Sidecar: auth always-on, protocol version, rich health
Auth is now impossible to turn off by accident. A blank auth_token is never allowed even on loopback: config load generates a token, writes it back into sidecar.toml (preserving the rest of the file), logs it, and continues -- so a forgotten or cleared token self-heals into a working, authenticated setup instead of silently disabling auth. No auth token configured. Generated new token: cb99... Saved to sidecar.toml. Authentication is on. Protocol versioning (PROTOCOL_VERSION = 1) lets the website and sidecar detect a mismatch immediately when a message shape changes. Every response carries an X-UOLink-Version header; /health and ws.hello include "protocol"; a request that declares a different X-UOLink-Version is rejected 409 with both versions so the mismatch is unambiguous. Bump the constant when a contract changes. /health is now a real troubleshooting panel: status (ok/degraded), protocol, plugin_connected (is the shard link up), database (SELECT 1), uptime, and last_event (the timestamp of the last line from the shard). Unauthenticated so monitoring can reach it. Verified: a blank token generates + persists + enforces (401 without, 200 with); X-UOLink-Version header on every response; 409 on a declared mismatch; /health reports degraded/plugin_connected:false with no shard, then flips to ok/true and a populated last_event once the shard connects. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -22,8 +22,8 @@ bind = "127.0.0.1:8080"
|
||||
# Shared secret the website must present on every request:
|
||||
# REST: Authorization: Bearer <token> (or X-Api-Key: <token>)
|
||||
# WebSocket: add ?token=<token> to the connect URL
|
||||
# Empty disables auth, which is only allowed on a loopback bind (a warning is logged).
|
||||
# Rotate by changing this value and restarting.
|
||||
# Authentication is ALWAYS on. If this is left blank, the sidecar generates a token
|
||||
# here on startup and logs it. Rotate by changing this value and restarting.
|
||||
auth_token = "replace-with-a-long-random-secret"
|
||||
|
||||
[store]
|
||||
|
||||
Reference in New Issue
Block a user