**Phase 92 final verification pass — all green.** This pass re-verified the completed tasks (all 5 task files already in `complete/`) against every completion criterion; no defects found, nothing to fix. - Verified: 9th identity var `grid_line` end-to-end (migration `0015` at head, model/`theming.py`/schemas/API, 422 + built-in→NULL tests present); `styles.css` zero hardcoded literals outside `:root` + derived `--brand-*` vars; 9th picker in theme form; wordmark themed; `theme.js` save/reset/re-show/mount live-sync; dedicated E2E suite + phase-91 suite updated. - `uv run pytest --cov=app --cov-report=term-missing` → **1845 passed, exit 0, TOTAL 99%** (>90%) - `uv run ruff check .` → clean; `uv run pyright` → 0 errors, 0 warnings - `uv run pytest tests/e2e/test_theme_save_and_coverage.py -v --no-cov` → **3 passed** (save-live, reset-live, whole-site) - `uv run pytest tests/e2e/test_admin_theme_tab.py -v --no-cov` → **5 passed** - Criteria: (1) Save/Reset repaint open page, no nav, SPA-nav survives, pre-paint intact ✅; (2) both `rg` gates green (only `:root` + documented `#fff` Stop label; zero SVG hex attrs), grid/selection/hovers/wash/wordmark E2E-proven ✅; (3) no-op contract live-checked: row-less `/` = no tag + exact A1 CSP, grid-only row = 9-var tag in `COLOR_FIELDS` order + sha256 CSP, with-row ≡ row-less bytes ✅; (4) full suite/coverage/lint/both E2E ✅; (5) commit left to the harness per instructions. - Deviations (previously made, probe-verified, kept): live repaint uses CSSOM `<html>` overrides because Chromium blocks `<style>` textContent mutations under the locked sha256-only CSP (tag text still mirrors the next load; `<html>` style exact-saved after Save, empty after Reset); wordmark themed via 3 `.brand-mark` CSS rules instead of inline styles (task 03's inline attrs were CSP-blocked — fixed during task 04). - Next pending phase: none — `todo/` contains only `92_theme_save_and_coverage`.
162 lines
9.6 KiB
HTML
162 lines
9.6 KiB
HTML
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
|
|
<meta name="description" content="Admin sign-in for Brain of Reese — unlocks the full Sources catalog and answer tuning.">
|
|
<title>Sign in · Brain of Reese</title>
|
|
<link rel="icon" type="image/svg+xml" href="/assets/favicon.svg">
|
|
<link rel="stylesheet" href="/assets/styles.css">
|
|
</head>
|
|
<body>
|
|
<a class="skip-link" href="#main">Skip to content</a>
|
|
|
|
<!-- Standard app frame + sticky header (phase 12 consistency). -->
|
|
<header class="app-header">
|
|
<div class="container header-inner">
|
|
<span class="brand">
|
|
<svg class="brand-mark" aria-hidden="true" viewBox="0 0 64 64"><path d="M32 4 55 18v28L32 60 9 46V18Z" stroke-width="4" stroke-linejoin="round"/><circle cx="32" cy="32" r="6.5"/><path d="M32 25.5V16M32 48v-9.5M25.5 32H16M48 32h-9.5" stroke-width="3" stroke-linecap="round"/></svg>
|
|
<span class="brand-text">Brain of <strong>Reese</strong></span>
|
|
</span>
|
|
<!-- Phase 46 (owner permission 2026-08-27, `TODO.md` L9): the
|
|
mobile hamburger — visible ≤640px only (CSS); opens the nav as
|
|
an animated dropdown. Behavior: assets/header.js. -->
|
|
<button type="button" class="nav-toggle" id="nav-toggle"
|
|
aria-expanded="false" aria-controls="app-nav" aria-label="Menu">
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round"><path d="M4 7h16M4 12h16M4 17h16"/></svg>
|
|
</button>
|
|
<nav class="app-nav" id="app-nav" aria-label="Primary">
|
|
<a href="/" class="nav-link">Chat</a>
|
|
<!-- Phase 19 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the Sources link is admin-only (owner
|
|
permission 2026-08-23) — hidden by default, header.js
|
|
reveals it once whoami says admin. The soft-gated page
|
|
itself is unchanged. -->
|
|
<a href="/sources.html" class="nav-link" id="nav-sources" hidden>RAG</a>
|
|
<!-- Phase 35 (owner permission 2026-08-26): the Git sources
|
|
link is admin-only — hidden by default, header.js
|
|
reveals it once whoami says admin, exactly like the
|
|
Sources link above. The phase-34 identical-header contract
|
|
requires it here too: every page's nav carries the same
|
|
four links (Chat, Sources, Git sources, Tuning). -->
|
|
<a href="/git-sources.html" class="nav-link" id="nav-git-sources" hidden>Sources</a>
|
|
<!-- Phase 29 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the Global Tuning link is admin-only (owner
|
|
permission 2026-08-25) — hidden by default, header.js
|
|
reveals it once whoami says admin, exactly like the
|
|
Sources link above. -->
|
|
<a href="/tuning.html" class="nav-link" id="nav-tuning" hidden>Tuning</a>
|
|
<!-- Phase 50 (owner permission 2026-08-29, `TODO.md` L5): the
|
|
History link is admin-only — hidden by default, header.js
|
|
reveals it once whoami says admin, exactly like the
|
|
Tuning link above. -->
|
|
<a href="/history.html" class="nav-link" id="nav-history" hidden>History</a>
|
|
<!-- Phase 79 (task 06): the Tokens link is admin-only —
|
|
hidden by default, header.js reveals it once whoami says
|
|
admin, exactly like the History link above (the
|
|
phase-34 one-bar contract: the SAME nav ships on every
|
|
page — test_nav_consistency pins the inventory parity).
|
|
Null-safe: header.js is a no-op on a page without it. -->
|
|
<a href="/tokens.html" class="nav-link" id="nav-tokens" hidden>Tokens</a>
|
|
<!-- Phase 91 (task 04): the Theme link is admin-only — hidden
|
|
by default, header.js reveals it once whoami says admin,
|
|
exactly like the Tokens link above (the phase-34 one-bar
|
|
contract: the SAME nav ships on every page —
|
|
test_nav_consistency pins the inventory parity).
|
|
Null-safe: header.js is a no-op on a page without it. -->
|
|
<a href="/theme.html" class="nav-link" id="nav-theme" hidden>Theme</a>
|
|
<!-- Phase 46 (mobile dropdown copy: sign-in — desktop bar copy is
|
|
outside the nav; see styles.css .sign-in-mobile rules). -->
|
|
<a href="/login.html?next=/" class="auth-link sign-in-link sign-in-mobile" id="sign-in-link-mobile" hidden>
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M10 4h8a2 2 0 0 1 2 2v12a2 2 0 0 1-2 2h-8"/><path d="M4 12h11"/><path d="m12 9 3 3-3 3"/></svg>
|
|
<span class="auth-label">Sign in</span>
|
|
</a>
|
|
<!-- Phase 46 (mobile dropdown copy — desktop bar copy is
|
|
outside the nav; see styles.css .sign-out-mobile rules). -->
|
|
<button type="button" class="auth-link sign-out-btn sign-out-mobile" id="sign-out-btn-mobile" aria-label="Sign out" hidden>
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M14 4H6a2 2 0 0 0-2 2v12a2 2 0 0 0 2 2h8"/><path d="M9 12h11"/><path d="m17 9 3 3-3 3"/></svg>
|
|
<span class="auth-label">Sign out</span>
|
|
</button>
|
|
</nav>
|
|
<!-- Phase 15: the tuning-notes panel (stored in Postgres, read
|
|
into every system prompt) — owned by the shared header
|
|
module (assets/header.js); the #steering-panel section
|
|
ships in every page's <main>. The navbar toggle was
|
|
removed at owner request (2026-08-28): note management
|
|
lives on /tuning.html. -->
|
|
<!-- Phase 16: single-admin auth — exactly one of Sign in / Sign
|
|
out is visible; /api/whoami decides at load (the shared
|
|
header module). Icon-only below 640px (aria-labels keep the
|
|
accessible names). -->
|
|
<a href="/login.html?next=/login.html" class="auth-link sign-in-link" id="sign-in-link" hidden>
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M10 4h8a2 2 0 0 1 2 2v12a2 2 0 0 1-2 2h-8"/><path d="M4 12h11"/><path d="m12 9 3 3-3 3"/></svg>
|
|
<span class="auth-label">Sign in</span>
|
|
</a>
|
|
<button type="button" class="auth-link sign-out-btn" id="sign-out-btn" aria-label="Sign out" hidden>
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M14 4H6a2 2 0 0 0-2 2v12a2 2 0 0 0 2 2h8"/><path d="M9 12h11"/><path d="m17 9 3 3-3 3"/></svg>
|
|
<span class="auth-label">Sign out</span>
|
|
</button>
|
|
</div>
|
|
</header>
|
|
|
|
<main id="main" class="app-main" tabindex="-1">
|
|
<!-- Phase 15 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the tuning-notes panel (stored notes, newest
|
|
first) — rendered + driven by assets/header.js (shared), not
|
|
the page script. First child of <main> on the non-chat pages;
|
|
the chat page keeps it after #kb-banner. -->
|
|
<section class="steering-panel" id="steering-panel" role="region"
|
|
aria-label="Tuning notes" hidden>
|
|
<div class="steering-panel-head">
|
|
<h2 class="steering-panel-title">Tuning notes</h2>
|
|
<p class="steering-panel-sub">Every note below steers all future answers.</p>
|
|
</div>
|
|
<ul class="steering-list" id="steering-list"></ul>
|
|
<p class="steering-empty" id="steering-empty">No tuning notes yet — press “Tune” under any answer to add one.</p>
|
|
</section>
|
|
<p class="visually-hidden" id="steering-announcer" role="status" aria-live="polite" aria-atomic="true"></p>
|
|
<div class="container login-shell">
|
|
<!-- Centered sign-in card (phase 16): one admin, one password. -->
|
|
<section class="login-card" aria-labelledby="login-title">
|
|
<h1 id="login-title">Sign in</h1>
|
|
<p class="login-sub">
|
|
One admin account, one password. Signing in unlocks the full
|
|
Sources catalog and the answer-tuning controls — chat stays open
|
|
to everyone either way.
|
|
</p>
|
|
<form id="login-form">
|
|
<label class="visually-hidden" for="login-password">Admin password</label>
|
|
<input
|
|
id="login-password"
|
|
name="password"
|
|
type="password"
|
|
autocomplete="current-password"
|
|
required
|
|
>
|
|
<button type="submit" class="login-submit" id="login-submit">Sign in</button>
|
|
</form>
|
|
<p id="login-error" class="login-error" role="alert" hidden></p>
|
|
</section>
|
|
</div>
|
|
</main>
|
|
|
|
<footer class="app-footer">
|
|
<div class="container footer-inner">
|
|
<span class="footer-text">Powered by self-hosted models</span>
|
|
</div>
|
|
</footer>
|
|
|
|
<!-- Phase 19 (full header from phase 34 — owner confirmation
|
|
2026-08-26): the login page carries the SAME shared header as
|
|
every other page (nav incl. the admin-only Tuning link, Tuning
|
|
toggle, Sync, New chat, the auth pair) + the #steering-panel in
|
|
<main>. The module loads through the page script's own
|
|
`import "./header.js"` (hoisted, evaluated before the page
|
|
script body calls initSharedHeader() at boot). -->
|
|
<!-- Phase 39: the brand layer — classic script, first on the page:
|
|
window.BOR_BRAND at parse time, refreshed from /api/config. -->
|
|
<script src="assets/brand.js"></script>
|
|
<script type="module" src="/assets/login.js"></script>
|
|
</body>
|
|
</html>
|