ACCOUNTS.md: unified registry with login_type, flat schema

This commit is contained in:
operator
2026-10-03 17:15:21 +00:00
parent c6ba4cce3d
commit ee7524d7f1
2 changed files with 53 additions and 40 deletions
+53 -40
View File
@@ -1,51 +1,64 @@
# Login registry — secret-free
# NetVM Account Registry
Which product login lives in which chrome-box profile, on which NetVM node,
with which egress, in what auth state. This is structure only: **no
passwords, no tokens, no session cookies, no OTP codes — ever.** Credential
pointers at most (e.g. "human", "credential-gateway:<id>").
One row per agent. All data in columns — no joins, no translation.
The `agent` name is the canonical identifier used everywhere:
node name, chrome-box profile, API `--account`, and the agent's display name.
The 1:1 chain: `login -> profile = node = Warp identity = veth/CDP slot =
consistent egress`. Network details live in NODES.md; this file maps the
human side (whose login, what for, does it work).
## Schema
## Auth states
| Column | Description |
|--------|-------------|
| agent | Canonical name. Used for node, profile, API account. |
| node | NetVM node name (== agent). |
| profile | Chrome-box profile (== agent). |
| login_type | How this session was authenticated: `email_otp`, `phone_otp`, `password`, `instagram` |
| meta_label | Label shown in Meta account selector (e.g., "Meta Account", "piparada") |
| email | Email used for login (if email_otp). Never store passwords. |
| phone_otp | `yes` if phone OTP was used. Never store the phone number. |
| instagram_linked | `yes`/`no`/`unknown` — whether Meta account has IG linked |
| status | `active`, `pending_auth`, `expired`, `disabled` |
| egress_ip | Current WARP egress IP for the node |
| cdp_port | CDP port for the browser |
| display_name | Agent's chosen display name in muse.ai (may differ from `agent`) |
| notes | Freeform context |
| state | meaning | who moves it |
|-------|---------|--------------|
| `pending-identity` | profile exists, no Warp identity yet | human runs `netvm-new-identity.sh <profile>` |
| `pending-auth` | node up, nobody logged in yet | human logs in (browser or credential gateway) |
| `2fa-pending` | login needs a human 2FA/OTP step | human via ethical-captcha handoff; OTP routed by email-alert |
| `active` | logged in, session healthy | operator verifies; automation may proceed |
| `expired` | session died | back to `pending-auth` (human) |
| `retired` | login no longer used | operator tears down node, archives row |
## Accounts
Operators never create or touch credentials. If it creates or touches a
credential, it is human-only. Everything else, operators handle.
| agent | node | profile | login_type | meta_label | email | phone_otp | instagram_linked | status | egress_ip | cdp_port | display_name | notes |
|-------|------|---------|------------|------------|-------|-----------|------------------|--------|-----------|----------|--------------|-------|
| muse | muse | muse | email_otp | ltd.pixels.ltd@gmail.com | ltd.pixels.ltd@gmail.com | no | unknown | active | 104.28.195.181 | 9410 | muse | Main dev agent. Logged in 2026-10-03 via email OTP on bl. |
| pip | pip | pip | phone_otp | piparada | - | yes | yes | pending_auth | 104.28.195.181 | 9420 | pip | Phone OTP login 2026-10-03. Renamed from 'Muse' to 'pip'. Session lost on browser restart 2026-10-03; needs re-auth. IG avatar visible in account selector. |
| 646 | 646 | 646 | phone_otp | Meta Account | - | yes | unknown | pending_auth | - | - | 646 | Shares phone number with piparada's account. Logged in 2026-10-03 via phone OTP (first Meta Account option). Node not yet created on bl. |
## Registry
## Login Type Details
| login | product | profile/node | purpose / owner | auth state | 2FA / verify route | notes |
|-------|---------|--------------|-----------------|------------|--------------------|-------|
| — | — | tp | orchestrator / operator-main | pending-auth | — | first node; no product login yet |
| — | — | smoke | muse-646-patha | active | — | 646's profile; muse.ai login completed 2026-10-03 |
### email_otp
- Flow: Enter email → Receive OTP via email → Enter OTP → Select account (if multiple)
- Used by: muse
- Credentials: Email address (stored). OTP is transient.
## Known login flows
### phone_otp
- Flow: Enter phone → Receive SMS OTP → Enter OTP → Select Meta account (if multiple)
- Used by: pip, 646
- Credentials: Phone number is NEVER stored (PII). Only `phone_otp=yes` flag.
- Note: One phone number can map to multiple Meta accounts (observed: 2 accounts).
### muse.ai (recon 2026-10-03, via CDP DOM)
- Homepage has "Log in" buttons (JS, no href). Click -> inline form, same URL.
- "Log in or create an account" — single field: "Mobile number or email (required)" + Continue.
- Phone/email OTP flow (SMS or email code). No password, no OAuth buttons.
- Human completes it in one visible session; operators verify + automate after.
### Meta Account Selection
When a phone number maps to multiple Meta accounts, muse.ai shows a selector:
- Screenshot: `docs/meta-account-selection.png`
- Each option is a SEPARATE Muse container (not linked profiles).
- The `meta_label` column records which option was selected.
- Instagram-linked accounts show IG avatar in selector.
## Provisioning a new login (dev)
## Naming Convention
1. Operator: `chrome-box create <profile>` (profile name = future node name).
2. Human: `netvm-new-identity.sh <profile>` (Warp identity — credential).
3. Operator: `netvm-node-up.sh <profile>`; add rows to NODES.md and here
(`pending-identity` -> `pending-auth`).
4. Human: authenticate the login in the profile's browser
(`netvm-chrome.sh <profile>` visible, or credential-gateway injection).
Row -> `active`.
5. Operator: verify with `netvm-exec.sh <profile> -- ...` / CDP; keep the
session warm. On 2FA: ethical-captcha handoff, OTP via email-alert.
**Rule:** The `agent` column value is used identically for:
- NetVM node name (`/etc/netvm/<agent>.conf`)
- Chrome-box profile (`~/.local/share/chrome-box/profiles/<agent>/`)
- API account (`muse-chat-api.py --account <agent>`)
- CDP port mapping (deterministic per agent)
**Exception:** `display_name` may differ (user-chosen in muse.ai UI).
Example: agent `pip` has display_name `pip` (renamed from 'Muse').
Do NOT use different names for node vs profile vs API. That causes bugs.
Binary file not shown.

After

Width:  |  Height:  |  Size: 29 KiB