Authenticate /hook/*, and make every hook a command hook
/hook/record and /hook/approve accepted anything that reached the port. That is not "loopback only": `tailscale serve` proxies tailnet traffic to 127.0.0.1, so anyone who could reach the tunnel could forge timeline events and answer approval prompts. Both endpoints now require a 32-byte secret from $GLANCE_HOME/hook.secret (0600, created once, never rotated so nothing in flight is 403'd mid-session), compared in constant time before the body is read, as an x-glance-hook header or a ?k= parameter. Requests carrying x-forwarded-* are refused outright: a local hook process never sends them and a tunnelled caller always does. The check applies to /hook/* only, so the dashboard is unaffected. While wiring that up: the 13 passive `type: "http"` hooks could never have worked. Grok Build's http runner rejects every scheme but https, then resolves the host and blocks private/link-local/CGNAT addresses (validate_hook_url + is_blocked_ip), so neither loopback-over-http nor *.ts.net (100.64/10) can be a hook target - and it sends no header but Content-Type, so such a hook could not authenticate anyway. They were failing validation silently on every event. All of them are now command hooks running bin/glance-record.mjs, which costs a Node start and can present the secret. hooks.json is generated from hooks/hooks.template.json by scripts/gen-hooks.mjs (npm run build, glance sync-hooks). It creates the secret, derives the approval hook's timeout from approval.timeoutMs instead of hand-copying 125, and refuses to write a hook that cannot fire: bad type, non-positive timeout, non-https http URL, missing bin/ script, or a leftover placeholder. A template that embeds the token makes the output 0600 with a warning. Fail-open is unchanged: a missing, stale or rejected secret degrades to "no telemetry", and glance-approve.mjs still allows on every error path. glance status warns when the on-disk secret no longer matches the daemon's. Validated with the e2e suite (190 checks, including no-token/wrong-token/ same-length-token 403s, ?k= acceptance, x-forwarded-* refusal, and the recorder's fail-open paths) and a clean npm run build. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
b3b6bf3f70
commit
5eec1940be
+21
-4
@@ -10,7 +10,15 @@
|
||||
* call Grok was already about to make. This hook can never introduce a new command.
|
||||
*/
|
||||
|
||||
import { baseUrl, envEnvelope, postJson, readConfig, readStdinJson } from "./glance-lib.mjs";
|
||||
import {
|
||||
approvalHookTimeoutSecs,
|
||||
baseUrl,
|
||||
envEnvelope,
|
||||
hookHeaders,
|
||||
postJson,
|
||||
readConfig,
|
||||
readStdinJson,
|
||||
} from "./glance-lib.mjs";
|
||||
|
||||
function allow() {
|
||||
process.exit(0);
|
||||
@@ -28,11 +36,20 @@ function deny(reason) {
|
||||
const payload = envEnvelope(await readStdinJson());
|
||||
const cfg = readConfig();
|
||||
|
||||
// Stay inside the hook timeout declared in hooks/hooks.json (125s).
|
||||
const waitMs = Math.min(115_000, Number(cfg.approval?.timeoutMs ?? 90_000) + 15_000);
|
||||
// Finish inside the hook timeout that scripts/gen-hooks.mjs wrote into hooks.json, with room
|
||||
// to spare: if Grok Build kills us first, the fail-open path below never gets to run.
|
||||
const waitMs = Math.min(
|
||||
approvalHookTimeoutSecs(cfg) * 1000 - 10_000,
|
||||
Number(cfg.approval?.timeoutMs ?? 90_000) + 15_000,
|
||||
);
|
||||
|
||||
try {
|
||||
const { data } = await postJson(`${baseUrl(cfg)}/hook/approve`, payload, waitMs);
|
||||
const { data } = await postJson(
|
||||
`${baseUrl(cfg)}/hook/approve`,
|
||||
payload,
|
||||
waitMs,
|
||||
hookHeaders(),
|
||||
);
|
||||
if (data && data.decision === "deny") deny(data.reason);
|
||||
allow();
|
||||
} catch {
|
||||
|
||||
Reference in New Issue
Block a user