fix: Always scrape dashboard session token from HTML - #404
Closed
Joselma-Jemk wants to merge 1 commit into
Closed
Conversation
The Hermes Agent dashboard uses an ephemeral session token injected via window.__HERMES_SESSION_TOKEN__ (changes on restart). The previous regex was incorrect - it matched only one underscore between HERMES and SESSION, but actual HTML has __HERMES_SESSION_TOKEN__. Fixed regex to match double underscores and always scrape token from HTML root page instead of using bearer token fallback. Fixes 401 Unauthorized errors when workspace calls dashboard API.
Owner
|
Closing as superseded by #432. The validated fix was folded into the consolidated batch branch |
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
window.__HERMES_SESSION_TOKEN__(changes on restart)Root Cause
The regex
window\.__(?:CLAUDE|HERMES)_SESSION_TOKEN__was incorrect - it matched only ONE underscore between HERMES and SESSION, but actual HTML has__HERMES_SESSION_TOKEN__(double underscores on both sides).Fixed regex:
/window\._+(?:CLAUDE|HERMES)_+SESSION_TOKEN__+\s*=\s*["']([^"']+)["']/Changes
src/server/gateway-capabilities.ts:DASHBOARD_TOKEN_REGEXto match double underscoresDASHBOARD_BEARER_TOKENpreference - always scrape HTML