mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 17:08:34 +08:00
Dev mode (npm run dev) was always using the hardcoded static default key 'openhands-dev-secret-key-change-in-prod' from config/defaults.json. Docker mode (docker/entrypoint.sh) generates a random key on first run and persists it to ~/.openhands/agent-canvas/secret-key.txt. When both modes share the same ~/.openhands directory, they used different keys — causing decryption failures for any settings encrypted by the other mode. Fix: remove the static default in dev-safe.mjs and instead use getOrCreatePersistedApiKey() with a new DEFAULT_SECRET_KEY_PATH constant pointing to the same secret-key.txt file that Docker reads/writes. Whichever mode runs first generates and persists the key; the other picks it up automatically on next start. - Add DEFAULT_SECRET_KEY_PATH export to dev-safe.mjs - Replace 'env.OH_SECRET_KEY || DEFAULT_SECRET_KEY' with 'env.OH_SECRET_KEY || getOrCreatePersistedApiKey(secretKeyPath, "secret")' - Update startup log to show persisted file path (not 'default (for local development)') - Remove now-unused 'defaults.secretKey' from config/defaults.json - Update AGENTS.md to reflect the new shared-file behavior Co-authored-by: openhands <openhands@all-hands.dev>