Prefill the demo's login and say on its home page that it's a simulation

Two demo-only affordances, both off by default everywhere else.

The login form starts with the demo's read-only account already in both
fields, so a visitor doesn't need credentials handed to them out of
band. It's a build-time opt-in: the web image is built with
VITE_DEMO_USERNAME/VITE_DEMO_PASSWORD, and the page prefills only when
it has both, so a deployment that sets neither -- every deployment
except the demo -- gets the ordinary empty form, and a half-configured
one can't leave a password next to an empty username box.

This does bake a password into a static bundle, which is fine for
exactly this case and nothing else: a Viewer-role account on a
deployment whose database is wiped and reseeded nightly. api.ts says so
next to the export, so nobody later points these at an account that can
do something.

The home page then explains what a visitor is actually looking at --
synthetic data from a simulated fleet, a nightly reset that discards
anything they change, and the features that are deliberately limited
(read-only account, alerts that notify a placeholder webhook, no
time-series charts). Gated on the same signal as the prefill rather than
a second flag that could drift out of sync with it.

Also carries the landing page's light/dark logo swap, which touches the
same file.
This commit is contained in:
2026-08-22 16:13:10 -07:00
parent bcb9a01cd6
commit 04e83f64a9
5 changed files with 186 additions and 4 deletions
+8
View File
@@ -28,10 +28,18 @@ ARG VITE_ENTERPRISE_AUTH_BASE_URL
# actually turned local auth on server-side too (LOCAL_AUTH_ENABLED).
# See api.ts's requestFrom/alertingRequest doc comment.
ARG VITE_LOCAL_AUTH_ENABLED=false
# Both unset by default: the login page only prefills when it has both,
# so every deployment that doesn't opt in gets an ordinary empty form.
# See web/src/lib/api.ts's demoUsername on why a public demo can bake a
# password in and nothing else should.
ARG VITE_DEMO_USERNAME
ARG VITE_DEMO_PASSWORD
ENV VITE_API_BASE_URL=${VITE_API_BASE_URL}
ENV VITE_ALERTING_API_BASE_URL=${VITE_ALERTING_API_BASE_URL}
ENV VITE_ENTERPRISE_AUTH_BASE_URL=${VITE_ENTERPRISE_AUTH_BASE_URL}
ENV VITE_LOCAL_AUTH_ENABLED=${VITE_LOCAL_AUTH_ENABLED}
ENV VITE_DEMO_USERNAME=${VITE_DEMO_USERNAME}
ENV VITE_DEMO_PASSWORD=${VITE_DEMO_PASSWORD}
RUN npm run build
# Not distroless: serving a static SPA needs *some* HTTP server, and