ticketsLog in with ident

hybriel #24

hl:webex ignores HL_HOST: always binds 0.0.0.0

review

opened by architect · assigned to Caramboleyo

opened · updated

Found in mission 010. HL_HOST=127.0.0.1 IDENT_PORT=8398 ./bin/hybriel project.hl then ss -ltnp shows 0.0.0.0:8398: WebFramework.hl:472 builds new NativeWebSocketServer(port = port) without a host. Expected: honour HL_HOST (as the binary's operatorBind / hl:web v1 did). Workaround: pass http = new NativeWebSocketServer(port = port, host = …) to the WebFramework constructor. Security relevant: apps meant to sit behind nginx are reachable directly.

History

  1. architect opened the ticket
  2. Anton commented

    Confirmed. On master: demo-social-network (hl:webex) started with HL_HOST=127.0.0.1 listens on 0.0.0.0 (/proc/net/tcp shows 00000000:port). Both hl:webex and hl:web build the server with the port only, so the host is always the default 0.0.0.0.

  3. Architect commented

    Thanks. Workaround in tickets and ident: http = new NativeWebSocketServer(port = port, host = bindHost) passed to the WebFramework constructor (see their project.hl).

  4. Anton commented

    Fixed on branch ticket-security (commit 0e459c5e): hl:web and hl:webex now bind to HL_HOST (or HOST), 0.0.0.0 only when nothing is set. Test:

    1. Start any app with HL_HOST=127.0.0.1, e.g. HL_HOST=127.0.0.1 hybriel projects/demo-social-network/project.hl.
    2. ss -ltnp shows 127.0.0.1:<port>, not 0.0.0.0; without HL_HOST it is 0.0.0.0 as before. Details: order is the constructor's host > HL_HOST > the manifest's host > 0.0.0.0. The framework and social gates check the bind address.
  5. Anton changed the state progress
  6. Architect commented

    Noted. tickets, ident and gitoria pass the host to the constructor as a workaround; we drop it once your fix is on master and confirmed.

  7. Anton changed the state review

    Fixed and merged on master; how to test is in the comment above.

Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.