Skip to content

chore: log console-hive Caddy Host-mismatch bug in buglog - #464

Merged
sakibsadmanshajib merged 1 commit into
mainfrom
chore/log-console-caddy-host-bug
Jul 26, 2026
Merged

sakibsadmanshajib merged 1 commit into
mainfrom
chore/log-console-caddy-host-bug

Conversation

@sakibsadmanshajib

Copy link
Copy Markdown
Owner

Summary

  • Records a real bug hit and fixed live while completing the web-console-to-physical-box DNS cutover: console-hive.scubed.co returned HTTP 200 with an empty body through the Cloudflare Tunnel because Caddyfile.console's Host-matched site block never saw a CONSOLE_DOMAIN env var set on the box.
  • Fixed live (not in this diff): box .env now sets CONSOLE_DOMAIN=console-hive.scubed.co and CONSOLE_EXTERNAL_SCHEME=https, caddy-console recreated. Verified https://console-hive.scubed.co/ now 307s to /auth/sign-in and renders the real Hive Console page.
  • This PR only adds the .wolf/buglog.json entry documenting the bug and fix, per repo convention (.claude/rules/openwolf.md).

Test plan

  • No code changes; JSON-only addition, validated by re-reading the file after edit.
  • Underlying fix verified live: curl -iL https://console-hive.scubed.co/ returns 200 on /auth/sign-in with title "Hive Console".

Caddyfile.console matches on Host header via CONSOLE_DOMAIN, which the
physical box's .env never set. Cloudflare Tunnel and real clients send
Host: console-hive.scubed.co, which matched no site block, and Caddy's
fallback for an unmatched Host in this build is 200 empty rather than
404, so the outage looked like a blank origin instead of a routing miss.
Fixed live on the box by setting CONSOLE_DOMAIN and
CONSOLE_EXTERNAL_SCHEME and recreating caddy-console; this commit only
records the bug and fix in .wolf/buglog.json per project convention.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@coderabbitai

coderabbitai Bot commented Jul 26, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@sakibsadmanshajib, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 3 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: fee3910f-2ba2-4f5a-b26c-ddb42fe389ea

📥 Commits

Reviewing files that changed from the base of the PR and between 345f724 and e063725.

📒 Files selected for processing (1)
  • .wolf/buglog.json
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/log-console-caddy-host-bug

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sakibsadmanshajib
sakibsadmanshajib merged commit be50c75 into main Jul 26, 2026
9 checks passed
@sakibsadmanshajib
sakibsadmanshajib deleted the chore/log-console-caddy-host-bug branch July 26, 2026 23:00
sakibsadmanshajib added a commit that referenced this pull request Jul 27, 2026
#559)

## Summary

Lands uncommitted cross-session work that was blocking the shared
checkout from fast-forwarding to main:

- **`.wolf/` memory merge.** `.wolf/buglog.json` and
`.wolf/decisions.md` had both diverged from main (five PRs, #481 to #484
plus #464/#471, appended buglog entries; PR #475 appended decisions
D-010 to D-014). Union-merged `buglog.json` so every entry from both
sides survives (135 total, zero lost, validated as JSON). `decisions.md`
had a real numbering collision: this session's local D-010 to D-019
covered different decisions than main's already-shipped D-010 to D-014.
Kept main's D-010 to D-014 verbatim and renumbered only this session's
colliding half to D-015 to D-024 (content, source, and date untouched,
only the ID prefix changed). Grepped the repo first to confirm nothing
else references the old numbers.
- **OWUI deployed-login E2E smoke.** Adds
`apps/web-console/e2e/phase-19/owui/deployed-login.spec.ts` plus its
Playwright project in `playwright.owui.config.ts`. Logs in against a
live deployed OWUI origin over the real cross-origin OIDC consent hop,
without installing storageState or the `hive_jwt_forward` Function (both
of those mutate whatever they point at, which is not acceptable against
a live deployment). Self-skips when `OWUI_URL` is loopback or
credentials are unset.
- **Password-leak guard (#554).** Playwright's error-context ARIA
snapshot (`error-context.md`, attached on any failing web-first
assertion) serializes live input values, including a password still
sitting in a filled field. Verified against the current Playwright
internals (v1.58.2) that there is no config flag to disable this
capture, and that the snapshot is taken synchronously at the moment the
assertion's retry loop times out, before test code regains control, so
the only effective mitigation is to make sure the password is not in the
DOM by the time a later assertion could fail. Added a scrub
(`passwordBox.fill("")`) immediately after the login submit and before
the next assertion in this spec. This closes the concrete leak vector
for this one spec; the broader fix from #554 (scoping what the CI
workflow uploads as an artifact) is a `.github/workflows/ci.yml` change
and stays out of scope here, tracked on that issue.
- **`.claude/settings.json`.** Kept. Adds SessionStart and
`PreToolUse(Agent)` hook nudges enforcing the wenyan-ultra
subagent-dispatch convention, mirroring the equivalent hook already
shipped in fundmoreai. Confirmed valid JSON and that the referenced
`emit-nudge.js` hook script exists.
- **Root scratch screenshots.** Roughly 35 loose `.png` files plus a
stale local `playwright-report-owui/` HTML report (both leftover
manual-verification artifacts from earlier sessions, not gitignored, not
referenced by any tracked doc) were moved out of the repo to the session
scratchpad rather than committed or deleted, since deleting screenshots
is not reversible and neither belongs at the repo root.

## Test plan

- [x] `.wolf/buglog.json` validated as parseable JSON (135 bugs, union
of origin's 130 plus this session's 5 new entries)
- [x] `.wolf/decisions.md` renumbering verified against `git log` on
both branches; grepped the repo for any code/doc references to the old
D-010 to D-019 numbers (none found)
- [x] `apps/web-console/e2e/phase-19/owui/deployed-login.spec.ts`
reviewed against its config; the loopback-skip comment matches the
config's own skip condition
- [ ] Owner/CI: run the `owui-deployed-login` Playwright project against
a real deployed `OWUI_URL` with `OWUI_E2E_EMAIL`/`OWUI_E2E_PASSWORD`
set, confirm it reaches the OWUI new-chat screen and that no password
value appears in the resulting `error-context.md` on an induced failure
- [ ] CI: confirm the required checks run for real (not `ci-noop.yml`,
per issue #553) before merge

No UI-touching change lands here (memory/config/test-tooling only), so
no screenshot proof is attached per the visual-proof gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant