Hserver Failure Notes: Authentication and Ingress · advanced

CSP connect-src Should Be a Small Network Allowlist

Browser-side health checks needed cross-origin access, but the fix was two explicit origins rather than a broad wildcard.

Current. Current engineering note based on recent hserver deployment, debugging, recovery, and production-hardening work in September 2026.

connect-src was added with only those two HTTPS origins, while the rest of the restrictive CSP stayed intact. The Access Hub needed JavaScript to probe two HTTPS dashboards, and the original CSP blocked those connections. Relaxing CSP globally would have fixed the feature while weakening the page's network boundary. The required browser capability was narrow: connect to exactly the canonical Ops and OTA origins. The policy had not encoded that legitimate use case.

Security-policy changes should grant the smallest capability that satisfies the application. A CSP is most useful when exceptions are specific enough to reveal unexpected new dependencies.

Assert critical CSP directives in CI and review origin additions like network firewall changes rather than ordinary frontend configuration. The concrete hserver evidence is commit cda0247, so this note is tied to an actual production change rather than a hypothetical failure.

Quick navigationEsc