Skip to content

feat(installer): add allow_insecure_origin setting - #2

Closed
sunyalou wants to merge 3 commits into
mainfrom
feat/allow-insecure-origin
Closed

sunyalou wants to merge 3 commits into
mainfrom
feat/allow-insecure-origin

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a top-level config.json boolean allow_insecure_origin (default false). When explicitly enabled it allows a non-loopback http:// public_url for development and test installations, and derives OAC_ALLOW_INSECURE_ORIGIN=1 into core.env and the Web environment. With the switch off, origin validation, the derived environment and the install summary are unchanged.

Tracks OAC-2. Baseline: origin/main @ 28d34ff0.

Merge gate: this PR must not merge before the OAC-3 PR (Core consumes OAC_ALLOW_INSECURE_ORIGIN). Until OAC-3 lands, a non-loopback http:// public_url passes installer validation but Core still rejects OAC_PUBLIC_URL at startup. End-to-end validation (a real Core starting with http://IP:8080 + OAC_ALLOW_INSECURE_ORIGIN, deriving ws://, Runtime gateway up) is to be done after OAC-3 merges.

Changes

  • deploy/install/config.schema.json: new top-level boolean; x-oac changeable / restarts core,web / derives OAC_ALLOW_INSECURE_ORIGIN / install flag --allow-insecure-origin.
  • deploy/install/configuration.py: valid_core_origin(value, allow_insecure=False) (default unchanged); core_environment and the Web environment derive OAC_ALLOW_INSECURE_ORIGIN=1 only when enabled.
  • deploy/install/config_model.py: the switch is threaded into validation; the per-field origin check and the cross-field HTTPS requirement relax only when it is true. Managed ingress still requires https + DNS (phase 2).
  • deploy/install/install.py: --allow-insecure-origin (store_true); public_origin accepts a canonical non-loopback http origin so the flag can seed one, while the switch-off path keeps the original parse-time error; summary node reachability follows the switch.
  • deploy/install/install_output.py, deploy/install/oac_cli.py: plaintext-HTTP risk warning in the install summary and in oac status.
  • Docs (English + Chinese) and the regenerated config-reference tables via scripts/config-reference.py.

TLS certificate verification is unchanged; no InsecureSkipVerify is introduced.

Verification

  • make check-names → OK (15 tests; OpenAgentCore name guard passed.)
  • make check-docs → OK (6 tests)
  • PYTHONDONTWRITEBYTECODE=1 python3 scripts/config-reference.py --check → OK
  • Installer unit tests (python3 -m unittest discover -s deploy/install -p 'test_*.py') → 236 run, 1 error + 2 skipped. The single error is test_node_proxy openssl setUpClass, which reproduces identically on clean origin/main (232 run / same 1 error) and is unrelated to this change.
  • make check-distribution → could not complete in the implementation runtime: it stops at go test ./services/web (go: command not found; the host has only go1.26.6 while go.mod/go.work require 1.26.8 and the toolchain cannot be fetched offline). scripts/core-distribution-manifest.test.py also needs pigz, which is absent. Neither touches this change (no Go/Web files changed). The sub-items that do run pass: node --test scripts/build-native-catalog.test.mjs (pass 1), scripts/publish-core-release.test.py (36 OK), scripts/install-release.test.py (28 OK), bash -n ... (OK), scripts/config-reference.py --check (OK). The CI distribution and website jobs cover the rest.
  • scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene, distribution, website.

Acceptance criteria

  1. allow_insecure_origin: true + public_url: "http://10.0.0.5:8080" → validation passes.
  2. Switch off → original errors unchanged: public_url: must be a canonical origin such as https://core.example: ... for the http URL, and public_url: an HTTPS origin is required when host is not loopback for a non-loopback host without a public URL.
  3. core.env contains OAC_ALLOW_INSECURE_ORIGIN="1" when on; the variable is absent when off.
  4. The config-reference table and the English/Chinese docs are in sync (scripts/config-reference.py --check passes).

Review

An independent blind review of the installer diff passed; the one raised blocker (Core consuming OAC_ALLOW_INSECURE_ORIGIN) was ruled out of scope and is tracked by OAC-3 — hence the merge gate above.

Add a top-level config.json boolean allow_insecure_origin (default false)
that lets public_url be a non-loopback http:// origin for development and
test installations. With the switch off, origin validation, derived
environment and the install summary are unchanged.

- config.schema.json: new setting, derives OAC_ALLOW_INSECURE_ORIGIN and
  install flag --allow-insecure-origin.
- config_model: thread the switch through validation; the per-field origin
  check and the cross-field HTTPS requirement relax only when it is true.
- configuration: derive OAC_ALLOW_INSECURE_ORIGIN=1 in core.env and the Web
  environment only when enabled.
- install.py: --allow-insecure-origin flag, relaxed public_origin parse,
  strict parse-time error kept when off, and node reachability for http.
- install_output / oac_cli status: plaintext HTTP risk warning.
- docs + regenerated config-reference tables (English and Chinese).

TLS certificate verification is unchanged.

Co-authored-by: multica-agent <github@multica.ai>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e1e2904973

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +209 to +210
if config["allow_insecure_origin"]:
result["OAC_ALLOW_INSECURE_ORIGIN"] = "1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Teach Core to honor the insecure-origin switch

With --allow-insecure-origin --public-url http://10.0.0.5:8080, this writes OAC_ALLOW_INSECURE_ORIGIN=1, but Core never reads that variable: publicURL still calls deployment.ValidateCoreURL, which rejects every non-loopback HTTP origin. Core therefore exits during startup for the newly documented configuration, so the installer cannot actually provision an insecure external HTTP origin until the Core validator is updated to honor the switch.

Useful? React with 👍 / 👎.

Comment on lines +200 to 202
if (not managed and not loopback_listener(full["host"])
and not (full["public_url"] or "").startswith("https://") and not full["allow_insecure_origin"]):
problems.append("public_url: an HTTPS origin is required when host is not loopback")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require a public URL for external listeners

For an external install with a non-loopback host, such as ingress: "external", host: "0.0.0.0", and allow_insecure_origin: true, omitting public_url now passes validation because the switch bypasses the whole HTTPS-origin requirement. The rendered services still bind Core and Web publicly, while local_public_url falls back to http://127.0.0.1:8091; this creates an externally exposed installation with no declared reachable public address and no plaintext warning. The switch should relax HTTPS to an explicit HTTP public_url, not allow a missing URL.

Useful? React with 👍 / 👎.

nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it
appends --allow-insecure-origin right after --core-url so the node installer
accepts a plain-HTTP Core origin for development; when false or omitted the
generated command is byte-for-byte unchanged.

Baseline: OAC-2 feat/allow-insecure-origin (e1e2904). Tracks OAC-8.
Co-authored-by: multica-agent <github@multica.ai>
…nsecure-origin

feat(web): forward --allow-insecure-origin from the node install command
@sunyalou

sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

失效关闭:上游 MiniMax-AI#402 重构(Compose + Go oac)删除了本 PR 涉及的全部 deploy/install/ 文件。重做见 OAC-2 任务 B(基于 origin/main 新开 PR)。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant