Skip to content

feat(onboarding): add one-shot bootstrap and first-run setup wizard - #293

Merged
nesquena-hermes merged 1 commit into
masterfrom
pr-285-final
Apr 12, 2026
Merged

feat(onboarding): add one-shot bootstrap and first-run setup wizard#293
nesquena-hermes merged 1 commit into
masterfrom
pr-285-final

Conversation

@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Adds a one-shot bootstrap launcher and a blocking first-run onboarding wizard that guides new users through the minimum Hermes setup entirely from the browser.

Original contribution: @gabogabucho (PR #285 — reviewed and hardened on pr-285-review)

What this adds

  • bootstrap.py — one-shot launcher: detects/installs hermes-agent, starts the WebUI, waits for health, opens the browser
  • api/onboarding.py — status endpoint, provider config persistence, completion flag
  • static/onboarding.js — 5-step wizard UI (system check → provider → workspace → password → finish)
  • static/i18n.js — onboarding copy in English + Spanish (68 keys each, full parity)
  • tests/test_onboarding_mvp.py + tests/test_onboarding_static.py — 14 new tests

Supported provider flows: OpenRouter, Anthropic, OpenAI, custom OpenAI-compatible.
OAuth/terminal-first flows (Nous Portal, Codex, Copilot) remain via hermes model.

Security hardening (applied during review)

  • /api/onboarding/setup restricted to loopback when auth is disabled
  • Newline injection guard in _write_env_file
  • esc() on all server-supplied values in innerHTML
  • Test isolation fix (send_key instead of bot_name in contamination test)
  • Skip markers for PyYAML-dependent tests in agent-less environments

Tests

693 passed, 0 failed (up from 679)

Closes #285

…285)

Adds a bootstrap launcher and a blocking first-run onboarding wizard that guides
new users through minimum Hermes setup from the browser UI.

Supported provider flows: OpenRouter, Anthropic, OpenAI, custom OpenAI-compatible.
OAuth/terminal-first flows remain via 'hermes model'.

Security hardening applied during review:
- /api/onboarding/setup restricted to loopback when auth disabled
- Newline injection guard in _write_env_file
- esc() on setup.unsupported_note in onboarding.js
- Test isolation fix (send_key instead of bot_name in contamination test)
- Skip markers for PyYAML-dependent tests in agent-less environments

Tests: 693 passed (up from 679)

Co-authored-by: gabogabucho <gabogabucho@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants