Skip to content

Hotfix remote Agent RFS reachback to use a reachable public origin #280

Description

@mydmdm

Summary

Remote connected Agentlets receive a loopback HUABU_RFS_URL such as:

http://127.0.0.1:3001/api/rfs/canvas-64f93a8d-08fe-4284-8a1b-a7cef6c36bb1

When Huabu Web is served on a public address and the Agentlet runs on another machine, that URL points at the Agentlet's own loopback interface rather than the Huabu server. The external Agent therefore cannot reach its Space through RFS.

This appears to have been present for some time but was hidden by local-Agentlet testing, where 127.0.0.1 happened to resolve to the same machine.

Impact

  • Remote external Agents cannot use their injected RFS reachback URL.
  • Prompts may imply that Space access is available even though the supplied endpoint is unreachable.
  • Local and remote Agentlets receive the same server-local loopback origin despite having different network reachability.

Expected behavior

  • The injected HUABU_RFS_URL uses a canonical, explicitly trusted Huabu public/reachable origin appropriate for remote Agentlets.
  • The Canvas-specific RFS path remains correct and authentication continues to use the existing scoped connection/token boundary.
  • Local development retains an explicit and predictable loopback default when no public deployment origin is configured.
  • Missing or invalid public-origin configuration fails explicitly for remote reachback rather than silently injecting an unusable loopback URL.

Investigation requirements

  • Trace the canonical URL from server/bootstrap configuration through external Agent workload compilation and environment injection.
  • Establish whether the current URL is hard-coded, inferred from listen/bind configuration, derived from an internal server URL, or reconstructed elsewhere.
  • Reuse an existing canonical public-origin/base-URL setting if one already exists; do not introduce a competing source of truth.
  • Do not trust arbitrary request Host / forwarded headers unless the repository already has an explicit trusted-proxy contract that validates them.
  • Verify behavior for local Agentlets, remote connected Agentlets, Web/public deployments, desktop/local development, and Canvas-specific URL construction.
  • Treat the public origin as configuration, not as a credential; never expose additional secrets or weaken RFS authentication.

Acceptance criteria

  • A remote connected Agentlet receives an RFS URL reachable from the Agentlet machine when Huabu is configured with a public origin.
  • The injected URL preserves the correct /api/rfs/<canvasId> path and existing authentication/token behavior.
  • Local development continues to work with a documented loopback default or explicit local configuration.
  • Invalid, unsupported, or missing required public-origin configuration produces an actionable error rather than an unreachable success-shaped URL.
  • URL normalization rejects unsafe schemes/credentials/fragments and avoids duplicate or missing path separators.
  • Tests cover public hostnames/IPs, non-default ports, optional base paths if supported, local fallback, remote behavior, and untrusted forwarded/Host input.
  • Relevant deployment, Agentlet, and Agent reachback architecture documentation is updated.

Non-goals

  • Changing RFS authentication or granting broader Space access.
  • Automatically discovering arbitrary public interfaces or NAT mappings.
  • Introducing a general reverse proxy, tunnel, or service-discovery system.
  • Synchronizing main and alpha as part of this functional hotfix.

Activity

  1. mydmdm commented on Oct 8, 2026

    @mydmdm
    ContributorAuthor

    Resolved by #282, merged into alpha as b2cbf9f39c91600ae277f072f19112a66bd95ebf. Remote Agent RFS and Agentlet endpoints now derive from the validated canonical HUABU_PUBLIC_ORIGIN; local fallback, authentication boundaries, non-default ports, validation, tests, and deployment documentation are covered.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions