Re-implements the dsh-web auth fix after the first attempt was contained for an
unauthenticated bypass and a header regression.
Design
No :8081 endpoint. The 0.0.0.0:8081 listener with no auth_request is removed; the script stashes any reappearing /etc/nginx/sites-enabled/dsh.token and never restores it (pending-reload marker on failure).
Login inside the Authentik-gated :80 block as location = /dsh-web-login, guarded by auth_request /outpost.goauthentik.io/auth/nginx, proxying to dsh-web with Host: tankodhs.sysloggh.net so the 30-day cookie is bound to the public authority (never 127.0.0.1:3080).
Non-disruptive token capture (scripts/capture-dsh-token.sh): reads candidates from the running service's journal scoped to the current systemd invocation, functionally verifies the live token (303), regenerates /etc/dsh-web/nginx-login.conf, reloads nginx only on change (nginx -t guarded, applied stamp, pending marker), flock-serialized. Never stops/starts dsh-web. Wired via dsh-web-token.service (ExecStartPost) + dsh-web-token.timer.
Restores x-dsh-task-board-proxy-token and Host $ak_origin_host.
Validated by no-mistakes run 01M28P5XAZ5NKF9Q60DT3VWCCF (outcome passed).
## Corrected dsh-web authentication (parent correction b34cd9a3d16422d3)
Re-implements the dsh-web auth fix after the first attempt was contained for an
unauthenticated bypass and a header regression.
### Design
1. **No `:8081` endpoint.** The `0.0.0.0:8081` listener with no `auth_request` is removed; the script stashes any reappearing `/etc/nginx/sites-enabled/dsh.token` and never restores it (pending-reload marker on failure).
2. **Login inside the Authentik-gated `:80` block** as `location = /dsh-web-login`, guarded by `auth_request /outpost.goauthentik.io/auth/nginx`, proxying to dsh-web with `Host: tankodhs.sysloggh.net` so the 30-day cookie is bound to the public authority (never `127.0.0.1:3080`).
3. **Non-disruptive token capture** (`scripts/capture-dsh-token.sh`): reads candidates from the running service's journal scoped to the current systemd invocation, functionally verifies the live token (`303`), regenerates `/etc/dsh-web/nginx-login.conf`, reloads nginx only on change (`nginx -t` guarded, applied stamp, pending marker), `flock`-serialized. Never stops/starts dsh-web. Wired via `dsh-web-token.service` (`ExecStartPost`) + `dsh-web-token.timer`.
4. Restores `x-dsh-task-board-proxy-token` and `Host $ak_origin_host`.
### Live acceptance (CT 112, 2026-09-11)
- Unauthenticated `:80 /dsh-web-login` -> 302 (Authentik); `:8081` -> 000
- Authenticated mint + cookie-jar replay -> 303 -> 200
- Restart `dsh-web`: include auto-refreshed in ~30s; pre-restart cookie still 200; new token mints 303
### Repo changes
- `scripts/capture-dsh-token.sh`, `zulip-health.prose.md` (B4, v3.2.0), `contract-registry.yaml`
Validated by no-mistakes run `01M28P5XAZ5NKF9Q60DT3VWCCF` (outcome `passed`).
- Add capture-dsh-token.sh script that captures the dsh-web launch token
- Add login endpoint (/dsh-web-login on :8081) that mints 30-day auth cookie
- Document the authentication flow in zulip-health.prose.md (Platform B4)
- Cookie is authority-bound to 127.0.0.1:3080 with 30-day expiry
- After first login, subsequent requests use the cookie — no token required
Correct the dsh-web authentication fix after parent correction:
- Remove the unauthenticated :8081 endpoint (0.0.0.0 bind with no
auth_request = full Authentik bypass for the LAN). The script now removes
/etc/nginx/sites-enabled/dsh.token automatically if it reappears.
- Put the login path inside the Authentik-gated :80 server block as
location = /dsh-web-login; proxy to dsh-web with Host =
tankodhs.sysloggh.net so the 30-day cookie is bound to the public
authority, never to 127.0.0.1:3080.
- Isolate the rotating token in a generated include
/etc/dsh-web/nginx-login.conf; reload nginx only when it changes.
- Replace the disruptive capture (systemctl stop/start dsh-web) with a
non-disruptive read of the running service's journal, scoped to the
current systemd invocation so a restarted process's stale token is never
reused while the new banner is still pending.
- Keep x-dsh-task-board-proxy-token and Host $ak_origin_host intact in '/'.
- Document the corrected design (B4) in zulip-health.prose.md, v3.2.0.
Live-verified 2026-09-11: no auth bypass (302), :8081 refused (000), a
cookie minted before two dsh-web restarts still returns 200, the refreshed
token mints a fresh cookie, and the systemd ExecStartPost/timer refreshes
the token automatically without touching dsh-web.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Corrected dsh-web authentication (parent correction b34cd9a3d16422d3)
Re-implements the dsh-web auth fix after the first attempt was contained for an
unauthenticated bypass and a header regression.
Design
:8081endpoint. The0.0.0.0:8081listener with noauth_requestis removed; the script stashes any reappearing/etc/nginx/sites-enabled/dsh.tokenand never restores it (pending-reload marker on failure).:80block aslocation = /dsh-web-login, guarded byauth_request /outpost.goauthentik.io/auth/nginx, proxying to dsh-web withHost: tankodhs.sysloggh.netso the 30-day cookie is bound to the public authority (never127.0.0.1:3080).scripts/capture-dsh-token.sh): reads candidates from the running service's journal scoped to the current systemd invocation, functionally verifies the live token (303), regenerates/etc/dsh-web/nginx-login.conf, reloads nginx only on change (nginx -tguarded, applied stamp, pending marker),flock-serialized. Never stops/starts dsh-web. Wired viadsh-web-token.service(ExecStartPost) +dsh-web-token.timer.x-dsh-task-board-proxy-tokenandHost $ak_origin_host.Live acceptance (CT 112, 2026-09-11)
:80 /dsh-web-login-> 302 (Authentik);:8081-> 000dsh-web: include auto-refreshed in ~30s; pre-restart cookie still 200; new token mints 303Repo changes
scripts/capture-dsh-token.sh,zulip-health.prose.md(B4, v3.2.0),contract-registry.yamlValidated by no-mistakes run
01M28P5XAZ5NKF9Q60DT3VWCCF(outcomepassed).