Skip to content

fix: read internal token from disk per-request, surface auth errors#97

Merged
blaspat merged 1 commit into
mainfrom
fix/token-disk-read-auth-errors
Jul 21, 2026
Merged

fix: read internal token from disk per-request, surface auth errors#97
blaspat merged 1 commit into
mainfrom
fix/token-disk-read-auth-errors

Conversation

@blaspat

@blaspat blaspat commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Two bugs that caused hermes node list to silently show all nodes as "disconnected":

Bug 1: Internal token cached at startup, never re-read

_verify_internal_auth cached the token in app.state.internal_token at gateway startup. If the token file was overwritten later (e.g. by auto-start in another profile), the server and CLI would disagree on the token → 401 → hermes node list returned empty connected set → all nodes showed "disconnected."

Fix: _verify_internal_auth now reads ~/.hermes/nodes-internal-token on every request via new _read_token_from_disk() helper. Comparison uses hmac.compare_digest.

Bug 2: CLI/tools silently swallowed auth errors

_connected_names() caught all exceptions and returned an empty set. A 401 from token mismatch looked identical to "no nodes connected."

Fix:

  • _connected_names returns set[str] | NoneNone means "cannot query server." 401/403 errors print a clear warning to stderr.
  • _cmd_list shows a warning banner and uses new STATE_UNKNOWN = "unknown" instead of "disconnected" when the server is unreachable.
  • _node_list_impl detects auth-error responses and returns an error field.

Two bugs:

1. Server: _verify_internal_auth cached the token in app.state at startup.
   If the token file was overwritten later (auto-start in another process),
   server and CLI disagreed -> 401 -> hermes node list silently showed all
   nodes as disconnected.  Now reads ~/.hermes/nodes-internal-token on every
   request via new _read_token_from_disk() helper.  Uses hmac.compare_digest.

2. CLI/tools: _connected_names and _node_list_impl silently swallowed auth
   errors.  _connected_names now returns set[str] | None; None means "cannot
   query".  401/403 print a clear stderr warning.  _cmd_list shows a warning
   banner and marks rows as "unknown" instead of "disconnected".  New state
   constant: STATE_UNKNOWN.

Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>
@blaspat
blaspat force-pushed the fix/token-disk-read-auth-errors branch from fc062de to d9b3a64 Compare July 21, 2026 04:38
@blaspat
blaspat merged commit 66a23dc into main Jul 21, 2026
2 checks passed
@blaspat
blaspat deleted the fix/token-disk-read-auth-errors branch July 21, 2026 05:00
blaspat added a commit that referenced this pull request Jul 21, 2026
* fix: read internal token from disk per-request, surface auth errors

Two bugs:

1. Server: _verify_internal_auth cached the token in app.state at startup.
   If the token file was overwritten later (auto-start in another process),
   server and CLI disagreed -> 401 -> hermes node list silently showed all
   nodes as disconnected.  Now reads ~/.hermes/nodes-internal-token on every
   request via new _read_token_from_disk() helper.  Uses hmac.compare_digest.

2. CLI/tools: _connected_names and _node_list_impl silently swallowed auth
   errors.  _connected_names now returns set[str] | None; None means "cannot
   query".  401/403 print a clear stderr warning.  _cmd_list shows a warning
   banner and marks rows as "unknown" instead of "disconnected".  New state
   constant: STATE_UNKNOWN.

Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>

* fix: rotating log for auto-start, quiet stdout

- Replace print()+append with RotatingFileHandler (5 MB cap, 1 backup)
- Only print lifecycle events to stdout (server started, failures, errors)
- Routine diagnostics go to file only (port checks, thread lifecycle, etc.)
- Remove stale import urllib.error (missed in #97)

Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>

---------

Signed-off-by: Blasius Patrick <blasius.patrick@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant