Conversation
Self-host operators can list exact http(s)://<ip literal>:<port> origins in EXECUTOR_ALLOWED_LOCAL_ORIGINS. The hosted HTTP client then lets those through while EXECUTOR_ALLOW_LOCAL_NETWORK=false keeps every other loopback and private address blocked. Entries must be IP literals, so DNS never decides; metadata addresses are refused; redirects are re-checked per hop.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Self-host can now allow a few exact local origins while
EXECUTOR_ALLOW_LOCAL_NETWORKstaysfalse. This lets an operator reach one service on the same host, such as a read-only API on127.0.0.1:<port>, without opening loopback, the LAN or the tailnet to built-in tools likeopenapi.previewSpecandintegrations.detect.HostedHttpClientOptions.allowedLocalOrigins, wired fromHostConfiginscoped-executor.ts. Self-host reads it fromEXECUTOR_ALLOWED_LOCAL_ORIGINS(comma-separated).http(s)://<ip literal>[:port]origin. Hostnames are rejected, so DNS never decides. Metadata addresses are refused. A malformed entry stops the server at boot.hosted/docker.mdxtable. The changeset isminor.Linked issue
Fixes #2149
Verification
bun run format:check: clean.bun run lint: 0 warnings and 0 errors.bun run typecheck:@executor-js/sdk,@executor-js/apiand@executor-js/host-selfhostreport no errors in changed files. The only errors locally are 20 infumadb's drizzle adapter (Cannot find module 'drizzle-orm'), the same count on unmodifiedmain, so the cause is my environment.bun run test:packages/core/sdk/src/hosted-http-client.test.tspasses (19 tests, 5 new). The newexecutor-config.test.tscases couldn't load locally for the samedrizzle-ormreason; CI will run them.EXECUTOR_ALLOWED_LOCAL_ORIGINS=http://127.0.0.1:<port>.previewSpecfetched that origin's spec and got HTTP 401 from its data paths. Live HTTP servers on other loopback ports and on the host's private bridge address were refused, while a public URL still went through. The server refuses to boot withhttp://localhost:<port>as an entry.New tests:
hosted-http-client.test.ts:localhost;executor-config.test.ts:Checklist
bun run changeset), or this change needs none.