feat(core): accept non-loopback HTTP origin behind OAC_ALLOW_INSECURE_ORIGIN (snapshot) - #7
Merged
Conversation
…_ORIGIN Add an explicitly named ValidateCoreURLAllowingInsecure variant and select it in processconfig.PublicURL when the deployment-owned OAC_ALLOW_INSECURE_ORIGIN is "1". ValidateCoreURL keeps its signature and default contract, so a Core without the switch behaves exactly as before and the shared origin vectors stay unchanged. Settings reports the effective allow_insecure_origin so GET /core/v1/installation carries it in the console snapshot, and the relaxed origin still derives ws:// through runtimeWebSocketURL. Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
OAC-3 重做(替代已关闭的 PR #3):Core 在
OAC_ALLOW_INSECURE_ORIGIN打开时接受非 loopback 的http://public origin,正常派生ws://daemon URL;默认关闭时行为与文案完全不变。落点按 OAC-9 报告 §3.1 任务 A:开关归属services/core/internal/processconfig,Settings()上报快照供GET /core/v1/installation与控制台读取。基线
origin/main=13a59e1b(旧 PR #3 基于28d34ff0的旧安装器架构,已关闭)。改动(6 文件,全在
services/core)internal/deployment/public_url.go:新增导出ValidateCoreURLAllowingInsecure,与ValidateCoreURL共享私有实现validateCoreURL(value, allowInsecure);唯一差异是开启时接受非 loopbackhttp。ValidateCoreURL签名与语义不变,共享向量不弱化;变体导出供任务 D(OAC-4)复用。internal/processconfig/config.go:新增allowInsecureOrigin()(仅"1"开启,与 daemonapps/daemon/internal/cli/connect_environment.go:45-47的insecureOriginAllowed()完全一致,无别名/fallback);PublicURL()开启时改用放宽变体,关闭时错误文案逐字节不变;Settings()新增顶层 keyallow_insecure_origin(默认false,restarts: ["core"],按 §2.3 裁决:Web 只读快照,无需重启 Web)。internal/deployment/rules_test.go(insecure 变体 + 断言默认契约仍拒绝非 loopback http)、internal/processconfig/config_test.go(开关开/关/非法值、关闭文案不变、Settings()上报默认 false / 开启 true)、cmd/server/process_configuration_test.go(开关开时PublicURL接受http://IP且runtimeWebSocketURL派生ws://IP/...;installationFacts快照携带allow_insecure_origin)、cmd/server/daemon_bootstrap_test.go(https→wss/http→ws映射,含非 loopback 与 IPv6)。未改
services/web、deploy/、api.Installation结构;快照经既有Settings()→installationFacts(services/core/cmd/server/installation.go:32-36)自动携带,不扩张接口。验收对照
http://IP仍被拒且文案不变TestPublicURLAcceptsInsecureOriginOnlyWhenEnabled断言精确错误文案;TestPublicURLMustBeACanonicalOrigin仍拒http://core.examplePublicURL接受http://IPTestPublicURLAcceptsInsecureOriginOnlyWhenEnabled、TestPublicURLDrivesInsecureWebSocketURLruntimeWebSocketURL产出ws://IP/...TestRuntimeWebSocketURL、TestPublicURLDrivesInsecureWebSocketURLGET /core/v1/installation上报allow_insecure_originTestInstallationFactsReportAllowInsecureOrigin(installationFacts→Settings(),值 true、默认 false)验证
make check-namesmake check-runtime-contractmake check-coreinternal/processconfig、internal/deployment、cmd/server等 56 包 ok;check-core-store461 tests ok;两个 Python 测试 ok;仅internal/nativeinstaller失败(见下)internal/nativeinstaller失败与本改动无关,且已独立确认:git diff 13a59e1b..HEAD -- services/core/internal/nativeinstaller为空(包字节未变);13a59e1b上同样 FAIL,报错一致:环境 curl 7.29.0/NSS 对--max-time 0.3报 “expected a proper numerical parameter”,且拒绝 httptest 证书(Certificate type not approved for application)。OAC_TEST_DATABASE_URL未配置,store 集成测试按设计 skip(package ok)。已知限制
OAC_ALLOW_INSECURE_ORIGIN=1时生效,此时凭据/API key 走明文,仅面向开发/测试。InsecureSkipVerify。Refs: OAC-3;OAC-9 §3.1 任务 A;替代已关闭的 PR #3。