mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 17:08:34 +08:00
* fix: unify session and automation API keys into a single credential Both the agent-server and automation backend now share the same API key value. The agent-server validates it via `X-Session-API-Key` and the automation backend validates it via `Authorization: Bearer …` — different header formats, same credential. Changes: - Frontend: automation axios client reads `VITE_SESSION_API_KEY` instead of the now-removed `VITE_AUTOMATION_API_KEY` - Dev launcher: removed separate `AUTOMATION_LOCAL_API_KEY` generation and persistence (`automation-api-key.txt`); `localApiKey` is set to `sessionApiKey` so both backends receive the same value - Static build: stopped baking `VITE_AUTOMATION_API_KEY` (the frontend reads from `VITE_SESSION_API_KEY`) - Docker entrypoint: `OPENHANDS_AUTOMATION_API_KEY`, `AUTOMATION_LOCAL_API_KEY`, and `AUTOMATION_AGENT_SERVER_API_KEY` all default to the session key when not explicitly overridden - Tests updated to verify unified key behavior Fixes the 401 on `/api/automation/v1` when the automation backend is running but no separate `VITE_AUTOMATION_API_KEY` was configured. Co-authored-by: openhands <openhands@all-hands.dev> * fix: use X-Session-API-Key header for automation backend auth (consistent with agent-server) Switch automation backend requests from `Authorization: Bearer …` to `X-Session-API-Key` header, matching the agent-server's auth pattern. Both backends now authenticate using the same header and the same key value (`VITE_SESSION_API_KEY`). Co-authored-by: openhands <openhands@all-hands.dev> * fix: address review — remove localApiKey alias, dead constant, add entrypoint guard - Remove `localApiKey` from config; all call sites now use `config.sessionApiKey` directly, making the unified-key intent obvious. - Delete `DEFAULT_AUTOMATION_API_KEY_PATH` constant and its export (no downstream consumers in beta). - Add fail-fast guard in docker/entrypoint.sh when no session key is available, instead of silently exporting empty strings. Co-authored-by: openhands <openhands@all-hands.dev> * fix: update stale comment on AUTOMATION_LOCAL_API_KEY to reflect unified session key Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev>
22 lines
714 B
TypeScript
22 lines
714 B
TypeScript
import { describe, expect, it } from "vitest";
|
|
|
|
import { buildAutomationBackendEnv } from "../../scripts/dev-static.mjs";
|
|
|
|
describe("dev-static", () => {
|
|
it("uses the same session key for both agent-server and automation backend auth", () => {
|
|
const env = buildAutomationBackendEnv({
|
|
agentServerPort: 18000,
|
|
ingressPort: 8000,
|
|
sessionApiKey: "shared-session-key",
|
|
stateDir: "/tmp/agent-canvas-state",
|
|
});
|
|
|
|
// Both backends receive the same key value
|
|
expect(env).toMatchObject({
|
|
AUTOMATION_AGENT_SERVER_URL: "http://localhost:18000",
|
|
AUTOMATION_AGENT_SERVER_API_KEY: "shared-session-key",
|
|
AUTOMATION_LOCAL_API_KEY: "shared-session-key",
|
|
});
|
|
});
|
|
});
|