Skip to content

feat(drivers): host.http_request with a per-driver cookie jar - #1505

Merged
frahlg merged 1 commit into
masterfrom
lua-http-request-cookie-jar
Oct 3, 2026
Merged

frahlg merged 1 commit into
masterfrom
lua-http-request-cookie-jar

Conversation

@frahlg

@frahlg frahlg commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Problem

The VW Group EU Data Act portal session lasts about an hour. vag_vehicle needs a pasted Cookie header each time, so the car's SoC disappears every hour until the owner pastes a new one (srcfl/device-drivers#143).

The driver could sign in itself, as evcc does, but the Lua host prevents it:

  • http_get/http_post turn 4xx into errors and follow redirects.
  • Lua sees no status, no Location and no response headers.
  • There is no cookie jar.
  • A signed read-only driver may POST to one exact sign-in path. The VW login posts two forms.

Change

host.http_request{method, url, headers, body} returns {status, headers, location, body}.

  • It never follows a redirect. The driver reads location and makes the next call, so Core checks every hop against allowed_hosts.
  • GET and POST only, https only, and only with a non-empty allowed_hosts.
  • POST goes through the same gate as http_post (allowWrite, or a declared sign-in path for a read-only driver).
  • Same TLS pinning, 15 s timeout and 1 MiB response cap as the other verbs.
  • Header names are lowercase. A driver without a wall clock can read the server time from headers.date.

Cookie jar per driver.

  • Held in memory only, so a driver restart starts a clean session.
  • Only http_request uses it.
  • It stores and sends cookies only for allowed hosts over https.
  • Set-Cookie is left out of the headers Lua sees, so session cookies stay out of Lua and logs.
  • host.http_cookies_clear() empties the jar before a fresh sign-in.

auth_post_paths in signed read-only metadata adds further exact sign-in paths next to auth_post_path. It flows through the catalog, driverrepo and RuntimePolicy. Each path matches exactly, as before.

Unchanged: http_get, http_post and http_patch. Drivers that do not call the new functions behave exactly as before. host_api stays at 1. The driver checks if host.http_request then and falls back to a pasted cookie on an older Core.

Paired PR

srcfl/device-drivers#156: vag_vehicle 0.2.0 signs in with email and password, renews the session, and reports SoC age from VW's clocks. The channel builder publishes auth_post_paths and guards POST through http_request. Merge this Core PR first; the driver works on an older Core in cookie mode.

Related

Validation

  • New lua_http_request_test.go, against a TLS test server reached through the pin:
    • sign-in with the jar
    • 4xx returned, not raised
    • redirect returned with location resolved
    • Set-Cookie hidden
    • Date readable
    • http_get does not use the jar
    • http_cookies_clear
    • an off-host next hop is refused
  • Refusal tests: empty allowlist, plain http, other host, unsupported method.
  • A read-only POST through http_request reaches only declared paths.
  • The jar drops other hosts and plain http.
  • Catalog test for auth_post_paths. Persist-secret test with only a path list.
  • Ran vag_vehicle 0.2.0 in this host's gopher-lua against a scripted VW portal: sign-in, a SoC read and a 300 s age all came through.
  • make verify: vet, test and build clean.
  • Not yet run against the live VW portal.

🤖 Generated with Claude Code

A driver that reads a cloud behind a web login (the VW Group EU Data
Act portal, srcfl/device-drivers#143) needs the response status and
Location, and somewhere to keep the session cookie. http_get/post
turn 4xx into errors, follow redirects and keep no cookies.

host.http_request{method, url, headers, body} returns
{status, headers, location, body}. It never follows a redirect, so
every hop is a separate call checked against allowed_hosts. GET and
POST only, https only, non-empty allowed_hosts only; POST uses the
http_post gate. Cookies live in an in-memory jar per driver that
stores and sends them only for allowed hosts; Set-Cookie is left out
of the headers Lua sees. host.http_cookies_clear() resets it.
http_get/post/patch are unchanged.

Signed read-only metadata may declare auth_post_paths next to
auth_post_path, for a login that posts more than one form. Each path
matches exactly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T05:30:08.861255Z c30adb5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@frahlg
frahlg merged commit 1bd74cc into master Oct 3, 2026
14 checks passed
@frahlg
frahlg deleted the lua-http-request-cookie-jar branch October 3, 2026 05:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant