fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(self-host): Memory tab 401 when opening the dash via LAN IP - #1637

Open
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6
Open

fix(self-host): Memory tab 401 when opening the dash via LAN IP#1637
Souravrajvi0 wants to merge 1 commit into
supermemoryai:mainfrom
Souravrajvi0:feat/lan-dash-auth-7ac6

Conversation

@Souravrajvi0

Copy link
Copy Markdown

Fixes#1538

Problem

On supermemory-server v0.0.8, the local dash at / loads when you browse via a LAN/public IP, but the Memory tab returns 401 Unauthorized for documents and stats.

Local auto-auth only applies when the request Host is localhost, 127.0.0.1, or ::1. /local-console.js calls POST /v3/documents/documents and GET /v3/container-tags/list with no Authorization header, so those requests 401 off-loopback. Sending the banner key as Authorization: Bearer sm_… succeeds on the same IP (the workaround the reporter already uses).

Reproduced on this VM against the official server-v0.0.8 linux-x64 binary:

CallResult
POST /v3/documents/documents127.0.0.1:6767 (no auth)200
Same path → LAN IP :6767 (no auth)401 {"error":"Unauthorized"}
LAN IP :6767 + Authorization: Bearer <banner key>200

The self-hosted binary is not built from this public tree, so this PR cannot change that Host check in-process.

This PR

  • Documents the Host-based auth gap, SSH-tunnel recommendation, and the header workaround.
  • Adds scripts/lan-dashboard-proxy.mjs, which forwards to supermemory-server and injects the api-key file when the Memory tab omits it. Opening http://<lan-ip>:6768 then loads documents/stats.

Verified: same LAN IP that 401s on :6767 returns 200 for POST /v3/documents/documents and GET /v3/container-tags/list through the proxy.

node --test scripts/lan-dashboard-proxy.test.mjs

A first-class fix still belongs in supermemory-server (send the key from the dash, or an explicit SUPERMEMORY_TRUSTED_HOSTS allowlist). Until a server-v* release includes that, the tunnel or this proxy unblocks LAN browsing.

supermemory-server only auto-applies the local API key when Host is
localhost/127.0.0.1/::1. The dash Memory tab never sends Authorization,
so documents and stats 401 on a LAN hostname (supermemoryai#1538).
Document the Host-based auth gap and add a small proxy that injects the
banner API key so the UI works at http://<lan-ip>:6768.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supermemory v0.0.8 |Cannot load documents and stats that's NOT from localhost

1 participant

@Souravrajvi0