Pre-launch — Gluecron is in final validation. Public signups and git hosting for non-owner users open after launch review.
CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
claude/adoring-hopper-5x74bqclaude/affectionate-feynman-ykrf1hclaude/architecture-audit-design-wxprenclaude/build-status-update-3MXsfclaude/charming-meitner-mllb5rclaude/compare-gate-gluecron-s4mFQclaude/confident-faraday-tikcwbclaude/continue-work-XMTlIclaude/crontech-gluecron-deploy-7MIECclaude/crontech-platform-setup-SeKfwclaude/design-2026claude/ecstatic-ptolemy-jMdigclaude/enhance-github-integration-QNHdGclaude/fix-aa-loop-issue-PonMQclaude/fix-actions-and-processclaude/fix-desktop-errors-XqoW8claude/fix-red-workflowsclaude/fix-website-access-6FKJNclaude/gatetest-integration-hardeningclaude/github-audit-improvements-bDFr9claude/gluecron-launch-status-FoMRlclaude/hopeful-lamport-olfCTclaude/issue-to-pr-and-protectionsclaude/jolly-heisenberg-2sg1Qclaude/launch-preparation-QmTb6claude/new-session-xk1l7claude/plan-platform-architecture-kkN4yclaude/platform-analysis-roadmap-1nUGLclaude/platform-launch-assessment-8dWV8claude/polish-platform-release-AeDrUclaude/resume-previous-work-KzyLwclaude/review-crontech-handoff-qYEVqclaude/review-project-completeness-lHhS2claude/review-readme-docs-ulqPKclaude/serene-edison-rj87weclaude/setup-multi-repo-dev-BCwNQclaude/ship-fixes-and-tests-Jvz1cclaude/site-audit-competitive-pctlwgclaude/site-migration-vercel-XstpKclaude/standalone-product-repos-XHFTDcopilot/feat-smart-empty-states-keyboard-first-enhancementcopilot/feat-smart-morning-digest-review-context-restorecopilot/fix-and-process-workflowscopilot/update-ai-powered-code-reviewfeat/debt-mapfeat/push-policy-codeowners-hardeningfeat/smart-digest-contextfeat/stage-impactfeat/t1-secret-migrationfeat/u-polishfeat/w-self-hostfeat/w2-claude-configfix/agent-journey-orphan-sweepgatetest/auto-fix-1776586424172gatetest/auto-fix-1776586534814gatetest/auto-fix-1776590685143gatetest/auto-fix-1776590808199mainops/redeploy-retriggerstyle/dxt-cta-themeworktree-agent-a3377aad30d55da26worktree-agent-a7ef607b7ee1d6c74
signing-keys.tsx6.6 KB · 209 lines
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
/**
 * Block J3 — Signing keys UI.
 *
 *   GET  /settings/signing-keys        — list + add form
 *   POST /settings/signing-keys        — add new key
 *   POST /settings/signing-keys/:id/delete
 */

import { Hono } from "hono";
import { Layout } from "../views/layout";
import type { AuthEnv } from "../middleware/auth";
import { requireAuth } from "../middleware/auth";
import {
  addSigningKey,
  deleteSigningKey,
  listSigningKeysForUser,
} from "../lib/signatures";
import { audit } from "../lib/notify";

const signingKeysRoutes = new Hono<AuthEnv>();
signingKeysRoutes.use("/settings/signing-keys", requireAuth);
signingKeysRoutes.use("/settings/signing-keys/*", requireAuth);

signingKeysRoutes.get("/settings/signing-keys", async (c) => {
  const user = c.get("user")!;
  const keys = await listSigningKeysForUser(user.id);
  const message = c.req.query("message");
  const error = c.req.query("error");
  return c.html(
    <Layout title="Signing keys" user={user}>
      <div class="settings-container">
        <h2>Signing keys</h2>
        <p style="color:var(--text-muted)">
          Register the GPG or SSH public key you use for{" "}
          <code>git commit -S</code>. Commits we can match to a registered key
          render with a <span style="color:var(--green);font-weight:600">Verified</span>{" "}
          badge. This is identity matching by fingerprint — cryptographic
          verification is future work.
        </p>
        {message && (
          <div class="auth-success" style="margin-top:12px">
            {decodeURIComponent(message)}
          </div>
        )}
        {error && (
          <div class="auth-error" style="margin-top:12px">
            {decodeURIComponent(error)}
          </div>
        )}

