The limits of the tunnel

Who can reach the server while the tunnel is up, what the code enforces, what it does not, and what happens when the tunnel fails or you lose a phone.

Public while it runs #

While the server runs with a tunnel, its address is reachable from the internet. The address is a Cloudflare quick tunnel hostname, and it is random on every run and dies with the server. It is not a private network, and nothing about it depends on the phone being yours: what stands between the internet and the run is what the code enforces, below.

AutoDev owns no relay. The traffic goes through Cloudflare's tunnel service, which AutoDev runs a client for and does not operate. The address starts with https://. The last hop, from cloudflared to AutoDev, is plain http on 127.0.0.1.

What the code enforces #

RequestWhat it needs
The page at /, with no credentialNothing. It shows the pairing page, with no project name, status or counts.
POST /pairAn open pairing code. 5 wrong attempts close it.
/pairing, which opens and reads a codeThe server's token. A paired cookie is not accepted.
Every other route: the check-in page, /answer, /command, /project, /unpair, /events and /view/<kind>The server's token as Authorization: Bearer, or a paired device's cookie. Anything else is answered 401.
POST /command with a cookieThe header X-AutoDev-Device: 1 as well.

Three more rules apply to every request:

The token comes from --token, from AUTODEV_WEB_TOKEN, or, when neither is set, it is generated: 24 random bytes. autodev serve prints a generated token and says to treat it like a password. A detached server keeps its token in serve.json, in ~/.autodev/, so the panel can connect to it.

Revoking a device #

Stopping the server forgets every paired device, so for a phone you have lost the way to cut it off is to turn remote access off. The devices live in the server's memory and nowhere else.

A phone can disconnect itself from its own menu. Nothing revokes one other device, and the panel has no control that revokes all of them without stopping the server.

The cookie's maximum age, about 400 days, is a request to the browser. The server does not check a device's age: it accepts a token until the server stops. A token that has been copied off a phone works for as long as the server runs.

When the tunnel fails #

A tunnel can fail to start in three ways, and the message of each is written as it is here:

In each case the server keeps running on loopback, and only this machine reaches it. A server started from the panel writes Tunnel unavailable — serving on loopback only. and the reason to the event log as serve.tunnel_failed, and the panel's address line reads Tunnel unavailable — loopback only. cloudflared missing covers the fix.

AutoDev keeps watching the tunnel after it has announced its address. If cloudflared exits later, or its process fails, AutoDev retracts the address, writes a serve.tunnel_down warning with the reason, and the address line changes to the same Tunnel unavailable — loopback only. It does not rebuild the tunnel: a new one has a new random hostname, and every phone would pair again. Turn remote access off and on to get one.

What this does not do #

Turning remote access on covers starting and stopping the server, and Every config key covers the settings that are not specific to it.