Skip to content

fix: use SDK.fetchJSON to include session token in API calls - #2

Open
CountZer0 wants to merge 1 commit into
tonbistudio:masterfrom
CountZer0:fix/session-token-auth
Open

CountZer0 wants to merge 1 commit into
tonbistudio:masterfrom
CountZer0:fix/session-token-auth

Conversation

@CountZer0

Copy link
Copy Markdown

Problem

Since Hermes Agent v2026.5.16 (PR NousResearch/hermes-agent#23220, commit ec9329e), the dashboard auth middleware in web_server.py no longer exempts /api/plugins/* routes from session-token authentication. All plugin API calls now require the X-Hermes-Session-Token header.

Canvas uses its own bare apiJSON() function with raw fetch() — no session token is sent. This causes 401 UNAUTHORIZED on every API call (status, project create, dev start, agent prompts, etc.).

Root Cause

dashboard/dist/index.js lines 47–75: custom apiJSON/postJSON/getJSON utilities use fetch() directly instead of SDK.fetchJSON, which automatically injects the X-Hermes-Session-Token header.

The Kanban plugin and other bundled plugins already use SDK.fetchJSON — Canvas was the outlier.

Fix

Replaced the apiJSON/postJSON/getJSON trio with calls to SDK.fetchJSON. This is a 1:1 swap — SDK.fetchJSON returns a Promise that resolves to parsed JSON, same as the old apiJSON.

  • Removes 15 lines of custom fetch wrapper
  • postJSON and getJSON now delegate to SDK.fetchJSON
  • No behavior change other than including the session token

Testing

  • Restart the Hermes dashboard (hermes dashboard --no-open)
  • Hard refresh browser (Cmd+Shift+R)
  • Open the Canvas tab — status, project create, and dev server controls should work without 401 errors

Closes #1

Replaced the custom apiJSON/postJSON/getJSON utilities with SDK.fetchJSON.
Since Hermes Agent v2026.5.16 (PR #23220, commit ec9329e) removed the blanket
/api/plugins/ auth exemption from web_server.py, all plugin API routes now
require the X-Hermes-Session-Token header. The SDK's fetchJSON automatically
injects this header — raw fetch() does not.

Without this fix, all Canvas API calls (project create, dev server management,
agent prompts) return 401 UNAUTHORIZED.

Closes tonbistudio#1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unauthorized bug

1 participant