hermes-agent/website
Ben 1443be72f7 docs(dashboard-auth): remove legacy session-token references
Sweeps user-facing docs (English + zh-Hans mirrors) to the new auth model
now that the legacy dashboard session token is gone:
- loopback bind: no identity gate (the bind is the boundary) + a
  Sec-Fetch-Site CSRF guard on mutating requests + localhost-only CORS
- gated (non-loopback) bind: pluggable OAuth/basic-auth provider; REST via
  session cookie, WS via single-use ?ticket=

Files:
- configuring-models.md: drop the X-Hermes-Session-Token header from the
  /api/model/* curl examples; replace the window.__HERMES_SESSION_TOKEN__
  'grab it from devtools' note with the no-loopback-auth / gated-cookie model
- features/kanban.md: kanban routes + WS no longer described as token-gated
  (loopback none; gated cookie + ?ticket=)
- features/web-dashboard.md: /api/pty WS auth reworded; the Security warning
  now names the loopback-bind boundary + CSRF guard + CORS instead of 'no
  authentication of its own', linking the gated auth section
- features/extending-the-dashboard.md: plugin routes 'require no identity
  auth on a loopback bind' (kept the --host 0.0.0.0 / untrusted-plugin warning)
- zh-Hans mirrors of all four

Left untouched (verified NOT the legacy token): HERMES_DASHBOARD_BASIC_AUTH_SECRET
(basic provider cookies), the basic-auth 'asks for a session token' login hint,
desktop i18n remote-gateway token strings (remote 'token' mode kept), faq /usage,
homeassistant session tokens.

Co-authored-by: Hermes subagent <noreply@nousresearch.com>
2026-06-17 10:03:13 +10:00
..
docs docs(dashboard-auth): remove legacy session-token references 2026-06-17 10:03:13 +10:00
i18n/zh-Hans/docusaurus-plugin-content-docs/current docs(dashboard-auth): remove legacy session-token references 2026-06-17 10:03:13 +10:00
scripts refactor(cron): rebrand Cron Recipes -> Automation Blueprints 2026-06-11 10:49:47 -07:00
src refactor(cron): rebrand Cron Recipes -> Automation Blueprints 2026-06-11 10:49:47 -07:00
static feat: add z-ai/glm-5.2 to OpenRouter and Nous model lists 2026-06-16 23:35:45 +05:30
.gitignore feat(skills-hub): health checks, freshness badge, and a watchdog cron (#32345) 2026-05-25 23:10:45 -07:00
docusaurus.config.ts docs: point desktop download links to site root (deprecate /desktop) (#46795) 2026-06-15 15:02:24 -04:00
package-lock.json docs(website): redirect old automation-templates URL to automation-blueprints 2026-06-12 09:46:27 -07:00
package.json docs(website): redirect old automation-templates URL to automation-blueprints 2026-06-12 09:46:27 -07:00
README.md docs: replace ASCII diagrams with Mermaid/lists, add linting note 2026-03-21 17:58:30 -07:00
sidebars.ts docs(skills): regenerate shop skill page after shop-app rename 2026-06-16 10:37:21 -07:00
tsconfig.json change(tooling): typecheck in CI, update ts to 6 2026-06-10 11:59:34 -04:00

Website

This website is built using Docusaurus, a modern static website generator.

Installation

yarn

Local Development

yarn start

This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.

Build

yarn build

This command generates static content into the build directory and can be served using any static contents hosting service.

Deployment

Using SSH:

USE_SSH=true yarn deploy

Not using SSH:

GIT_USER=<Your GitHub username> yarn deploy

If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.

Diagram Linting

CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.