fix(desktop): serve the current SSH session token
This commit is contained in:
@@ -102,7 +102,8 @@ def mount_spa(application: FastAPI):
|
||||
with a missing dist per-request (404 JSON / ``check_dir=False``), so a long-lived
|
||||
``--skip-build`` process recovers the moment a build appears on disk — no restart.
|
||||
"""
|
||||
from hermes_cli.web_server import WEB_DIST, _DASHBOARD_EMBEDDED_CHAT_ENABLED, _SESSION_TOKEN, app
|
||||
from hermes_cli import web_server as _web_server
|
||||
from hermes_cli.web_server import WEB_DIST, _DASHBOARD_EMBEDDED_CHAT_ENABLED, app
|
||||
|
||||
# `hermes serve` is the headless backend: it must NEVER serve the browser SPA, even if a
|
||||
# dist is lying around, so only the JSON-RPC/WS/API surface is reachable.
|
||||
@@ -120,7 +121,7 @@ def mount_spa(application: FastAPI):
|
||||
if full_path == "" and not gated:
|
||||
return HTMLResponse(
|
||||
"<!doctype html><html><head><script>"
|
||||
f"window.__HERMES_SESSION_TOKEN__={json.dumps(_SESSION_TOKEN)};"
|
||||
f"window.__HERMES_SESSION_TOKEN__={json.dumps(_web_server._SESSION_TOKEN)};"
|
||||
"window.__HERMES_AUTH_REQUIRED__=false;"
|
||||
f"</script></head><body>{_HEADLESS_MSG}</body></html>",
|
||||
headers=_NO_STORE,
|
||||
@@ -151,7 +152,7 @@ def mount_spa(application: FastAPI):
|
||||
return JSONResponse({"error": "Frontend not built. Run: cd web && npm run build"}, status_code=404)
|
||||
chat_js = "true" if _DASHBOARD_EMBEDDED_CHAT_ENABLED else "false"
|
||||
gated = bool(getattr(app.state, "auth_required", False))
|
||||
token_js = "" if gated else f'window.__HERMES_SESSION_TOKEN__="{_SESSION_TOKEN}";'
|
||||
token_js = "" if gated else f'window.__HERMES_SESSION_TOKEN__="{_web_server._SESSION_TOKEN}";'
|
||||
bootstrap_script = (
|
||||
f"<script>{token_js}"
|
||||
f"window.__HERMES_DASHBOARD_EMBEDDED_CHAT__={chat_js};"
|
||||
|
||||
@@ -5110,6 +5110,25 @@ class TestHeadlessServeTokenPage:
|
||||
assert _json.loads(match.group(1)) == ws._SESSION_TOKEN
|
||||
assert "window.__HERMES_AUTH_REQUIRED__=false" in resp.text
|
||||
|
||||
def test_root_uses_ssh_token_applied_after_spa_mount(self, monkeypatch):
|
||||
import json
|
||||
import re
|
||||
|
||||
import hermes_cli.web_server as ws
|
||||
|
||||
monkeypatch.setattr(ws, "_SESSION_TOKEN", "before-mount")
|
||||
client, ws = self._headless_client(monkeypatch, gated=False)
|
||||
|
||||
ws._apply_ssh_session_token("after-mount")
|
||||
resp = client.get("/")
|
||||
match = re.search(
|
||||
r'window\.__HERMES_SESSION_TOKEN__\s*=\s*("(?:\\.|[^"\\])*")',
|
||||
resp.text,
|
||||
)
|
||||
|
||||
assert match, resp.text
|
||||
assert json.loads(match.group(1)) == "after-mount"
|
||||
|
||||
def test_root_stays_404_json_when_auth_gated(self, monkeypatch):
|
||||
client, ws = self._headless_client(monkeypatch, gated=True)
|
||||
resp = client.get("/")
|
||||
|
||||
Reference in New Issue
Block a user