Files
truf-server/openspec/changes/simplify-dashboard/proposal.md
T
2026-09-30 20:30:56 +03:00

30 lines
1.7 KiB
Markdown

## Why
The existing six-page dashboard mixes PostgreSQL authority with retired compatibility files, producing contradictory queue counts and incomplete time-window statistics. Operators need one fast, obvious view that answers the same questions as the current manual status checks and can locate a finding without exposing raw credentials.
## What Changes
- Replace the visible multi-page dashboard with one PostgreSQL-authoritative observability page.
- Add accurate preset and custom time windows applied in SQL before aggregation or row limits.
- Show scanner activity, findings, errors, new and current alive credentials, queue state, and compact runtime health in one view.
- Add unified lookup by pasted credential, SHA-256 identity, finding ID/UID, target, path, commit, or other redacted metadata.
- Hash credential-like lookup input immediately and never query or render raw secret columns.
- Remove legacy queue-file, global runner-state, TSV-gated, log-browsing, and advanced/debug panels from the visible interface.
- Keep the dashboard read-only, loopback-only, and supervisor-managed.
## Capabilities
### New Capabilities
- `single-page-observability`: Accurate time-window scanner statistics, current runtime state, alive credential summaries, and safe finding lookup on one page.
### Modified Capabilities
None.
## Impact
- Primary implementation: `app/dashboard.py`.
- Focused behavior and security coverage: `tests/test_dashboard_behavior.py` and `tests/test_dashboard_secret_guard.py`.
- PostgreSQL remains authoritative; no database migration, mutation endpoint, new service, or external API is introduced.
- Existing supervisor lifecycle and disabled-by-default startup policy remain unchanged.