Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions apps/web/PRODUCT.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,8 +42,8 @@ workbench.

- Paired console (`services/core-console`): the administrator signs in with the
deployment's Core key, the administration credential the installer writes to
`admin/core.key` under the installation directory (by default
`~/.parsar/core/admin/core.key`; keeping and rotating it is described in
`secrets/core.key` under the installation directory (by default
`~/.parsar/core/secrets/core.key`; keeping and rotating it is described in
[Core key](../../docs/getting-started/operations.md#core-key)). There are no
console accounts or usernames. The browser sends the key only to sign in and
keeps only the session cookie; the console server holds the Core key and forwards
Expand Down
2 changes: 1 addition & 1 deletion apps/web/src/features/first-run/ConsoleAccess.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ import "./console-access.css";
* directory, and that file under the default installation directory. The
* sign-in help names both.
*/
const CORE_KEY_LOCATION = { file: "admin/core.key", defaultPath: "~/.parsar/core/admin/core.key" } as const;
const CORE_KEY_LOCATION = { file: "secrets/core.key", defaultPath: "~/.parsar/core/secrets/core.key" } as const;

const ConsoleAccountContext = createContext<{ logout: () => Promise<void> } | null>(null);
export const useConsoleAccount = () => useContext(ConsoleAccountContext);
Expand Down
4 changes: 2 additions & 2 deletions docs/web/core-connection.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ application's caller-managed `self_hosted` Runtime, including its own E2B setup.

The console exposes `GET /console/auth` and `POST /console/auth/login` and
`/logout`. The administrator signs in with the deployment's Core key, which the
installer writes to `admin/core.key` under the installation directory (by default
`~/.parsar/core/admin/core.key`; see [Core key](../getting-started/operations.md#core-key)).
installer writes to `secrets/core.key` under the installation directory (by default
`~/.parsar/core/secrets/core.key`; see [Core key](../getting-started/operations.md#core-key)).
The server compares it in constant time and answers with a same-origin session
cookie held only in its memory; the key is never logged or returned, and the
browser does not store it. A console restart or a Core key rotation requires
Expand Down