9 bg=colour18' -setw -g window-status-format ' #I#[fg=colour237]:#[fg=colour250]#W#[fg=colour244]#F ' - -setw -g window-status-bell-style 'fg=colour255 bg=colour1 bold' -# ...existing code... -# messages -set -g message-style 'fg=#ffffff bg=red bold' -# Change the font color for the exit pane confirmation message -set -g message-command-style 'fg=#ffffff bg=red bold' - -# ...existing code... - -# messages -# set -g message-style 'fg=colour232 bg=colour16 bold' - -########################## -### END DESIGN CHANGES ### -########################## - -########################## -### EASY MOUSE SCROLL ### -########################## - -set -g mouse on -set -ga terminal-overrides ',*256color*:smcup@:rmcup@' diff --git a/src/servers/api/users/templates/.zshenv b/src/servers/api/users/templates/.zshenv deleted file mode 100644 index 33cf15ff..00000000 --- a/src/servers/api/users/templates/.zshenv +++ /dev/null @@ -1 +0,0 @@ -skip_global_compinit=1 diff --git a/src/servers/api/users/templates/.zshrc b/src/servers/api/users/templates/.zshrc deleted file mode 100644 index 5ab94bfe..00000000 --- a/src/servers/api/users/templates/.zshrc +++ /dev/null @@ -1,75 +0,0 @@ -# If you come from bash you might have to change your $PATH. -export PATH=$HOME/.local/bin:$PATH - -# Skip insecure directory check (system zsh dirs may be group-writable) -ZSH_DISABLE_COMPFIX=true - -# Path to your Oh My Zsh installation. -export ZSH="$HOME/.oh-my-zsh" - -# Set name of the theme to load --- if set to "random", it will -# load a random theme each time Oh My Zsh is loaded, in which case, -# to know which specific one was loaded, run: echo $RANDOM_THEME -# See https://github.com/ohmyzsh/ohmyzsh/wiki/Themes -ZSH_THEME="" - -# Which plugins would you like to load? -# Standard plugins can be found in $ZSH/plugins/ -# Custom plugins may be added to $ZSH_CUSTOM/plugins/ -# Example format: plugins=(rails git textmate ruby lighthouse) -# Add wisely, as too many plugins slow down shell startup. -plugins=(git) - -source $ZSH/oh-my-zsh.sh - -# ============================================================================ -# STARSHIP PROMPT -# ============================================================================ -if [[ -f "$HOME/.config/starship-officer.toml" ]]; then - export STARSHIP_CONFIG="$HOME/.config/starship-officer.toml" -fi - -# Auto-install starship if not available (host mode) -if ! command -v starship &> /dev/null; then - if [[ ! -x "$HOME/.local/bin/starship" ]]; then - mkdir -p "$HOME/.local/bin" - echo "Installing starship..." - curl -sS https://starship.rs/install.sh | sh -s -- -y -b "$HOME/.local/bin" 2>/dev/null - fi - export PATH="$HOME/.local/bin:$PATH" -fi - -eval "$(starship init zsh)" - -# ============================================================================ -# EZA ALIASES (colors and icons for ls) -# ============================================================================ -alias ls='eza --icons' -alias la='eza --icons -la' -alias ll='eza --icons -l' -alias lll='eza --icons -lA' -alias lh='eza --icons -lhA' -alias ltr='eza --icons -ltr' -alias l='eza --icons -la' - -# Other common aliases (oh-my-zsh standard) -alias grep='grep --color=auto' -alias less='less -R' -alias diff='diff --color=auto' -alias cp='cp -iv' -alias mv='mv -iv' -alias rm='rm -i' -alias mkdir='mkdir -p' -alias which='which -a' -alias history='fc -l 1' - -alias n="nvim" -alias vim="n" -alias sz="source ~/.zshrc" -alias ld="lazydocker" -alias hr="hyprctl reload" -alias hir="omarchy-restart-hypridle" -alias setupmines="WINEPREFIX=~/wine/minesweeper winecfg" -alias httpserver="python -m http.server 8888" - -clear diff --git a/src/servers/api/users/templates/starship-officer.toml b/src/servers/api/users/templates/starship-officer.toml deleted file mode 100644 index cdaea4a9..00000000 --- a/src/servers/api/users/templates/starship-officer.toml +++ /dev/null @@ -1,19 +0,0 @@ -format = "${env_var.USER}:$hostname $directory $character" - -[env_var.USER] -format = "[$env_value]($style)" -style = "bold #0891B2" - -[hostname] -ssh_only = false -format = "[officer.dev]($style)" -style = "bold yellow" - -[directory] -truncation_length = 3 -truncate_to_repo = false -style = "blue" - -[character] -success_symbol = ">" -error_symbol = ">"