diff --git a/hermes_cli/web_server_dashboard.py b/hermes_cli/web_server_dashboard.py index ca54274b82..c0bc261ca0 100644 --- a/hermes_cli/web_server_dashboard.py +++ b/hermes_cli/web_server_dashboard.py @@ -102,7 +102,8 @@ def mount_spa(application: FastAPI): with a missing dist per-request (404 JSON / ``check_dir=False``), so a long-lived ``--skip-build`` process recovers the moment a build appears on disk — no restart. """ - from hermes_cli.web_server import WEB_DIST, _DASHBOARD_EMBEDDED_CHAT_ENABLED, _SESSION_TOKEN, app + from hermes_cli import web_server as _web_server + from hermes_cli.web_server import WEB_DIST, _DASHBOARD_EMBEDDED_CHAT_ENABLED, app # `hermes serve` is the headless backend: it must NEVER serve the browser SPA, even if a # dist is lying around, so only the JSON-RPC/WS/API surface is reachable. @@ -120,7 +121,7 @@ def mount_spa(application: FastAPI): if full_path == "" and not gated: return HTMLResponse( "{_HEADLESS_MSG}", headers=_NO_STORE, @@ -151,7 +152,7 @@ def mount_spa(application: FastAPI): return JSONResponse({"error": "Frontend not built. Run: cd web && npm run build"}, status_code=404) chat_js = "true" if _DASHBOARD_EMBEDDED_CHAT_ENABLED else "false" gated = bool(getattr(app.state, "auth_required", False)) - token_js = "" if gated else f'window.__HERMES_SESSION_TOKEN__="{_SESSION_TOKEN}";' + token_js = "" if gated else f'window.__HERMES_SESSION_TOKEN__="{_web_server._SESSION_TOKEN}";' bootstrap_script = ( f"