Hotline Computer 0.8.0
Hotline Computer 0.8.0 types a login by name on the login's own sites and makes a passkey that is the teammate's own.
PUT /secretstakes three kinds of secret. A bare string is a variable, as in 0.7.0, so a desk on 0.15.x keeps working unchanged. An object tagged"kind": "login"carriessites,username,passwordand, when the site asks for six digits, a TOTP seed. An object tagged"kind": "passkey"carriesrpId,credentialId, the private key and the user handle and names. The set is replaced whole each time and lives in the service's memory and nowhere else; one entry the computer cannot keep refuses the whole set with a 400 that names it.browser filltakessecretin place oftext:NAMEfor a variable,NAME.username,NAME.passwordorNAME.code— the six RFC 6238 digits of this moment, computed here from the seed — for a login. A login is typed only when the page's origin is one of the login's sites: same scheme and port, same host or a subdomain of one, and a site ishttps://unless it is localhost. Any other page is refused with a sentence that names the rule. The answer says which field was filled and with which name; the password, the digits and a private key are replaced with[redacted NAME.password],[redacted NAME.totp]and[redacted NAME.privateKey]in every tool answer. Usernames and sites are not secrets and are not redacted.- A passkey is the teammate's own, because a person's never leaves their authenticator. Every granted passkey is loaded into a WebAuthn virtual authenticator on each browser tab, from the delivered set at every start and change, so a site's
navigator.credentials.get()is answered inside Chromium and nothing is typed. - Making one is the desk's act.
PUT /passkeys/registration {"rpId"}arms this computer for one site for ten minutes and readies the browser; while armed, and only on that site,navigator.credentials.create()may mint one credential. A guard script on every document gates creation behind a token the page cannot read, and the service's own check on every look removes any credential that is neither delivered nor minted under the current arming, so the teammate cannot give itself a passkey, keep one made for another site, or keep one past the ten minutes.GET /passkeys/registrationanswersidle,armed, orregisteredwith the minted credential as a whole passkey record;DELETEends the arming. Bearer-only, like/secrets. state infolists the stored secrets by name and kind, and the skill tells the agent how each kind is used and that it will never see a value.
Hotline desk 0.16.0 is the first that stores logins, arms a passkey and grants either; a desk on 0.15.x drives this computer as before and grants variables alone. Existing computers retain their running version until updated from the teammate's pane; state info and state guide identify the attached computer.
Validation: native ARM64/x86_64 release gates passed all 22 scenarios per architecture, the image contract (now including the login and passkey pass), restart plus recreate recovery on the same home and store volumes, image-identity checks, and cold pulls.
Cold registry pulls: 18.63 s ARM64 / 20.84 s x86_64. Downloaded-image start-to-health: 0.358 s / 0.879 s. Compressed layers: 425,050,395 / 424,904,919 bytes. The combined image digest is sha256:0c5e0e60c087b534a7eb08d1ef54e7ecb56a90971ad41ce0da69668f442e7431.
Use ghcr.io/1broseidon/hotline-computer:0.8.0.