diff --git a/nix/host-modules/hive-forge/default.nix b/nix/host-modules/hive-forge/default.nix index 11c60eeb..f79b0367 100644 --- a/nix/host-modules/hive-forge/default.nix +++ b/nix/host-modules/hive-forge/default.nix @@ -418,18 +418,6 @@ in # disallowed hosts"). Allow loopback + RFC-1918 sources # so an in-hive mirror of the hyperhive repo works. migrations.ALLOW_LOCALNETWORKS = true; - # `ALLOWED_HOST_LIST` is forgejo's webhook SSRF allow-list, and - # it's a STRICT whitelist (only listed hosts deliver). Its - # default is the `external` builtin: all public unicast IPs are - # allowed, private/loopback denied. We must KEEP `external` so - # user-repo webhooks to public hosts (github, slack, …) keep - # working, and ADD the hive gateway host on top: the config-PR + - # knowledge webhooks target `https:///webhook/*`, - # which resolves to a private (RFC-1918) gateway IP that - # `external` alone would deny (so they'd only ever be caught by - # the 5-min poll fallback). Naming the single gateway host is - # tighter than the broad `private` builtin. - webhook.ALLOWED_HOST_LIST = "external,${hyperhiveDomain}"; log.LEVEL = "Warn"; ui = { DEFAULT_THEME = "catppuccin-vibec0re";