From 93f365c8be91b665faab5f180184f9e8b7bc9863 Mon Sep 17 00:00:00 2001 From: sunyalou Date: Sat, 3 Oct 2026 12:17:11 +0800 Subject: [PATCH] feat(web): forward --allow-insecure-origin from the node install command nodeInstallCommand gains an optional allowInsecureOrigin flag. When true it appends --allow-insecure-origin right after --core-url so the node installer accepts a plain-HTTP Core origin for development; when false or omitted the generated command is byte-for-byte unchanged. Baseline: OAC-2 feat/allow-insecure-origin (e1e29049). Tracks OAC-8. Co-authored-by: multica-agent --- .../src/features/sandbox/enrollment-command.test.ts | 13 +++++++++++++ apps/web/src/features/sandbox/enrollment-command.ts | 11 +++++++---- 2 files changed, 20 insertions(+), 4 deletions(-) diff --git a/apps/web/src/features/sandbox/enrollment-command.test.ts b/apps/web/src/features/sandbox/enrollment-command.test.ts index 180c4e1b9..d73434971 100644 --- a/apps/web/src/features/sandbox/enrollment-command.test.ts +++ b/apps/web/src/features/sandbox/enrollment-command.test.ts @@ -19,6 +19,19 @@ printf '==> Verifying node installer...\\n' && printf '%s %s\\n' '${digest}' "$d/node-install.pyz" | sha256sum -c --status && printf '%s\\n' 'secret'\\''onetime' | $s \${s:+--preserve-env=http_proxy,https_proxy,no_proxy,HTTP_PROXY,HTTPS_PROXY,NO_PROXY} python3 "$d/node-install.pyz" \${NO_COLOR+--no-color} --enrollment-token-stdin --source-url 'https://console.example' --core-url 'https://core.example' --provider 'docker' --installation-id '7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f')`); }); + it("appends --allow-insecure-origin right after --core-url when the switch is on", () => { + const command = nodeInstallCommand({ token: "secret'onetime", coreUrl: "http://10.0.0.5:8080", sourceUrl: "http://10.0.0.5:8080", provider: "docker", installationId: "7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f", scriptDigest: digest, allowInsecureOrigin: true }); + expect(command).toContain("--core-url 'http://10.0.0.5:8080' --allow-insecure-origin --provider 'docker'"); + // The flag is forwarded once, and only in the installer's own argument list. + expect(command.match(/--allow-insecure-origin/g)).toHaveLength(1); + expect(command.endsWith("--provider 'docker' --installation-id '7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f')")).toBe(true); + }); + it("leaves the command byte-for-byte unchanged when the switch is off or omitted", () => { + const args = { token: "secret'onetime", coreUrl: "https://core.example", sourceUrl: "https://console.example", provider: "docker" as const, installationId: "7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f", scriptDigest: digest }; + expect(nodeInstallCommand({ ...args, allowInsecureOrigin: false })).toBe(install()); + expect(nodeInstallCommand(args)).toBe(install()); + expect(nodeInstallCommand({ ...args, allowInsecureOrigin: false })).not.toContain("--allow-insecure-origin"); + }); it("creates the exact uninstall commands, with no token", () => { const uninstall = () => nodeUninstallCommand({ sourceUrl: "https://console.example", installationId: "7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f", scriptDigest: digest }); expect(uninstall()).toBe(` (umask 077; d=$(mktemp -d) || exit; trap 'rm -rf "$d"' EXIT; s=; [ "$(id -u)" -eq 0 ] || s=sudo diff --git a/apps/web/src/features/sandbox/enrollment-command.ts b/apps/web/src/features/sandbox/enrollment-command.ts index f67f7d301..ac873d668 100644 --- a/apps/web/src/features/sandbox/enrollment-command.ts +++ b/apps/web/src/features/sandbox/enrollment-command.ts @@ -25,12 +25,15 @@ const runInstaller = `$s \${s:+--preserve-env=http_proxy,https_proxy,no_proxy,HT /** * Adds this host as a node. The one-time token reaches the installer only on * standard input (`printf` is a shell builtin), never in an argument, the - * environment or sudo's command line. + * environment or sudo's command line. `allowInsecureOrigin` forwards the + * installer's `--allow-insecure-origin`, which lets a plain-HTTP Core origin + * enroll; it stays off unless the caller explicitly asks for it, so the default + * command is byte-for-byte unchanged. */ -export function nodeInstallCommand({ token, coreUrl, sourceUrl, provider, installationId, scriptDigest }: { - token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; +export function nodeInstallCommand({ token, coreUrl, sourceUrl, provider, installationId, scriptDigest, allowInsecureOrigin = false }: { + token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; allowInsecureOrigin?: boolean; }): string { - return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)} --provider ${quote(provider)} --installation-id ${quote(installationId)})`; + return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)}${allowInsecureOrigin ? " --allow-insecure-origin" : ""} --provider ${quote(provider)} --installation-id ${quote(installationId)})`; } /**