Skip to content

fix: apply the mobile allowlist to orchestration requests - #909

Merged
leynier merged 1 commit into
mainfrom
fix/orchestration-mobile-allowlist
Oct 6, 2026
Merged

leynier merged 1 commit into
mainfrom
fix/orchestration-mobile-allowlist

Conversation

@leynier

@leynier leynier commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Summary

orchestration.* requests were routed in client_request_dispatch.rs before handle_request, so the only check they got was require_auth. An authenticated paired phone or relay client could therefore call every orchestration verb (reset, cancel, policy approval, send, reply, inbox reads), even though mobile_request_allowed lists none of them. The orchestration router now calls require_authenticated_local_request, so non-local clients get the same "Mobile clients cannot call terminal host request" refusal as every other verb outside the allowlist. Local clients (desktop app, CLI, hub self-client) are unchanged.

This is the first PR of the inbox stack: the inbox verbs added later are reachable from the phone only through explicit allowlist entries.

Validation

  • New orchestration_mobile_access_tests drive the real dispatcher (handle_line) with local, paired mobile, relay and unauthenticated clients. With the fix reverted, the phone could run orchestration.reset and both tests failed; with the fix they pass.
  • cargo clippy -p alera-cli --all-targets -- -D warnings and cargo test -p alera-cli (1847 unit tests plus integration tests) pass locally.
  • dart run tool/quality/check_max_lines.dart passes.

Risk

A mobile build that relied on calling orchestration.* directly would now be refused; the mobile app does not call any orchestration verb today.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed the orchestration mobile allowlist gate against the early dispatch path, the allowlist, and the new dispatcher tests.

  • Allowlist on the early router — handle_orchestration_request now calls require_authenticated_local_request before any verb runs, so a paired phone or relay client is refused unless that exact verb is on the mobile allowlist.
  • Dispatcher tests — Local, phone, relay, and unauthenticated clients drive handle_line. A phone orchestration.reset is refused and does not clear a message a local client already sent.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

@leynier
leynier force-pushed the fix/orchestration-mobile-allowlist branch from bc65340 to 02d985d Compare October 6, 2026 16:17
@leynier
leynier added this pull request to stack #919 October 6, 2026 16:17
@leynier
leynier force-pushed the fix/orchestration-mobile-allowlist branch from 02d985d to b58dbf9 Compare October 6, 2026 18:14
@leynier
leynier merged commit 1d5e1c8 into main Oct 6, 2026
19 checks passed
@leynier
leynier deleted the fix/orchestration-mobile-allowlist branch October 6, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant