rdmsm4x-changelog-20260824-2256-dataroo-401-help-page
rdmsm4x-changelog-20260824-2256-dataroo-401-help-page
Summary: dev.dataroo.net's bare 401 dead-end (seen when clicking links inside the Claude desktop app, whose embedded Electron viewer has no Basic-auth dialog) now serves a helpful custom 401 page pointing to a real browser or the tailnet mirror. Auth unchanged.
Scope
- Host: rdmsm4x only (auth_proxy container for dev.dataroo.net).
Root cause (verified independently, 22:52–22:53 EDT)
- Not a server/auth fault.
curl -sI https://dev.dataroo.net/tyrell/returns 401 withWWW-Authenticate: Basic realm="dataroo development wiki". - auth_proxy log: every no-prompt 401 carries UA
Claude/1.34493.1 … Electron/42.9.2(Claude desktop app's embedded viewer — cannot show Basic-auth dialogs);richhfrom real Chrome got 200 on /tyrell/ at 22:52:15 EDT. - Tailnet mirror https://rdmsm4x-1.kangaroo-kitefin.ts.net/ (Tailscale Serve → 127.0.0.1:8787, intentional no-auth) probed 200.
- Matches the tyrell.build session's diagnosis (cross-session message
+ their RESOLVED entry in
~/dev/sites/dev.dataroo.net/ISSUES.md); mutual-verification rule satisfied.
Files touched
~/dataroo.net/nginx_auth.conf— addederror_page 401 = @auth_help;on the dev.dataroo.net server block and alocation @auth_helpreturning a styled HTML 401 body (explains the embedded-viewer limitation; links the ts.net mirror). No change tosatisfy any, allow-list, rate limit, or htpasswd.- Backup:
~/dataroo.net/nginx_auth.conf.bak-20260824-2253.
Commands run
docker run --rm --network dataroo_default -v …nginx_auth.conf:/etc/nginx/nginx.conf:ro … nginx:alpine nginx -t(syntax test)docker compose -f ~/dataroo.net/docker-compose.yml up -d --force-recreate auth_proxy(required once: the conf is a single-file bind mount and the edit replaced the inode, orphaning it in the container)- Header-dedupe edit via inode-preserving
cat tmp > file, thendocker exec dataroo-auth_proxy-1 nginx -t && nginx -s reload.
Verification evidence (22:55 EDT)
HTTP/2 401+ exactly oneWWW-Authenticate: Basicheader on https://dev.dataroo.net/tyrell/ (browser prompt behavior preserved).- New body served (contains "needs a sign-in prompt" + ts.net link).
- Wrong credentials → still 401. Tailnet mirror → still 200.
dataroo-auth_proxy-1Up (healthy).
Undo
cp ~/dataroo.net/nginx_auth.conf.bak-20260824-2253 ~/dataroo.net/nginx_auth.conf && docker compose -f ~/dataroo.net/docker-compose.yml up -d --force-recreate auth_proxy
Outstanding owner actions
- None required. Optional: re-add current IPv4 egress to the auto-allow list (removed 08-23 as unverifiable/dynamic — see conf comments) or move to a Cloudflare Access / Tailscale-only policy if Rich wants promptless IPv4 at home.