The wasm bundle ships no auth code: the daemon proxies the device-login flow over /api/auth/* using the same prebuilt op-auth library and the same ~/.openpencil/auth credential store as the desktop GUI, so a session started in either host signs both in. The web shell opens the verification page in a popup, polls flow progress into the shared login modal, and re-checks session health every 30s. The proxy refuses non-loopback binds outside managed mode — the daemon session belongs to its owner, not to whoever can reach the port. |
||
|---|---|---|
| .. | ||
| assets | ||
| examples | ||
| notes | ||
| src | ||
| tests | ||
| Cargo.toml | ||