fix(desktop): serve the current SSH session token

This commit is contained in:
thinkingsheep
2026-09-04 22:46:49 +08:00
committed by kshitij
parent b499ab11fe
commit 1866921d33
2 changed files with 23 additions and 3 deletions
+4 -3
View File
@@ -102,7 +102,8 @@ def mount_spa(application: FastAPI):
with a missing dist per-request (404 JSON / ``check_dir=False``), so a long-lived
``--skip-build`` process recovers the moment a build appears on disk — no restart.
"""
from hermes_cli.web_server import WEB_DIST, _DASHBOARD_EMBEDDED_CHAT_ENABLED, _SESSION_TOKEN, app
from hermes_cli import web_server as _web_server
from hermes_cli.web_server import WEB_DIST, _DASHBOARD_EMBEDDED_CHAT_ENABLED, app
# `hermes serve` is the headless backend: it must NEVER serve the browser SPA, even if a
# dist is lying around, so only the JSON-RPC/WS/API surface is reachable.
@@ -120,7 +121,7 @@ def mount_spa(application: FastAPI):
if full_path == "" and not gated:
return HTMLResponse(
"<!doctype html><html><head><script>"
f"window.__HERMES_SESSION_TOKEN__={json.dumps(_SESSION_TOKEN)};"
f"window.__HERMES_SESSION_TOKEN__={json.dumps(_web_server._SESSION_TOKEN)};"
"window.__HERMES_AUTH_REQUIRED__=false;"
f"</script></head><body>{_HEADLESS_MSG}</body></html>",
headers=_NO_STORE,
@@ -151,7 +152,7 @@ def mount_spa(application: FastAPI):
return JSONResponse({"error": "Frontend not built. Run: cd web && npm run build"}, status_code=404)
chat_js = "true" if _DASHBOARD_EMBEDDED_CHAT_ENABLED else "false"
gated = bool(getattr(app.state, "auth_required", False))
token_js = "" if gated else f'window.__HERMES_SESSION_TOKEN__="{_SESSION_TOKEN}";'
token_js = "" if gated else f'window.__HERMES_SESSION_TOKEN__="{_web_server._SESSION_TOKEN}";'
bootstrap_script = (
f"<script>{token_js}"
f"window.__HERMES_DASHBOARD_EMBEDDED_CHAT__={chat_js};"
+19
View File
@@ -5110,6 +5110,25 @@ class TestHeadlessServeTokenPage:
assert _json.loads(match.group(1)) == ws._SESSION_TOKEN
assert "window.__HERMES_AUTH_REQUIRED__=false" in resp.text
def test_root_uses_ssh_token_applied_after_spa_mount(self, monkeypatch):
import json
import re
import hermes_cli.web_server as ws
monkeypatch.setattr(ws, "_SESSION_TOKEN", "before-mount")
client, ws = self._headless_client(monkeypatch, gated=False)
ws._apply_ssh_session_token("after-mount")
resp = client.get("/")
match = re.search(
r'window\.__HERMES_SESSION_TOKEN__\s*=\s*("(?:\\.|[^"\\])*")',
resp.text,
)
assert match, resp.text
assert json.loads(match.group(1)) == "after-mount"
def test_root_stays_404_json_when_auth_gated(self, monkeypatch):
client, ws = self._headless_client(monkeypatch, gated=True)
resp = client.get("/")