fix(shell): daemon-start and health-poll auth handling; policy panel freshness
Some checks failed
Security / Security check (push) Failing after 2s

Review follow-ups on the auth-status work:

- Both daemon-start paths classified an auth-rejected hub as "daemon
  dead" via healthy() and showed a start-failure dialog while the
  shell banner above correctly blamed the token. They now share
  daemonAnswers(): only an unreachable probe counts as down.
- An auth-rejected poll now re-reads ~/.chain/hub-auth-token and
  reconnects when the file changed, so a token fixed outside Studio
  (CLI, editor) heals the connection without a restart — previously
  the client kept the stale in-memory token forever and the banner's
  own advice could not work.
- An endpoint switch resets the failure streak, so a stale in-flight
  probe can no longer let the unreachable banner blame the new
  endpoint for the old one's misses.
- The auth-policy panel re-queries when the hub token is saved or
  cleared in the panel above (reloadTick), instead of keeping a
  stale admin-denied hint; it also renders the hub's new
  reload_required flag as a pending-reload warning (DE+EN).
- today-pipeline.md still documented ~/.fai/today after the rename;
  the FAB theme comment now states the both-themes intent.

flutter analyze clean; 71 tests green including four new ones.

Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
This commit is contained in:
flemming-it 2026-07-15 05:50:24 +02:00
parent 2a1cbc82c3
commit 7cc8bab9b9
13 changed files with 242 additions and 16 deletions

View file

@ -23,7 +23,18 @@ class HubAuthPolicyPanel extends StatefulWidget {
@visibleForTesting
final Future<int> Function()? reloader;
const HubAuthPolicyPanel({super.key, this.loader, this.reloader});
/// Bumped by the parent whenever an adjacent action changed the
/// connection's auth state (token saved or cleared in the panel
/// above) the policy view reloads instead of showing a stale
/// "store an admin token" hint next to the just-stored token.
final int reloadTick;
const HubAuthPolicyPanel({
super.key,
this.loader,
this.reloader,
this.reloadTick = 0,
});
@override
State<HubAuthPolicyPanel> createState() => _HubAuthPolicyPanelState();
@ -42,6 +53,14 @@ class _HubAuthPolicyPanelState extends State<HubAuthPolicyPanel> {
_load();
}
@override
void didUpdateWidget(covariant HubAuthPolicyPanel oldWidget) {
super.didUpdateWidget(oldWidget);
if (widget.reloadTick != oldWidget.reloadTick) {
_load();
}
}
Future<void> _load() async {
setState(() {
_loading = true;
@ -193,6 +212,15 @@ class _HubAuthPolicyPanelState extends State<HubAuthPolicyPanel> {
color: theme.colorScheme.tertiary,
),
],
if (p.reloadRequired) ...[
const SizedBox(height: ChainSpace.xs),
_hintRow(
theme,
Icons.sync_problem_outlined,
l.authPolicyReloadRequired,
color: theme.colorScheme.tertiary,
),
],
if (p.tokens.isNotEmpty) ...[
const SizedBox(height: ChainSpace.sm),
for (final t in p.tokens) _tokenRow(theme, l, t),