3 Commits

Author SHA1 Message Date
AletheiaVox
7bb9d8473b fix(security): require auth on every MCP request; stop stale refreshes banning clients
- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH:
  an unauthenticated request no longer reaches whichever phone is online alone.
- Mcp-Session-Id is no longer a credential; the Bearer token is checked on
  every request (MCP auth spec).
- Refresh tokens live 90 days (was 30, equal to the access token, so they
  were always dead when first needed).
- A rejected refresh no longer counts toward the IP ban: a client with an
  expired token was retrying into a self-renewing ban on its own IP.
- 401s carry the RFC 9728 WWW-Authenticate discovery header.
2026-09-27 12:55:16 +02:00
Aletheia
63d7176ee6 fix(governor): disabled means disabled, and timed commands stop accruing heat
enabled gated only Governor.check(). The heat model, the heartbeat
piggyback and the list_devices footer all ran unconditionally, so a
governor that was switched off could still report heat, still print
COOLDOWN, and still drive the phone's ACTIVE->COOLDOWN transition while
blocking nothing. tick() now returns early when disabled and clears
carried-over state; to_dict() reports enabled:false with zeroed values;
the list_devices footer is omitted.

Separately, current_intensity was only ever cleared by record_stop(),
whose three callers are an explicit stop, a phone emergency stop and the
dead man's switch. A pattern ending on its own duration told the server
nothing, so heat integrated at the last commanded intensity against idle
hardware forever. Commands now pass their duration through to
record_command() and the intensity expires when it lapses. duration:0
still means run-until-stop. For escalate the expiry is duration +
hold_seconds, and only when hold_seconds > 0, per the hold contract.

Adds tests/verify_governor.py: 22 offline checks over the disabled path,
timed-command expiry, and the enabled-path invariants. Existing
verify_server.py still passes 23/23.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-27 22:41:29 +02:00
Aletheia
b8a52e9658 test: offline verification suite for server and relay clients
Two self-contained scripts, no hardware or network needed:

- tests/verify_server.py boots the FastAPI app in-process against a
  throwaway database and walks the full surface: health, MCP protocol
  (202 notifications, version negotiation, tool schemas), the complete
  OAuth flow (register -> authorize -> code -> token -> authenticated
  MCP session), and the per-user safety config round-trip.
- tests/verify_relays.py drives both relay clients' pattern engines
  against a recorded fake of the Intiface layer: indefinite durations,
  the escalate hold contract, error-mid-ramp stops, pattern
  supersession, tracked auto-stops, feature_index routing, and the
  stop-unknown-device fallback.

Run before shipping changes: python tests/verify_server.py &&
python tests/verify_relays.py

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 20:28:03 +02:00