# SPDX-License-Identifier: Apache-2.0 """Log in with the vault: the gateway types the password (and a TOTP code, if the entry has one) into the page. Your code and your agent only ever name the entry; they never see a value. Then save the session to resume later. Setup, once (an admin stores the login; values can be written but never read back): cbu vault set fixture # on the gateway host, or in the admin console (/admin), or: python -c "from webpilot import Admin; Admin().set_vault('', 'fixture', username='demo', password='demo-password')" # (Admin() reads WEBPILOT_URL and WEBPILOT_ADMIN_TOKEN) Run (with examples/fixture_site.py started): export WEBPILOT_URL=http://localhost:8931 WEBPILOT_TOKEN=cbu_... python examples/python/vault_login.py # site "fixture" at $WEBPILOT_FIXTURE/login python examples/python/vault_login.py fixture http://host.docker.internal:8765/login """ from __future__ import annotations import os import sys from webpilot import WebPilot FIXTURE = os.environ.get("WEBPILOT_FIXTURE", "http://host.docker.internal:8765") site = sys.argv[1] if len(sys.argv) > 1 else "fixture" login_url = sys.argv[2] if len(sys.argv) > 2 else f"{FIXTURE}/login" with WebPilot() as wp: entries = {e.site: e for e in wp.vault()} # names only: site, username, field names if site not in entries: sys.exit(f"no vault entry {site!r}; ask an admin to store it (see the top of this file)") print(f"vault entry {site!r}: user {entries[site].username!r}, fields {entries[site].fields}") tab = wp.open(login_url, mode="act") # logging in is a write: it needs an act tab try: result = tab.login(site, login_url=login_url) print(f"login: {result.status} at {result.url} ({result.message})") if result.status == "handoff_required" and result.handoff: print("a person must finish this step (e.g. a code from their phone):", result.handoff.url) elif result.status == "logged_in": page = tab.goto(login_url.rsplit("/", 1)[0] + "/account") print(page.title, "-", " ".join(tab.read_text().split())[:120]) saved = tab.save_session(site) # cookies and storage, encrypted on the gateway print(f"saved session {saved.name!r}: {saved.cookies} cookies for {saved.host}") # Later, in a fresh tab: wp.open(mode="act").load_session(site) — no password needed. finally: tab.close()