Skip to content

Require opt-in for plugin deployment over private HTTP - #1682

Merged
BenCodez merged 1 commit into
masterfrom
codex/private-http-deployment-opt-in
Sep 30, 2026
Merged

BenCodez merged 1 commit into
masterfrom
codex/private-http-deployment-opt-in

Conversation

@BenCodez

@BenCodez BenCodez commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

Require an explicit Control.AllowInsecureHttpPluginDeployment: true before executable VotingPlugin staging is prepared, advertised or polled over a non-local literal private-network/link-local HTTP endpoint. The setting defaults to false when absent and is documented in both backend and proxy defaults.

Normal private-network HTTP Control registration, configuration, inspection and presence remain supported without the opt-in. Proxy voting is unchanged. HTTPS, literal loopback (including IPv6), and existing proven direct same-node hosted Control remain eligible by default. localhost still requires the existing hosting proof. Public HTTP and arbitrary HTTP hostnames remain prohibited even with the opt-in.

Security boundary

A deployment's expected SHA-256 and matching JAR travel over the same Control connection. A MITM on plaintext private HTTP can substitute both, so a checksum alone does not authenticate the executable source. Opted-in private HTTP connectors emit a prominent initialization warning covering node credentials, deployment metadata, executable artifacts and the recommendation to use HTTPS. Disabled deployment routes emit an actionable initialization diagnostic without continuous polling noise.

The centralized deployment endpoint policy distinguishes HTTPS, local HTTP, opted-in private HTTP, private HTTP without opt-in, and unsupported endpoints. Both connectors use that policy for preparation and capability admission; the actual artifact deployment checks it again with the captured opt-in. Existing overloads remain available and default to the safe policy.

The separate credential-endpoint eligibility contract is unchanged: HTTPS or proven same-node loopback HTTP. This option does not relax credential endpoint authorization, redirects, staging destinations, JAR validation or SHA-256 verification.

Compatibility

  • No migration, config rewrite, backend synchronization or proxy-method change.
  • Existing HTTPS and local hosted/loopback deployment remains available.
  • Existing non-local private HTTP Control continues normal operation; only executable deployment now requires explicit opt-in.
  • Restart/recreate the connector after changing the deployment policy.
  • No Control API/capability version change or coordinator update required.

Validation

  • Focused deployment, backend/proxy Control connector, Velocity config, hosted-Control and auto-enrollment tests: 136 passed.
  • mvn -B -f VotingPlugin/pom.xml clean package: 1,683 tests passed, plus 4 packaged-artifact checks, 57.536 seconds.
  • Downloadable JAR: 10,456,452 bytes, below the 10 MiB gate; core isolation and packaged runtime checks passed.
  • git diff --check: passed.
  • Full diff manually inspected; fresh independent read-only review: No findings.

Coverage includes IPv4 private ranges and boundaries, IPv6 unique-local/link-local/loopback, proven same-node hosting, HTTPS with both flag values, rejection of public/arbitrary HTTP even with opt-in, unsupported protocols, stricter credential eligibility, actual backend/proxy connector construction without deployment capability or staging readiness, config defaults and explicit opt-in readers, and rejection before artifact network access.

No live Control deployment was performed. Private HTTP opted in by the administrator remains vulnerable to network-path interception/modification; HTTPS is the recommended protection.

Summary by CodeRabbit

  • Security
    • Plugin deployments over private-network HTTP are disabled by default and require explicit opt-in. HTTPS, loopback HTTP, and verified same-node HTTP remain available; public HTTP and arbitrary HTTP hostnames are not allowed.
    • A warning appears when private-network HTTP deployment is enabled, since unencrypted deployment traffic may be intercepted or modified.
  • Documentation
    • Clarified endpoint eligibility, configuration, and security considerations for plugin deployments.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-30T02:27:16.555783Z d87d6a2 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 81c8ffea-8a0a-4756-9cff-7736487e7729

📥 Commits

Reviewing files that changed from the base of the PR and between 5e86b79 and d87d6a2.

📒 Files selected for processing (15)
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/config/Config.java
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/control/BackendControlConnector.java
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/control/PluginDeploymentService.java
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/VotingPluginProxyConfig.java
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/bungee/BungeeConfig.java
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/control/ControlConnector.java
  • VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfig.java
  • VotingPlugin/src/main/resources/Config.yml
  • VotingPlugin/src/main/resources/bungeeconfig.yml
  • VotingPlugin/src/test/java/com/bencodez/votingplugin/control/BackendControlConnectorProtocolTest.java
  • VotingPlugin/src/test/java/com/bencodez/votingplugin/control/PluginDeploymentServiceTest.java
  • VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/control/ControlConnectorTest.java
  • VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfigControlTest.java
  • docs/control-agent-contract.md
  • docs/control-connector.md

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: build
  • GitHub Check: Analyze (java-kotlin)
  • GitHub Check: Analyze (actions)
🧰 Additional context used
📓 Path-based instructions (3)
Source excerpt: Do not translate an inspection request into a configuration operation.

📄 CodeRabbit inference engine (docs/control-agent-contract.md)

Files:

  • docs/control-agent-contract.md
Source excerpt: Do not raise these by patching around validation; correct the topology or connectivity problem instead.

📄 CodeRabbit inference engine (docs/control-connector.md)

Files:

  • docs/control-connector.md
Source excerpt: `auto-create-vote-sites` is intentionally narrower than `common-settings`: it reads/writes only `Config.yml -> AutoCreateVoteSites`.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • VotingPlugin/src/main/resources/Config.yml
🪛 LanguageTool
docs/control-agent-contract.md

[style] ~203-~203: The double modal “requires proven” is nonstandard (only accepted in certain dialects). Consider “to be proven”.
Context: ... the opt-in; localhost still requires proven direct local hosting. An opted-in conne...

(NEEDS_FIXED)

🔇 Additional comments (15)
VotingPlugin/src/main/java/com/bencodez/votingplugin/config/Config.java (1)

28-31: LGTM!

VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/VotingPluginProxyConfig.java (1)

78-81: LGTM!

VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/bungee/BungeeConfig.java (1)

59-62: LGTM!

VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfig.java (1)

227-230: LGTM!

VotingPlugin/src/main/resources/Config.yml (1)

1177-1180: LGTM!

Also applies to: 1204-1205

VotingPlugin/src/main/resources/bungeeconfig.yml (1)

513-516: LGTM!

Also applies to: 518-518

VotingPlugin/src/test/java/com/bencodez/votingplugin/control/BackendControlConnectorProtocolTest.java (1)

7-7: LGTM!

Also applies to: 33-41, 43-68

VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfigControlTest.java (1)

23-32: LGTM!

VotingPlugin/src/main/java/com/bencodez/votingplugin/control/PluginDeploymentService.java (1)

123-127: LGTM!

Also applies to: 131-133, 456-458, 464-464, 468-510, 526-527, 534-534, 540-540, 542-542

VotingPlugin/src/test/java/com/bencodez/votingplugin/control/PluginDeploymentServiceTest.java (1)

136-164: LGTM!

Also applies to: 166-174, 179-179

VotingPlugin/src/main/java/com/bencodez/votingplugin/control/BackendControlConnector.java (1)

75-75: LGTM!

Also applies to: 146-152, 491-491

VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/control/ControlConnector.java (1)

92-92: LGTM!

Also applies to: 154-154, 164-165, 182-182, 265-268, 271-272, 283-283, 354-354

VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/control/ControlConnectorTest.java (1)

105-142: LGTM!

Also applies to: 1053-1053, 1057-1057

docs/control-agent-contract.md (1)

197-207: LGTM!

docs/control-connector.md (1)

215-232: LGTM!


📝 Walkthrough

Walkthrough

Private-network HTTP plugin deployment now requires an explicit setting that defaults to false. Endpoint policy and backend and proxy connectors use this setting to decide whether to prepare and execute deployment staging. HTTPS, loopback HTTP, and proven same-node HTTP retain their existing allowances.

