Skip to content

feat(web): forward --allow-insecure-origin from the node install command - #5

Merged
sunyalou merged 1 commit into
feat/allow-insecure-originfrom
feat/node-install-command-allow-insecure-origin
Oct 3, 2026
Merged

sunyalou merged 1 commit into
feat/allow-insecure-originfrom
feat/node-install-command-allow-insecure-origin

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

nodeInstallCommand 生成节点安装命令时支持 allow_insecure_origin 开关:开关打开时在 --core-url 之后追加 --allow-insecure-origin,让节点安装器接受非 loopback 的 http:// Core origin;默认关闭时生成命令逐字不变。

Tracks OAC-8(OAC-4 节点链路的 C 部分)。

改动

  • apps/web/src/features/sandbox/enrollment-command.ts:nodeInstallCommand 新增可选参数 allowInsecureOrigin(默认 false);为 true 时在 --core-url '<coreUrl>' 之后、--provider 之前插入 --allow-insecure-origin;为 false/省略时输出与现状逐字一致。
  • apps/web/src/features/sandbox/enrollment-command.test.ts:新增开关开/关两个用例;现有精确串断言(默认路径)保持通过。

不改 TLS 校验,不引入 InsecureSkipVerify;不涉及浏览器存储、URL、日志或凭据。

验证

  • make check-web-unit:通过(EXIT=0)
    • @oac/agents-client typecheck Done、@oac/web typecheck Done
    • 单测 765 passed + 441 passed
    • @oac/web build ✓ built
  • make check-names:通过(15 tests;OpenAgentCore name guard passed.)
  • 聚焦:vitest run src/features/sandbox/enrollment-command.test.ts → 15 passed

基线与依赖 / 合并策略

验收标准

  1. allowInsecureOrigin: true → 命令含 --core-url '<url>' --allow-insecure-origin --provider ...,且该 flag 只出现一次。
  2. allowInsecureOrigin: false 或省略 → 与改动前的默认命令逐字一致(现有精确串断言 + 新增相等断言)。

审查

本 PR 仅为一个纯增量可选参数与两个单测,默认路径无行为变化;请对完整 diff 盲审。

nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it
appends --allow-insecure-origin right after --core-url so the node installer
accepts a plain-HTTP Core origin for development; when false or omitted the
generated command is byte-for-byte unchanged.

Baseline: OAC-2 feat/allow-insecure-origin (e1e2904). Tracks OAC-8.
Co-authored-by: multica-agent <github@multica.ai>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 93f365c8be

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; allowInsecureOrigin?: boolean;
}): string {
return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)} --provider ${quote(provider)} --installation-id ${quote(installationId)})`;
return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)}${allowInsecureOrigin ? " --allow-insecure-origin" : ""} --provider ${quote(provider)} --installation-id ${quote(installationId)})`;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Teach the node installer to honor the emitted flag

When a caller sets allowInsecureOrigin: true, this command invokes the downloaded node-install.pyz with an option its argparse definition does not accept (deploy/install/node_install.py:1258-1273), and that installer's origin() validator still rejects non-loopback http URLs. The intended external-HTTP enrollment therefore exits during argument parsing before installation begins; add the flag and conditional origin validation to the installer in the same change.

AGENTS.md reference: AGENTS.md:L13-L13

Useful? React with 👍 / 👎.

Comment on lines +33 to +34
export function nodeInstallCommand({ token, coreUrl, sourceUrl, provider, installationId, scriptDigest, allowInsecureOrigin = false }: {
token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; allowInsecureOrigin?: boolean;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Propagate the setting into the actual enrollment flow

For an installation with allow_insecure_origin=true and a non-loopback http:// public URL, this parameter is never true in the real dialog: NodeEnrollment.tsx:139 calls nodeInstallCommand without it, so this default wins, and nodeSourceUrl in core-origin.ts:23-25 rejects the HTTP URL before a command can be shown. Administrators therefore still receive the HTTPS configuration blocker and cannot enroll a node; plumb the applied setting and relax that source-origin gate only when it is enabled.

Useful? React with 👍 / 👎.

@sunyalou
sunyalou merged commit 136d393 into feat/allow-insecure-origin Oct 3, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant