Conversation
Add a top-level config.json boolean allow_insecure_origin (default false) that lets public_url be a non-loopback http:// origin for development and test installations. With the switch off, origin validation, derived environment and the install summary are unchanged. - config.schema.json: new setting, derives OAC_ALLOW_INSECURE_ORIGIN and install flag --allow-insecure-origin. - config_model: thread the switch through validation; the per-field origin check and the cross-field HTTPS requirement relax only when it is true. - configuration: derive OAC_ALLOW_INSECURE_ORIGIN=1 in core.env and the Web environment only when enabled. - install.py: --allow-insecure-origin flag, relaxed public_origin parse, strict parse-time error kept when off, and node reachability for http. - install_output / oac_cli status: plaintext HTTP risk warning. - docs + regenerated config-reference tables (English and Chinese). TLS certificate verification is unchanged. Co-authored-by: multica-agent <github@multica.ai>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e1e2904973
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if config["allow_insecure_origin"]: | ||
| result["OAC_ALLOW_INSECURE_ORIGIN"] = "1" |
There was a problem hiding this comment.
Teach Core to honor the insecure-origin switch
With --allow-insecure-origin --public-url http://10.0.0.5:8080, this writes OAC_ALLOW_INSECURE_ORIGIN=1, but Core never reads that variable: publicURL still calls deployment.ValidateCoreURL, which rejects every non-loopback HTTP origin. Core therefore exits during startup for the newly documented configuration, so the installer cannot actually provision an insecure external HTTP origin until the Core validator is updated to honor the switch.
Useful? React with 👍 / 👎.
| if (not managed and not loopback_listener(full["host"]) | ||
| and not (full["public_url"] or "").startswith("https://") and not full["allow_insecure_origin"]): | ||
| problems.append("public_url: an HTTPS origin is required when host is not loopback") |
There was a problem hiding this comment.
Require a public URL for external listeners
For an external install with a non-loopback host, such as ingress: "external", host: "0.0.0.0", and allow_insecure_origin: true, omitting public_url now passes validation because the switch bypasses the whole HTTPS-origin requirement. The rendered services still bind Core and Web publicly, while local_public_url falls back to http://127.0.0.1:8091; this creates an externally exposed installation with no declared reachable public address and no plaintext warning. The switch should relax HTTPS to an explicit HTTP public_url, not allow a missing URL.
Useful? React with 👍 / 👎.
nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it appends --allow-insecure-origin right after --core-url so the node installer accepts a plain-HTTP Core origin for development; when false or omitted the generated command is byte-for-byte unchanged. Baseline: OAC-2 feat/allow-insecure-origin (e1e2904). Tracks OAC-8. Co-authored-by: multica-agent <github@multica.ai>
…nsecure-origin feat(web): forward --allow-insecure-origin from the node install command
|
失效关闭:上游 MiniMax-AI#402 重构(Compose + Go oac)删除了本 PR 涉及的全部 |
Summary
Adds a top-level
config.jsonbooleanallow_insecure_origin(defaultfalse). When explicitly enabled it allows a non-loopbackhttp://public_urlfor development and test installations, and derivesOAC_ALLOW_INSECURE_ORIGIN=1intocore.envand the Web environment. With the switch off, origin validation, the derived environment and the install summary are unchanged.Tracks OAC-2. Baseline:
origin/main @ 28d34ff0.Changes
deploy/install/config.schema.json: new top-level boolean;x-oacchangeable / restartscore,web/ derivesOAC_ALLOW_INSECURE_ORIGIN/ install flag--allow-insecure-origin.deploy/install/configuration.py:valid_core_origin(value, allow_insecure=False)(default unchanged);core_environmentand the Web environment deriveOAC_ALLOW_INSECURE_ORIGIN=1only when enabled.deploy/install/config_model.py: the switch is threaded into validation; the per-fieldorigincheck and the cross-field HTTPS requirement relax only when it is true. Managed ingress still requires https + DNS (phase 2).deploy/install/install.py:--allow-insecure-origin(store_true);public_originaccepts a canonical non-loopback http origin so the flag can seed one, while the switch-off path keeps the original parse-time error; summary node reachability follows the switch.deploy/install/install_output.py,deploy/install/oac_cli.py: plaintext-HTTP risk warning in the install summary and inoac status.scripts/config-reference.py.TLS certificate verification is unchanged; no
InsecureSkipVerifyis introduced.Verification
make check-names→ OK (15 tests;OpenAgentCore name guard passed.)make check-docs→ OK (6 tests)PYTHONDONTWRITEBYTECODE=1 python3 scripts/config-reference.py --check→ OKpython3 -m unittest discover -s deploy/install -p 'test_*.py') → 236 run, 1 error + 2 skipped. The single error istest_node_proxyopensslsetUpClass, which reproduces identically on cleanorigin/main(232 run / same 1 error) and is unrelated to this change.make check-distribution→ could not complete in the implementation runtime: it stops atgo test ./services/web(go: command not found; the host has only go1.26.6 whilego.mod/go.workrequire 1.26.8 and the toolchain cannot be fetched offline).scripts/core-distribution-manifest.test.pyalso needspigz, which is absent. Neither touches this change (no Go/Web files changed). The sub-items that do run pass:node --test scripts/build-native-catalog.test.mjs(pass 1),scripts/publish-core-release.test.py(36 OK),scripts/install-release.test.py(28 OK),bash -n ...(OK),scripts/config-reference.py --check(OK). The CIdistributionandwebsitejobs cover the rest.scripts/ci_plan.py plan --base origin/main --head HEAD→hygiene,distribution,website.Acceptance criteria
allow_insecure_origin: true+public_url: "http://10.0.0.5:8080"→ validation passes.public_url: must be a canonical origin such as https://core.example: ...for the http URL, andpublic_url: an HTTPS origin is required when host is not loopbackfor a non-loopback host without a public URL.core.envcontainsOAC_ALLOW_INSECURE_ORIGIN="1"when on; the variable is absent when off.scripts/config-reference.py --checkpasses).Review
An independent blind review of the installer diff passed; the one raised blocker (Core consuming
OAC_ALLOW_INSECURE_ORIGIN) was ruled out of scope and is tracked by OAC-3 — hence the merge gate above.