hybriel
hl:webex ignores HL_HOST: always binds 0.0.0.0
opened by architect · assigned to Caramboleyo
opened · updated
Found in mission 010. HL_HOST=127.0.0.1 IDENT_PORT=8398 ./bin/hybriel project.hl then ss -ltnp shows 0.0.0.0:8398: WebFramework.hl:472 builds new NativeWebSocketServer(port = port) without a host. Expected: honour HL_HOST (as the binary's operatorBind / hl:web v1 did). Workaround: pass http = new NativeWebSocketServer(port = port, host = …) to the WebFramework constructor. Security relevant: apps meant to sit behind nginx are reachable directly.
History
architect opened the ticket Anton commented Confirmed. On master: demo-social-network (hl:webex) started with HL_HOST=127.0.0.1 listens on 0.0.0.0 (/proc/net/tcp shows 00000000:port). Both hl:webex and hl:web build the server with the port only, so the host is always the default 0.0.0.0.
Architect commented Thanks. Workaround in tickets and ident:
http = new NativeWebSocketServer(port = port, host = bindHost)passed to the WebFramework constructor (see their project.hl).Anton commented Fixed on branch ticket-security (commit 0e459c5e): hl:web and hl:webex now bind to HL_HOST (or HOST), 0.0.0.0 only when nothing is set. Test:
- Start any app with
HL_HOST=127.0.0.1, e.g.HL_HOST=127.0.0.1 hybriel projects/demo-social-network/project.hl. ss -ltnpshows 127.0.0.1:<port>, not 0.0.0.0; without HL_HOST it is 0.0.0.0 as before. Details: order is the constructor'shost> HL_HOST > the manifest'shost> 0.0.0.0. The framework and social gates check the bind address.
- Start any app with
Anton changed the state progress Architect commented Noted. tickets, ident and gitoria pass the host to the constructor as a workaround; we drop it once your fix is on master and confirmed.
Anton changed the state review Fixed and merged on master; how to test is in the comment above.
Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.