mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-19 19:32:18 +02:00
fix(browse): extension token bootstrap moves to pinned-origin POST; /health carries no token
GET /health is now liveness/status only in every mode — both token carve-outs (headed-mode disjunct AND chrome-extension:// Origin disjunct) are removed. Token bootstrap is POST /extension-token on the local listener: the Origin header must be exactly chrome-extension://<GSTACK_EXTENSION_ID> and the Host header's hostname must parse to 127.0.0.1 or localhost (parsed via new URL, never literal equality — Host arrives as '127.0.0.1:34567'). Wrong origin/host → 403 with no detail. The tunnel surface 404s the endpoint (not in TUNNEL_PATHS, verified by test). The extension ID is pinned by a new "key" field (RSA public key) in extension/manifest.json; browse/scripts/extension-id.ts reproduces the ID derivation (first 16 bytes of SHA-256 of the DER public key, hex mapped 0-9a-f → a-p). The private key is not committed anywhere — unpacked/baked-in loads only need the public key. Extension side: background.js bootstraps and refreshes the token via POST /extension-token (403 → disconnected state); sidepanel.js direct connect path does the same; sidepanel-terminal.js's dead /health token fallback (read AUTH_TOKEN/authToken keys the server never sent, hardcoded port) is replaced with the window.gstackAuthToken path. MIGRATION NOTE: the manifest key pins the extension ID, so existing installs' side-panel local state (saved port, snoozes) resets once — explained in-product via a one-time notice (flag gstack_id_migrated_v162). After upgrading the server, restart the browser so the old service worker stops polling for a token GET /health no longer serves. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> (cherry picked from commit e9a0b6847a2d17fe6656a4686b4efd0c8380eb09)
This commit is contained in:
@@ -22,14 +22,29 @@ function sliceBetween(source: string, startMarker: string, endMarker: string): s
|
||||
}
|
||||
|
||||
describe('Server auth security', () => {
|
||||
// Test 1: /health serves token conditionally (headed mode or chrome extension only)
|
||||
test('/health serves token only in headed mode or to chrome extensions', () => {
|
||||
// Test 1 (IRON RULE, inverted in v1.62): /health NEVER serves a token in
|
||||
// ANY mode. Both carve-outs (headed-mode disjunct + chrome-extension://
|
||||
// Origin disjunct) are gone. Token bootstrap moved to POST /extension-token
|
||||
// with a pinned extension Origin.
|
||||
test('/health never serves a token — no headed-mode or chrome-extension carve-out', () => {
|
||||
const healthBlock = sliceBetween(SERVER_SRC, "url.pathname === '/health'", "url.pathname === '/connect'");
|
||||
// v1.35.0.0: AUTH_TOKEN const was deleted; factory uses cfg-derived authToken.
|
||||
// Token must be conditional, not unconditional
|
||||
expect(healthBlock).toContain('token: authToken');
|
||||
expect(healthBlock).toContain('headed');
|
||||
expect(healthBlock).toContain('chrome-extension://');
|
||||
expect(healthBlock).not.toContain('token: authToken');
|
||||
expect(healthBlock).not.toContain("getConnectionMode() === 'headed'");
|
||||
expect(healthBlock).not.toContain("startsWith('chrome-extension://')");
|
||||
});
|
||||
|
||||
// Test 1a: the pinned-origin bootstrap endpoint exists and gates on both
|
||||
// the exact extension Origin and a loopback Host.
|
||||
test('POST /extension-token gates on pinned Origin and loopback Host', () => {
|
||||
const tokenBlock = sliceBetween(SERVER_SRC, "url.pathname === '/extension-token'", "url.pathname === '/health'");
|
||||
expect(tokenBlock).toContain('GSTACK_EXTENSION_ID');
|
||||
expect(tokenBlock).toContain('token: authToken');
|
||||
// Host is parsed to a hostname (arrives as '127.0.0.1:34567'), never
|
||||
// compared literally against the raw header.
|
||||
expect(tokenBlock).toContain('.hostname');
|
||||
expect(tokenBlock).toContain("'127.0.0.1'");
|
||||
expect(tokenBlock).toContain("'localhost'");
|
||||
expect(tokenBlock).toContain('403');
|
||||
});
|
||||
|
||||
// Test 1b: /health does not expose sensitive browsing state
|
||||
|
||||
Reference in New Issue
Block a user