Unverified Commit 285c5695 authored by Lemon-miaow's avatar Lemon-miaow
Browse files

fix: keep the Passkey hostname in local sign-in guidance

parent 373af3b0
Loading
Loading
Loading
Loading
+2 −1
Changes for deploy/bootstrap.sh: 2 added lines, 1 removed line.
Original line number Diff line number Diff line
@@ -5881,7 +5881,8 @@ summary_next() {
  log "$rule"
  if [ "$owner" = yes ]; then
    log "Felis is running. Sign in at https://$(auth_hostname admin_hostname "op.console.${FELIS_ROOT_DOMAIN}")"
    log "(https://${NODE_IP}:${FELIS_PANEL_NODEPORT} until the edge routes it there)."
    log "Local access: https://$(auth_hostname admin_hostname "op.console.${FELIS_ROOT_DOMAIN}"):${FELIS_PANEL_NODEPORT}"
    log "Passkey requires the configured hostname; direct IP access cannot use Passkey."
    log "Email, edge and storage settings: sudo felis setup"
    log "$rule"
    return 0
+15 −0
Changes for deploy/bootstrap_test.sh: 15 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -5316,6 +5316,21 @@ out="$(WORKER_TOKEN_FILE="$badtoken" bash -c '
expect "worker refuses a copied server token before changing the machine" 'worker accepts only CA-pinned bootstrap tokens' "$out"
rm -f "$badtoken"

# Local panel URLs must keep the WebAuthn hostname, including before edge setup.
out="$(bash -c '
  bootstrap_from_tui() { return 1; }
  owner_state() { echo yes; }
  auth_hostname() { echo "$2"; }
  log() { printf "%s\n" "$*"; }
  FELIS_ROOT_DOMAIN=10.211.55.6.nip.io NODE_IP=10.211.55.6 FELIS_PANEL_NODEPORT=30443
  '"$(bsfn summary_next)"'
  summary_next
')"
expect "local sign-in URL preserves the Passkey hostname" \
  "Local access: https://op.console.10.211.55.6.nip.io:30443" "$out"
expect "local sign-in explains why IP access cannot use Passkey" \
  "direct IP access cannot use Passkey" "$out"

# SELinux rejects /run paths when the policy aliases them to /var/run.
node_fcontext="$(bsfn install_node_control_service | awk '/^  if .*command -v semanage/,/^  fi/')"
[ -n "$node_fcontext" ] && [ "$(printf '%s\n' "$node_fcontext" | wc -l)" -lt 12 ] \