Skip to content

feat(installer): add allow_insecure_origin setting - #8

Merged
sunyalou merged 1 commit into
mainfrom
feat/installer-allow-insecure-origin
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
feat/installer-allow-insecure-origin

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Summary

Task B of OAC-2 on the post-refactor architecture. Upstream PR MiniMax-AI#402 replaced the Python deploy/install/ installer with deploy/compose/ + deploy/install.sh + a Go oac, so the earlier installer PR (#2) was obsolete. Core already consumes the switch (Task A, merged as PR #7), but the deployment side had no way to set it.

This PR adds --allow-insecure-origin to install.sh / install.dev.sh, writes OAC_ALLOW_INSECURE_ORIGIN=1 to the installation .env, and passes that variable through to the Core service in compose.yaml. Default stays off: without the flag the variable is absent, so Core keeps rejecting a non-loopback HTTP origin with its original message. TLS certificate verification is unchanged.

Baseline: origin/main @ 8551deb4.

Changes

  • deploy/compose/compose.yaml: pass OAC_ALLOW_INSECURE_ORIGIN to the core service only (${OAC_ALLOW_INSECURE_ORIGIN:-}); the web service is unchanged (Web reads the Core snapshot, not the env).
  • deploy/install.sh: --allow-insecure-origin flag, usage text, and the conditional .env line.
  • deploy/install.dev.sh: the same flag and .env line for a local checkout.
  • deploy/compose/test_compose.py: OAC_ALLOW_INSECURE_ORIGIN defaults to empty on core, and a new test asserts it passes through to core only.
  • deploy/test_install.py: a new test asserts the .env key is written only with the flag, plus the help-text assertion.
  • docs/configuration.md and docs/getting-started/install-options.md (+ Chinese translations, source_hash updated): document the setting, the flag, and the plaintext risk.

Verification

Run on the branch (feat/installer-allow-insecure-origin @ 92b7566f, base origin/main @ 8551deb4):

  • make check-names → OK (15 tests; OpenAgentCore name guard passed.)
  • make check-docs → OK (6 tests)
  • make check-ci → OK (46 tests)
  • make check-website → OK (build + 22 tests, including the Chinese-translation freshness check)
  • make check-distribution → OK (exit 0)
    • Limitation (pre-existing, unrelated to this change): this host's /usr/bin/openssl is OpenSSL 1.0.2k, while deploy/node/test_node_proxy.py calls openssl … -addext; an earlier deploy/node test resets PATH to node_install.SAFE_PATH, which drops the directory providing OpenSSL 3.6.3, so the deploy/node suite fails in setUpClass on the raw host. With the modern OpenSSL directory added to SAFE_PATH (the workaround the OAC-2 test verifier documented) the full target passes. CI uses a newer system OpenSSL and is unaffected. This change touches no deploy/node code.
  • python3 deploy/test_install.py → OK (4 tests), deploy/compose suite → OK (5 tests)
  • python3 scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene, distribution, compose, website

Acceptance (Task B)

--allow-insecure-origin writes .env and check-config reads it; without it, a non-loopback http:// fails before the installation can be managed. Demonstrated with the merged Core binary (go build ./services/core/cmd/server):

# switch off + http://10.0.0.5:8080
OAC_PUBLIC_URL must be a canonical HTTPS origin without path, credentials, query or fragment, such as https://core.example; plain HTTP is accepted only for a loopback host   (exit 1)

# switch on + http://10.0.0.5:8080
(exit 0)

# switch on + http://10.0.0.5:8080/path
OAC_PUBLIC_URL must be a canonical origin without path, credentials, query or fragment, such as https://core.example; plain HTTP is accepted because OAC_ALLOW_INSECURE_ORIGIN is set   (exit 1)

The .env → Compose → Core hop is covered by test_compose.py (pass-through to core only) and test_install.py (the .env key is written only with the flag).

Merge order

Task A (Core, OAC-3) is already merged (PR #7). This is task B; tasks C (OAC-6, Web console) and D (OAC-4/OAC-8, node link) follow the confirmed A → B → C → D order. This PR can be reviewed and merged now; C and D rebase on it.

Write OAC_ALLOW_INSECURE_ORIGIN=1 to the installation .env when install.sh
(or install.dev.sh) runs with --allow-insecure-origin, and pass it through
to Core in compose.yaml. Core already reads the switch (processconfig) to
accept a non-loopback plain-HTTP OAC_PUBLIC_URL; the deployment side owned
no way to set it after the Compose refactor.

Default stays off: without the flag the variable is absent and Core keeps
rejecting a non-loopback HTTP origin with its original message. TLS
certificate verification is unchanged.

- deploy/compose/compose.yaml: pass OAC_ALLOW_INSECURE_ORIGIN to core only.
- deploy/install.sh, deploy/install.dev.sh: --allow-insecure-origin flag,
  usage text, and .env line.
- deploy/compose/test_compose.py, deploy/test_install.py: cover the
  pass-through and the .env key.
- docs/configuration.md, docs/getting-started/install-options.md and their
  Chinese translations.

Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit 3f0a737 into main Oct 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant