Require the hook-event secret unconditionally, not only under a managed tunnel

COD-54 gated the /api/hook-event + /api/status-telemetry localhost bypass
behind the shared X-Codeman-Hook-Secret only WHILE a managed tunnel was
running, keeping a plain localhost bypass otherwise. But Codeman can't detect
a user's OWN loopback reverse proxy (their own `cloudflared --url`,
`tailscale serve`, nginx -> 127.0.0.1), which proxies internet traffic into
the loopback origin with req.ip === 127.0.0.1 — so that setup kept the unsafe
plain bypass.

Require the secret on the loopback bypass unconditionally. Managed-session
hooks already always present it (X-Codeman-Hook-Secret from
$CODEMAN_HOOK_SECRET_FILE, generated for every instance), so the legitimate
hook channel is unaffected; only the previously-unguarded own-proxy path is
now rejected. Drops the now-unused getTunnelRunning param from
registerAuthMiddleware.

Tests: cod54-hook-event-auth (tunnel-down now also requires the secret, plus
a good-secret positive case); auth-security (hook tests present the secret to
reach schema validation).
This commit is contained in:
Aamer Akhter
2026-06-14 12:46:58 -04:00
parent e742d00c98
commit f0f43ddbad
4 changed files with 37 additions and 39 deletions
+7 -6
View File
@@ -14,6 +14,7 @@ import { describe, it, expect, beforeAll, afterAll, beforeEach, afterEach, vi }
import { WebServer } from '../src/web/server.js';
import { TmuxManager } from '../src/tmux-manager.js';
import { SettingsUpdateSchema } from '../src/web/schemas.js';
import { getHookSecret, HOOK_SECRET_HEADER } from '../src/config/hook-secret.js';
const AUTH_PORT = 3160;
const NOAUTH_PORT = 3161;
@@ -250,28 +251,28 @@ describe('Auth Security', () => {
});
describe('Hook Event Endpoint', () => {
it('should allow hook events from localhost without auth', async () => {
it('should allow hook events from localhost with the hook secret (no Basic auth)', async () => {
const res = await fetch(`${baseUrl}/api/hook-event`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
headers: { 'Content-Type': 'application/json', [HOOK_SECRET_HEADER]: getHookSecret() },
body: JSON.stringify({
event: 'stop',
sessionId: 'nonexistent-session',
data: {},
}),
});
// Should pass auth (localhost bypass) but may 404 on session — that's fine
// The key assertion is it does NOT return 401
// Should pass auth (localhost bypass + hook secret) but may 404 on session — that's fine.
// The key assertion is it does NOT return 401 (COD-91: secret required even with no tunnel).
expect(res.status).not.toBe(401);
});
it('should reject hook events with invalid schema', async () => {
const res = await fetch(`${baseUrl}/api/hook-event`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
headers: { 'Content-Type': 'application/json', [HOOK_SECRET_HEADER]: getHookSecret() },
body: JSON.stringify({ invalid: 'data' }),
});
// Schema validation should catch this
// Past the auth gate (valid secret) → schema validation should catch this (not a 401).
expect(res.status).not.toBe(401); // Not an auth error
});
});
+15 -6
View File
@@ -4,15 +4,19 @@
* The `/api/hook-event` localhost bypass let tunnel traffic (cloudflared
* --url http://127.0.0.1:port) reach the loopback origin with req.ip ===
* 127.0.0.1 and drive respawn/Ralph signals unauthenticated. The fix gates
* the bypass behind a shared hook secret WHEN A TUNNEL IS RUNNING, while
* keeping the plain localhost bypass for the normal loopback-only case so
* already-deployed (pre-secret) hooks and the loop's own channel keep working.
* the bypass behind a shared hook secret. COD-91 makes that requirement
* UNCONDITIONAL — the loopback bypass requires the secret whether or not a
* managed tunnel is running, because Codeman can't detect a user's own loopback
* reverse proxy (own cloudflared / `tailscale serve` / nginx → 127.0.0.1).
* Managed-session hooks always present the secret, so the legitimate channel
* keeps working.
*
* Tests:
* - tunnel running + no secret → 401 (closes the hole)
* - tunnel running + bad secret → 401
* - tunnel running + good secret → not 401 (allowed)
* - tunnel NOT running + no secret → not 401 (back-compat regression guard)
* - tunnel NOT running + no secret → 401 (COD-91: secret required unconditionally)
* - tunnel NOT running + good secret → not 401 (allowed)
* - rate limiting: rapid unauthorized hook POSTs eventually 429
*
* Port: 3230 (tunnel-running), 3231 (tunnel-down), 3232 (rate-limit)
@@ -83,7 +87,7 @@ describe('COD-54 hook-event auth — tunnel running requires secret', () => {
});
});
describe('COD-54 hook-event auth — tunnel down keeps localhost bypass (back-compat)', () => {
describe('COD-91 hook-event auth — tunnel down ALSO requires the secret', () => {
let server: WebServer;
let baseUrl: string;
let isRunningSpy: ReturnType<typeof vi.spyOn>;
@@ -105,8 +109,13 @@ describe('COD-54 hook-event auth — tunnel down keeps localhost bypass (back-co
delete process.env.CODEMAN_USERNAME;
});
it('still allows a localhost hook POST WITHOUT a secret (existing hooks + loop channel keep working)', async () => {
it('rejects a localhost hook POST WITHOUT a secret even with no tunnel (COD-91)', async () => {
const res = await postHook(baseUrl);
expect(res.status).toBe(401);
});
it('allows a localhost hook POST WITH the correct secret when no tunnel is running', async () => {
const res = await postHook(baseUrl, { [HOOK_SECRET_HEADER]: getHookSecret() });
expect(res.status).not.toBe(401);
});
});