refactor(auth): /api/* boundary + drop sessionGateEnabled flag (#537) #539
Closed
claude-desktop
wants to merge 1 commit from
refactor/api-prefix-and-session-gate into main
pull from: refactor/api-prefix-and-session-gate
merge into: charles:main
charles:main
charles:chore/sync-pre-push-from-forge-base
charles:fix/flows-yaml-dispatch-identity
charles:feat/board-tap-to-assign
charles:dev/1107
charles:code-lead/1106
charles:code-lead/1108
charles:dev/1104
charles:code-lead/1103
charles:code-lead/1080
charles:dev/1087
charles:feat/flows-yaml-ci-events
charles:chore/board-drop-stalled-and-density-controls
charles:fix/flows-yaml-routes-always-register
charles:flows-yaml/api-defaults
charles:dev/1023
charles:fix/event-log-history-bleed
charles:fix/janitor-fix-ci-logs-and-cap
charles:dev/1022
charles:fix/board-card-provider
charles:code-lead/1036
charles:dev/1025
charles:code-lead/1020
charles:dev/1017
charles:code-lead/1026
charles:feat/web-shortcut-registry-1018
charles:dev/1015
charles:code-lead/1009
charles:code-lead/1008
charles:dev/975
charles:dev/969
charles:dev/973
charles:dev/967
charles:code-lead/968
charles:code-lead/953
charles:dev/970
charles:dev/976
charles:code-lead/966
charles:code-lead/956
charles:code-lead/951
charles:dev/962
charles:dev/963
charles:dev/977
charles:dev/955
charles:dev/983
charles:dev/961
charles:dev/974
charles:code-lead/950
charles:code-lead/939
charles:dev/941
charles:dev/940
charles:dev/937
charles:dev/938
charles:dev/936
charles:dev/935
charles:feat/web-i18n-fr-locale
charles:feat/spec-editor-ui-polish
charles:chore/drop-legacy-compat
charles:fix/skills-drop-preview-pane
charles:fix/882-skills-safety-rail
charles:dev/911
charles:dev/909
charles:dev/923
charles:dev/917
charles:dev/915
charles:feat/879-sr11-m2-drop-legacy-skill
charles:code-lead/873
charles:dev/881
charles:code-lead/869
charles:dev/867
charles:code-lead/845
charles:code-lead/843
charles:code-lead/844
charles:dev/837
charles:dev/861
charles:dev/849
charles:code-lead/837
charles:code-lead/842
charles:fix/dedup-rebase-inflight
charles:dev/838
charles:code-lead/847
charles:dev/833
charles:code-lead/848
charles:pr/838
charles:code-lead/841
charles:feat/settings-save-bar/836
charles:code-lead/840
charles:dev/846
charles:code-lead/839
charles:dev/832
charles:fix/board-sse-stale-cache
charles:dev/834
charles:dev/835
charles:feat/settings-breadcrumbs
charles:feat/forge-oauth-credentials
charles:refactor/service-config-consolidation
charles:feat/agent-tokens-to-secrets
charles:feat/gitlab-oauth-to-db
charles:feat/authelia-rip-and-voice-fixes
charles:fix/rebase-storm-and-dead-letter
charles:code-lead/797
charles:code-lead/796
charles:dev/811
charles:code-lead/798
charles:dev/810
charles:code-lead/795
charles:dev/808
charles:code-lead/794
charles:dev/805
charles:dev/802
charles:dev/803
charles:feat/avatar-menu-settings-entry
charles:feat/per-agent-token-tracking
charles:dev/793
charles:dev/747
charles:dev/752
charles:code-lead/790
charles:code-lead/759
charles:dev/756
charles:dev/760
charles:dev/741
charles:dev/767
charles:dev/740
charles:dev/709
charles:dev/644
charles:dev/637
charles:boss/614
charles:dev/600
charles:dev/611
charles:dev/585
charles:fix/login-bonus-fixes
charles:boss/544
charles:dev/542
charles:dev/489
charles:boss/531
charles:boss/518
charles:dev/499
charles:boss/516
charles:dev/530
charles:dev/517
charles:dev/519
charles:dev/515
charles:dev/522
charles:dev/503
charles:dev/471
charles:boss/329
charles:dev/417
charles:dev/418
charles:dev/402
charles:boss/327
charles:dev/334
charles:dev/332
charles:boss/326
charles:boss/325
charles:dev/331
charles:boss/324
charles:boss/323
charles:boss/322
charles:dev/294
charles:test/s11-task-analytics
charles:dev/262
charles:boss/270
charles:dev/268
charles:foreman/ui-consolidation-spec
charles:dev/234
charles:boss/196
charles:boss/176
charles:boss/164
charles:fix/124-session-persist-bind
charles:boss/52
charles:dev/87
charles:boss/73
charles:dev/77
charles:dev/81
charles:dev/82
charles:boss/79
charles:dev/42
charles:dev/35
charles:boss/7
No reviewers
Labels
Clear labels
area:agents
Agent types, pool scheduling, per-instance config
area:dashboard
Dashboard UI and observability surfaces
area:database
DB layer — schema, migrations, ORM, raw SQL
area:design
UI/UX mockup work — routes to designer agent
area:design-review
Design review dispatch — routes to design-reviewer agent
area:flows
Flow runner — YAML loader, executor, op registry, expression eval
area:infra
Deployment, isolation, containers, systemd units
area:meta
Tracking, scaffolding, project setup
area:security
Security — routes to reviewer-security (opus)
area:sessions
Session-id store, Claude SDK resume logic
area:webhook
Forgejo webhook routing and handlers
area:workdir
Clone cache, worktrees, git identity
security
Security-sensitive issue
type:bug
Bug
type:chore
Chore
type:meta
Tracking or decisions, not implementation work
type:user-story
User story
No labels
area:agents
area:dashboard
area:database
area:design
area:design-review
area:flows
area:infra
area:meta
area:security
area:sessions
area:webhook
area:workdir
security
type:bug
type:chore
type:meta
type:user-story
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
charles/claude-hooks!539
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refactor/api-prefix-and-session-gate"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #537.
Why
The session gate had three layers fighting:
sessionGateEnableddefaulting topublicBaseUrl !== nullauth.session_gate_enabledoverrideOn a fresh deployment with no
public_base_urland no override, the gate auto-disabled, the SPA mounted, every/api-style call returned blank or errored silently, and the user saw an empty dashboard with no path to log in. The hardcoded list was also brittle —/favicon.icowas missing and surfaced as a confusing 401 in DevTools.What
Single auth boundary by path prefix:
/api/*→ session-cookie required/login,/oauth/*,/webhook/*,/health, favicons) → openNo flags, no inference, no list.
Server
apps/server/src/main.tswith/api/(~83 routes)/login,/logout,/oauth/*,/webhook/*,/webhooks/*,/health,/manifest.webmanifest,/icon*.svg,/favicon.ico,/,/dashboard,/app,/app/*session-middleware.ts:isSessionGateExempt(path)reduces to!path.startsWith("/api/")plus aCLAUDE_HOOKS_DISABLE_AUTH=1test escape hatchmakeSessionGateMiddleware()no longer takes{ enabled }. Always enforces within/api/*webhook-config.ts: dropsessionGateEnabledfield, schema entry, and inference. Deprecatedauth.session_gate_enabledinagents.jsonwarns and is otherwise ignoredWeb
apiUrl(path)helper inlib/api.tsprefixes/apifor paths that aren't already there (and aren't login/oauth/app static)jsonFetchroutes throughapiUrlfetch("/...")andnew EventSource(\/...`)callsites inlib/api.ts,lib/board.ts,lib/foreman.ts,components/app-shell.tsxrewritten to/api/...`features/flows/flowsApi.ts:httpFetchwrapsapiUrl(path)lib/sse.ts: default URL/events→/api/eventsTests
apps/server/package.jsontest + qa scripts setCLAUDE_HOOKS_DISABLE_AUTH=1so existing suites that don't thread a session cookie keep runningsession-middleware.test.ts+session-gate.test.tsclear the bypass locally and hit/api/*paths. Both greenwebhook-config.test.ts: drop thesessionGateEnableddescribe block (5 tests)Known follow-up
~77 server tests still fail. Two buckets, both mechanical:
req("GET", "/queue", …)style acrossmain-agents.test.ts,main.test.ts,auth.test.ts,flows-routes.test.ts, etc.). Surgical s//queue//api/queue/g style, but I avoided a mass regex pass because the first attempt over-matched and broke fixtures.auth.test.tsand themutating routes — 403 when Remote-User is absentblock test the oldRemote-User/trust_proxyshape that the proxmox-iac side already removed. They exercise dead code now and should be deleted.Both are bounded — should be one or two follow-up commits on this branch before merge.
Verification
bun run typecheckcleanbun test apps/server/src/http/session-middleware.test.ts15/15 greenbun test apps/server/src/http/session-gate.test.ts21/21 greenlocalStorage.clearflake on main, unrelatedTest plan
claude.jacquin.app/with no cookie → 302 to/login→/app/loginrenders, no blank-screen failure mode/api/boardreturns 200 with the cookie, 401 without/webhook/forgejostill accepts forge POSTs without a session cookieClosing — superseded by #538 for the gate fix (#537), which landed cleaner with all server tests green. The
/api/*boundary refactor in this PR is orthogonal cleanup; reopening as a separate follow-up issue against today's main rather than carrying the 77 known test failures forward.Branch
refactor/api-prefix-and-session-gateretained for reference until the follow-up issue picks up the route-rename + SPAapiUrlhelper work.Pull request closed