52 lines
2.7 KiB
Markdown
52 lines
2.7 KiB
Markdown
# Login registry — secret-free
|
|
|
|
Which product login lives in which chrome-box profile, on which NetVM node,
|
|
with which egress, in what auth state. This is structure only: **no
|
|
passwords, no tokens, no session cookies, no OTP codes — ever.** Credential
|
|
pointers at most (e.g. "human", "credential-gateway:<id>").
|
|
|
|
The 1:1 chain: `login -> profile = node = Warp identity = veth/CDP slot =
|
|
consistent egress`. Network details live in NODES.md; this file maps the
|
|
human side (whose login, what for, does it work).
|
|
|
|
## Auth states
|
|
|
|
| state | meaning | who moves it |
|
|
|-------|---------|--------------|
|
|
| `pending-identity` | profile exists, no Warp identity yet | human runs `netvm-new-identity.sh <profile>` |
|
|
| `pending-auth` | node up, nobody logged in yet | human logs in (browser or credential gateway) |
|
|
| `2fa-pending` | login needs a human 2FA/OTP step | human via ethical-captcha handoff; OTP routed by email-alert |
|
|
| `active` | logged in, session healthy | operator verifies; automation may proceed |
|
|
| `expired` | session died | back to `pending-auth` (human) |
|
|
| `retired` | login no longer used | operator tears down node, archives row |
|
|
|
|
Operators never create or touch credentials. If it creates or touches a
|
|
credential, it is human-only. Everything else, operators handle.
|
|
|
|
## Registry
|
|
|
|
| login | product | profile/node | purpose / owner | auth state | 2FA / verify route | notes |
|
|
|-------|---------|--------------|-----------------|------------|--------------------|-------|
|
|
| — | — | tp | orchestrator / operator-main | pending-auth | — | first node; no product login yet |
|
|
| — | — | smoke | dev test rig | pending-auth | — | dedicated test profile; muse.ai loads, no login yet |
|
|
|
|
## Known login flows
|
|
|
|
### muse.ai (recon 2026-10-03, via CDP DOM)
|
|
- Homepage has "Log in" buttons (JS, no href). Click -> inline form, same URL.
|
|
- "Log in or create an account" — single field: "Mobile number or email (required)" + Continue.
|
|
- Phone/email OTP flow (SMS or email code). No password, no OAuth buttons.
|
|
- Human completes it in one visible session; operators verify + automate after.
|
|
|
|
## Provisioning a new login (dev)
|
|
|
|
1. Operator: `chrome-box create <profile>` (profile name = future node name).
|
|
2. Human: `netvm-new-identity.sh <profile>` (Warp identity — credential).
|
|
3. Operator: `netvm-node-up.sh <profile>`; add rows to NODES.md and here
|
|
(`pending-identity` -> `pending-auth`).
|
|
4. Human: authenticate the login in the profile's browser
|
|
(`netvm-chrome.sh <profile>` visible, or credential-gateway injection).
|
|
Row -> `active`.
|
|
5. Operator: verify with `netvm-exec.sh <profile> -- ...` / CDP; keep the
|
|
session warm. On 2FA: ethical-captcha handoff, OTP via email-alert.
|