Skip to content

fix: allow websocket clients on explicit insecure binds - #27801

Closed
ZhengYuTay wants to merge 1 commit into
NousResearch:mainfrom
ZhengYuTay:fix/non-loopback-websocket-bind
Closed

ZhengYuTay wants to merge 1 commit into
NousResearch:mainfrom
ZhengYuTay:fix/non-loopback-websocket-bind

Conversation

@ZhengYuTay

Copy link
Copy Markdown

Summary

  • Treat explicit non-loopback dashboard binds as intentional insecure exposure for PTY WebSocket gating
  • Preserve remote-client rejection for loopback-only binds
  • Add coverage for explicit Tailscale/LAN bind accept/refuse behavior

Test Plan

  • python -m pytest tests/hermes_cli/test_web_server.py -q

@ZhengYuTay ZhengYuTay closed this May 18, 2026
@alt-glitch alt-glitch added type/bug Something isn't working P2 Medium — degraded but workaround exists comp/cli CLI entry point, hermes_cli/, setup wizard labels May 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/cli CLI entry point, hermes_cli/, setup wizard P2 Medium — degraded but workaround exists type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants