auth: drop the user environment provisioning

provisionUserEnvironment seeded a managed home under DATA_PATH/<email> — shell
configs from a template dir, plus a generated CLAUDE.md and settings.json — and
bootstrap called it fire-and-forget when the owner account was created. It is
outdated: the managed home is not where anything runs. Task runs, terminals and
chats all execute in getOwnerHomeDir (the real login home, HOME_DIR), not the
getHomeDir tree this was populating.

Removed the function, its four template files, and the call in bootstrap. No
setup script referenced it — checked all of scripts/*.sh — and bootstrap was its
only caller anywhere in the tree.

getHomeDir and toShellUsername stay in data-path.ts: pipeline-executor and
pipeline-job-manager still use them.

This leaves src/servers/generate-container-context.ts with zero consumers, since
provision was the only thing importing it. Left in place rather than deleted in
the same commit — it is 173 lines that build a CLAUDE.md and a settings.json for
an agent, which is plausibly wanted somewhere else, and that is a call for the
owner rather than a side effect of this cleanup.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-04 13:31:30 +00:00
co-authored by Claude Opus 5
parent e661e3738f
commit 99f1006669
6 changed files with 0 additions and 288 deletions
-8
View File
@@ -4,7 +4,6 @@ import argon2 from 'argon2';
import * as errors from '@@/custom-errors'; import * as errors from '@@/custom-errors';
import { validatePassword } from './validate-password'; import { validatePassword } from './validate-password';
import { validateUsername } from './validate-username'; import { validateUsername } from './validate-username';
import { provisionUserEnvironment } from '../users/provision';
// Single-step bootstrap for the one account Officer supports: the server owner is created directly as // Single-step bootstrap for the one account Officer supports: the server owner is created directly as
// active, with no email-verification round-trip. Gated to an empty user table. // active, with no email-verification round-trip. Gated to an empty user table.
@@ -38,12 +37,5 @@ export const bootstrapHandler: Handler = async function (ctx) {
status: 'Active', status: 'Active',
}); });
// Provision the super admin's environment (DATA_PATH/<email> + configs) on creation. This is the only
// account-creation flow for a single-user platform, and nothing else provisions the first user.
// Fire-and-forget, mirroring verifyHandler.
provisionUserEnvironment(user.email, user.username ?? validUsername).catch((err) => {
console.error('[bootstrap] failed to provision super admin environment:', err);
});
return ctx.json({ ok: true }); return ctx.json({ ok: true });
}; };
-85
View File
@@ -1,85 +0,0 @@
import { existsSync, mkdirSync } from 'node:fs';
import { join } from 'node:path';
import { DATA_PATH, getHomeDir, toShellUsername } from '@@/data-path';
import { generateContainerContext, generateClaudeSettings } from '@@/generate-container-context';
const TEMPLATE_DIR = join(import.meta.dir, 'templates');
const copyTemplate = async (src: string, dest: string) => {
if (existsSync(dest)) return;
const content = await Bun.file(src).text();
await Bun.write(dest, content);
};
export async function provisionUserEnvironment(email: string, username: string): Promise<boolean> {
const shellUsername = toShellUsername(username, email);
const homeDir = getHomeDir(email);
const userRoot = join(DATA_PATH, email);
console.log(`[provision] provisioning environment for ${email}`);
// Ensure data directories exist
mkdirSync(userRoot, { recursive: true });
mkdirSync(homeDir, { recursive: true });
// Seed shell config files
await seedShellConfigs(homeDir);
// Generate and write CLAUDE.md + settings.json
const contextFile = generateContainerContext(email);
const claudeDir = join(homeDir, '.claude');
mkdirSync(claudeDir, { recursive: true });
const contextContent = await Bun.file(contextFile).text();
await Bun.write(join(claudeDir, 'CLAUDE.md'), contextContent);
