Let an agent share a running web app through a private dev tunnel - #82
Merged
splitbrain merged 1 commit intoOct 3, 2026
Merged
Conversation
A box had no way to show the person a web app that runs in it. The new share-app skill gives a port in the box a public HTTPS link through Microsoft Dev Tunnels. The tunnel is private, so only the GitHub account of the deployment's login can open it. The settings page has a Dev Tunnels card. The service takes only a token that GitHub issued to its own app, so the card has a login and no paste form. The orchestrator runs GitHub's device flow itself and stores the access token and the refresh token. The access token lasts eight hours, so the credential refresh renews it, also after it has expired. Every box gets a placeholder in DEVTUNNELS_TOKEN, and the proxy swaps in the real token on the Dev Tunnels hosts. Two proxy rules had to change for hosting to work: - While the CLI hosts a tunnel, it sends a token that the service issued for that tunnel, under the "tunnel" scheme. The proxy refused that as a foreign credential. A credential can now name such pass-through schemes, and values under them pass at that credential's hosts. - The interception engine refused every WebSocket upgrade, which blocked the relay connection. An upgrade now gets the same checks as a request. It is forwarded when it needs no swap, and refused when it would carry the placeholder or a foreign credential. The box image carries the devtunnel CLI, pinned to a release and to the checksum of each build.
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A box had no way to show you a web app that runs in it. The new
share-appskill gives a port in the box a public HTTPS link through Microsoft Dev Tunnels, which is free and hosted. The tunnel is private: only the GitHub account of the deployment's login can open it. You click the link, sign in with GitHub once, and see the app.The credential
The settings page has a new Dev Tunnels card with a Log in button and no paste form. The service accepts only tokens that GitHub issued to its own GitHub App, so a personal access token does not work.
DEVTUNNELS_TOKEN. The proxy swaps in the real token on*.rel.tunnels.api.visualstudio.com.Two proxy changes
Pass-through schemes. While
devtunnel hostruns, the CLI sends a token that the service issued for that one tunnel, asAuthorization: tunnel <token>, to the same hosts. The proxy refused that as a foreign credential. A credential can now name pass-through schemes, and values under them pass unchanged at that credential's hosts only. Any other unknown value is still refused.WebSockets on intercepted hosts. The interception engine refused every WebSocket upgrade, which blocked the tunnel's relay connection. An upgrade now gets the same checks as a request:
The engine forwards upgrades unchanged, so a forwarded upgrade cannot carry the real credential. Only a swap puts the real credential on the wire, and an upgrade that needs a swap is refused.
Box image
devtunnelCLI, pinned to release 1.0.2094 and to the checksum of each build, like glab.share-appskill, which the entrypoint installs at every start. It creates a private tunnel through the API, hosts it with the CLI, gives you the link, and deletes the tunnel at the end.Testing
SSL_CERT_FILE, the API calls to the global and the regional host passed, the relay WebSocket connected, and the public URL served the page.Not tested yet, because it needs a deployment built from this branch:
After the merge: log in on the card, then ask an agent in a box to share an app with the
share-appskill.