Skip to content

Allow plain HTTP on private networks - #408

Merged
RyanLee-Dev merged 2 commits into
mainfrom
allow-plain-http-on-private-networks
Oct 3, 2026
Merged

RyanLee-Dev merged 2 commits into
mainfrom
allow-plain-http-on-private-networks

Conversation

@RyanLee-Dev

@RyanLee-Dev RyanLee-Dev commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • One rule in internal/origin: plain HTTP is allowed for loopback and literal private-network addresses (10/8, 172.16/12, 192.168/16, fc00::/7). Core's OAC_PUBLIC_URL check, the node identity endpoint, the daemon's remote_url and the Python node installer all use it; testdata/plain_http_hosts.json checks the Go and Python copies. E2B still needs HTTPS.
  • Web: Add node and Clean up the host take the public URL Core accepted, unless it is local_only. Removed the now-unused lib/connection.ts. Copy no longer says HTTPS is required for nodes.
  • install.sh: defaults OAC_PUBLIC_URL to http://<private address>:<web port> when published on 0.0.0.0, otherwise http://localhost:<web port> (this also fixes --web-port without --public-url, which left Web accepting only localhost:8080). Prints step progress instead of Compose output, the services' logs on a failed start, then the console URL, the Core key (with sudo in commands when run through sudo) and next steps.
  • EN/ZH docs updated.

Test plan

  • go test for origin, deployment, node, processconfig, oac, web, daemon cli
  • python3 -m unittest for deploy/node and deploy/test_install.py
  • Web tsc and vitest

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Grafana serves HTTP by default and treats root_url as the address
browsers use. OAC_PUBLIC_URL, node Core URLs, the daemon remote_url
and artifact downloads accept http or https. install.sh defaults
the public URL to the host's private address so machines on the
LAN can open Web. E2B still rejects a loopback public URL because
its guests reach Core from the internet.
@RyanLee-Dev
RyanLee-Dev force-pushed the allow-plain-http-on-private-networks branch from e4f58d5 to 24b01d6 Compare October 3, 2026 05:23
@blacksmith-sh

This comment has been minimized.

Grafana treats root_url as the browser address, http or https.
OAC_PUBLIC_URL does the same; the test still rejects paths, mixed
case and other schemes.
@RyanLee-Dev
RyanLee-Dev merged commit b4e5d8e into main Oct 3, 2026
24 checks passed
@RyanLee-Dev
RyanLee-Dev deleted the allow-plain-http-on-private-networks branch October 3, 2026 05:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant