Skip to content

Fix --dev failing config validation - #139

Merged
jR4dh3y merged 2 commits into
staging/mainfrom
hoplite/euhesperides-d9702ac5--dev-mode
Oct 1, 2026
Merged

jR4dh3y merged 2 commits into
staging/mainfrom
hoplite/euhesperides-d9702ac5--dev-mode

Conversation

@usehoplite

@usehoplite usehoplite Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Problem

boxbox --dev, the documented way to run locally without logging in, exits at startup:

Failed to load configuration error="password for user \"dev\" must be a bcrypt hash ($2a$, $2b$, or $2y$)"

--dev creates a placeholder user so that config validation passes, and it hashed that password with bcrypt.MinCost (4). Validation only accepts hashes of cost 10 or more (bcrypt.DefaultCost). It fails on master and on staging/main, and bun run dev:test and docs/development.md both depend on it.

Change

  • Hash the placeholder with bcrypt.DefaultCost. Startup takes about 50 ms longer.
  • Move the dev credential setup from main() into setDevCredentials() in cmd/server/devmode.go, so a test can call it.
  • Add devmode_test.go, which sets the dev credentials and loads a config through the real config.Load.

Verification

  • The test unsets every BOXBOX_*, FM_* and CONFIG_PATH variable first and restores them afterwards, so a developer's own settings cannot change the result. With BOXBOX_TRUSTED_PROXIES=proxy.local set, it fails without that step and passes with it.
  • The test fails with the old cost (password for user "dev" must be a bcrypt hash) and passes with the fix.
  • Ran the built binary with --dev and a config that says host: 0.0.0.0. It logged DEVELOPMENT MODE: authentication disabled; listening on loopback only and bound 127.0.0.1:18096. GET /api/v1/files/list/media returned 200 with no token. In a real browser, / opened /browse with the folder listing and no login, and there were no page errors.
  • go vet ./cmd/... and gofmt are clean.
  • Not tested: bun run dev:test (scripts/local-test.ts), and --dev on non-Linux.

Targets staging/main.


Written by anthropic/claude-sonnet-5-5 in the Hoplite agent harness.

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
box-box Ready Ready Preview Oct 1, 2026 8:30am UTC

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9460e989-61a1-4f87-9870-5fc78fb9929a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread backend/cmd/server/devmode_test.go
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>
@jR4dh3y
jR4dh3y merged commit dac86d9 into staging/main Oct 1, 2026
8 checks passed
jR4dh3y added a commit that referenced this pull request Oct 1, 2026
* Fix auto_discover mounts being dropped at startup (#131)

* Fix auto_discover mounts being dropped at startup

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Make the auto_discover test pick a mounted directory and check it is returned

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Make chunk_size_mb control browser upload chunks (#132)

* Make chunk_size_mb control browser upload chunks

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Share one chunk size request across upload workers and respect cancel

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Resolve virtual paths in one place (#133)

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Parse WebSocket and job data at the boundary (#134)

* Parse WebSocket and job data at the boundary

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Validate job progress range, add parser tests, log rejected frames briefly

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Move frontend state to runes and split the browse page (#136)

* Migrate jobs and websocket stores to runes

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Migrate settings store to runes and split out appearance helpers

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Migrate auth store to runes

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Split the browse page into composables

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Keep the WebSocket reconnect backoff when connect runs in an effect

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Fix the auth API docs, drop stale comments, add AGENTS.md (#137)

* Fix the auth API docs, drop stale spec comments, add AGENTS.md

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Add the frontend test command to AGENTS.md

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Correct the logout docs and scope the path rule

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Fix --dev failing config validation (#139)

* Fix --dev failing config validation

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Isolate the dev credentials test from inherited BoxBox settings

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Test the WebSocket reconnect backoff (#138)

* Test the WebSocket reconnect backoff

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Keep the connection mode on WebSocket retries and test the attempt limit

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Fix browsing discovered mount points

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

* Skip inaccessible auto-discovered mounts

Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

---------

Co-authored-by: usehoplite[bot] <288093033+usehoplite[bot]@users.noreply.github.com>
Co-authored-by: Radhey Kalra <radheykalra901@gmail.com>

This branch was successfully deployed

1 active deployment
Preview — 266ff5dc Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant