summaryrefslogtreecommitdiff
path: root/docs/DECISIONS.md
diff options
context:
space:
mode:
Diffstat (limited to 'docs/DECISIONS.md')
-rw-r--r--docs/DECISIONS.md14
1 files changed, 14 insertions, 0 deletions
diff --git a/docs/DECISIONS.md b/docs/DECISIONS.md
index c18f49b..e317758 100644
--- a/docs/DECISIONS.md
+++ b/docs/DECISIONS.md
@@ -275,6 +275,20 @@ kept verbatim from the STATE.md they were pruned from (2026-09-21).
the key parts of #11 and #28; `make check` rejects F-keys, `^N` and
`^Enter` in `clients/`.
+30. **Web frontend (2026-09-23)**: bokftui runs in the browser through
+ ttyd in its own container (`bokf-web`), behind a login gate in C
+ (`bokfweb`) that authenticates with bokfd's `session.open` — no second
+ password store — and one login: the gate hands the bokfd session to
+ the TUI through a terminal handle that only works with the login's
+ cookie. Caddy in the container does the routing and `forward_auth`;
+ TLS stays with the host's existing Caddy (port 443 was taken), which
+ proxies `bokf.makandra.eu` to `127.0.0.1:8790`. Every terminal is an
+ isolated process (private HOME, limits, `BOKF_WEB=1`: no local files or
+ programs). bokfd's login limiter became per user name (it was one
+ global counter, so any 5 wrong guesses locked out everybody) and the
+ gate limits per client address. Audience: the owner and Petter first,
+ prepared for more users.
+
## Completed work formerly listed under "Pending decisions"
- Attachments are complete: download (voucher detail `f`, Underlag `Enter`,