Prefill the demo's login and say on its home page that it's a simulation
Two demo-only affordances, both off by default everywhere else. The login form starts with the demo's read-only account already in both fields, so a visitor doesn't need credentials handed to them out of band. It's a build-time opt-in: the web image is built with VITE_DEMO_USERNAME/VITE_DEMO_PASSWORD, and the page prefills only when it has both, so a deployment that sets neither -- every deployment except the demo -- gets the ordinary empty form, and a half-configured one can't leave a password next to an empty username box. This does bake a password into a static bundle, which is fine for exactly this case and nothing else: a Viewer-role account on a deployment whose database is wiped and reseeded nightly. api.ts says so next to the export, so nobody later points these at an account that can do something. The home page then explains what a visitor is actually looking at -- synthetic data from a simulated fleet, a nightly reset that discards anything they change, and the features that are deliberately limited (read-only account, alerts that notify a placeholder webhook, no time-series charts). Gated on the same signal as the prefill rather than a second flag that could drift out of sync with it. Also carries the landing page's light/dark logo swap, which touches the same file.
This commit is contained in:
@@ -28,10 +28,18 @@ ARG VITE_ENTERPRISE_AUTH_BASE_URL
|
||||
# actually turned local auth on server-side too (LOCAL_AUTH_ENABLED).
|
||||
# See api.ts's requestFrom/alertingRequest doc comment.
|
||||
ARG VITE_LOCAL_AUTH_ENABLED=false
|
||||
# Both unset by default: the login page only prefills when it has both,
|
||||
# so every deployment that doesn't opt in gets an ordinary empty form.
|
||||
# See web/src/lib/api.ts's demoUsername on why a public demo can bake a
|
||||
# password in and nothing else should.
|
||||
ARG VITE_DEMO_USERNAME
|
||||
ARG VITE_DEMO_PASSWORD
|
||||
ENV VITE_API_BASE_URL=${VITE_API_BASE_URL}
|
||||
ENV VITE_ALERTING_API_BASE_URL=${VITE_ALERTING_API_BASE_URL}
|
||||
ENV VITE_ENTERPRISE_AUTH_BASE_URL=${VITE_ENTERPRISE_AUTH_BASE_URL}
|
||||
ENV VITE_LOCAL_AUTH_ENABLED=${VITE_LOCAL_AUTH_ENABLED}
|
||||
ENV VITE_DEMO_USERNAME=${VITE_DEMO_USERNAME}
|
||||
ENV VITE_DEMO_PASSWORD=${VITE_DEMO_PASSWORD}
|
||||
RUN npm run build
|
||||
|
||||
# Not distroless: serving a static SPA needs *some* HTTP server, and
|
||||
|
||||
Reference in New Issue
Block a user