fix: revert to shared internal auth token, defer generation until after bind#95
Merged
Conversation
…er bind Three changes: 1. _internal_token_path() always returns ~/.hermes/nodes-internal-token (removes HERMES_HOME profile-scoping) in both wsserver/server.py and tools.py 2. Token generation moved from before _serve() to after the bind-wait loop in lifecycle.py — if we bound the port, generate fresh token; if port was occupied (kate profile), read the existing shared token. 3. Removed unused 'import os' from tools.py This fixes the profile collision: default gateway owns port 7000 and generates the token; kate gateway reads it and authenticates against the running server. Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Profile-scoped token files caused auth mismatch: default gateway wrote token A to its path, kate gateway wrote token B to its path. Tools on different profiles got 401.
Fix
_internal_token_path()always returns~/.hermes/nodes-internal-token— shared across profilesrunner.start()import osfrom tools.pyThis restores the pre-auth behavior where one gateway owns port 7000 and all profiles share the transport.