Connect to a server

How the Client App connects to a Pagis server, and the trust that a connection gives the server.

Connect only to a server you trust

When you connect to a server, this computer becomes a Host of that server. The server and its Administrator can then run commands on this computer, with the same access as you. Connect only to a server whose Administrator you trust.

Set up the connection

"Connect to a Pagis server" shows the Server address field, and the setup page takes that address and nothing else: no email address and no password. It checks the address before it sends it: an empty or malformed address gets a message under the field, and the field takes the focus. The main process checks the request again and refuses a request with no address in words for a person. The client installs nothing, supervises nothing and keeps no key. It checks that a Pagis server answers at the address and that its release is inside the client's Compatibility Range: the client's own version and every later version that promises the same API. When the server has no Administrator yet, the client says so and names the Administration Interface that finishes setup. Each of these problems shows under the field, and the setup window stays. When the checks pass, the client keeps the origin in userData/server.json, closes the setup window and opens the product window at the server's origin. There the Product App shows its own sign-in page, and the Person signs in on it, as in the Slack and Mattermost clients. When the cookie jar of the product window holds a Session of the server, the client registers this machine as a Host of the server.

Start the Client App again

The client checks the range again on every start and refuses a server outside it, with a message that says which end to update. The next start opens the same server, signed in while the Session of the last sign-in lasts. When that server does not answer, or its release is outside the range, the setup page says so and offers "Try again" and "Choose another setup". It offers no repair, because the client installed nothing. Quit stops no process, because the client started none.

Only over https

The client connects to a server only over https://. It refuses an http:// address before it sends a request, unless the host is loopback (127.0.0.1, [::1] or localhost), such as an SSH tunnel. The refusal names the https setups of Serve several People: Caddy, Tailscale Serve and Cloudflare Tunnel. A server.json that holds an http:// origin of another computer fails at the start, and the setup page shows the refusal. The client follows no redirect before the product window opens, and uses the TLS certificate check of the platform. On an https:// origin, its cookie jar holds the Session cookie as Secure, also where the server set it without Secure (ADR-0024).

The trust of a connection

When you connect to a server, this computer becomes a Host of that server. The server and its Administrator can then run commands on this computer, with the same access as you. Under "Connect to a Pagis server", the setup page states this in one line under the Server address field: "Connect only to a server you trust." The client registers as a Host of the signed-in Person and runs every dispatch frame the server sends, as the OS user who started it. The approval, the effect class, the allow rules for each machine and the audit row all live on the server, and the client applies no check of its own, on purpose: a second confirmation here would ask a question the server's approval card already asked, and it would not change the trust. So a person who takes control of the server can also run commands on this computer (ADR-0015). The client trusts the server that TLS authenticates, and it registers as a Host on no clear-text connection to another machine.

Edit on GitHub

On this page