hermes-agent/apps
Ben 6cf12eef4e feat(desktop): drop legacy session token for the local spawned backend
The desktop's local backend binds to loopback, where the gateway now
enforces no identity token (REST via Phase 2, WS via Phase 4 — the
peer-IP + Host/Origin guard is the boundary). So the desktop's local
token machinery is dead weight and is removed:

- stop generating HERMES_DASHBOARD_SESSION_TOKEN + passing it to the two
  local-spawn child envs
- fetchJson omits X-Hermes-Session-Token when the token is falsy
- the local connection uses token:null + a credential-free WS URL
  (new buildGatewayWsUrlNoAuth helper, electron-free + unit-tested)
- delete dashboard-token.cjs (+ its test): it existed solely to reconcile
  the served __HERMES_SESSION_TOKEN__ drift for the local backend, which
  the server now ignores on loopback

The REMOTE auth modes are untouched: 'token' (user-saved token for a
remote loopback/--insecure gateway, still sent as X-Hermes-Session-Token
+ ?token=) and 'oauth' (cookie + ?ticket=) both work exactly as before.

Co-authored-by: Hermes subagent <noreply@nousresearch.com>

Note: windows-child-process.test.cjs has one pre-existing failure on
origin/main (a stale source-scan needle 'execFileSync(pyExe'); unrelated
to this change and left as-is.
2026-06-17 09:56:27 +10:00
..
bootstrap-installer fix(desktop): move tsconfig to es2023 2026-06-15 12:07:17 -04:00
desktop feat(desktop): drop legacy session token for the local spawned backend 2026-06-17 09:56:27 +10:00
shared fix(desktop): move tsconfig to es2023 2026-06-15 12:07:17 -04:00