fix(daemon): stop prefilling the daemon key in the templates - #1083
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
💤 Files with no reviewable changes (3)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughSix daemon templates now default Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Daemon templates no longer prefill example passwords, and the intended registration safeguards remain in place. No actionable merge-blocking risk was identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Removing prefilled example keys reduces the chance of registering a daemon with a shared, publicly known credential. Required keys remain enforced for HaRP and HTTPS registrations. Deprecated HTTP proxy configurations can still omit a key; their effective exposure depends on how the proxy is deployed. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5af1dad to
1f738bd
Compare
Signed-off-by: Oleksandr Piskun <oleksandr2088@icloud.com>
1f738bd to
4a639fc
Compare
The daemon templates in the registration form prefilled the HaRP shared key with
some_very_secure_password, and the deprecated Docker Socket Proxy templates withsome_secure_passwordorenter_haproxy_password. The field is a password field, so the value stayed hidden, and a daemon could be registered with a documentation example key without the admin ever typing or seeing it.The templates now leave the key empty. For HaRP daemons the form's existing check keeps Register disabled until a key of at least 12 characters is entered, and the placeholder points to
HP_SHARED_KEYof the HaRP container. An empty field shows the length rule as a plain hint and turns red only once a shorter key is typed, so the form no longer opens with an error. For the deprecated Docker Socket Proxy templates the password stays optional over HTTP, as before.A spec test makes sure no template prefills a key again. The warning about example keys from #1082 stays, since the
occ app_api:daemon:register --helpexamples and the documentation still use them.