Skip to content

fix: bind login OAuth to paired API origin and default local execute to public network - #21

Merged
kody-bot merged 1 commit into
mainfrom
devin/1790975349-local-execute-hardening
Oct 2, 2026
Merged

kody-bot merged 1 commit into
mainfrom
devin/1790975349-local-execute-hardening

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

Security hardening from the Open API + CLI audit (findings 3 and 7).

  • OAuth fallback bound to the paired API origin (finding 3): resolveLocalExecuteBearer used to send the kody login OAuth access token to whatever --api-url / KODY_API_URL pointed at, as long as it was HTTPS. Now isPairedApiUrl(apiUrl, mcpUrl) must pass before the OAuth fallback is used:

    • https://api.<mcp host>, e.g. kody.codes/mcp ↔ api.kody.codes
    • preview workers: <name>.<sub>.workers.dev ↔ <name>-api.<sub>.workers.dev
    • loopback ↔ loopback on any port

    Anything else throws an error that names the expected API origin and tells you to use kody auth bootstrap --code … --api-url <api> or KODY_API_TOKEN. An explicit --token / KODY_API_TOKEN, or a stored per-origin bootstrap token, still works for any HTTPS API URL.

  • Local workerd is public-network-only by default (finding 7): createWorkerdConfig now sets allow = ["public"]. The new --allow-private-network flag restores ["public", "private", "local"], and using it without execute --local is an error. The loopback CapabilityProxy bridge is a separate external service, so it keeps working either way.

  • README, help text, and skills/kody/SKILL.md are updated.

Behavior change: local scripts that fetch LAN or localhost services now need --allow-private-network. kody login users who point --local at a non-paired API origin need a bootstrap code or KODY_API_TOKEN for that host.

Companion server-side PR: kentcdodds/kody#2848 (findings 1, 2, 4, 5, 6).

Testing

npm run validate passes: typecheck, 138 tests, and build. New tests cover the paired, mismatched, explicit-token, stored-token, loopback, and preview cases, the network allow list with and without the flag, and the flag validation.

Co-Authored-By: Kent C. Dodds <me@kentcdodds.com>
@kentcdodds

Copy link
Copy Markdown
Owner Author

bugbot run

@cursor

cursor Bot commented Oct 2, 2026

Copy link
Copy Markdown

Skipping Bugbot: Bugbot is disabled for this repository. Visit the Bugbot dashboard to update your settings.

@kody-bot
kody-bot merged commit 6979f10 into main Oct 2, 2026
5 checks passed
@kody-bot
kody-bot deleted the devin/1790975349-local-execute-hardening branch October 2, 2026 22:25
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.10.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants