Repository navigation
feat(drivers): host.http_request with a per-driver cookie jar - #1505
Merged
Merged
Conversation
A driver that reads a cloud behind a web login (the VW Group EU Data Act portal, srcfl/device-drivers#143) needs the response status and Location, and somewhere to keep the session cookie. http_get/post turn 4xx into errors, follow redirects and keep no cookies. host.http_request{method, url, headers, body} returns {status, headers, location, body}. It never follows a redirect, so every hop is a separate call checked against allowed_hosts. GET and POST only, https only, non-empty allowed_hosts only; POST uses the http_post gate. Cookies live in an in-memory jar per driver that stores and sends them only for allowed hosts; Set-Cookie is left out of the headers Lua sees. host.http_cookies_clear() resets it. http_get/post/patch are unchanged. Signed read-only metadata may declare auth_post_paths next to auth_post_path, for a login that posts more than one form. Each path matches exactly. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The VW Group EU Data Act portal session lasts about an hour.
vag_vehicleneeds a pasted Cookie header each time, so the car's SoC disappears every hour until the owner pastes a new one (srcfl/device-drivers#143).The driver could sign in itself, as evcc does, but the Lua host prevents it:
http_get/http_postturn 4xx into errors and follow redirects.Locationand no response headers.Change
host.http_request{method, url, headers, body}returns{status, headers, location, body}.locationand makes the next call, so Core checks every hop againstallowed_hosts.allowed_hosts.http_post(allowWrite, or a declared sign-in path for a read-only driver).headers.date.Cookie jar per driver.
http_requestuses it.Set-Cookieis left out of the headers Lua sees, so session cookies stay out of Lua and logs.host.http_cookies_clear()empties the jar before a fresh sign-in.auth_post_pathsin signed read-only metadata adds further exact sign-in paths next toauth_post_path. It flows through the catalog,driverrepoandRuntimePolicy. Each path matches exactly, as before.Unchanged:
http_get,http_postandhttp_patch. Drivers that do not call the new functions behave exactly as before.host_apistays at 1. The driver checksif host.http_request thenand falls back to a pasted cookie on an older Core.Paired PR
srcfl/device-drivers#156:
vag_vehicle0.2.0 signs in with email and password, renews the session, and reports SoC age from VW's clocks. The channel builder publishesauth_post_pathsand guards POST throughhttp_request. Merge this Core PR first; the driver works on an older Core in cookie mode.Related
Validation
lua_http_request_test.go, against a TLS test server reached through the pin:locationresolvedSet-CookiehiddenDatereadablehttp_getdoes not use the jarhttp_cookies_clearhttp_requestreaches only declared paths.auth_post_paths. Persist-secret test with only a path list.vag_vehicle0.2.0 in this host's gopher-lua against a scripted VW portal: sign-in, a SoC read and a 300 s age all came through.make verify: vet, test and build clean.🤖 Generated with Claude Code