mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-20 20:00:45 +02:00
fix(browse): extension token bootstrap moves to pinned-origin POST; /health carries no token
GET /health is now liveness/status only in every mode — both token carve-outs (headed-mode disjunct AND chrome-extension:// Origin disjunct) are removed. Token bootstrap is POST /extension-token on the local listener: the Origin header must be exactly chrome-extension://<GSTACK_EXTENSION_ID> and the Host header's hostname must parse to 127.0.0.1 or localhost (parsed via new URL, never literal equality — Host arrives as '127.0.0.1:34567'). Wrong origin/host → 403 with no detail. The tunnel surface 404s the endpoint (not in TUNNEL_PATHS, verified by test). The extension ID is pinned by a new "key" field (RSA public key) in extension/manifest.json; browse/scripts/extension-id.ts reproduces the ID derivation (first 16 bytes of SHA-256 of the DER public key, hex mapped 0-9a-f → a-p). The private key is not committed anywhere — unpacked/baked-in loads only need the public key. Extension side: background.js bootstraps and refreshes the token via POST /extension-token (403 → disconnected state); sidepanel.js direct connect path does the same; sidepanel-terminal.js's dead /health token fallback (read AUTH_TOKEN/authToken keys the server never sent, hardcoded port) is replaced with the window.gstackAuthToken path. MIGRATION NOTE: the manifest key pins the extension ID, so existing installs' side-panel local state (saved port, snoozes) resets once — explained in-product via a one-time notice (flag gstack_id_migrated_v162). After upgrading the server, restart the browser so the old service worker stops polling for a token GET /health no longer serves. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> (cherry picked from commit e9a0b6847a2d17fe6656a4686b4efd0c8380eb09)
This commit is contained in:
@@ -504,7 +504,8 @@
|
||||
window.gstackScanForPTYInject = async function (text, origin) {
|
||||
if (!text) return { allow: false, verdict: 'BLOCK', reasons: ['empty-text'] };
|
||||
try {
|
||||
const resp = await fetch('http://127.0.0.1:34567/pty-inject-scan', {
|
||||
const serverPort = getServerPort() || 34567;
|
||||
const resp = await fetch(`http://127.0.0.1:${serverPort}/pty-inject-scan`, {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
@@ -529,21 +530,13 @@
|
||||
};
|
||||
|
||||
// The auth token for /pty-inject-scan comes from the same source the
|
||||
// sidepanel uses for /pty-session — a runtime fetch from /health (which
|
||||
// already returns AUTH_TOKEN in headed mode per CLAUDE.md's v1.1 TODO).
|
||||
// We don't echo the token here; this helper is a thin proxy around the
|
||||
// existing pattern.
|
||||
// sidepanel uses for /pty-session — window.gstackAuthToken, set by
|
||||
// sidepanel.js after the pinned-origin POST /extension-token bootstrap.
|
||||
// The old fallback here fetched /health and read token keys the server
|
||||
// never sent (AUTH_TOKEN/authToken) — dead code since /health stopped
|
||||
// carrying any token.
|
||||
async function getAuthTokenForScan() {
|
||||
if (window.__gstackPtyScanToken) return window.__gstackPtyScanToken;
|
||||
try {
|
||||
const resp = await fetch('http://127.0.0.1:34567/health');
|
||||
const body = await resp.json();
|
||||
const token = body.AUTH_TOKEN || body.authToken || '';
|
||||
if (token) window.__gstackPtyScanToken = token;
|
||||
return token;
|
||||
} catch {
|
||||
return '';
|
||||
}
|
||||
return getAuthToken() || '';
|
||||
}
|
||||
|
||||
async function connect() {
|
||||
|
||||
Reference in New Issue
Block a user