From cfc91e0a424163869c64d30e55d55a53f18a3dbf Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Tue, 1 Sep 2026 14:08:32 +0200 Subject: refactor(node): JSON-only control API, Node page absorbs the admin dashboard Remove the node daemon's server-rendered admin UI (GET / and /audit, the _render_* helpers and inline templates) and the `meshbay-node ui` CLI verb. The loopback control API stays; it is now JSON only, ruff-clean, and 453 lines (was 1074). Also drop three never-wired endpoints (/api/config, /api/chat/history, /ws/chat, plus broadcast_chat) and the pointless 18000/tcp firewall profiles. The desktop client's Node page (static/node-page.js) takes over what the dashboard showed, reorganised into six tabs (Overview, Groups, Roster, Peers, Audit, Settings): - Overview: version, node id, QUIC port, hub, index-cache maintenance - Roster: node-wide view with unpin - Peers and Audit: auto-load on open, no Load button - Audit: real usernames and group names (resolved from the roster and node.toml), Previous/Next pagination newest-first, Export CSV of every matching row - Settings: node settings, STUN, ICE, denylist, then Unlink from hub Backend: audit.get_entries gains `offset`; /api/audit and /api/peers resolve ids to names via a new _display_names helper; CSP tightened to default-src 'none' now that no HTML is served. draft-v6 sections 2.11 and 2.12 corrected -- the Node page uses the loopback API, not MNP. One capability is intentionally dropped: browser-based admin on a headless server. The CLI covers every operation there. See docs/refactor-node-ui.md. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01MQCaZnde4Bjjdu84dhSuF5 --- docs/PACKAGING-GUIDE.md | 15 +++------------ 1 file changed, 3 insertions(+), 12 deletions(-) (limited to 'docs/PACKAGING-GUIDE.md') diff --git a/docs/PACKAGING-GUIDE.md b/docs/PACKAGING-GUIDE.md index bb3a3bd..0f9997d 100644 --- a/docs/PACKAGING-GUIDE.md +++ b/docs/PACKAGING-GUIDE.md @@ -157,18 +157,9 @@ sudo firewall-cmd --reload sudo ufw allow "MeshBay Cast" ``` -### Node admin UI - -Opens TCP 18000. - -```bash -# Fedora (firewalld) -sudo firewall-cmd --permanent --add-service=meshbay-node -sudo firewall-cmd --reload - -# Ubuntu (ufw) -sudo ufw allow "MeshBay Node" -``` +The node's own administration surface is a loopback API (127.0.0.1 only, +per-run token) reached by the CLI and the desktop client's Node page. It is +never network-exposed and ships no firewall profile. --- -- cgit v1.2.3