Repository navigation
chore: log console-hive Caddy Host-mismatch bug in buglog - #464
Conversation
Caddyfile.console matches on Host header via CONSOLE_DOMAIN, which the physical box's .env never set. Cloudflare Tunnel and real clients send Host: console-hive.scubed.co, which matched no site block, and Caddy's fallback for an unmatched Host in this build is 200 empty rather than 404, so the outage looked like a blank origin instead of a routing miss. Fixed live on the box by setting CONSOLE_DOMAIN and CONSOLE_EXTERNAL_SCHEME and recreating caddy-console; this commit only records the bug and fix in .wolf/buglog.json per project convention.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
Next review available in: 3 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
#559) ## Summary Lands uncommitted cross-session work that was blocking the shared checkout from fast-forwarding to main: - **`.wolf/` memory merge.** `.wolf/buglog.json` and `.wolf/decisions.md` had both diverged from main (five PRs, #481 to #484 plus #464/#471, appended buglog entries; PR #475 appended decisions D-010 to D-014). Union-merged `buglog.json` so every entry from both sides survives (135 total, zero lost, validated as JSON). `decisions.md` had a real numbering collision: this session's local D-010 to D-019 covered different decisions than main's already-shipped D-010 to D-014. Kept main's D-010 to D-014 verbatim and renumbered only this session's colliding half to D-015 to D-024 (content, source, and date untouched, only the ID prefix changed). Grepped the repo first to confirm nothing else references the old numbers. - **OWUI deployed-login E2E smoke.** Adds `apps/web-console/e2e/phase-19/owui/deployed-login.spec.ts` plus its Playwright project in `playwright.owui.config.ts`. Logs in against a live deployed OWUI origin over the real cross-origin OIDC consent hop, without installing storageState or the `hive_jwt_forward` Function (both of those mutate whatever they point at, which is not acceptable against a live deployment). Self-skips when `OWUI_URL` is loopback or credentials are unset. - **Password-leak guard (#554).** Playwright's error-context ARIA snapshot (`error-context.md`, attached on any failing web-first assertion) serializes live input values, including a password still sitting in a filled field. Verified against the current Playwright internals (v1.58.2) that there is no config flag to disable this capture, and that the snapshot is taken synchronously at the moment the assertion's retry loop times out, before test code regains control, so the only effective mitigation is to make sure the password is not in the DOM by the time a later assertion could fail. Added a scrub (`passwordBox.fill("")`) immediately after the login submit and before the next assertion in this spec. This closes the concrete leak vector for this one spec; the broader fix from #554 (scoping what the CI workflow uploads as an artifact) is a `.github/workflows/ci.yml` change and stays out of scope here, tracked on that issue. - **`.claude/settings.json`.** Kept. Adds SessionStart and `PreToolUse(Agent)` hook nudges enforcing the wenyan-ultra subagent-dispatch convention, mirroring the equivalent hook already shipped in fundmoreai. Confirmed valid JSON and that the referenced `emit-nudge.js` hook script exists. - **Root scratch screenshots.** Roughly 35 loose `.png` files plus a stale local `playwright-report-owui/` HTML report (both leftover manual-verification artifacts from earlier sessions, not gitignored, not referenced by any tracked doc) were moved out of the repo to the session scratchpad rather than committed or deleted, since deleting screenshots is not reversible and neither belongs at the repo root. ## Test plan - [x] `.wolf/buglog.json` validated as parseable JSON (135 bugs, union of origin's 130 plus this session's 5 new entries) - [x] `.wolf/decisions.md` renumbering verified against `git log` on both branches; grepped the repo for any code/doc references to the old D-010 to D-019 numbers (none found) - [x] `apps/web-console/e2e/phase-19/owui/deployed-login.spec.ts` reviewed against its config; the loopback-skip comment matches the config's own skip condition - [ ] Owner/CI: run the `owui-deployed-login` Playwright project against a real deployed `OWUI_URL` with `OWUI_E2E_EMAIL`/`OWUI_E2E_PASSWORD` set, confirm it reaches the OWUI new-chat screen and that no password value appears in the resulting `error-context.md` on an induced failure - [ ] CI: confirm the required checks run for real (not `ci-noop.yml`, per issue #553) before merge No UI-touching change lands here (memory/config/test-tooling only), so no screenshot proof is attached per the visual-proof gate.
Summary
console-hive.scubed.coreturned HTTP 200 with an empty body through the Cloudflare Tunnel because Caddyfile.console's Host-matched site block never saw aCONSOLE_DOMAINenv var set on the box..envnow setsCONSOLE_DOMAIN=console-hive.scubed.coandCONSOLE_EXTERNAL_SCHEME=https,caddy-consolerecreated. Verifiedhttps://console-hive.scubed.co/now 307s to/auth/sign-inand renders the real Hive Console page..wolf/buglog.jsonentry documenting the bug and fix, per repo convention (.claude/rules/openwolf.md).Test plan
curl -iL https://console-hive.scubed.co/returns 200 on/auth/sign-inwith title "Hive Console".