Document member dashboard (Steps 1-4 complete); add to components table

This commit is contained in:
inference-bot committed 2026-09-14 11:18:55 -06:00
1 parent cb55c8b2a9
commit 20e76b4edf
2 files changed
+11 -3

No files matched your search

+9 -2
View File
@@ -163,8 +163,15 @@ Member (browser) ──SSO──▶ Member Dashboard (new Cloudron app, "members
### Step 4 — Member dashboard (Phase 3)
- New Cloudron app in the "members" group (SSO-gated). Read-only (spend/keys/usage) + broker calls for create/revoke.
- **Gate:** a member logs in, sees only their own data, creates and revokes a key end-to-end, and the app holds no master key (verify via env inspection).
**COMPLETED (2026-09-14).** New Cloudron app `code/member-dashboard`, deployed at `dashboard.inference.coop`.
- **App**: FastAPI, `proxyAuth` SSO (identity via `X-Forwarded-User` header), holds NO privileged credentials.
- **Access**: restricted to the `members` group via `POST /apps/:id/configure/access_restriction` (same model as Loomio).
- **Calls the portal broker** (`GET/POST/DELETE /broker/*`) with `BROKER_SECRET`, scoped to the logged-in member's email.
- **UI**: brand-matched Monitor surface — balance vs. spend bar, API key list (create/revoke), self-contained (no external requests).
- **Verified**: `/api/usage` and create→list→revoke all work end-to-end against Dan's real team (balance $15, spend $0).
**Note:** proxyAuth header name (`X-Forwarded-User`) confirmed via Cloudron forum + source; verified empirically by exec'ing into the app. The app also accepts `X-Remote-User`/`X-Auth-Request-Email` fallbacks.
### Step 5 — Admin dashboard (Phase 4)