Repository navigation
Conversation
Slice 15. A bare GET / no longer hands out a token. Perch gets the safe token through a one-time, five-minute link that sets an HttpOnly cookie. The power token is Bearer-only and never served over HTTP. Requests with a non-loopback Host (DNS rebinding) or a foreign Origin are refused with 403. Credentials are checked before the body is read. POWER_METHODS is reserved in @tyto/protocol, disjoint from the safe set; a safe token calling one gets unauthorized. npm start writes host.json (no token) and 0600 token files under TYTO_HOME instead of appending a token to the repo .env, and clears them on exit. Also: allowlist the MV3 manifest public key in gitleaks (turns main green), pin Node to what jsdom supports with .nvmrc and engine-strict, and stop telling operators the host reads .env. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Member
Author
|
Closing: we chose agent-browser instead of building Tyto's own browser stack. Decision, measurements, and the CI fix are in #4. The commits stay reachable from this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #2 (contract). Retarget to
mainafter #2 merges.Why
The power surface (raw CDP, cookies) makes a leaked host token catastrophic. The audit found two ways to leak it today:
GET /returned the token as a cookie.What
POWER_METHODSis reserved in@tyto/protocoland disjoint fromPERCH_SAFE_METHODS.unauthorized. Power methods themselves arrive in Slice 18./. A bareGET /sets no cookie.Hostother than127.0.0.1:<port>orlocalhost:<port>gets 403.Origingets 403..envwrites.npm startwrites~/.tyto/host.json(no token) and~/.tyto/tokens/{power,safe}at mode 0600, atomically, and clears them on exit.TYTO_HOST_TOKENstill pins the power token (e2e).main.startHost.mainred since PR Point LLM Relay at ai.noctusoft.com/v1 #1..nvmrc(26),engine-strict, andengines: ^22.22.2 || ^24.15.0 || >=26, matching jsdom. CI's 22.23.2 satisfies it..env.exampledescribe the new token flow. They also stop claiming the host reads.env, which it never did.Behavior change to note
The MV3 side panel (deferred) can't reach a real host: requests from
chrome-extension://are refused. It already couldn't, because the host never answered the CORS preflight. The Tier 3 e2e test stubs the host, so it's unaffected.Tests
The Slice 15 tests were written first (
packages/host/test/hardening.test.ts), plus protocol scope tests and updated out-of-the-box tests. For example,a HEAD request does not consume a Perch linkwas confirmed failing before the fix.npm run check: 43 files, 266 tests, typecheck clean (Node 26).gitleaks detect --config .gitleaks.toml --redact: no leaks.npm installon Node 22.11:EBADENGINE, as intended.Live e2e was not run locally; the nightly workflow covers it.
🤖 Generated with Claude Code