feat(web): forward --allow-insecure-origin from the node install command - #5
Conversation
nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it appends --allow-insecure-origin right after --core-url so the node installer accepts a plain-HTTP Core origin for development; when false or omitted the generated command is byte-for-byte unchanged. Baseline: OAC-2 feat/allow-insecure-origin (e1e2904). Tracks OAC-8. Co-authored-by: multica-agent <github@multica.ai>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 93f365c8be
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; allowInsecureOrigin?: boolean; | ||
| }): string { | ||
| return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)} --provider ${quote(provider)} --installation-id ${quote(installationId)})`; | ||
| return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)}${allowInsecureOrigin ? " --allow-insecure-origin" : ""} --provider ${quote(provider)} --installation-id ${quote(installationId)})`; |
There was a problem hiding this comment.
Teach the node installer to honor the emitted flag
When a caller sets allowInsecureOrigin: true, this command invokes the downloaded node-install.pyz with an option its argparse definition does not accept (deploy/install/node_install.py:1258-1273), and that installer's origin() validator still rejects non-loopback http URLs. The intended external-HTTP enrollment therefore exits during argument parsing before installation begins; add the flag and conditional origin validation to the installer in the same change.
AGENTS.md reference: AGENTS.md:L13-L13
Useful? React with 👍 / 👎.
| export function nodeInstallCommand({ token, coreUrl, sourceUrl, provider, installationId, scriptDigest, allowInsecureOrigin = false }: { | ||
| token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; allowInsecureOrigin?: boolean; |
There was a problem hiding this comment.
Propagate the setting into the actual enrollment flow
For an installation with allow_insecure_origin=true and a non-loopback http:// public URL, this parameter is never true in the real dialog: NodeEnrollment.tsx:139 calls nodeInstallCommand without it, so this default wins, and nodeSourceUrl in core-origin.ts:23-25 rejects the HTTP URL before a command can be shown. Administrators therefore still receive the HTTPS configuration blocker and cannot enroll a node; plumb the applied setting and relax that source-origin gate only when it is enabled.
Useful? React with 👍 / 👎.
目标
nodeInstallCommand生成节点安装命令时支持allow_insecure_origin开关:开关打开时在--core-url之后追加--allow-insecure-origin,让节点安装器接受非 loopback 的http://Core origin;默认关闭时生成命令逐字不变。Tracks OAC-8(OAC-4 节点链路的 C 部分)。
改动
apps/web/src/features/sandbox/enrollment-command.ts:nodeInstallCommand新增可选参数allowInsecureOrigin(默认false);为true时在--core-url '<coreUrl>'之后、--provider之前插入--allow-insecure-origin;为false/省略时输出与现状逐字一致。apps/web/src/features/sandbox/enrollment-command.test.ts:新增开关开/关两个用例;现有精确串断言(默认路径)保持通过。不改 TLS 校验,不引入
InsecureSkipVerify;不涉及浏览器存储、URL、日志或凭据。验证
make check-web-unit:通过(EXIT=0)@oac/agents-clienttypecheck Done、@oac/webtypecheck Done@oac/webbuild ✓ builtmake check-names:通过(15 tests;OpenAgentCore name guard passed.)vitest run src/features/sandbox/enrollment-command.test.ts→ 15 passed基线与依赖 / 合并策略
feat/allow-insecure-origin(e1e29049),本 PR base 指向该分支(stacked);PR feat(installer): add allow_insecure_origin setting #2 合入main后 GitHub 会自动把 base 重定向到main。enrollment-command.ts与其单测,这两个文件在 PR feat(installer): add allow_insecure_origin setting #2 中未被修改,因此本提交也可直接 rebase/摘到main,diff 不变。--allow-insecure-origin传给node-install.pyz,deploy/install/node_install.py需接受该参数(属 OAC-4 节点链路范围,不在本 PR)。NodeEnrollment.tsx把开关值传给nodeInstallCommand)属 OAC-6 的 PR feat(web): allow a plain-HTTP public URL with allow_insecure_origin #4 范围;本 PR 不重复实现、不改该文件,避免与 feat(web): allow a plain-HTTP public URL with allow_insecure_origin #4 冲突。验收标准
allowInsecureOrigin: true→ 命令含--core-url '<url>' --allow-insecure-origin --provider ...,且该 flag 只出现一次。allowInsecureOrigin: false或省略 → 与改动前的默认命令逐字一致(现有精确串断言 + 新增相等断言)。审查
本 PR 仅为一个纯增量可选参数与两个单测,默认路径无行为变化;请对完整 diff 盲审。