Capsule
Desktop companion for The Tempus Project. Point it at a TTP site, sign in with a username and password or paste an API token, and work against that install from the desktop.
This replaces the old TempusToolkit Electron stub. The keepers were the login ? stored-token ? home flow. Hardcoded LAN URLs, nodeIntegration, and the leftover WoW-folder picker did not come along.
Run it
From this folder (Windows source checkout is fine ? Capsule is Node, not PHP):
npm install
npm run dev
npm start previews a production build. There is no local TTP site on the Windows checkout. Login needs a reachable install (typically the Ubuntu host) with api/apiAccessPersonal on for user-token calls.
How auth works
All HTTP runs in the main process. The renderer never sees the token and never talks to the site directly, so TTP?s same-origin CORS policy does not apply.
| Action | Endpoint | Notes |
|---|---|---|
| Password sign-in | POST /api/login |
username + password, application/x-www-form-urlencoded. Same limiter as browser login. No CSRF, no Turnstile. MFA accounts return { mfa } instead of a token. |
| MFA code / method | POST /api/login/mfa/{loginCode} |
auth_code or mfaMethodSelect. loginCode stays in the main process. |
| MFA reset | POST /api/login/mfa/{loginCode}/reset |
Clears the chosen method so the picker shows again. |
| Confirm identity | GET /api/profile |
Bearer user token. Also used to hydrate username after login. GET /api/users/find/{username} remains available. |
| Workspace | GET /api/notifications, GET /api/messages |
First page after connect. Plugin-off responses show as unavailable. |
| Search | GET /api/search |
Header search. q, resource, page. |
| Profile save | POST /api/profile/update |
Name, avatar, prefs. |
| Mail / notices | POST /api/messages/?, POST /api/notifications/? |
View, reply, create, read, delete. |
| Contact / bugs | POST /api/contact, POST /api/bugreport |
Footer pages when those plugins are enabled. |
| Existing token | Admin ? Tokens | Personal or app token. A user token hydrates the workspace; an app token can connect but cannot call the user API. |
The token is stored under Electron userData (session.json). safeStorage encrypts it when the OS keychain is available. MFA loginCode is not stored.
App-facing pairing notes live with the PHP app: repos/ttp/docs/capsule.md.
Layout
| Path | Job |
|---|---|
src/main/ |
Window, session file, TTP HTTP, IPC |
src/preload/ |
window.capsule bridge |
src/renderer/ |
Login, MFA, TTP-styled chrome, and live API views |
The logged-in header follows the public TTP shell (text-bg-dark, FA 6.7.1, Bootstrap 5.3). Search stays visible and centered. Account is a top-right dropdown like the site. Notifications and messages are the same bell / envelope menus. Profile edit covers User CP preferences except email, password, and phone ? those open {site}/usercp/?. Lists load from the site API after sign-in. The footer matches TTP copyright and social icons. Above that: dark-mode toggle, Privacy Policy, Terms of Service, Contact, and Report a Bug. No subscribe box. Privacy and terms open the connected site; contact and bug reports stay in-app.
Remote
This checkout starts with no git remote. When the repo exists on the project host:
ssh://git@git.thetempusproject.com:2222/the-tempus-project/capsule.git