Skip to content

v0.9.0

Choose a tag to compare

@1broseidon 1broseidon released this 21 Sep 20:10
· 33 commits to main since this release

Hotline Computer 0.9.0 asks the person before a passkey is made.

  • While the desk has armed the computer for a site, a call to navigator.credentials.create() in the managed browser is no longer answered by the browser on its own. A guard in every document of every tab that carries passkeys parks the call and keeps what the site asked for: the site, the origin, the account's name and display name. GET /passkeys/registration then answers asked with that ask (id, rpId, origin, rpName, userName, userDisplayName, askedAt) for the desk to put before the person.
  • POST /passkeys/registration/answer {"id": …, "approved": true|false} carries the person's answer back. Approved, the page is told to go ahead, the tab's virtual authenticator mints, and GET answers approved and then registered with the minted credential as before. Denied, the site gets a NotAllowedError, as it would from a person cancelling the browser's own prompt, and the arming ends with the denial, so neither a site nor a teammate can keep asking. An answer to a request that is not waiting is a 409.
  • The guard holds one request before the person at a time, and rejects create() for any other site, or with none armed, with a NotAllowedError that says so. An approved request that the page never carries through to a credential makes way for the next after 30 s.
  • An arming on a fresh browser is kept when the armed site does not open. The courtesy visit to https://<rpId>/ is logged when it fails instead of refusing the arming with a 503, which it did for a site that only exists inside the container.

Hotline desk 0.17.0 is the first that shows the request as a card on the teammate's tape, with Approve and Deny, and carries the answer back; a desk on 0.16.x arms this computer and finds the registration waiting in asked, which it does not answer, so pair it with 0.17.0 to make passkeys. A 0.17.0 desk on a 0.8.x computer still mints without asking. Existing computers retain their running version until updated from the teammate's pane; state info and state guide identify the attached computer.

Validation: native ARM64/x86_64 release gates passed all 22 scenarios per architecture, the image contract (now including the ask, approve and deny passes), restart plus recreate recovery on the same home and store volumes, image-identity checks, and cold pulls.

Cold registry pulls: 16.22 s ARM64 / 21.53 s x86_64. Downloaded-image start-to-health: 0.290 s / 0.486 s. Compressed layers: 425,188,702 / 425,047,451 bytes. The combined image digest is sha256:1618f34e20c78a27b8a0208a3ad471a2cb23b5b97ed63332202f9568e5ca0b3e.

Use ghcr.io/1broseidon/hotline-computer:0.9.0.