        <h3 style="margin-top:24px">Your keys</h3>
        {keys.length === 0 ? (
          <div class="panel-empty" style="padding:16px">
            No signing keys yet.
          </div>
        ) : (
          <div class="panel">
            {keys.map((k) => (
              <div
                class="panel-item"
                style="flex-direction:column;align-items:stretch;gap:4px"
              >
                <div style="display:flex;justify-content:space-between;gap:12px;flex-wrap:wrap">
                  <div>
                    <span
                      style="font-size:10px;padding:2px 6px;border-radius:3px;background:var(--bg-subtle);text-transform:uppercase;margin-right:6px"
                    >
                      {k.keyType}
                    </span>
                    <span style="font-weight:600">{k.title}</span>
                    {k.email && (
                      <span
                        style="font-size:12px;color:var(--text-muted);margin-left:8px"
                      >
                        {k.email}
                      </span>
                    )}
                  </div>
                  <form
                    method="POST"
                    action={`/settings/signing-keys/${k.id}/delete`}
                  >
                    <button
                      type="submit"
                      class="btn btn-sm"
                      style="font-size:11px"
                    >
                      Delete
                    </button>
                  </form>
                </div>
                <div
                  style="font-family:var(--font-mono);font-size:11px;color:var(--text-muted);word-break:break-all"
                >
                  {k.fingerprint}
                </div>
              </div>
            ))}
          </div>
        )}

        <h3 style="margin-top:24px">Add a key</h3>
        <form
          method="POST"
          action="/settings/signing-keys"
          class="auth-form"
          style="max-width:720px"
        >
          <div class="form-group">
            <label for="sk-title">Title</label>
            <input
              type="text"
              id="sk-title"
              name="title"
              placeholder="e.g. Work laptop"
              required
              maxLength={120}
            />
          </div>
          <div class="form-group">
            <label for="sk-type">Key type</label>
            <select id="sk-type" name="key_type" required>
              <option value="gpg">GPG</option>
              <option value="ssh">SSH</option>
            </select>
          </div>
          <div class="form-group">
            <label for="sk-email">Email (optional)</label>
            <input
              type="email"
              id="sk-email"
              name="email"
              placeholder="commit-author@example.com"
              maxLength={200}
            />
          </div>
          <div class="form-group">
            <label for="sk-public">Public key</label>
            <textarea
              id="sk-public"
              name="public_key"
              rows={10}
              required
              placeholder="-----BEGIN PGP PUBLIC KEY BLOCK-----&#10;...&#10;-----END PGP PUBLIC KEY BLOCK-----&#10;&#10;or: ssh-ed25519 AAAA... you@laptop"
              style="font-family:var(--font-mono);font-size:12px"
            />
          </div>
          <button type="submit" class="btn btn-primary">
            Add key
          </button>
        </form>
      </div>
    </Layout>
  );
});

signingKeysRoutes.post("/settings/signing-keys", async (c) => {
  const user = c.get("user")!;
  const body = await c.req.parseBody();
  const keyType = String(body.key_type || "").toLowerCase() as "gpg" | "ssh";
  const title = String(body.title || "");
  const publicKey = String(body.public_key || "");
  const email = String(body.email || "");

  const result = await addSigningKey({
    userId: user.id,
    keyType,
    title,
    publicKey,
    email,
  });

  if (!result.ok) {
    return c.redirect(
      `/settings/signing-keys?error=${encodeURIComponent(result.error)}`
    );
  }
  await audit({
    userId: user.id,
    action: "signing_keys.add",
    targetId: result.id,
    metadata: { keyType, fingerprint: result.fingerprint },
  });
  return c.redirect(
    `/settings/signing-keys?message=${encodeURIComponent(
      `Added key ${result.fingerprint.slice(0, 24)}…`
    )}`
  );
});

signingKeysRoutes.post("/settings/signing-keys/:id/delete", async (c) => {
  const user = c.get("user")!;
  const id = c.req.param("id");
  const ok = await deleteSigningKey(id, user.id);
  if (ok) {
    await audit({
      userId: user.id,
      action: "signing_keys.delete",
      targetId: id,
    });
  }
  return c.redirect(
    `/settings/signing-keys?${ok ? "message" : "error"}=${encodeURIComponent(
      ok ? "Key removed." : "Key not found"
    )}`
  );
});

export default signingKeysRoutes;