From 6b6025af16b04ab59406e9f59a619ac23c5f66a0 Mon Sep 17 00:00:00 2001 From: Ivo Oskamp Date: Fri, 19 Jun 2026 13:51:33 +0200 Subject: [PATCH] Dev build 2026-06-19 13:51 --- containers/clearview/site/app.js | 48 +++++++++++++ containers/clearview/site/index.html | 20 +++++- .../src/clearview_app/api_onboarding.py | 30 +++++--- .../src/clearview_app/api_settings.py | 43 +++++++++++ .../clearview/src/clearview_app/config.py | 5 +- .../clearview/src/clearview_app/main.py | 2 + .../migrations/versions/0004_app_settings.py | 37 ++++++++++ .../clearview/src/clearview_app/models.py | 17 +++++ .../clearview/src/clearview_app/onboarding.py | 42 ++++++----- .../clearview/src/clearview_app/schemas.py | 16 +++++ .../src/clearview_app/settings_service.py | 71 +++++++++++++++++++ .../clearview/src/clearview_app/version.py | 2 +- docs/changelog-develop.md | 13 ++++ 13 files changed, 312 insertions(+), 34 deletions(-) create mode 100644 containers/clearview/src/clearview_app/api_settings.py create mode 100644 containers/clearview/src/clearview_app/migrations/versions/0004_app_settings.py create mode 100644 containers/clearview/src/clearview_app/settings_service.py diff --git a/containers/clearview/site/app.js b/containers/clearview/site/app.js index 7e5d9d5..aeb4901 100644 --- a/containers/clearview/site/app.js +++ b/containers/clearview/site/app.js @@ -1871,9 +1871,57 @@ function renderUserBadge(me) { reloadUsersTable().catch(function (err) { console.error('users reload failed', err); }); } else if (sub === 'audit') { reloadAuditTable().catch(function (err) { console.error('audit reload failed', err); }); + } else if (sub === 'general') { + wireOnboardingSettingsOnce(); + loadOnboardingSettings().catch(function (err) { console.error('onboarding settings load failed', err); }); } } + let _onboardingSettingsWired = false; + + function wireOnboardingSettingsOnce() { + if (_onboardingSettingsWired) return; + const form = document.getElementById('onboardingSettingsForm'); + if (!form) return; + _onboardingSettingsWired = true; + form.addEventListener('submit', async function (ev) { + ev.preventDefault(); + const statusEl = document.getElementById('onboardingSettingsStatus'); + const fd = new FormData(form); + const body = { + client_id: (fd.get('client_id') || '').trim(), + redirect_uri: (fd.get('redirect_uri') || '').trim(), + }; + const secret = (fd.get('client_secret') || '').trim(); + // Blank secret = keep the stored one (write-only field). + if (secret) body.client_secret = secret; + try { + await requestJson('/api/settings/onboarding', { + method: 'PUT', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify(body), + }); + if (statusEl) statusEl.textContent = 'Saved.'; + await loadOnboardingSettings(); + } catch (err) { + if (statusEl) statusEl.textContent = 'Save failed: ' + err.message; + } + }); + } + + async function loadOnboardingSettings() { + const form = document.getElementById('onboardingSettingsForm'); + if (!form) return; + const user = window.__clearviewUser; + if (!user || user.role !== 'admin') return; // endpoint is admin-only + const data = await requestJson('/api/settings/onboarding'); + form.querySelector('[name="client_id"]').value = data.client_id || ''; + form.querySelector('[name="redirect_uri"]').value = data.redirect_uri || ''; + const secretInput = form.querySelector('[name="client_secret"]'); + secretInput.value = ''; + secretInput.placeholder = data.client_secret_set ? '•••••••• (leave blank to keep)' : 'Not set'; + } + function navigateTo(route) { var hash; if (route === 'scan-sharepoint') hash = '#/scan/sharepoint'; diff --git a/containers/clearview/site/index.html b/containers/clearview/site/index.html index d3c37cc..ff3bc89 100644 --- a/containers/clearview/site/index.html +++ b/containers/clearview/site/index.html @@ -583,7 +583,25 @@
-

Runtime configuration is currently controlled via environment variables in stack/.env. See the TECHNICAL.md document for the full list (timeouts, retries, scan caps, onboarding).

+
+

Microsoft onboarding

+

Credentials for the Microsoft admin-consent / scan-app onboarding flow. Stored in the database.

+
+ + + +
+ + +
+
+