feat(onboarding): add one-shot bootstrap and first-run setup wizard - #293
Merged
Conversation
…285) Adds a bootstrap launcher and a blocking first-run onboarding wizard that guides new users through minimum Hermes setup from the browser UI. Supported provider flows: OpenRouter, Anthropic, OpenAI, custom OpenAI-compatible. OAuth/terminal-first flows remain via 'hermes model'. Security hardening applied during review: - /api/onboarding/setup restricted to loopback when auth disabled - Newline injection guard in _write_env_file - esc() on setup.unsupported_note in onboarding.js - Test isolation fix (send_key instead of bot_name in contamination test) - Skip markers for PyYAML-dependent tests in agent-less environments Tests: 693 passed (up from 679) Co-authored-by: gabogabucho <gabogabucho@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a one-shot bootstrap launcher and a blocking first-run onboarding wizard that guides new users through the minimum Hermes setup entirely from the browser.
Original contribution: @gabogabucho (PR #285 — reviewed and hardened on
pr-285-review)What this adds
bootstrap.py— one-shot launcher: detects/installs hermes-agent, starts the WebUI, waits for health, opens the browserapi/onboarding.py— status endpoint, provider config persistence, completion flagstatic/onboarding.js— 5-step wizard UI (system check → provider → workspace → password → finish)static/i18n.js— onboarding copy in English + Spanish (68 keys each, full parity)tests/test_onboarding_mvp.py+tests/test_onboarding_static.py— 14 new testsSupported provider flows: OpenRouter, Anthropic, OpenAI, custom OpenAI-compatible.
OAuth/terminal-first flows (Nous Portal, Codex, Copilot) remain via
hermes model.Security hardening (applied during review)
/api/onboarding/setuprestricted to loopback when auth is disabled_write_env_fileesc()on all server-supplied values ininnerHTMLTests
693 passed, 0 failed (up from 679)
Closes #285