Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions apps/web/src/features/sandbox/enrollment-command.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,19 @@ printf '==> Verifying node installer...\\n' &&
printf '%s %s\\n' '${digest}' "$d/node-install.pyz" | sha256sum -c --status &&
printf '%s\\n' 'secret'\\''onetime' | $s \${s:+--preserve-env=http_proxy,https_proxy,no_proxy,HTTP_PROXY,HTTPS_PROXY,NO_PROXY} python3 "$d/node-install.pyz" \${NO_COLOR+--no-color} --enrollment-token-stdin --source-url 'https://console.example' --core-url 'https://core.example' --provider 'docker' --installation-id '7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f')`);
});
it("appends --allow-insecure-origin right after --core-url when the switch is on", () => {
const command = nodeInstallCommand({ token: "secret'onetime", coreUrl: "http://10.0.0.5:8080", sourceUrl: "http://10.0.0.5:8080", provider: "docker", installationId: "7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f", scriptDigest: digest, allowInsecureOrigin: true });
expect(command).toContain("--core-url 'http://10.0.0.5:8080' --allow-insecure-origin --provider 'docker'");
// The flag is forwarded once, and only in the installer's own argument list.
expect(command.match(/--allow-insecure-origin/g)).toHaveLength(1);
expect(command.endsWith("--provider 'docker' --installation-id '7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f')")).toBe(true);
});
it("leaves the command byte-for-byte unchanged when the switch is off or omitted", () => {
const args = { token: "secret'onetime", coreUrl: "https://core.example", sourceUrl: "https://console.example", provider: "docker" as const, installationId: "7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f", scriptDigest: digest };
expect(nodeInstallCommand({ ...args, allowInsecureOrigin: false })).toBe(install());
expect(nodeInstallCommand(args)).toBe(install());
expect(nodeInstallCommand({ ...args, allowInsecureOrigin: false })).not.toContain("--allow-insecure-origin");
});
it("creates the exact uninstall commands, with no token", () => {
const uninstall = () => nodeUninstallCommand({ sourceUrl: "https://console.example", installationId: "7f3c2a90-5b1e-4c2d-9e3f-0a1b2c3d4e5f", scriptDigest: digest });
expect(uninstall()).toBe(` (umask 077; d=$(mktemp -d) || exit; trap 'rm -rf "$d"' EXIT; s=; [ "$(id -u)" -eq 0 ] || s=sudo
Expand Down
11 changes: 7 additions & 4 deletions apps/web/src/features/sandbox/enrollment-command.ts
Original file line number Diff line number Diff line change
Expand Up @@ -25,12 +25,15 @@ const runInstaller = `$s \${s:+--preserve-env=http_proxy,https_proxy,no_proxy,HT
/**
* Adds this host as a node. The one-time token reaches the installer only on
* standard input (`printf` is a shell builtin), never in an argument, the
* environment or sudo's command line.
* environment or sudo's command line. `allowInsecureOrigin` forwards the
* installer's `--allow-insecure-origin`, which lets a plain-HTTP Core origin
* enroll; it stays off unless the caller explicitly asks for it, so the default
* command is byte-for-byte unchanged.
*/
export function nodeInstallCommand({ token, coreUrl, sourceUrl, provider, installationId, scriptDigest }: {
token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string;
export function nodeInstallCommand({ token, coreUrl, sourceUrl, provider, installationId, scriptDigest, allowInsecureOrigin = false }: {
token: string; coreUrl: string; sourceUrl: string; provider: "docker" | "microsandbox"; installationId: string; scriptDigest: string; allowInsecureOrigin?: boolean;
Comment on lines +33 to +34

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Propagate the setting into the actual enrollment flow

For an installation with allow_insecure_origin=true and a non-loopback http:// public URL, this parameter is never true in the real dialog: NodeEnrollment.tsx:139 calls nodeInstallCommand without it, so this default wins, and nodeSourceUrl in core-origin.ts:23-25 rejects the HTTP URL before a command can be shown. Administrators therefore still receive the HTTPS configuration blocker and cannot enroll a node; plumb the applied setting and relax that source-origin gate only when it is enabled.

Useful? React with 👍 / 👎.

}): string {
return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)} --provider ${quote(provider)} --installation-id ${quote(installationId)})`;
return `${nodeInstaller(sourceUrl, scriptDigest)}printf '%s\\n' ${quote(token)} | ${runInstaller} --enrollment-token-stdin --source-url ${quote(sourceUrl)} --core-url ${quote(coreUrl)}${allowInsecureOrigin ? " --allow-insecure-origin" : ""} --provider ${quote(provider)} --installation-id ${quote(installationId)})`;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Teach the node installer to honor the emitted flag

When a caller sets allowInsecureOrigin: true, this command invokes the downloaded node-install.pyz with an option its argparse definition does not accept (deploy/install/node_install.py:1258-1273), and that installer's origin() validator still rejects non-loopback http URLs. The intended external-HTTP enrollment therefore exits during argument parsing before installation begins; add the flag and conditional origin validation to the installer in the same change.

AGENTS.md reference: AGENTS.md:L13-L13

Useful? React with 👍 / 👎.

}

/**
Expand Down