feat: add --chat-hook-allow-insecure to allow plain HTTP chat hook URLs (#27896)

Adds a hidden `--chat-hook-allow-insecure` /
`CODER_CHAT_HOOK_ALLOW_INSECURE` deployment option (default `false`)
that allows the chat lifecycle hook URL to use plain HTTP for any host.

The HTTPS requirement is enforced at two points, and the flag relaxes
both: `DeploymentValues.Validate()` rejects `http` hook URLs at startup,
and the hook dispatcher's `validateHookURL` allows `http` only for
loopback hosts. With the flag set, any-host `http` is accepted; the
host, fragment/userinfo, secret, and timeout checks are unchanged, and
non-http(s) schemes still fail. This removes the need for an HTTPS
reverse proxy when testing a hook consumer on a trusted network.

Following security review feedback, the flag description and docs state
that plain HTTP lets an on-path attacker forge hook responses (which
control agent execution), and `coder server` logs a startup warning
(with a redacted hook URL) when hooks run over plain HTTP.

Docs, generated API types, and the server config golden are updated
accordingly.

> Mux acted on Mike's behalf to create this PR.
This commit is contained in:
Michael Suchacz
2026-08-05 22:41:17 +02:00
committed by GitHub
parent 3e2a8bd421
commit 4b9880afa6
16 changed files with 161 additions and 41 deletions
+1
View File
@@ -233,6 +233,7 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
"chat": {
"acquire_batch_size": 0,
"debug_logging_enabled": true,
"hook_allow_insecure": true,
"hook_enabled": true,
"hook_secret": "string",
"hook_timeout": 0,
+5
View File
@@ -1082,6 +1082,7 @@
"chat": {
"acquire_batch_size": 0,
"debug_logging_enabled": true,
"hook_allow_insecure": true,
"hook_enabled": true,
"hook_secret": "string",
"hook_timeout": 0,
@@ -2455,6 +2456,7 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
{
"acquire_batch_size": 0,
"debug_logging_enabled": true,
"hook_allow_insecure": true,
"hook_enabled": true,
"hook_secret": "string",
"hook_timeout": 0,
@@ -2480,6 +2482,7 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|-------------------------|----------------------------|----------|--------------|-------------|
| `acquire_batch_size` | integer | false | | |
| `debug_logging_enabled` | boolean | false | | |
| `hook_allow_insecure` | boolean | false | | |
| `hook_enabled` | boolean | false | | |
| `hook_secret` | string | false | | |
| `hook_timeout` | integer | false | | |
@@ -5921,6 +5924,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"chat": {
"acquire_batch_size": 0,
"debug_logging_enabled": true,
"hook_allow_insecure": true,
"hook_enabled": true,
"hook_secret": "string",
"hook_timeout": 0,
@@ -6547,6 +6551,7 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
"chat": {
"acquire_batch_size": 0,
"debug_logging_enabled": true,
"hook_allow_insecure": true,
"hook_enabled": true,
"hook_secret": "string",
"hook_timeout": 0,