Self-hosted AI workspace.
Find a file
Léo b19d327f03
fix(auth): derive the session cookie Secure flag from the request scheme (#6048)
* fix(auth): derive the session cookie Secure flag from the request scheme

SECURE_COOKIES only marked the login cookie Secure when it was explicitly
set to true, so an HTTPS login on an install that never set it handed out a
session cookie the browser is happy to send back in cleartext.

Unset now derives the flag from the request: the connection scheme, which
uvicorn's proxy-headers middleware rewrites for the proxies it trusts, or
X-Forwarded-Proto for a terminator that is not on a trusted address. That
is the same test core/middleware.py already applies before sending HSTS, so
the two stop disagreeing about whether a request arrived over TLS. An
explicit true still forces the flag on and an explicit false turns it off
for an install still answering on both HTTP and HTTPS. Strictly more Secure
flags than before and never fewer.

Empty counts as unset, because docker-compose pinned SECURE_COOKIES=false
for every container; the compose files now pass the variable through
unset, the way FASTEMBED_CACHE_PATH already does.

The helper and its decision order come from #3799, which was closed for
being too large to review and whose six replacement PRs dropped this fix.

Part of #3803.

* docs(setup): flag the leftover SECURE_COOKIES=false on upgrades

The old default was false, so an install set up before scheme derivation
can still carry an explicit SECURE_COOKIES=false in its own .env. That
value stays authoritative, so HTTPS logins keep getting a non-Secure
session cookie even after the tracked compose defaults are updated by a
pull. Say so where people look: the security notes and the variable's
own comment in .env.example.

* docs(setup): align TLS guidance with scheme-derived cookies

---------

Co-authored-by: Alexandre Teixeira <alexandremagteixeira@gmail.com>
2026-08-16 22:56:36 +01:00
.github fix(ci): match the screenshot checkbox by wording, not emphasis (#6073) 2026-08-16 16:26:08 +01:00
companion fix(companion): honor configured pairing address (#6060) 2026-08-15 21:11:10 +02:00
config/searxng Generate SearXNG secret on first boot 2026-06-01 11:03:02 +09:00
core feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
docker fix(docker): make host Docker socket opt-in (#4902) 2026-06-30 19:54:51 +02:00
docs fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
integrations Add Codex and Claude document draft integration 2026-06-09 14:27:53 +09:00
licenses perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994) 2026-08-16 22:43:12 +01:00
mcp_servers refactor(model-routing): centralize explicit foreground fallback policy (#6020) 2026-08-14 08:10:30 +01:00
routes fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
scripts fix(docker): migrate retained SearXNG settings (#6055) 2026-08-16 04:17:58 +02:00
services fix(skills): harden skill import against DNS rebinding and SSRF TOCTOU (#5986) 2026-08-14 13:33:06 +01:00
specs chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
src fix(tasks): scope action_tidy_research broken-file sweep to admins (#6069) 2026-08-16 13:19:56 +01:00
static perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994) 2026-08-16 22:43:12 +01:00
swift/odysseus-mlx-image-bridge Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
tests fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
.dockerignore fix(devops): harden docker config defaults (#4349) 2026-06-16 04:03:43 +01:00
.env.example fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
.gitattributes perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994) 2026-08-16 22:43:12 +01:00
.gitignore pwa missing icons added (#428) 2026-06-15 16:00:13 +09:00
ACKNOWLEDGMENTS.md perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994) 2026-08-16 22:43:12 +01:00
app.py feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
build-macos-app.sh fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032) 2026-08-15 23:09:01 -06:00
build-windows-portable.ps1 feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
CONTRIBUTING.md chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
docker-compose.gpu-amd.yml fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
docker-compose.gpu-nvidia.yml fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
docker-compose.yml fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
Dockerfile Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
install-service.sh Odysseus v1.0 2026-05-31 23:58:26 +09:00
launch-windows.ps1 fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032) 2026-08-15 23:09:01 -06:00
launcher.py feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
LICENSE chore: backport main-only changes to dev AGPL relicense + Cookbook serve fix (#3704) 2026-06-09 23:20:34 +02:00
odysseus-ui.service fix: systemd service should serve on port 7000 to match Docker/setup/README (#1297) 2026-06-03 02:04:37 +09:00
Odysseus.spec feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
package-lock.json chore(deps): remove unused @anthropic-ai/sdk dependency (#4566) 2026-06-19 09:40:35 +02:00
package.json chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
pyproject.toml test: add fast lane and duration visibility (#3659) 2026-06-09 20:11:47 +02:00
README.md feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
requirements-optional.txt chore(deps): bump the python group with 3 updates (#3991) 2026-06-15 19:25:15 +09:00
requirements.txt fix(mcp): keep built-in servers on SDK v1 (#5820) 2026-07-28 18:11:34 +01:00
ROADMAP.md Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
SECURITY.md fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
setup.py fix(setup): load .env so a pre-seeded admin password is honored on native installs (#4787) 2026-06-23 20:08:05 +02:00
start-macos.sh fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032) 2026-08-15 23:09:01 -06:00
THREAT_MODEL.md feat(auth): define Default/Local owner contract (#5795) 2026-08-15 20:27:26 +01:00
update_windows.bat Windows: add Docker update script 2026-06-02 20:45:32 +09:00

Odysseus

A self-hosted AI workspace for chat, agents, research, documents, email, notes, calendar, and local model workflows.

Quick Start · Setup Guide · Contributing · Roadmap

Packaging status

Odysseus interface


Quick Start

dev is the default branch and gets the newest changes first. Use main if you want the more curated branch.

git clone https://github.com/odysseus-dev/odysseus.git
cd odysseus
cp .env.example .env
docker compose up -d --build

Open http://localhost:7000 when the containers are healthy. The first admin password is printed in docker compose logs odysseus.

Native installs, GPU notes, Windows/macOS instructions, HTTPS, and configuration live in the setup guide.

Features

  • Chat + Agents — local/API models, tools, MCP, files, shell, skills, and memory.
  • Cookbook — hardware-aware model recommendations, downloads, and serving.
  • Deep Research — multi-step web research with source reading and report generation.
  • Compare — blind side-by-side model testing and synthesis.
  • Documents — writing-first editor with AI edits, suggestions, Markdown, HTML, CSV, and syntax highlighting.
  • Email — IMAP/SMTP inbox with triage, tags, summaries, reminders, and reply drafts.
  • Notes, Tasks + Calendar — reminders, todos, scheduled agent tasks, and CalDAV sync.
  • Extras — gallery/image editor, themes, uploads, web search, presets, sessions, and 2FA.

Demo

A full hover-to-play tour lives on the landing page: docs/index.html.

Contributing

Help is welcome. The best entry points are fresh-install testing, provider setup bugs, mobile/editor polish, docs, and small focused refactors. See CONTRIBUTING.md and ROADMAP.md.

Security

Odysseus is a self-hosted workspace with powerful local tools. Keep auth enabled, keep private data out of Git, and do not expose raw model/service ports publicly.

  • Keep AUTH_ENABLED=true for any network-accessible deployment.
  • Keep LOCALHOST_BYPASS=false outside local development.

Deployment details are in the setup guide.

Star History

Star History Chart

License

AGPL-3.0-or-later -- see LICENSE and ACKNOWLEDGMENTS.md.