Skip to content

Review follow-ups from rc.13: identity headers, origin normaliser, docs contradictions #110

Description

@catinspace-au

Rows still open from the rc.13 manual-test review.

  • TS2: docs/operating.md:100 says the HyperDX page never hands out the ClickHouse password, but operating.md:143 says NEXT_PUBLIC_* inlines it. Verify against the fork's bundle and delete the false statement.
  • TS3: config/proxy/hyperdx.yaml:59 dropped the X-OIDC-* overwrite with nothing replacing it, so in header-dev a client on :8090/:8000 can assert its own identity. Add request_headers_to_remove for both headers on both listeners.
  • TS9: scripts/_common.py:222 LOOPBACK_ORIGINS misses http://[::1] and http://0.0.0.0. Add them.
  • TS10: docker-compose.yml:1088 interpolates DFE_EXTERNAL_ORIGIN into the CSP list unescaped, so a semicolon rewrites the policy. Validate the shape (scheme://host[:port]) in the make guard.
  • TS12: docs/operating.md:97 still says the engine API answers unauthenticated on :3000, contradicting the file's own opening line and the engine. Fix the sentence.
  • CD5: scripts/test_source.py _ui_origin returns the external origin regardless of bind scope, overriding DFE_POST_HOST and adopting an https scheme nothing serves. Keep DFE_POST_HOST ahead and reject a non-http origin.
  • CD7: Makefile:21 and scripts/_common.py:244 disagree on a trailing slash, so http://localhost/ passes make and renders http://localhost/:3000. Give both one shared normaliser.

From the 2026-09-14 review of the rc.13 merges; rc.14.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    rc14Targets the 2.2.0-rc.14 stack

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions