Apps refuse to send their token over plain http:// to a public address
CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Web typecheck and unit tests (push) Successful in 12s
CI & Build / Python tests (push) Successful in 13s
Android / Core and FFI clippy and tests (push) Successful in 56s
CI & Build / integration (push) Successful in 1m20s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m23s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m33s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 4m22s
Desktop (Tauri) / Update manifest (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Successful in 9m13s
Android / Build the server image (push) Successful in 1s
CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 3s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 3s
CI & Build / Web typecheck and unit tests (push) Successful in 12s
CI & Build / Python tests (push) Successful in 13s
Android / Core and FFI clippy and tests (push) Successful in 56s
CI & Build / integration (push) Successful in 1m20s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m23s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 3m33s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 4m22s
Desktop (Tauri) / Update manifest (push) Successful in 4s
Android / Kotlin + Rust (APK) (push) Successful in 9m13s
Android / Build the server image (push) Successful in 1s
Family idea #5105, practice 13, as the operator chose on 2026-10-08. The check lives in the shared core, so the desktop and Android both get it. compat::cleartext_allowed decides from the address text alone, with no DNS lookup. It allows https:// always. It allows http:// to private, loopback, link-local and CGNAT IPs (CGNAT covers Tailscale), to fc00::/7, fe80::/10 and ::1, to single-label names, and to LAN suffixes (.local, .lan, .home.arpa, .ts.net and others). The refusal runs in two places: - probe, so linking stops before a password or token is sent; - the top of run_cycle, so a device linked before this change stops syncing with a message telling it to re-link, instead of sending its token on every cycle. The server is unchanged and never forces HTTPS (rule 94). Plain http:// on a LAN links and syncs as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -38,6 +38,11 @@ pub async fn run_cycle(
|
||||
base_url: &str,
|
||||
token: &str,
|
||||
) -> Result<SyncOutcome, String> {
|
||||
// A device linked to a public plain-http:// address before links were checked
|
||||
// stops here, rather than sending its token in the clear on every cycle. Its
|
||||
// sync error says to re-link over https:// (family idea #5105, practice 13).
|
||||
super::compat::refuse_public_cleartext(base_url)?;
|
||||
|
||||
// What this server can do, asked before anything is sent: files attached here,
|
||||
// and removed attachments and previews, go only to a server advertising
|
||||
// `attachment_sync`. An older one keeps them queued on this device until it is
|
||||
|
||||
Reference in New Issue
Block a user