// SPDX-License-Identifier: Apache-2.0 // Log in with the vault: the gateway types the password (and a TOTP code, if the entry has one) into the page. // Your code and your agent only ever name the entry; they never see a value. Then save the session to resume later. // // Setup, once (an admin stores the login; values can be written but never read back): // cbu vault set fixture # on the gateway host, or in the admin console (/admin), or: // new Admin().setVault("", "fixture", { username: "demo", password: "demo-password" }) // # (Admin reads WEBPILOT_URL and WEBPILOT_ADMIN_TOKEN) // // Run (with examples/fixture_site.py started): // export WEBPILOT_URL=http://localhost:8931 WEBPILOT_TOKEN=cbu_... // node vault_login.ts # site "fixture" at $WEBPILOT_FIXTURE/login // node vault_login.ts fixture http://host.docker.internal:8765/login import { WebPilot } from "webpilot-si"; const FIXTURE = process.env["WEBPILOT_FIXTURE"] ?? "http://host.docker.internal:8765"; const site = process.argv[2] ?? "fixture"; const loginUrl = process.argv[3] ?? `${FIXTURE}/login`; const wp = new WebPilot(); const entry = (await wp.vault()).find((e) => e.site === site); // names only: site, username, field names if (!entry) { console.error(`no vault entry ${JSON.stringify(site)}; ask an admin to store it (see the top of this file)`); process.exit(1); } console.log(`vault entry ${JSON.stringify(site)}: user ${JSON.stringify(entry.username)}, fields ${entry.fields.join(", ")}`); const tab = await wp.open(loginUrl, { mode: "act" }); // logging in is a write: it needs an act tab try { const result = await tab.login(site, { loginUrl }); console.log(`login: ${result.status} at ${result.url} (${result.message})`); if (result.status === "handoff_required" && result.handoff) { console.log("a person must finish this step (e.g. a code from their phone):", result.handoff.url); } else if (result.status === "logged_in") { const page = await tab.goto(loginUrl.replace(/\/[^/]*$/, "/account")); console.log(page.title, "-", (await tab.readText()).split(/\s+/).join(" ").slice(0, 120)); const saved = await tab.saveSession(site); // cookies and storage, encrypted on the gateway console.log(`saved session ${JSON.stringify(saved.name)}: ${saved.cookies} cookies for ${saved.host}`); // Later, in a fresh tab: (await wp.open(undefined, { mode: "act" })).loadSession(site) — no password needed. } } finally { await tab.close(); }