Skip to content

feat(web): carry --allow-insecure-origin in the node install command - #10

Merged
sunyalou merged 1 commit into
mainfrom
feat/oac8-node-command-allow-insecure-origin
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
feat/oac8-node-command-allow-insecure-origin

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

任务 D 的 Web 部分(OAC-8 重做):nodeInstallCommand 生成节点安装命令时携带 --allow-insecure-origin,让节点安装器接受非 loopback 的 http:// Core origin。开关只读 Core 安装快照;默认关闭时生成命令逐字不变。

Tracks OAC-8(OAC-9 §3.1 任务 D Web 落点)。基线 origin/main 3f0a737b。

改动

  • apps/web/src/features/sandbox/enrollment-command.ts:nodeInstallCommand 新增可选参数 allowInsecureOrigin(默认 false);为 true 时在 --core-url '<url>' 之后、--provider 之前插入 --allow-insecure-origin;为 false/省略时输出与现状逐字一致。
  • apps/web/src/features/sandbox/NodeEnrollment.tsx:把任务 C 已由快照算出的 insecure(allowsInsecureOrigin(installation.data) 且 public_url 为 http://)传给 nodeInstallCommand。这是任务 C 无法完成的一跳(参数此前不存在),否则参数为死代码、开关无法到达命令;不新增开关来源,不读 env、不改 /console/config、不改 services/web/*。
  • apps/web/src/features/sandbox/enrollment-command.test.ts:开关开/关各一用例;现有精确串断言保持通过。
  • apps/web/e2e/nodes.spec.ts:insecure 场景补断言,命令含 --core-url 'http://10.0.0.5:8080' --allow-insecure-origin。

验证

  • make check-web-unit → 通过(EXIT=0):@oac/agents-client、@oac/web typecheck Done;单测 agents-client 765 passed + web 450 passed;@oac/web build ✓。
  • make check-names → 通过(15 tests;OpenAgentCore name guard passed.)。
  • 聚焦 vitest run src/features/sandbox/enrollment-command.test.ts → 15 passed。
  • pnpm --filter @oac/web typecheck(含 e2e)→ 通过。
  • python3 scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene, web, web-acceptance。
  • make check-web-acceptance 本环境无法执行:本机无 Google Chrome,自带 Chromium 缺 libatk-1.0.so.0 等系统库(与任务 C 记录同一限制);由 CI web-acceptance 覆盖(含本次新增断言)。

范围与依赖

  • 按 OAC-9 §3.1 任务 D:Web 落点为 enrollment-command.ts + 测试;本 PR 另含 NodeEnrollment.tsx 的一行调用方接线,原因是任务 C 合并时 nodeInstallCommand 尚无该参数,接线无法提前落地。
  • 节点安装器接受 --allow-insecure-origin 属任务 D 的安装器部分(deploy/node/node_install.py),依赖任务 B(PR feat(installer): add allow_insecure_origin setting #8,已合入 3f0a737b)。
  • 不改 TLS 校验,不引入 InsecureSkipVerify;默认关闭逐字保真。

验收

  1. allowInsecureOrigin: true → 命令含 --core-url '<url>' --allow-insecure-origin,该 flag 只出现一次。
  2. allowInsecureOrigin: false/省略 → 与改动前逐字一致。
  3. 开关开且 public_url 为 http://IP 时,Add node 生成的安装命令带该 flag(e2e insecure 场景断言)。

审查

请对完整 diff 盲审。

nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it
appends --allow-insecure-origin right after --core-url, so the node installer
accepts a plain-HTTP Core origin; when false or omitted the generated command
is byte-for-byte unchanged.

NodeEnrollment passes the switch read from Core's installation snapshot
(allowsInsecureOrigin), so the snapshot stays the single source. Adds the
on/off vitest cases and an e2e assertion for the flag.

Baseline: origin/main 3f0a737. Tracks OAC-8 (task D, Web part).
Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit 54ce8d0 into main Oct 3, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant