SIGN IN SIGN UP

Sign-in with AEGIS (device link) + designed cmux-style DMG installer

Cockpit login now works like Cursor/Warp — user clicks "Sign in with
AEGIS" in Settings, the OS default browser opens aegistraces.com,
they auth on Supabase, and marketing hands the license back to the
local gateway via a 127.0.0.1 loopback callback. No key pasting.

  Gateway  (packages/gateway-mcp/src/api/license.ts)
    +POST /api/v1/license/link-start    — mint one-time nonce + URL
    +GET  /api/v1/license/link-callback — verify nonce, activate, HTML

  Marketing (apps/marketing/src/pages/desktop/link.astro)
    Checks session, looks up user's active license_key, 302s back to
    the gateway callback. Only 127.0.0.1 http callbacks allowed
    (phishing guard); nonce passed through opaquely.

  Cockpit  (apps/compliance-cockpit/src/components/settings/license-panel.tsx)
    +Sign-in-with-AEGIS button + 2s status poll + Tauri shell.open
    fallback to window.open in browser mode.

Also ships the cmux-style .dmg installer (dmg-assets/background.png
+ bundle.macOS.dmg config with app-icon left, arrow center, Apps
folder right). Note: macOS Automation permission for Terminal →
Finder must be granted once for bundle_dmg.sh to succeed.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
J
Justin Yuan committed
8d418ffbf49751e30465772e2877ec8f9b84fde7
Parent: f2744aa