Changes

Plugin deployment endpoint policy

Layer / File(s) Summary
Expose the deployment opt-in
VotingPlugin/src/main/java/com/bencodez/votingplugin/config/Config.java, VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/VotingPluginProxyConfig.java, VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/bungee/BungeeConfig.java, VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfig.java, VotingPlugin/src/main/resources/Config.yml, VotingPlugin/src/main/resources/bungeeconfig.yml, VotingPlugin/src/test/java/com/bencodez/votingplugin/control/BackendControlConnectorProtocolTest.java, VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfigControlTest.java
Backend and proxy configuration expose Control.AllowInsecureHttpPluginDeployment, defaulting to false. Configuration comments describe its scope and risks. Tests verify the default and explicit enablement.
Enforce endpoint rules
VotingPlugin/src/main/java/com/bencodez/votingplugin/control/PluginDeploymentService.java, VotingPlugin/src/test/java/com/bencodez/votingplugin/control/PluginDeploymentServiceTest.java
Endpoint policy permits HTTPS and loopback HTTP without opt-in. Private and link-local HTTP require opt-in unless same-node hosting is proven. Public HTTP, arbitrary hostnames, unsupported schemes, and unproven localhost remain disallowed.
Apply policy to connector staging
VotingPlugin/src/main/java/com/bencodez/votingplugin/control/BackendControlConnector.java, VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/control/ControlConnector.java, VotingPlugin/src/test/java/com/bencodez/votingplugin/control/BackendControlConnectorProtocolTest.java, VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/control/ControlConnectorTest.java, docs/control-agent-contract.md, docs/control-connector.md
Both connectors apply endpoint policy before preparing deployment staging and pass the opt-in to deployment execution. Tests verify disabled staging and capability advertisement for private HTTP without opt-in. Documentation describes the endpoint rules and warning.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant BungeeConfig
  participant ControlConnector
  participant PluginDeploymentService
  BungeeConfig->>ControlConnector: supplies private HTTP deployment setting
  ControlConnector->>PluginDeploymentService: evaluates endpoint policy
  PluginDeploymentService-->>ControlConnector: returns allow decision and initialization message
  ControlConnector->>PluginDeploymentService: passes setting when executing deployment
Loading

Merge Risk: ⚪ Minimal · up to d87d6

Private-network HTTP plugin deployment now requires an explicit opt-in that is off by default, which tightens security. Nothing in the supplied change indicates a merge-blocking problem. Users who deploy over private HTTP must set the option after upgrading.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d87d6

The change reduces default exposure by requiring explicit approval for private-network HTTP deployment. Enabled plaintext deployment still permits interception of credentials and executable content. No introduced or materially worsened attack path was established, but some authority and recovery assumptions remain unresolved.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — When private HTTP deployment is enabled, an attacker controlling that network connection can target the node bearer credential and substitute deployment metadata together with a matching executable JAR. Successful later activation would inherit the affected server or proxy process privileges; broader tenant or infrastructure exposure is not established.

Security Findings and Attack Paths

  • inferred — The documented plaintext substitution condition predates this PR because private HTTP deployment was previously eligible without opt-in. The PR narrows default reachability rather than introducing that condition; it does not make an opted-in connection authenticated through SHA-256 alone.

Trust Boundaries and Controls

  • observed — Known production artifact clients disable redirects. The public deployment service still accepts a caller-supplied HTTP client, so redirect containment remains caller-owned rather than intrinsically enforced by the service. This dependency is unchanged.
  • observed — The same-node exception uses an existing helper that matches enabled hosted configuration, listener host, port, and origin shape. The inspected helper does not itself verify a running local child or physical interface ownership. Runtime evidence supporting that locality assumption remains incomplete.

Resilience and Maintainability Implications

  • observed — Recovery-only connectors suppress new deployment preparation. Centralized policy categories also provide initialization diagnostics for disabled or unsupported routes and an explicit plaintext warning for opted-in private HTTP, reducing duplicated eligibility decisions.

Hardening Proposals

  • proposed — If opt-in is intended to represent approval independent of the Control connection, reserve that setting to local administration and explicitly define whether disabling it invalidates pending staged artifacts. Independently authenticated artifact signatures could further separate executable authority from plaintext transport.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.28% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 43 functions across 11 files. (4 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: requiring explicit opt-in for plugin deployment over private HTTP.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 16.28% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 43 functions across 11 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@BenCodez
BenCodez merged commit bae0462 into master Sep 30, 2026
6 checks passed
@BenCodez
BenCodez deleted the codex/private-http-deployment-opt-in branch September 30, 2026 02:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant