Skip to content

feat(core): accept non-loopback HTTP origin behind OAC_ALLOW_INSECURE_ORIGIN (snapshot) - #7

Merged
sunyalou merged 1 commit into
mainfrom
feat/core-allow-insecure-origin-snapshot
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
feat/core-allow-insecure-origin-snapshot

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

OAC-3 重做(替代已关闭的 PR #3):Core 在 OAC_ALLOW_INSECURE_ORIGIN 打开时接受非 loopback 的 http:// public origin,正常派生 ws:// daemon URL;默认关闭时行为与文案完全不变。落点按 OAC-9 报告 §3.1 任务 A:开关归属 services/core/internal/processconfig,Settings() 上报快照供 GET /core/v1/installation 与控制台读取。

基线 origin/main = 13a59e1b(旧 PR #3 基于 28d34ff0 的旧安装器架构,已关闭)。

改动(6 文件,全在 services/core)

  • internal/deployment/public_url.go:新增导出 ValidateCoreURLAllowingInsecure,与 ValidateCoreURL 共享私有实现 validateCoreURL(value, allowInsecure);唯一差异是开启时接受非 loopback http。ValidateCoreURL 签名与语义不变,共享向量不弱化;变体导出供任务 D(OAC-4)复用。
  • internal/processconfig/config.go:新增 allowInsecureOrigin()(仅 "1" 开启,与 daemon apps/daemon/internal/cli/connect_environment.go:45-47 的 insecureOriginAllowed() 完全一致,无别名/fallback);PublicURL() 开启时改用放宽变体,关闭时错误文案逐字节不变;Settings() 新增顶层 key allow_insecure_origin(默认 false,restarts: ["core"],按 §2.3 裁决:Web 只读快照,无需重启 Web)。
  • 测试:internal/deployment/rules_test.go(insecure 变体 + 断言默认契约仍拒绝非 loopback http)、internal/processconfig/config_test.go(开关开/关/非法值、关闭文案不变、Settings() 上报默认 false / 开启 true)、cmd/server/process_configuration_test.go(开关开时 PublicURL 接受 http://IP 且 runtimeWebSocketURL 派生 ws://IP/...;installationFacts 快照携带 allow_insecure_origin)、cmd/server/daemon_bootstrap_test.go(https→wss / http→ws 映射,含非 loopback 与 IPv6)。

未改 services/web、deploy/、api.Installation 结构;快照经既有 Settings() → installationFacts(services/core/cmd/server/installation.go:32-36)自动携带,不扩张接口。

验收对照

验收 结果
关闭时 http://IP 仍被拒且文案不变 TestPublicURLAcceptsInsecureOriginOnlyWhenEnabled 断言精确错误文案;TestPublicURLMustBeACanonicalOrigin 仍拒 http://core.example
开启时 PublicURL 接受 http://IP TestPublicURLAcceptsInsecureOriginOnlyWhenEnabled、TestPublicURLDrivesInsecureWebSocketURL
runtimeWebSocketURL 产出 ws://IP/... TestRuntimeWebSocketURL、TestPublicURLDrivesInsecureWebSocketURL
GET /core/v1/installation 上报 allow_insecure_origin TestInstallationFactsReportAllowInsecureOrigin(installationFacts → Settings(),值 true、默认 false)

验证

命令 结果
make check-names PASS
make check-runtime-contract PASS(exit 0)
make check-core internal/processconfig、internal/deployment、cmd/server 等 56 包 ok;check-core-store 461 tests ok;两个 Python 测试 ok;仅 internal/nativeinstaller 失败(见下)

internal/nativeinstaller 失败与本改动无关,且已独立确认:

  • git diff 13a59e1b..HEAD -- services/core/internal/nativeinstaller 为空(包字节未变);
  • 在 clean base 13a59e1b 上同样 FAIL,报错一致:环境 curl 7.29.0/NSS 对 --max-time 0.3 报 “expected a proper numerical parameter”,且拒绝 httptest 证书(Certificate type not approved for application)。

OAC_TEST_DATABASE_URL 未配置,store 集成测试按设计 skip(package ok)。

已知限制

  • 放宽仅在显式 OAC_ALLOW_INSECURE_ORIGIN=1 时生效,此时凭据/API key 走明文,仅面向开发/测试。
  • 不改 TLS 证书校验,不引入 InsecureSkipVerify。

Refs: OAC-3;OAC-9 §3.1 任务 A;替代已关闭的 PR #3。

…_ORIGIN

Add an explicitly named ValidateCoreURLAllowingInsecure variant and select it
in processconfig.PublicURL when the deployment-owned OAC_ALLOW_INSECURE_ORIGIN
is "1". ValidateCoreURL keeps its signature and default contract, so a Core
without the switch behaves exactly as before and the shared origin vectors stay
unchanged. Settings reports the effective allow_insecure_origin so
GET /core/v1/installation carries it in the console snapshot, and the relaxed
origin still derives ws:// through runtimeWebSocketURL.

Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit 8551deb into main Oct 3, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant