Skip to content

fix(security): require auth for non-loopback health - #93

Merged
AlisinaDevelo merged 1 commit into
mainfrom
fix/health-boundary
Sep 7, 2026
Merged

AlisinaDevelo merged 1 commit into
mainfrom
fix/health-boundary

Conversation

@AlisinaDevelo

@AlisinaDevelo AlisinaDevelo commented Sep 7, 2026 •

Copy link
Copy Markdown
Owner

Summary\n\nRemediates security finding sf-health-plaintext-001 from the StreamHive security audit. The optional HTTP health listener now fails closed for non-loopback binds unless an explicit bearer token is configured; sensitive diagnostic routes require Authorization: Bearer , while /livez and /readyz remain available for probes.\n\n## Changes\n\n- add -health-auth-token and constant-time bearer validation\n- keep loopback health compatibility and make the non-loopback boundary explicit\n- wire demo tokens through both Compose files and all Compose health clients\n- document the P2P/health TLS separation and reverse-proxy/private-network requirement\n- add acceptance coverage for address classification, missing/wrong/valid tokens, and probe access\n\n## Verification\n\n- go test -race -count=1 -run '^TestRun_healthServer' ./... passed\n- go vet ./... passed\n- go test -race -run '^$' ./... passed\n- Docker Compose config validation passed for both Compose files\n- shell syntax validation passed for updated demo scripts\n- full local race suite was attempted; unrelated durable-store/lifecycle tests hit Windows File.Sync Access is denied under the configured D-backed temp filesystem, so the complete Linux-hosted Actions matrix is authoritative\n\nPlease run the complete hosted Actions matrix, including Docker Compose demos, before merge.

Copilot AI lite review requested due to automatic review settings September 7, 2026 10:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@AlisinaDevelo
AlisinaDevelo merged commit fece3af into main Sep 7, 2026
41 checks passed
@AlisinaDevelo
AlisinaDevelo deleted the fix/health-boundary branch September 7, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants