Skip to content

docs: no-internal-auth design ruling + README Upgrading section - #1377

Open
waleedkadous wants to merge 2 commits into
mainfrom
docs/arch-no-internal-auth
Open

docs: no-internal-auth design ruling + README Upgrading section#1377
waleedkadous wants to merge 2 commits into
mainfrom
docs/arch-no-internal-auth

Conversation

@waleedkadous

@waleedkadous waleedkadous commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Two doc additions:

  1. arch.md Key Design Decision 8 — records the owner ruling from issue tower: no internal authentication — any request reaching the tunnel reaches every Tower endpoint; all auth lives at the codevos.ai edge #1375: Tower deliberately has no internal auth (localhost binding for local, codevos.ai edge for tunnel-borne, origin-restricted management endpoints per PR [#1370] Fix tunnel path bypass that let a remote request deregister the tower #1374). Prevents re-litigating the decision as a vulnerability.

  2. README Upgrading section — adopter-requested: documents that upgrading is two steps (global npm install + per-project codev update), why skipping step 2 causes 'agents stopped following the protocol' reports, VS Code extension update path, and the Tower restart note.

@waleedkadous waleedkadous changed the title arch: record Tower no-internal-auth-by-design decision (#1375 ruling) docs: no-internal-auth design ruling + README Upgrading section Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant