Repository navigation
fix: bind login OAuth to paired API origin and default local execute to public network - #21
Merged
Merged
Conversation
Co-Authored-By: Kent C. Dodds <me@kentcdodds.com>
Owner
Author
|
bugbot run |
|
Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings. |
|
🎉 This PR is included in version 1.10.1 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security hardening from the Open API + CLI audit (findings 3 and 7).
OAuth fallback bound to the paired API origin (finding 3):
resolveLocalExecuteBearerused to send thekody loginOAuth access token to whatever--api-url/KODY_API_URLpointed at, as long as it was HTTPS. NowisPairedApiUrl(apiUrl, mcpUrl)must pass before the OAuth fallback is used:https://api.<mcp host>, e.g.kody.codes/mcp↔api.kody.codes<name>.<sub>.workers.dev↔<name>-api.<sub>.workers.devAnything else throws an error that names the expected API origin and tells you to use
kody auth bootstrap --code … --api-url <api>orKODY_API_TOKEN. An explicit--token/KODY_API_TOKEN, or a stored per-origin bootstrap token, still works for any HTTPS API URL.Local workerd is public-network-only by default (finding 7):
createWorkerdConfignow setsallow = ["public"]. The new--allow-private-networkflag restores["public", "private", "local"], and using it withoutexecute --localis an error. The loopback CapabilityProxy bridge is a separate external service, so it keeps working either way.README, help text, and
skills/kody/SKILL.mdare updated.Behavior change: local scripts that fetch LAN or localhost services now need
--allow-private-network.kody loginusers who point--localat a non-paired API origin need a bootstrap code orKODY_API_TOKENfor that host.Companion server-side PR: kentcdodds/kody#2848 (findings 1, 2, 4, 5, 6).
Testing
npm run validatepasses: typecheck, 138 tests, and build. New tests cover the paired, mismatched, explicit-token, stored-token, loopback, and preview cases, the network allow list with and without the flag, and the flag validation.