const settingsFile = generateClaudeSettings(email, shellUsername);
const settingsContent = await Bun.file(settingsFile).text();
await Bun.write(join(claudeDir, 'settings.json'), settingsContent);
console.log(`[provision] provisioning complete for ${email}`);
return true;
}
async function seedShellConfigs(homeDir: string): Promise<void> {
// .zshenv (must be first — prevents system compinit before oh-my-zsh)
await copyTemplate(join(TEMPLATE_DIR, '.zshenv'), join(homeDir, '.zshenv'));
// .zshrc
await copyTemplate(join(TEMPLATE_DIR, '.zshrc'), join(homeDir, '.zshrc'));
// .tmux.conf
await copyTemplate(join(TEMPLATE_DIR, '.tmux.conf'), join(homeDir, '.tmux.conf'));
// starship config
const configDir = join(homeDir, '.config');
mkdirSync(configDir, { recursive: true });
await copyTemplate(join(TEMPLATE_DIR, 'starship-officer.toml'), join(configDir, 'starship-officer.toml'));
// Oh My Zsh — copy from host install
const ohMyZshDest = join(homeDir, '.oh-my-zsh');
if (!existsSync(ohMyZshDest)) {
const hostOhMyZsh = join(process.env.HOME ?? '', '.oh-my-zsh');
if (existsSync(hostOhMyZsh)) {
Bun.spawnSync({ cmd: ['cp', '-r', hostOhMyZsh, ohMyZshDest], stdout: 'ignore', stderr: 'ignore' });
} else {
Bun.spawnSync({
cmd: ['git', 'clone', '--depth=1', 'https://github.com/ohmyzsh/ohmyzsh.git', ohMyZshDest],
stdout: 'ignore',
stderr: 'ignore',
});
}
}
// LazyVim config
const nvimDir = join(homeDir, '.config', 'nvim');
if (!existsSync(nvimDir)) {
const hostNvim = join(process.env.HOME ?? '', '.config', 'nvim');
if (existsSync(hostNvim)) {
Bun.spawnSync({ cmd: ['cp', '-r', hostNvim, nvimDir], stdout: 'ignore', stderr: 'ignore' });
}
}
// Ensure .local/bin exists
mkdirSync(join(homeDir, '.local', 'bin'), { recursive: true });
}
-100
View File
@@ -1,100 +0,0 @@
########## TPM AUTO-INSTALL + SESSION PERSISTENCE ##########
# Auto-install TPM if missing
if-shell '[ ! -d ~/.tmux/plugins/tpm ]' \
'run-shell "git clone https://github.com/tmux-plugins/tpm ~/.tmux/plugins/tpm"'
# Plugin list
set -g @plugin 'tmux-plugins/tpm'
# remap prefix from 'C-b' to 'C-a'
unbind C-b
set-option -g prefix C-a
bind-key C-a send-prefix
set -g base-index 1
# split panes using | and -
unbind '"'
unbind %
bind | split-window -h
bind - split-window -v
# reload config file (change file location to your the tmux.conf you want to use)
unbind r
bind r source-file ~/.tmux.conf \; display-message "Config reloaded!" \; refresh-client -S
# switch panes using Alt-arrow without prefix
bind -n M-Left select-pane -L
bind -n M-Right select-pane -R
bind -n M-Up select-pane -U
bind -n M-Down select-pane -D
# switch panes using Alt-HJKL without prefix
bind -n M-h select-pane -L
bind -n M-l select-pane -R
bind -n M-k select-pane -U
bind -n M-j select-pane -D
# Enable mouse control (clickable windows, panes, resizable panes)
# don't rename windows automatically
set-option -g allow-rename off
######################
### DESIGN CHANGES ###
######################
# loud or quiet?
set -g visual-activity off
set -g visual-bell off
set -g visual-silence off
setw -g monitor-activity off
set -g bell-action none
# modes
setw -g clock-mode-colour colour12
setw -g mode-style 'fg=colour1 bg=colour18 bold'
# panes
set -g pane-border-style 'fg=colour19 bg=colour0'
set -g pane-active-border-style 'bg=colour0 fg=colour9'
# statusbar
set -g status-position bottom
set -g status-justify left
set -g status-style 'bg=colour2 fg=colour23'
# set -g status-left '#[fg=white,bg=black,bold] pastilhas #[default]'
set -g status-left '#[fg=#ffffff,bg=#000000,bold] #{USER}@#H #[default]'
# set -g status-left-length 20
set -g status-right '#[fg=#ffffff,bg=colour1] %d/%m #[fg=#ffffff,bg=colour8] %H:%M:%S '
set -g status-right-length 50
set -g status-left-length 20
setw -g window-status-current-style 'fg=colour1 bg=colour19 bold'
setw -g window-status-current-format ' #I#[fg=colour249]:#[fg=colour255]#W#[fg=colour249]#F '
setw -g window-status-style 'fg=colour9 bg=colour18'
setw -g window-status-format ' #I#[fg=colour237]:#[fg=colour250]#W#[fg=colour244]#F '
setw -g window-status-bell-style 'fg=colour255 bg=colour1 bold'
