- AuthGate replaces the raw token prompt: first-run setup form (creates
the admin) when no accounts exist, email/password sign-in with a
forgot-password flow, and a collapsible raw-API-token fallback for
legacy/script setups.
- /reset is a public page where invite and password-reset links land;
success stores the fresh session and enters the dashboard.
- Users section (admin-only nav): invite by email (link always shown,
emailed when SMTP is configured), admin/disable toggles, reset links,
and delete with the shared-resources handoff spelled out.
- Sidebar shows who is signed in; sign-out revokes the session
server-side.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019ws7xj5Ej623hh4GXQCYYR
The dashboard was a single route that swapped section components via a
`section` state field. Convert it to the App Router's multi-page model so
each left-nav selection is its own route (/, /repositories, /agents,
/schedules, /approvals, /servers, /activity, /shared, /login), making the
pages modular and independently updatable.
- Move the token gate + store provider + sidebar into a persistent frame
(AppFrame + Shell) rendered by the root layout, so auth, the polling
loop, and shared state survive client-side navigation.
- Sidebar items are now <Link> routes; the active item and the store's
polled section are derived from the URL (lib/nav).
- Each section gets an app/<section>/page.tsx; Runs stays at root and keeps
its full-height split layout, the rest render in the shared scroll frame.
- Emit per-route index.html (trailingSlash) so the FastAPI StaticFiles
mount serves clean slash-terminated URLs with no SPA rewrite.
- Regenerate the bundled static export.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PsAeGVadULRzPhV2PRDttM