mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
The desktop's local backend binds to loopback, where the gateway now enforces no identity token (REST via Phase 2, WS via Phase 4 — the peer-IP + Host/Origin guard is the boundary). So the desktop's local token machinery is dead weight and is removed: - stop generating HERMES_DASHBOARD_SESSION_TOKEN + passing it to the two local-spawn child envs - fetchJson omits X-Hermes-Session-Token when the token is falsy - the local connection uses token:null + a credential-free WS URL (new buildGatewayWsUrlNoAuth helper, electron-free + unit-tested) - delete dashboard-token.cjs (+ its test): it existed solely to reconcile the served __HERMES_SESSION_TOKEN__ drift for the local backend, which the server now ignores on loopback The REMOTE auth modes are untouched: 'token' (user-saved token for a remote loopback/--insecure gateway, still sent as X-Hermes-Session-Token + ?token=) and 'oauth' (cookie + ?ticket=) both work exactly as before. Co-authored-by: Hermes subagent <noreply@nousresearch.com> Note: windows-child-process.test.cjs has one pre-existing failure on origin/main (a stale source-scan needle 'execFileSync(pyExe'); unrelated to this change and left as-is. |
||
|---|---|---|
| .. | ||
| bootstrap-installer | ||
| desktop | ||
| shared | ||