mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 15:18:09 +08:00
Both `npm run dev` (Docker) and `npm run dev:dangerously-dockerless` previously generated a fresh random SESSION_API_KEY per process. The key was passed to the agent-server (OH_SESSION_API_KEYS_0) and to Vite (VITE_SESSION_API_KEY), but the frontend's `openhands-backends` localStorage entry was seeded only on the very first load. After a single restart, the persisted entry's `apiKey` no longer matched the agent-server, leading to 401s until the user manually edited the backend. Fix this by giving `buildSafeDevConfig` a stable default: - `getOrCreatePersistedSessionApiKey()` reads / creates `~/.openhands/agent-canvas/session-api-key.txt` (mode 0600). The in-memory cache is keyed by path so tests can use `mkdtemp` paths. - `OH_SESSION_API_KEY_PATH` env var overrides the file location (used by tests; can also be used to pin in unusual setups). - Existing env overrides (SESSION_API_KEY / OH_SESSION_API_KEYS_0 / VITE_SESSION_API_KEY) still take precedence. Because dev:docker and dev:dangerously-dockerless both flow through the shared `buildSafeDevConfig`, they automatically pick up the same persisted key and stay in sync with the Vite-baked VITE_SESSION_API_KEY. On the frontend, `readStoredBackends` now also re-seeds the default Local backend when storage parses to `[]` or contains only invalid entries (previously only `null` triggered seeding). This is safe now that the persisted key keeps the seed valid across restarts. Tests: - New `getOrCreatePersistedSessionApiKey` tests covering creation, reuse, whitespace trimming, and empty-file regeneration. - New `buildSafeDevConfig` / `buildConfig` tests covering the on-disk fallback, restart parity (dev:docker vs dev:dangerously-dockerless), and env-override precedence. - New backend-registry storage tests covering re-seed on missing, empty, and all-invalid storage states. - Existing tests that previously hit the real `~/.openhands/agent-canvas/session-api-key.txt` were updated to use isolated `OH_SESSION_API_KEY_PATH` temp dirs. Co-authored-by: openhands <openhands@all-hands.dev>