Skip to content

fix(agent): hash code assets without Web Crypto so AI tools work over non-secure origins - #576

Open
cakelesscoder wants to merge 1 commit into
CoreBunch:mainfrom
cakelesscoder:pr/websafe-sha256
Open

cakelesscoder wants to merge 1 commit into
CoreBunch:mainfrom
cakelesscoder:pr/websafe-sha256

Conversation

@cakelesscoder

Copy link
Copy Markdown

Summary

The runtime code-asset tools hash content with crypto.subtle.digest. crypto.subtle only exists in a secure context — HTTPS or localhost.

Instatic is self-hosted, so reaching the admin over a LAN or Tailscale IP on plain http:// is an ordinary deployment rather than an edge case. In that context crypto.subtle is undefined, so the first code-asset tool call throws crypto.subtle is undefined and the agent stops mid-turn.

This adds a dependency-free sha256Hex in src/core/utils/sha256.ts and uses it for the read→patch optimistic-concurrency fingerprint in codeAssetTools.ts.

That fingerprint is self-consistent and client-only — it answers "did this file change between read and patch" and never bears cryptographic security — so a pure-JS SHA-256 is a drop-in, and it returns byte-identical digests in every context. No new dependency; it's ~100 lines of standard SHA-256.

Verification

  • bun run build
  • bun test
  • bun run lint
  • Docker/deployment check — not relevant (no deployment surface touched)

New test src/__tests__/utils/sha256.test.ts checks the implementation against native WebCrypto across the empty string and known vectors, multi-byte UTF-8, every message-length residue around the 55/56/64-byte padding boundaries, and single-character sensitivity.

Checklist

  • Tests cover behavior changes.
  • Docs were updated when behavior, config, deployment, or public surfaces changed. — no doc-visible surface changed; the fix is internal to an existing tool.
  • No compatibility shim was added for old pre-release behavior.
  • No secrets, local databases, uploads, or generated artifacts are included.

Split out of a larger branch so it can be reviewed on its own — it's independent of any AI provider and fixes the existing agent tooling on non-secure origins.

… non-secure origins

The runtime code-asset tools hashed content with `crypto.subtle.digest`, which
is only defined in a secure context (HTTPS or localhost). When the CMS is reached
over a LAN/Tailscale IP on plain http:// — a non-secure context — `crypto.subtle`
is undefined, so the first code-asset tool call threw "crypto.subtle is undefined"
and the agent hung.

Add a dependency-free `sha256Hex` (src/core/utils/sha256.ts) that produces the
identical 64-char digest in any context, and use it for the read→patch
optimistic-concurrency fingerprint. The hash is a self-consistent, client-only
fingerprint — never cryptographic-security-bearing — so a pure-JS SHA-256 is a
drop-in. New test verifies it byte-for-byte against native WebCrypto across
UTF-8 and all padding boundaries.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
(cherry picked from commit 78dbb7a63251bca132bb5ed58f0b15e179817acf)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant