Repository navigation
fix(security): require auth for non-loopback health - #93
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary\n\nRemediates security finding sf-health-plaintext-001 from the StreamHive security audit. The optional HTTP health listener now fails closed for non-loopback binds unless an explicit bearer token is configured; sensitive diagnostic routes require Authorization: Bearer , while /livez and /readyz remain available for probes.\n\n## Changes\n\n- add -health-auth-token and constant-time bearer validation\n- keep loopback health compatibility and make the non-loopback boundary explicit\n- wire demo tokens through both Compose files and all Compose health clients\n- document the P2P/health TLS separation and reverse-proxy/private-network requirement\n- add acceptance coverage for address classification, missing/wrong/valid tokens, and probe access\n\n## Verification\n\n- go test -race -count=1 -run '^TestRun_healthServer' ./... passed\n- go vet ./... passed\n- go test -race -run '^$' ./... passed\n- Docker Compose config validation passed for both Compose files\n- shell syntax validation passed for updated demo scripts\n- full local race suite was attempted; unrelated durable-store/lifecycle tests hit Windows File.Sync Access is denied under the configured D-backed temp filesystem, so the complete Linux-hosted Actions matrix is authoritative\n\nPlease run the complete hosted Actions matrix, including Docker Compose demos, before merge.