feat: pair and publish independent whole-house applications - #24
Merged
Merged
Conversation
Adds persistent multi-home credentials and a pairing flow so an agent never re-exports MIAKAPP_HOME_KEY and never signs in on the owner's behalf. - miakapp pair redeems a one-time code (stdin pipe or hidden prompt; --code allowed, never echoed) at a pinned HTTPS issuer: discovery must name that exact issuer before the code is sent, redirects are refused, and the POST /v1/pairing/redeem response must be no-store, name the same issuer and carry its key_id inside home_key. The new key is stored as a new context, others are kept, and a publication token exchange proves it works. - ~/.miakapp/config.json (no secrets) and credentials.json (keys only), 0600 in a 0700 directory, atomic temp+fsync+rename under a lock file; loose permissions, symlinks, foreign owners and swapped keys are refused. - context list/show/use/remove, never printing a key. - Per-invocation selection: --context, MIAKAPP_CONTEXT, MIAKAPP_HOME_KEY (CI), then the context paired with the home in miakapp.yaml. A context or a known key for another home is refused before any request. - status reads the live pointer (RFC 0004 component-pointer); publish and activate default --expected-generation to it, still compare-and-set. - init defaults --home/--control-plane from the selected context. - MCP exposes pair, status and the context actions; remove needs confirm. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Agent guide (docs + packaged asset), agent-pack block, CLI and template READMEs: - §0 defines done as a published, verified interface and a working link — never a screenshot, mockup or offline prototype — separates publishing a V4 interface (in scope, reversible) from changing the physical installation (explicit request only), and states no platform source is needed. - §3 requires a committed docs/inventory.md (source, meaning, freshness, readers, command) before design; the V1 covers the real data, never invents values, distinguishes current/stale/unavailable and shows no plumbing text. - §8/§9 document pair, contexts, credential precedence, status and the optional --expected-generation; the pack block points at pairing. - Template: publish:home no longer hardcodes generation 0 (it failed on every second publication); control plane uses the production issuer control.miakapp.com expected by the backend instead of control.miakapp.app. - Tests: the guide must mention every command and the deliverable rules. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- miakapp.yaml takes exactly one of app: (miakapp.app/1, the new
default) or component: (miakapp.component/1, unchanged). app.requires
may declare only state_read and call; events, media and protocol-
reserved miakapp.* functions are refused before any upload.
- publish sends the project's ABI and refuses a control plane that
echoes another one at upload, finalization or activation; upload,
release and pointer reads accept both ABIs.
- Discovery accepts the optional runtime_diagnostics_endpoint (checked
to be under the issuer) and home_url_template (exactly
<origin>/app?home={home_id}). publish/status/activate print home_url,
the resident link, and the bundle as artifact_url; with no template
home_url is null rather than invented.
- init --kind app|component, app by default (dist/app.js); the MCP
tool exposes kind.
- New @miakapp/app package: typed window.miakapp, connect(), paths(),
subscribe(), call() and the closed call error codes.
- templates/home: a DOM house app (own layout, CSS, hash routing, stale
and outcome-unknown handling) bundled as one IIFE, with a tested view
model; the semantic component stays buildable (build:component).
- Agent guide and agent-pack block default to whole-house apps, require
handing over home_url and forbid household data in the bundle.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The control plane issues upload_url as {issuer}/v1/component-uploads/
{uploadId} (RFC 0004 13.2) and serves delivery only there. The CLI
required the URL under /v1/homes/{home}/component-uploads/ and refused
every real capability as a contract error; its fake control plane
shared the mistake, so the suite never noticed. Found by running the
CLI against the real control plane in the emulators. The fake now
issues and serves the issuer-level URL and refuses delivery under the
home path, like the real one.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification