ACCOUNTS.md: unified registry with login_type, flat schema
This commit is contained in:
+53
-40
@@ -1,51 +1,64 @@
|
|||||||
# Login registry — secret-free
|
# NetVM Account Registry
|
||||||
|
|
||||||
Which product login lives in which chrome-box profile, on which NetVM node,
|
One row per agent. All data in columns — no joins, no translation.
|
||||||
with which egress, in what auth state. This is structure only: **no
|
The `agent` name is the canonical identifier used everywhere:
|
||||||
passwords, no tokens, no session cookies, no OTP codes — ever.** Credential
|
node name, chrome-box profile, API `--account`, and the agent's display name.
|
||||||
pointers at most (e.g. "human", "credential-gateway:<id>").
|
|
||||||
|
|
||||||
The 1:1 chain: `login -> profile = node = Warp identity = veth/CDP slot =
|
## Schema
|
||||||
consistent egress`. Network details live in NODES.md; this file maps the
|
|
||||||
human side (whose login, what for, does it work).
|
|
||||||
|
|
||||||
## Auth states
|
| Column | Description |
|
||||||
|
|--------|-------------|
|
||||||
|
| agent | Canonical name. Used for node, profile, API account. |
|
||||||
|
| node | NetVM node name (== agent). |
|
||||||
|
| profile | Chrome-box profile (== agent). |
|
||||||
|
| login_type | How this session was authenticated: `email_otp`, `phone_otp`, `password`, `instagram` |
|
||||||
|
| meta_label | Label shown in Meta account selector (e.g., "Meta Account", "piparada") |
|
||||||
|
| email | Email used for login (if email_otp). Never store passwords. |
|
||||||
|
| phone_otp | `yes` if phone OTP was used. Never store the phone number. |
|
||||||
|
| instagram_linked | `yes`/`no`/`unknown` — whether Meta account has IG linked |
|
||||||
|
| status | `active`, `pending_auth`, `expired`, `disabled` |
|
||||||
|
| egress_ip | Current WARP egress IP for the node |
|
||||||
|
| cdp_port | CDP port for the browser |
|
||||||
|
| display_name | Agent's chosen display name in muse.ai (may differ from `agent`) |
|
||||||
|
| notes | Freeform context |
|
||||||
|
|
||||||
| state | meaning | who moves it |
|
## Accounts
|
||||||
|-------|---------|--------------|
|
|
||||||
| `pending-identity` | profile exists, no Warp identity yet | human runs `netvm-new-identity.sh <profile>` |
|
|
||||||
| `pending-auth` | node up, nobody logged in yet | human logs in (browser or credential gateway) |
|
|
||||||
| `2fa-pending` | login needs a human 2FA/OTP step | human via ethical-captcha handoff; OTP routed by email-alert |
|
|
||||||
| `active` | logged in, session healthy | operator verifies; automation may proceed |
|
|
||||||
| `expired` | session died | back to `pending-auth` (human) |
|
|
||||||
| `retired` | login no longer used | operator tears down node, archives row |
|
|
||||||
|
|
||||||
Operators never create or touch credentials. If it creates or touches a
|
| agent | node | profile | login_type | meta_label | email | phone_otp | instagram_linked | status | egress_ip | cdp_port | display_name | notes |
|
||||||
credential, it is human-only. Everything else, operators handle.
|
|-------|------|---------|------------|------------|-------|-----------|------------------|--------|-----------|----------|--------------|-------|
|
||||||
|
| muse | muse | muse | email_otp | ltd.pixels.ltd@gmail.com | ltd.pixels.ltd@gmail.com | no | unknown | active | 104.28.195.181 | 9410 | muse | Main dev agent. Logged in 2026-10-03 via email OTP on bl. |
|
||||||
|
| pip | pip | pip | phone_otp | piparada | - | yes | yes | pending_auth | 104.28.195.181 | 9420 | pip | Phone OTP login 2026-10-03. Renamed from 'Muse' to 'pip'. Session lost on browser restart 2026-10-03; needs re-auth. IG avatar visible in account selector. |
|
||||||
|
| 646 | 646 | 646 | phone_otp | Meta Account | - | yes | unknown | pending_auth | - | - | 646 | Shares phone number with piparada's account. Logged in 2026-10-03 via phone OTP (first Meta Account option). Node not yet created on bl. |
|
||||||
|
|
||||||
## Registry
|
## Login Type Details
|
||||||
|
|
||||||
| login | product | profile/node | purpose / owner | auth state | 2FA / verify route | notes |
|
### email_otp
|
||||||
|-------|---------|--------------|-----------------|------------|--------------------|-------|
|
- Flow: Enter email → Receive OTP via email → Enter OTP → Select account (if multiple)
|
||||||
| — | — | tp | orchestrator / operator-main | pending-auth | — | first node; no product login yet |
|
- Used by: muse
|
||||||
| — | — | smoke | muse-646-patha | active | — | 646's profile; muse.ai login completed 2026-10-03 |
|
- Credentials: Email address (stored). OTP is transient.
|
||||||
|
|
||||||
## Known login flows
|
### phone_otp
|
||||||
|
- Flow: Enter phone → Receive SMS OTP → Enter OTP → Select Meta account (if multiple)
|
||||||
|
- Used by: pip, 646
|
||||||
|
- Credentials: Phone number is NEVER stored (PII). Only `phone_otp=yes` flag.
|
||||||
|
- Note: One phone number can map to multiple Meta accounts (observed: 2 accounts).
|
||||||
|
|
||||||
### muse.ai (recon 2026-10-03, via CDP DOM)
|
### Meta Account Selection
|
||||||
- Homepage has "Log in" buttons (JS, no href). Click -> inline form, same URL.
|
When a phone number maps to multiple Meta accounts, muse.ai shows a selector:
|
||||||
- "Log in or create an account" — single field: "Mobile number or email (required)" + Continue.
|
- Screenshot: `docs/meta-account-selection.png`
|
||||||
- Phone/email OTP flow (SMS or email code). No password, no OAuth buttons.
|
- Each option is a SEPARATE Muse container (not linked profiles).
|
||||||
- Human completes it in one visible session; operators verify + automate after.
|
- The `meta_label` column records which option was selected.
|
||||||
|
- Instagram-linked accounts show IG avatar in selector.
|
||||||
|
|
||||||
## Provisioning a new login (dev)
|
## Naming Convention
|
||||||
|
|
||||||
1. Operator: `chrome-box create <profile>` (profile name = future node name).
|
**Rule:** The `agent` column value is used identically for:
|
||||||
2. Human: `netvm-new-identity.sh <profile>` (Warp identity — credential).
|
- NetVM node name (`/etc/netvm/<agent>.conf`)
|
||||||
3. Operator: `netvm-node-up.sh <profile>`; add rows to NODES.md and here
|
- Chrome-box profile (`~/.local/share/chrome-box/profiles/<agent>/`)
|
||||||
(`pending-identity` -> `pending-auth`).
|
- API account (`muse-chat-api.py --account <agent>`)
|
||||||
4. Human: authenticate the login in the profile's browser
|
- CDP port mapping (deterministic per agent)
|
||||||
(`netvm-chrome.sh <profile>` visible, or credential-gateway injection).
|
|
||||||
Row -> `active`.
|
**Exception:** `display_name` may differ (user-chosen in muse.ai UI).
|
||||||
5. Operator: verify with `netvm-exec.sh <profile> -- ...` / CDP; keep the
|
Example: agent `pip` has display_name `pip` (renamed from 'Muse').
|
||||||
session warm. On 2FA: ethical-captcha handoff, OTP via email-alert.
|
|
||||||
|
Do NOT use different names for node vs profile vs API. That causes bugs.
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 29 KiB |
Reference in New Issue
Block a user