feat(web): offer plain-HTTP node commands with allow_insecure_origin - #9
Merged
Merged
Conversation
Redo the Web side of the switch on the current main. The console reads `allow_insecure_origin` only from Core's installation settings snapshot, so there is no second source and no `/console/config` field. - apps/web: `isValidDirectCoreBaseUrl`/`nodeSourceUrl` take an `allowInsecure` flag; NodeEnrollment and NodeCleanupDialog compute the switch from the snapshot and offer `http://IP:8080` commands. Add node warns that the enrollment token and node credentials travel unencrypted; the cleanup dialog drops "HTTPS" from its message only when the switch is on. - Fixture gains "http" (switch off) and "insecure" (switch on) installation modes; nodes.spec.ts covers both and closes the Add node dialog before reopening it over the same #nodes hash (OAC-11). - Docs note the switch in the console's public-address section. Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
在新架构(
origin/main8551deb4)上重做 Web 控制台的allow_insecure_origin支持(替代已关闭的 PR #4)。开关打开时 Add node 生成http://IP:8080注册命令并显示明文风险警告,主机清理同样生成 http 卸载命令;默认关闭时命令与文案逐字不变。不改 TLS 校验,不引入InsecureSkipVerify。关键设计(与旧 PR #4 的差异)
CoreInstallation.configuration.settings的allow_insecure_origin读取开关(allowsInsecureOrigin(installation))。不读OAC_ALLOW_INSECURE_ORIGIN、不改services/web/config.go/node_installation.go、不在/console/config新增字段、不改console-config.ts——旧 PR feat(web): allow a plain-HTTP public URL with allow_insecure_origin #4 的 Web 侧 env 回退已按 OAC-9 设计移除。改动
apps/web/src/lib/connection.ts:isValidDirectCoreBaseUrl(value, allowInsecure = false),仅开关打开时接受非 loopback HTTP;凭据/查询/片段/非 http(s) 仍拒绝。apps/web/src/features/sandbox/core-origin.ts:nodeSourceUrl(installation, allowInsecure = false);新增allowsInsecureOrigin(installation)(仅快照)。apps/web/src/features/sandbox/NodeEnrollment.tsx:由快照计算开关,放宽命令来源;开关打开且public_url为 HTTP 时显示明文风险警告。apps/web/src/features/sandbox/NodeCleanupDialog.tsx:同样由快照计算开关并放宽卸载命令来源;仅在开关打开时去掉提示文案里的 "HTTPS"。apps/web/src/features/sandbox/SandboxManagerView.css:明文告警样式。apps/web/src/lib/locale-strings.ts:明文告警与放宽后卸载文案的中文条目。installation新增"http"(HTTP 地址、开关关)与"insecure"(同一地址、开关开)两种模式;apps/web/e2e/nodes.spec.ts覆盖开关开/关两侧。docs/web/console-server.md+docs/zh/web/console-server.md(公开地址小节,含source_hash)。OAC-11 e2e 修复(并入本 PR)
nodes.spec.ts新增用例在再次openConsole之前先Close dialog并断言弹窗隐藏,避免 same-document 导航不重载时残留遮罩拦截点击(根因见 OAC-11);用例保留。Set a public HTTPS address before adding nodes.(上游a2946a7f后)。验证
make check-web-unit:通过(typecheck + agents-client 765 + web 448 单测 + build)。make check-names:通过。core-origin.test.ts、connection.test.ts、NodeCleanupDialog.test.tsx共 57 例通过。make check-web-acceptance:本环境无法执行——Chromium distribution 'chrome' is not found at /opt/google/chrome/chrome(本机无 Google Chrome、无 root 安装,自带 Chromium 需 GLIBC_2.25 而本机 2.17),82 failed 全为同一浏览器启动错误。已 push,CI 的web-acceptance作业会补跑,结果见 PR Checks。已知限制
web-acceptance作业(本机架构性不可执行,见上)。.env/compose)与节点链路在任务 B/D。