Repository navigation
fix(dashboard): honour HERMES_DASHBOARD_INSECURE env var for Docker/reverse-proxy deployments - #60411
Closed
kyssta-exe wants to merge 1 commit into
Closed
kyssta-exe wants to merge 1 commit into
kyssta-exe wants to merge 1 commit into
Conversation
…everse-proxy deployments Root cause: The June 2026 security hardening made should_require_auth() ignore the --insecure CLI flag on non-loopback binds. While the CLI flag was rightly deprecated as a security risk (it left unauthenticated public dashboards exposed to internet scanners), the HERMES_DASHBOARD_INSECURE env var was also silently broken — Docker/reverse-proxy deployments that explicitly set this env var to signal 'auth is handled upstream' still got the 'no auth providers registered' SystemExit. Fix: Restore honouring the HERMES_DASHBOARD_INSECURE env var in should_require_auth(). The env var is the deliberate operator opt-out — it's used by Docker/reverse-proxy deployments where authentication is provided by an upstream proxy, not by Hermes itself. The --insecure CLI flag remains a no-op (documented as such in the warning message, which now also tells users about the env var workaround). Changes: - hermes_cli/web_server.py: should_require_auth() checks HERMES_DASHBOARD_INSECURE env var and returns False when set - hermes_cli/web_server.py: start_server() warning now mentions HERMES_DASHBOARD_INSECURE as the supported bypass - hermes_cli/main.py: _maybe_setup_dashboard_auth_interactively() docstring updated to mention the env var as a no-op condition Fixes NousResearch#59113
Author
|
Stale — 6-7 days without merge activity. Can resubmit if still needed. |
Could we reopen this please, issue still exists. |
|
Confirming this was also a problem on our side. We first needed the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The June 2026 security hardening (hermes-0day MCP-persistence campaign) made
should_require_auth()ignore the--insecureCLI flag on non-loopback binds. This correctly closed a security hole — but it also silently broke theHERMES_DASHBOARD_INSECUREenv var, which is the documented mechanism for Docker/reverse-proxy deployments.Docker users who set
HERMES_DASHBOARD_INSECURE=1+HERMES_DASHBOARD_HOST=0.0.0.0expect to run without auth behind their own proxy. Instead they get:Changes
hermes_cli/web_server.py:should_require_auth()— CheckHERMES_DASHBOARD_INSECUREenv var and returnFalsewhen set (alongside the existing loopback-address check). The env var is the deliberate operator opt-out; the--insecureCLI flag remains a no-op.hermes_cli/web_server.py:start_server()— The warning message for--insecurenow mentionsHERMES_DASHBOARD_INSECURE=1as the supported bypass.hermes_cli/main.py:_maybe_setup_dashboard_auth_interactively()— Docstring updated to list the env var as a no-op condition (the function already checksshould_require_auth()which now returnsFalsewhen the env var is set).Security
The
--insecureCLI flag remains a no-op (intentionally deprecated). Only theHERMES_DASHBOARD_INSECUREenv var is honoured — this is the mechanism that Docker/reverse-proxy operators already set to explicitly opt out of auth. The env var requires a process restart to change, so it cannot be toggled via a web request.Fixes #59113