Files
grok-glance/bin/glance-approve.mjs
T
iceBear67andClaude Opus 5 5eec1940be Authenticate /hook/*, and make every hook a command hook
/hook/record and /hook/approve accepted anything that reached the port. That is
not "loopback only": `tailscale serve` proxies tailnet traffic to 127.0.0.1, so
anyone who could reach the tunnel could forge timeline events and answer
approval prompts. Both endpoints now require a 32-byte secret from
$GLANCE_HOME/hook.secret (0600, created once, never rotated so nothing in
flight is 403'd mid-session), compared in constant time before the body is
read, as an x-glance-hook header or a ?k= parameter. Requests carrying
x-forwarded-* are refused outright: a local hook process never sends them and a
tunnelled caller always does. The check applies to /hook/* only, so the
dashboard is unaffected.

While wiring that up: the 13 passive `type: "http"` hooks could never have
worked. Grok Build's http runner rejects every scheme but https, then resolves
the host and blocks private/link-local/CGNAT addresses (validate_hook_url +
is_blocked_ip), so neither loopback-over-http nor *.ts.net (100.64/10) can be a
hook target - and it sends no header but Content-Type, so such a hook could not
authenticate anyway. They were failing validation silently on every event. All
of them are now command hooks running bin/glance-record.mjs, which costs a Node
start and can present the secret.

hooks.json is generated from hooks/hooks.template.json by scripts/gen-hooks.mjs
(npm run build, glance sync-hooks). It creates the secret, derives the approval
hook's timeout from approval.timeoutMs instead of hand-copying 125, and refuses
to write a hook that cannot fire: bad type, non-positive timeout, non-https
http URL, missing bin/ script, or a leftover placeholder. A template that
embeds the token makes the output 0600 with a warning.

Fail-open is unchanged: a missing, stale or rejected secret degrades to "no
telemetry", and glance-approve.mjs still allows on every error path. glance
status warns when the on-disk secret no longer matches the daemon's.

Validated with the e2e suite (190 checks, including no-token/wrong-token/
same-length-token 403s, ?k= acceptance, x-forwarded-* refusal, and the
recorder's fail-open paths) and a clean npm run build.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-09 04:52:17 +00:00

58 lines
1.6 KiB
JavaScript
Executable File

#!/usr/bin/env node
/**
* PreToolUse hook: the remote approval gate.
*
* Asks the daemon what to do with this tool call. The daemon holds the request open while
* your phone decides, then answers allow/deny. Every failure path here is fail-open —
* a daemon that is down, slow, or confused must not be able to block your agent.
*
* Denying is the only outcome that changes behaviour, and approving only lets through a
* call Grok was already about to make. This hook can never introduce a new command.
*/
import {
approvalHookTimeoutSecs,
baseUrl,
envEnvelope,
hookHeaders,
postJson,
readConfig,
readStdinJson,
} from "./glance-lib.mjs";
function allow() {
process.exit(0);
}
function deny(reason) {
// Belt and braces: the documented deny signals are a JSON decision on stdout *and*
// exit code 2. We emit both so a change in precedence cannot silently allow.
process.stdout.write(
JSON.stringify({ decision: "deny", reason: reason || "Denied from grok-glance" }),
);
process.exit(2);
}
const payload = envEnvelope(await readStdinJson());
const cfg = readConfig();
// Finish inside the hook timeout that scripts/gen-hooks.mjs wrote into hooks.json, with room
// to spare: if Grok Build kills us first, the fail-open path below never gets to run.
const waitMs = Math.min(
approvalHookTimeoutSecs(cfg) * 1000 - 10_000,
Number(cfg.approval?.timeoutMs ?? 90_000) + 15_000,
);
try {
const { data } = await postJson(
`${baseUrl(cfg)}/hook/approve`,
payload,
waitMs,
hookHeaders(),
);
if (data && data.decision === "deny") deny(data.reason);
allow();
} catch {
allow();
}