feat: Phase 3b — proper Web UI for memories, projects, settings
Replaces the debug /me + /connect pages with a real authed app shell.
Pages
- / — anonymous landing; redirects to /dashboard once signed in
- /dashboard — recent memories + top projects, quick "new memory" action
- /memories — searchable list with hybrid (vector+FTS+tags) scoring;
per-result rank breakdown shown inline
- /memories/[id] — view + inline edit toggle + delete
- /memories/new — create form with project autocomplete
- /projects — list with memory counts and last-activity
- /projects/[key] — that project's memories
- /settings — read-only Authentik profile + link to tokens
- /settings/tokens — list / create / revoke CLI tokens
Old URLs preserved as redirects:
- /me → /dashboard
- /connect → /settings/tokens
Stack additions
- Tailwind v4 with CSS-first @theme tokens (dark only for now)
- App shell in app/(authed)/ — auth guard + top nav with global search box
- Lightweight UI primitives in app/_components/ui/ (Button, Input, Card,
Badge, EmptyState, Container, PageHeader)
- Search logic extracted from MCP tool into lib/memories.ts so Web UI and
MCP both call the same RRF code path
- Memory CRUD via Server Actions in lib/memory-actions.ts; audit_log
rows are tagged actor='web' to distinguish from MCP writes
Per-token revoke
- New cli_tokens table (id, user_id, jti unique, name, created_at,
last_used_at, expires_at, revoked_at) — migration 0001_cli_tokens.sql
- mintCliToken now records jti + name; verifyCliToken enforces revocation
for tracked tokens. Legacy tokens minted before this change (no jti)
are accepted on signature alone until they expire naturally.
- /settings/tokens lists active + revoked tokens with one-click revoke
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
-- cli_tokens: registry of HMAC-signed tokens minted at /connect.
|
||||
--
|
||||
-- Each row corresponds to one issued JWT. The token's `jti` claim is the
|
||||
-- unique identifier — we store the full jti, not a hash, since the jti
|
||||
-- itself isn't a secret (it's just a UUID; the signing material is
|
||||
-- CLI_TOKEN_SECRET).
|
||||
--
|
||||
-- Soft-delete via revoked_at — never DROP rows; audit value lasts past
|
||||
-- the JWT's natural expiration.
|
||||
|
||||
CREATE TABLE "cli_tokens" (
|
||||
"id" uuid PRIMARY KEY DEFAULT gen_random_uuid(),
|
||||
"user_id" uuid NOT NULL REFERENCES "users"("id") ON DELETE CASCADE,
|
||||
"jti" text NOT NULL UNIQUE,
|
||||
"name" text NOT NULL,
|
||||
"created_at" timestamptz NOT NULL DEFAULT now(),
|
||||
"last_used_at" timestamptz,
|
||||
"expires_at" timestamptz NOT NULL,
|
||||
"revoked_at" timestamptz
|
||||
);
|
||||
|
||||
CREATE INDEX "cli_tokens_user_idx" ON "cli_tokens" ("user_id");
|
||||
CREATE INDEX "cli_tokens_user_active_idx" ON "cli_tokens" ("user_id", "revoked_at")
|
||||
WHERE "revoked_at" IS NULL;
|
||||
Reference in New Issue
Block a user