Files
OpenHands/scripts
Robert Brennanandopenhands 5d16a6cbcf Persist dev session API key to disk and re-seed default backend (#240)
Both `npm run dev` (Docker) and `npm run dev:dangerously-dockerless`
previously generated a fresh random SESSION_API_KEY per process. The
key was passed to the agent-server (OH_SESSION_API_KEYS_0) and to Vite
(VITE_SESSION_API_KEY), but the frontend's `openhands-backends`
localStorage entry was seeded only on the very first load. After a
single restart, the persisted entry's `apiKey` no longer matched the
agent-server, leading to 401s until the user manually edited the
backend.

Fix this by giving `buildSafeDevConfig` a stable default:

- `getOrCreatePersistedSessionApiKey()` reads / creates
  `~/.openhands/agent-canvas/session-api-key.txt` (mode 0600). The
  in-memory cache is keyed by path so tests can use `mkdtemp` paths.
- `OH_SESSION_API_KEY_PATH` env var overrides the file location
  (used by tests; can also be used to pin in unusual setups).
- Existing env overrides (SESSION_API_KEY / OH_SESSION_API_KEYS_0 /
  VITE_SESSION_API_KEY) still take precedence.

Because dev:docker and dev:dangerously-dockerless both flow through
the shared `buildSafeDevConfig`, they automatically pick up the
same persisted key and stay in sync with the Vite-baked
VITE_SESSION_API_KEY.

On the frontend, `readStoredBackends` now also re-seeds the default
Local backend when storage parses to `[]` or contains only invalid
entries (previously only `null` triggered seeding). This is safe now
that the persisted key keeps the seed valid across restarts.

Tests:
- New `getOrCreatePersistedSessionApiKey` tests covering creation,
  reuse, whitespace trimming, and empty-file regeneration.
- New `buildSafeDevConfig` / `buildConfig` tests covering the
  on-disk fallback, restart parity (dev:docker vs
  dev:dangerously-dockerless), and env-override precedence.
- New backend-registry storage tests covering re-seed on missing,
  empty, and all-invalid storage states.
- Existing tests that previously hit the real
  `~/.openhands/agent-canvas/session-api-key.txt` were updated to
  use isolated `OH_SESSION_API_KEY_PATH` temp dirs.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-09 13:54:14 -07:00
..