diff --git a/ACCOUNTS.md b/ACCOUNTS.md index 4c49bf8..7d3433e 100644 --- a/ACCOUNTS.md +++ b/ACCOUNTS.md @@ -1,51 +1,64 @@ -# Login registry — secret-free +# NetVM Account Registry -Which product login lives in which chrome-box profile, on which NetVM node, -with which egress, in what auth state. This is structure only: **no -passwords, no tokens, no session cookies, no OTP codes — ever.** Credential -pointers at most (e.g. "human", "credential-gateway:"). +One row per agent. All data in columns — no joins, no translation. +The `agent` name is the canonical identifier used everywhere: +node name, chrome-box profile, API `--account`, and the agent's display name. -The 1:1 chain: `login -> profile = node = Warp identity = veth/CDP slot = -consistent egress`. Network details live in NODES.md; this file maps the -human side (whose login, what for, does it work). +## Schema -## Auth states +| Column | Description | +|--------|-------------| +| agent | Canonical name. Used for node, profile, API account. | +| node | NetVM node name (== agent). | +| profile | Chrome-box profile (== agent). | +| login_type | How this session was authenticated: `email_otp`, `phone_otp`, `password`, `instagram` | +| meta_label | Label shown in Meta account selector (e.g., "Meta Account", "piparada") | +| email | Email used for login (if email_otp). Never store passwords. | +| phone_otp | `yes` if phone OTP was used. Never store the phone number. | +| instagram_linked | `yes`/`no`/`unknown` — whether Meta account has IG linked | +| status | `active`, `pending_auth`, `expired`, `disabled` | +| egress_ip | Current WARP egress IP for the node | +| cdp_port | CDP port for the browser | +| display_name | Agent's chosen display name in muse.ai (may differ from `agent`) | +| notes | Freeform context | -| state | meaning | who moves it | -|-------|---------|--------------| -| `pending-identity` | profile exists, no Warp identity yet | human runs `netvm-new-identity.sh ` | -| `pending-auth` | node up, nobody logged in yet | human logs in (browser or credential gateway) | -| `2fa-pending` | login needs a human 2FA/OTP step | human via ethical-captcha handoff; OTP routed by email-alert | -| `active` | logged in, session healthy | operator verifies; automation may proceed | -| `expired` | session died | back to `pending-auth` (human) | -| `retired` | login no longer used | operator tears down node, archives row | +## Accounts -Operators never create or touch credentials. If it creates or touches a -credential, it is human-only. Everything else, operators handle. +| agent | node | profile | login_type | meta_label | email | phone_otp | instagram_linked | status | egress_ip | cdp_port | display_name | notes | +|-------|------|---------|------------|------------|-------|-----------|------------------|--------|-----------|----------|--------------|-------| +| muse | muse | muse | email_otp | ltd.pixels.ltd@gmail.com | ltd.pixels.ltd@gmail.com | no | unknown | active | 104.28.195.181 | 9410 | muse | Main dev agent. Logged in 2026-10-03 via email OTP on bl. | +| pip | pip | pip | phone_otp | piparada | - | yes | yes | pending_auth | 104.28.195.181 | 9420 | pip | Phone OTP login 2026-10-03. Renamed from 'Muse' to 'pip'. Session lost on browser restart 2026-10-03; needs re-auth. IG avatar visible in account selector. | +| 646 | 646 | 646 | phone_otp | Meta Account | - | yes | unknown | pending_auth | - | - | 646 | Shares phone number with piparada's account. Logged in 2026-10-03 via phone OTP (first Meta Account option). Node not yet created on bl. | -## Registry +## Login Type Details -| login | product | profile/node | purpose / owner | auth state | 2FA / verify route | notes | -|-------|---------|--------------|-----------------|------------|--------------------|-------| -| — | — | tp | orchestrator / operator-main | pending-auth | — | first node; no product login yet | -| — | — | smoke | muse-646-patha | active | — | 646's profile; muse.ai login completed 2026-10-03 | +### email_otp +- Flow: Enter email → Receive OTP via email → Enter OTP → Select account (if multiple) +- Used by: muse +- Credentials: Email address (stored). OTP is transient. -## Known login flows +### phone_otp +- Flow: Enter phone → Receive SMS OTP → Enter OTP → Select Meta account (if multiple) +- Used by: pip, 646 +- Credentials: Phone number is NEVER stored (PII). Only `phone_otp=yes` flag. +- Note: One phone number can map to multiple Meta accounts (observed: 2 accounts). -### muse.ai (recon 2026-10-03, via CDP DOM) -- Homepage has "Log in" buttons (JS, no href). Click -> inline form, same URL. -- "Log in or create an account" — single field: "Mobile number or email (required)" + Continue. -- Phone/email OTP flow (SMS or email code). No password, no OAuth buttons. -- Human completes it in one visible session; operators verify + automate after. +### Meta Account Selection +When a phone number maps to multiple Meta accounts, muse.ai shows a selector: +- Screenshot: `docs/meta-account-selection.png` +- Each option is a SEPARATE Muse container (not linked profiles). +- The `meta_label` column records which option was selected. +- Instagram-linked accounts show IG avatar in selector. -## Provisioning a new login (dev) +## Naming Convention -1. Operator: `chrome-box create ` (profile name = future node name). -2. Human: `netvm-new-identity.sh ` (Warp identity — credential). -3. Operator: `netvm-node-up.sh `; add rows to NODES.md and here - (`pending-identity` -> `pending-auth`). -4. Human: authenticate the login in the profile's browser - (`netvm-chrome.sh ` visible, or credential-gateway injection). - Row -> `active`. -5. Operator: verify with `netvm-exec.sh -- ...` / CDP; keep the - session warm. On 2FA: ethical-captcha handoff, OTP via email-alert. +**Rule:** The `agent` column value is used identically for: +- NetVM node name (`/etc/netvm/.conf`) +- Chrome-box profile (`~/.local/share/chrome-box/profiles//`) +- API account (`muse-chat-api.py --account `) +- CDP port mapping (deterministic per agent) + +**Exception:** `display_name` may differ (user-chosen in muse.ai UI). +Example: agent `pip` has display_name `pip` (renamed from 'Muse'). + +Do NOT use different names for node vs profile vs API. That causes bugs. diff --git a/docs/meta-account-selection.png b/docs/meta-account-selection.png new file mode 100644 index 0000000..0a8e454 Binary files /dev/null and b/docs/meta-account-selection.png differ