Sign-in with AEGIS (device link) + designed cmux-style DMG installer
Cockpit login now works like Cursor/Warp — user clicks "Sign in with
AEGIS" in Settings, the OS default browser opens aegistraces.com,
they auth on Supabase, and marketing hands the license back to the
local gateway via a 127.0.0.1 loopback callback. No key pasting.
Gateway (packages/gateway-mcp/src/api/license.ts)
+POST /api/v1/license/link-start — mint one-time nonce + URL
+GET /api/v1/license/link-callback — verify nonce, activate, HTML
Marketing (apps/marketing/src/pages/desktop/link.astro)
Checks session, looks up user's active license_key, 302s back to
the gateway callback. Only 127.0.0.1 http callbacks allowed
(phishing guard); nonce passed through opaquely.
Cockpit (apps/compliance-cockpit/src/components/settings/license-panel.tsx)
+Sign-in-with-AEGIS button + 2s status poll + Tauri shell.open
fallback to window.open in browser mode.
Also ships the cmux-style .dmg installer (dmg-assets/background.png
+ bundle.macOS.dmg config with app-icon left, arrow center, Apps
folder right). Note: macOS Automation permission for Terminal →
Finder must be granted once for bundle_dmg.sh to succeed.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> J
Justin Yuan committed
8d418ffbf49751e30465772e2877ec8f9b84fde7
Parent: f2744aa