# ...existing code...
# messages
set -g message-style 'fg=#ffffff bg=red bold'
# Change the font color for the exit pane confirmation message
set -g message-command-style 'fg=#ffffff bg=red bold'
# ...existing code...
# messages
# set -g message-style 'fg=colour232 bg=colour16 bold'
##########################
### END DESIGN CHANGES ###
##########################
##########################
### EASY MOUSE SCROLL ###
##########################
set -g mouse on
set -ga terminal-overrides ',*256color*:smcup@:rmcup@'
-1
View File
@@ -1 +0,0 @@
skip_global_compinit=1
-75
View File
@@ -1,75 +0,0 @@
# If you come from bash you might have to change your $PATH.
export PATH=$HOME/.local/bin:$PATH
# Skip insecure directory check (system zsh dirs may be group-writable)
ZSH_DISABLE_COMPFIX=true
# Path to your Oh My Zsh installation.
export ZSH="$HOME/.oh-my-zsh"
# Set name of the theme to load --- if set to "random", it will
# load a random theme each time Oh My Zsh is loaded, in which case,
# to know which specific one was loaded, run: echo $RANDOM_THEME
# See https://github.com/ohmyzsh/ohmyzsh/wiki/Themes
ZSH_THEME=""
# Which plugins would you like to load?
# Standard plugins can be found in $ZSH/plugins/
# Custom plugins may be added to $ZSH_CUSTOM/plugins/
# Example format: plugins=(rails git textmate ruby lighthouse)
# Add wisely, as too many plugins slow down shell startup.
plugins=(git)
source $ZSH/oh-my-zsh.sh
# ============================================================================
# STARSHIP PROMPT
# ============================================================================
if [[ -f "$HOME/.config/starship-officer.toml" ]]; then
export STARSHIP_CONFIG="$HOME/.config/starship-officer.toml"
fi
# Auto-install starship if not available (host mode)
if ! command -v starship &> /dev/null; then
if [[ ! -x "$HOME/.local/bin/starship" ]]; then
mkdir -p "$HOME/.local/bin"
echo "Installing starship..."
curl -sS https://starship.rs/install.sh | sh -s -- -y -b "$HOME/.local/bin" 2>/dev/null
fi
export PATH="$HOME/.local/bin:$PATH"
fi
eval "$(starship init zsh)"
# ============================================================================
# EZA ALIASES (colors and icons for ls)
# ============================================================================
alias ls='eza --icons'
alias la='eza --icons -la'
alias ll='eza --icons -l'
alias lll='eza --icons -lA'
alias lh='eza --icons -lhA'
alias ltr='eza --icons -ltr'
alias l='eza --icons -la'
# Other common aliases (oh-my-zsh standard)
alias grep='grep --color=auto'
alias less='less -R'
alias diff='diff --color=auto'
alias cp='cp -iv'
alias mv='mv -iv'
alias rm='rm -i'
alias mkdir='mkdir -p'
alias which='which -a'
alias history='fc -l 1'
alias n="nvim"
alias vim="n"
alias sz="source ~/.zshrc"
alias ld="lazydocker"
alias hr="hyprctl reload"
alias hir="omarchy-restart-hypridle"
alias setupmines="WINEPREFIX=~/wine/minesweeper winecfg"
alias httpserver="python -m http.server 8888"
clear
@@ -1,19 +0,0 @@
format = "${env_var.USER}:$hostname $directory $character"
[env_var.USER]
format = "[$env_value]($style)"
style = "bold #0891B2"
[hostname]
ssh_only = false
format = "[officer.dev]($style)"
style = "bold yellow"
[directory]
truncation_length = 3
truncate_to_repo = false
style = "blue"
[character]
success_symbol = ">"
error_symbol = ">"