fix: default WebUI bind host back to loopback (#412)

* fix: change default bind host to loopback for security across all components

* fix: update documentation and tests for loopback host configuration and security warnings
This commit is contained in:
Xi Zhang
2026-08-07 17:13:57 +01:00
committed by GitHub
parent b40b6f784d
commit 0c21a01f6f
12 changed files with 162 additions and 116 deletions
+15 -4
View File
@@ -346,10 +346,21 @@ def test_deploy_host_falls_back_when_config_lacks_field(monkeypatch, tmp_path):
assert captured["host_passed"] == "127.0.0.1"
def test_deploy_host_whitespace_collapses_to_default(monkeypatch, tmp_path):
"""``--host " "`` would reach socket.bind() as an empty string and raise
an opaque gaierror; it must degrade to the default instead."""
config = _make_config(default_workdir=str(tmp_path))
def test_deploy_blank_host_keeps_config_value(monkeypatch, tmp_path):
"""``--host " "`` means "not passed" (as in serve), so it must not discard
the configured bind."""
config = _make_config(
default_workdir=str(tmp_path), langgraph_dev_host="192.168.1.5"
)
captured = _run_deploy_once(monkeypatch, config, host=" ")
assert captured["host_passed"] == "192.168.1.5"
def test_deploy_blank_host_and_blank_config_use_default(monkeypatch, tmp_path):
"""Whitespace on both sides would reach socket.bind() as an empty string
and raise an opaque gaierror; it degrades to the default instead."""
config = _make_config(default_workdir=str(tmp_path), langgraph_dev_host=" ")
captured = _run_deploy_once(monkeypatch, config, host=" ")
assert captured["host_passed"] == "127.0.0.1"