Skip to content

fix: A2App agent-token gate is bypassed by sending any Origin header - #452

Merged
korivi-CraftOS merged 5 commits into
V1.4.3from
ahmad/a2app-auth-bypass
Sep 23, 2026
Merged

korivi-CraftOS merged 5 commits into
V1.4.3from
ahmad/a2app-auth-bypass

Conversation

@ahmad-ajmal

Copy link
Copy Markdown
Collaborator

No description provided.

@ahmad-ajmal ahmad-ajmal self-assigned this Sep 21, 2026
@ahmad-ajmal
ahmad-ajmal force-pushed the ahmad/a2app-auth-bypass branch from 4e59385 to 7bec4b2 Compare September 21, 2026 14:22
@ahmad-ajmal
ahmad-ajmal added this pull request to stack #455 September 22, 2026 06:08
@ahmad-ajmal
ahmad-ajmal force-pushed the ahmad/a2app-auth-bypass branch from ecda1c0 to 1fd07a8 Compare September 22, 2026 09:45
@korivi-CraftOS
korivi-CraftOS merged commit 44f052c into V1.4.3 Sep 23, 2026
6 checks passed
korivi-CraftOS added a commit that referenced this pull request Sep 23, 2026
Replaces killing by port-substring and by process name with a ledger of
processes we started, identified by pid + creation time so a recycled pid
can never be mistaken for ours.

Conflict resolution, app/agent_app/manager.py:
#452 moved the tunnel lifecycle out of manager.py into sharing.py, while
this branch was fixing the cloudflared reap in manager.py's old copy.
Taking either side alone loses something: ours drops the reap fix, theirs
resurrects code that no longer belongs here. Resolved by keeping the
sharing.py structure and PORTING the fix to where the tunnel now lives:

  * sharing.py registers each cloudflared it starts in the ledger
    (ROLE_TUNNEL, pid + start time);
  * _kill_orphans reaps by that recorded identity instead of running
    `Stop-Process -Name cloudflared` / `pkill -f cloudflared`, which took
    down every cloudflared on the machine -- including a tunnel the user
    runs for their own production work.

Without this port the mass-kill would have survived the merge silently,
since #452 carried it across into sharing.py untouched.

Suite on the merged result: 1257 passed, 0 failed. This also clears the
pre-existing failure in tests/test_agent_app_launch_lock.py
(TestLiveness::test_a_live_external_app_is_not_dead), which was failing on
V1.4.3 before any of these PRs -- the rewritten listener detection fixes it.
korivi-CraftOS pushed a commit that referenced this pull request Sep 23, 2026
Documentation only: two AGENT.md files (the live agent_file_system copy and the template), version 8 -> 9.

Verified the claims against the code on V1.4.3 rather than taking them on trust -- EXCLUSIVE_SOURCES, memory.processing_threshold, _merge_triggers and set_skip_unprocessed_logging all exist and behave as described.

The gate was failing on a stale base: the branch was 9 commits behind, so the run was still testing the old validate.ts with its unused verifySystemHashes import, which #452 removed. Updating the branch produced a clean run on all three platforms.
@zfoong
zfoong deleted the ahmad/a2app-auth-bypass branch September 29, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants