Skip to content

bb-block production: allow the Apps Platform control-plane host - #332

Open
nathan-thillairajah wants to merge 1 commit into
mainfrom
nthillairajah/bb-block-production-cli
Open

nathan-thillairajah wants to merge 1 commit into
mainfrom
nthillairajah/bb-block-production-cli

Conversation

@nathan-thillairajah

Copy link
Copy Markdown
Contributor

The CLI rejects the bb-block production Apps Platform ingress before making a request. Add compose-ctrl.block.builderlab.xyz to the exact control-plane allowlist so the existing BBIdentity authentication and app lifecycle commands can reach production.

Extend the existing allowlist test to cover the production origin, explicit port 443, and rejection of HTTP, lookalike domains, other ports, userinfo, and app hosts. The existing chat and agent laws are unaffected.

Validation: 51 Apps Platform tests passed, rustfmt passed, and a local bb build successfully authenticated, fetched the production contract, created a test app, deployed its baseline version, and confirmed exact-version readiness. Browser consent and provider-tool execution have not yet been verified.

@nathan-thillairajah
nathan-thillairajah requested a review from a team September 16, 2026 17:42

@morgmart morgmart left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Automated code review

COMMENT: The exact PR comparison cleanly adds the bb-block production control-plane hostname to the existing exact-host HTTPS allowlist and adds discriminating acceptance and rejection coverage. No concrete implementation findings remain. All 11 supplied GitHub check runs completed successfully, although required checks independently govern merge readiness. Architecture ownership of the newly trusted credential recipient needs Morgan's decision.

Deterministic publication result: 0 blocking and 0 non-blocking inline finding(s) publishable; 0 duplicate(s) suppressed; 0 blocking screenshot-evidence requirement(s) in this review body.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants