diff --git a/host-stacks/vds-kzntsv/sched-custom/custom-entry.mjs b/host-stacks/vds-kzntsv/sched-custom/custom-entry.mjs index 779dcda..130be4d 100644 --- a/host-stacks/vds-kzntsv/sched-custom/custom-entry.mjs +++ b/host-stacks/vds-kzntsv/sched-custom/custom-entry.mjs @@ -51,12 +51,13 @@ const mcpHandler = createMcpHttpHandler({ client: mcpClient, readonly: process.e let uiBundle = null; try { uiBundle = readFileSync(DEFAULT_UI_BUNDLE); } catch { /* bundle missing → morda 404s its script */ } -// One HTTP server, auth at the boundary: everything EXCEPT /api/health (probe, open) and -// /sched-ui.bundle.js (static UI assets) requires `Authorization: Bearer SCHED_ADMIN_KEY`. -// This closes the MCP + admin API + morda exposed WITHOUT a token (vitya found /mcp open). -const AUTH_OPEN_PATHS = ['/api/health']; +// One HTTP server, auth at the boundary. OPEN (no token): /api/health (probe) + the UI itself +// (/ and /sched-ui.bundle.js — static login page/JS bundle, ZERO data; data comes from /api/*). +// AUTH required (Bearer SCHED_ADMIN_KEY): /api/* (except health) and /mcp — the actual data plane. +// This is the vitya correction: morda stays reachable (it's just the login form), data plane is locked. +const AUTH_OPEN_PATHS = ['/api/health', '/sched-ui.bundle.js']; function isOpenPath(p) { - return AUTH_OPEN_PATHS.includes(p) || p === '/sched-ui.bundle.js'; + return AUTH_OPEN_PATHS.includes(p) || p === '/'; // UI root = static login page, no data } function isAuthorized(req) { if (!ADMIN_KEY) return true; // dev mode, open