A non-loopback dashboard.public_url engaged the ticket-only auth gate for EVERY hermes serve on the machine — including the private loopback backends the Desktop app spawns for itself (HERMES_DESKTOP=1). Those backends authenticate with the per-spawn session token, which the gated WS path refuses outright, so Desktop failed to boot with: Local Hermes backend is HTTP-reachable but the WebSocket (/api/ws) rejected the session token. The public_url describes a DIFFERENT deployment: the actual public dashboard is a separate process on a non-loopback bind whose own startup keeps its gate. Exempting Desktop-owned loopback backends therefore never opens the public surface. Exemption requires ALL of: loopback bind, HERMES_DESKTOP=1 (set by every Desktop spawn path, local and SSH), and an operator-minted credential (HERMES_DASHBOARD_SESSION_TOKEN, SSH session token, or owner nonce). Non-Desktop serves and non-loopback binds keep the exact previous behaviour — verified by regression tests on both sides of the boundary. Fixes #96490
2 lines
8 B
Plaintext
2 lines
8 B
Plaintext
Agi-Asi
|