feat(cred): harden client onboarding with Instagram linking portal, age verification bypass, and fleet runbook

This commit is contained in:
operator
2026-10-04 21:43:32 +00:00
parent 7902622852
commit 178ddc5dbf
10 changed files with 898 additions and 41 deletions
+29 -3
View File
@@ -1878,11 +1878,11 @@ def cmd_cred_initiate(args):
else:
st = res.get("status")
if st == "awaiting_otp":
print("\n" + c_warn(f"[APPROVAL_NEEDED] Code sent to {args.email} for node '{args.node}'.") + "\n")
print("\n" + c_yellow(f"[APPROVAL_NEEDED] Code sent to {args.email} for node '{args.node}'.") + "\n")
print(f" Submit OTP with: super cred submit-otp --node {args.node} --otp <code>\n")
sys.exit(2)
elif st == "active":
print("\n" + c_ok(f"[SUCCESS] Node '{args.node}' is already authenticated and active.") + "\n")
print("\n" + c_green(f"[SUCCESS] Node '{args.node}' is already authenticated and active.") + "\n")
else:
print(f"[{st.upper()}] {res.get('message') or res.get('detail')}")
sys.exit(res.get("code", 1))
@@ -1896,7 +1896,7 @@ def cmd_cred_submit_otp(args):
else:
st = res.get("status")
if st == "active":
print("\n" + c_ok(f"[SUCCESS] Node '{args.node}' successfully signed in!") + "\n")
print("\n" + c_green(f"[SUCCESS] Node '{args.node}' successfully signed in!") + "\n")
else:
print(f"[{st.upper()}] {res.get('message') or res.get('detail')}")
sys.exit(res.get("code", 1))
@@ -1919,6 +1919,26 @@ def cmd_cred_status(args):
print(f" Detail : {c_dim(res['detail'])}")
print()
def cmd_cred_link_instagram(args):
import cred_client
client = cred_client.CredClient()
res = client.link_instagram(args.node, notify=getattr(args, "notify", False))
if getattr(args, "json", False):
print(json.dumps(res, indent=2))
else:
print("\n" + c_bold(f"=== INSTAGRAM LINKING: {args.node} ===") + "\n")
if res.get("error"):
print(c_err(f" Error: {res['error']}"))
sys.exit(1)
print(f" Tailscale Portal: {c_cyan(res['portal_url'])}")
print(f" Direct IP Portal: {c_cyan(res['portal_ip_url'])}")
oauth_preview = res['direct_oauth_url'][:75] + "..." if res.get('direct_oauth_url') else "-"
print(f" OAuth URL : {c_dim(oauth_preview)}")
if getattr(args, "notify", False):
n_badge = badge_ok("SENT") if res['email_notified'] else badge_err("FAILED")
print(f" Email Alert : {n_badge}")
print("\n" + c_yellow(" → Tap either Tailscale link from your phone/browser to complete Meta age verification.") + "\n")
def cmd_cred_list(args):
import cred_client
client = cred_client.CredClient()
@@ -3082,6 +3102,10 @@ def build_parser():
p_c_stat = cred_sub.add_parser("status", parents=[common], help="Query onboarding & vitality status for a node")
p_c_stat.add_argument("--node", required=True, help="Node label")
p_c_link = cred_sub.add_parser("link-instagram", parents=[common], help="Generate Tailscale one-tap portal & OAuth link for age verification")
p_c_link.add_argument("--node", required=True, help="Node label")
p_c_link.add_argument("--notify", action="store_true", help="Send email alert to operator via local MTA")
cred_sub.add_parser("list", parents=[common], help="List all registered nodes and vitality statuses")
# Domain: HARVEST
@@ -3356,6 +3380,8 @@ def main():
cmd_cred_submit_otp(args)
elif act == "status":
cmd_cred_status(args)
elif act == "link-instagram":
cmd_cred_link_instagram(args)
else:
parser.print_help()
elif args.domain == "harvest":