Implement WP-0009-T04: Control Plane interactive UI on whynot-design

Builds the Control Plane's browser UI (login, dashboard, Phase
registration, Development Credit entry/proposal/review, credential
admin, audit log) as a FastAPI + Jinja2 app over the already-finished
T03 backend, rather than from scratch — whynot-design's Lit web
components are vendored as static assets (source commit 4b62cffc,
v0.4.1), with lit itself resolved via an esm.sh CDN import map.

Session auth re-checks the credential token against the database on
every request rather than trusting the session cookie's cached rights,
so a mid-session revocation takes effect immediately.

9 new Docker-gated HTTP-level tests via FastAPI's TestClient (no
browser-automation tool available, so real rendering of the <wn-*>
components was never visually verified). All four WP-0009 tasks are
now done; workplan marked finished.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-30 15:43:16 +02:00
parent 5fbae0df02
commit c89b4aa4a5
24 changed files with 3486 additions and 3 deletions

View file

@ -0,0 +1,38 @@
{% extends "base.html" %}
{% block title %}Credentials — Target Revenue Control Plane{% endblock %}
{% block content %}
<wn-page-header>
<span slot="title">Manage credentials (Admin)</span>
</wn-page-header>
{% if new_token %}
<wn-banner variant="warning">
New credential issued for <strong>{{ new_token_label }}</strong>. Copy it now —
it will not be shown again: <code>{{ new_token }}</code>
</wn-banner>
{% endif %}
<h3>Issue a new credential</h3>
<form class="wn-form" method="post" action="/admin/credentials">
<wn-field-row label="Credential label (human name)">
<wn-input name="credential_label" required></wn-input>
</wn-field-row>
<wn-field-row label="Rights">
<wn-select name="rights">
<option value="viewer">viewer</option>
<option value="contributor">contributor</option>
<option value="operator">operator</option>
<option value="admin">admin</option>
</wn-select>
</wn-field-row>
<wn-button type="submit" variant="primary">Issue credential</wn-button>
</form>
<h3>Revoke a credential</h3>
<form class="wn-form" method="post" action="/admin/credentials/revoke">
<wn-field-row label="Token to revoke">
<wn-input name="token" required></wn-input>
</wn-field-row>
<wn-button type="submit" variant="secondary">Revoke</wn-button>
</form>
{% endblock %}