Summary
Remote connected Agentlets receive a loopback HUABU_RFS_URL such as:
http://127.0.0.1:3001/api/rfs/canvas-64f93a8d-08fe-4284-8a1b-a7cef6c36bb1
When Huabu Web is served on a public address and the Agentlet runs on another machine, that URL points at the Agentlet's own loopback interface rather than the Huabu server. The external Agent therefore cannot reach its Space through RFS.
This appears to have been present for some time but was hidden by local-Agentlet testing, where 127.0.0.1 happened to resolve to the same machine.
Impact
- Remote external Agents cannot use their injected RFS reachback URL.
- Prompts may imply that Space access is available even though the supplied endpoint is unreachable.
- Local and remote Agentlets receive the same server-local loopback origin despite having different network reachability.
Expected behavior
- The injected
HUABU_RFS_URL uses a canonical, explicitly trusted Huabu public/reachable origin appropriate for remote Agentlets.
- The Canvas-specific RFS path remains correct and authentication continues to use the existing scoped connection/token boundary.
- Local development retains an explicit and predictable loopback default when no public deployment origin is configured.
- Missing or invalid public-origin configuration fails explicitly for remote reachback rather than silently injecting an unusable loopback URL.
Investigation requirements
- Trace the canonical URL from server/bootstrap configuration through external Agent workload compilation and environment injection.
- Establish whether the current URL is hard-coded, inferred from listen/bind configuration, derived from an internal server URL, or reconstructed elsewhere.
- Reuse an existing canonical public-origin/base-URL setting if one already exists; do not introduce a competing source of truth.
- Do not trust arbitrary request
Host / forwarded headers unless the repository already has an explicit trusted-proxy contract that validates them.
- Verify behavior for local Agentlets, remote connected Agentlets, Web/public deployments, desktop/local development, and Canvas-specific URL construction.
- Treat the public origin as configuration, not as a credential; never expose additional secrets or weaken RFS authentication.
Acceptance criteria
Non-goals
- Changing RFS authentication or granting broader Space access.
- Automatically discovering arbitrary public interfaces or NAT mappings.
- Introducing a general reverse proxy, tunnel, or service-discovery system.
- Synchronizing
main and alpha as part of this functional hotfix.
Summary
Remote connected Agentlets receive a loopback
HUABU_RFS_URLsuch as:When Huabu Web is served on a public address and the Agentlet runs on another machine, that URL points at the Agentlet's own loopback interface rather than the Huabu server. The external Agent therefore cannot reach its Space through RFS.
This appears to have been present for some time but was hidden by local-Agentlet testing, where
127.0.0.1happened to resolve to the same machine.Impact
Expected behavior
HUABU_RFS_URLuses a canonical, explicitly trusted Huabu public/reachable origin appropriate for remote Agentlets.Investigation requirements
Host/ forwarded headers unless the repository already has an explicit trusted-proxy contract that validates them.Acceptance criteria
/api/rfs/<canvasId>path and existing authentication/token behavior.Non-goals
mainandalphaas part of this functional hotfix.