Skip to content

feat(web): HTTP Basic auth for the page behind a tunnel - #1

Merged
matthewtsmith merged 1 commit into
mainfrom
feat/web-auth
Sep 19, 2026
Merged

matthewtsmith merged 1 commit into
mainfrom
feat/web-auth

Conversation

@matthewtsmith

Copy link
Copy Markdown
Member

Summary

  • webAuth: { user, password } in foreman.json (machine config, off-repo) enables HTTP Basic auth on the status page.
  • With it set, every route including GET / demands the credentials (401 + WWW-Authenticate: Basic realm="foreman"), and the localhost-only Host check is dropped so ngrok http <webPort> can reach the page. Without it, behaviour is unchanged.
  • foreman stop/go/model/cap send the credentials to the daemon.
  • Password compared in constant time; never logged or served, same rule as slackWebhookUrl.
  • README section "Reaching the page from outside this Mac"; design doc foreman.json table row.

Test plan

  • pnpm typecheck, pnpm test (588 pass; 7 new in src/config.test.ts, src/web.test.ts)
  • Existing no-auth suite untouched and green
  • Dogfood: set webAuth, restart daemon, ngrok http 8090, browser prompts once, foreman stop still works

Note: pnpm lint reports three pre-existing errors on main (src/ci.ts:24, src/pick.ts:119, src/web.html:120), not from this change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01L7dDnwXgZhAo9E6fne4tQP

`webAuth: { user, password }` in foreman.json makes every route, the page
itself included, demand Basic credentials and drops the localhost-only Host
check, so a tunnel such as ngrok can reach the page. Absent, nothing changes.
`ctl` sends the credentials to the daemon too. The password is compared in
constant time and, like the Slack webhook, is never logged or served.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L7dDnwXgZhAo9E6fne4tQP
@matthewtsmith
matthewtsmith merged commit a70811b into main Sep 19, 2026
1 check passed
@matthewtsmith
matthewtsmith deleted the feat/web-auth branch September 19, 2026 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant