feat(web): carry --allow-insecure-origin in the node install command - #10
Merged
Merged
Conversation
nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it appends --allow-insecure-origin right after --core-url, so the node installer accepts a plain-HTTP Core origin; when false or omitted the generated command is byte-for-byte unchanged. NodeEnrollment passes the switch read from Core's installation snapshot (allowsInsecureOrigin), so the snapshot stays the single source. Adds the on/off vitest cases and an e2e assertion for the flag. Baseline: origin/main 3f0a737. Tracks OAC-8 (task D, Web part). Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
任务 D 的 Web 部分(OAC-8 重做):
nodeInstallCommand生成节点安装命令时携带--allow-insecure-origin,让节点安装器接受非 loopback 的http://Core origin。开关只读 Core 安装快照;默认关闭时生成命令逐字不变。Tracks OAC-8(OAC-9 §3.1 任务 D Web 落点)。基线
origin/main3f0a737b。改动
apps/web/src/features/sandbox/enrollment-command.ts:nodeInstallCommand新增可选参数allowInsecureOrigin(默认false);为true时在--core-url '<url>'之后、--provider之前插入--allow-insecure-origin;为false/省略时输出与现状逐字一致。apps/web/src/features/sandbox/NodeEnrollment.tsx:把任务 C 已由快照算出的insecure(allowsInsecureOrigin(installation.data)且public_url为http://)传给nodeInstallCommand。这是任务 C 无法完成的一跳(参数此前不存在),否则参数为死代码、开关无法到达命令;不新增开关来源,不读 env、不改/console/config、不改services/web/*。apps/web/src/features/sandbox/enrollment-command.test.ts:开关开/关各一用例;现有精确串断言保持通过。apps/web/e2e/nodes.spec.ts:insecure 场景补断言,命令含--core-url 'http://10.0.0.5:8080' --allow-insecure-origin。验证
make check-web-unit→ 通过(EXIT=0):@oac/agents-client、@oac/webtypecheck Done;单测 agents-client 765 passed + web 450 passed;@oac/webbuild ✓。make check-names→ 通过(15 tests;OpenAgentCore name guard passed.)。vitest run src/features/sandbox/enrollment-command.test.ts→ 15 passed。pnpm --filter @oac/web typecheck(含 e2e)→ 通过。python3 scripts/ci_plan.py plan --base origin/main --head HEAD→hygiene, web, web-acceptance。make check-web-acceptance本环境无法执行:本机无 Google Chrome,自带 Chromium 缺libatk-1.0.so.0等系统库(与任务 C 记录同一限制);由 CIweb-acceptance覆盖(含本次新增断言)。范围与依赖
enrollment-command.ts+ 测试;本 PR 另含NodeEnrollment.tsx的一行调用方接线,原因是任务 C 合并时nodeInstallCommand尚无该参数,接线无法提前落地。--allow-insecure-origin属任务 D 的安装器部分(deploy/node/node_install.py),依赖任务 B(PR feat(installer): add allow_insecure_origin setting #8,已合入3f0a737b)。InsecureSkipVerify;默认关闭逐字保真。验收
allowInsecureOrigin: true→ 命令含--core-url '<url>' --allow-insecure-origin,该 flag 只出现一次。allowInsecureOrigin: false/省略 → 与改动前逐字一致。public_url为http://IP时,Add node 生成的安装命令带该 flag(e2e insecure 场景断言)。审查
请对完整 diff 盲审。