Add secure single-port HTTP proxy transport - #1594
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (1)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1fd3be90b5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d27636bdcf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1d30c94201
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e9bbe03612
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex security review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 38a37ddb1b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex security review |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 57226856ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex security review |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aa0f8d8ba5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex security review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 63e8f9ddd9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Security Review
Here are some automated security review suggestions for this pull request.
Reviewed commit: 63e8f9ddd9
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 67e9d1262a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 57517d7593
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9b9232b110
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7fec7976a4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f8113897b2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7495519d61
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e23a9691d0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fa1296ea07
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bfea6f1b63
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b6d0f774bd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 48841b80d8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ``` | ||
|
|
||
| 2. Allow TCP port `1297` to the proxy. `PublicEndpoint` must resolve directly to this VotingPlugin listener. | ||
| 3. Restart the proxy and run `/votingpluginbungee httpcode <server>`. The name must exactly identify the intended backend; generate a separate code for each backend. |
There was a problem hiding this comment.
Use the registered command name in the HTTP setup
Following this quick setup always invokes an unregistered command: Bungee registers only votingpluginproxy in VotingPluginBungeeCommand.java:14, and Velocity registers votingpluginproxy with the vpp alias in VotingPluginVelocity.java:352. The same incorrect /votingpluginbungee name is printed after listener startup and repeated for revocation, so administrators following the new instructions cannot generate the connection code needed to enroll any backend; document /votingpluginproxy or register the advertised alias.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
🟡 Changes recommended
The new restart/rollback plumbing appears to leave non-HTTP transports closed after a failed replacement, and plugin-message relay registration may duplicate when the underlying PluginMessage instance changes.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds a new BungeeMethod: HTTP transport that allows backends to communicate with a proxy over a single outbound HTTPS connection, including automated enrollment (private CA + per-backend client certs), pinned TLS, bounded long-polling, and durable delivery/ack semantics. This fits into VotingPlugin’s proxy/backends communication layer as an additional transport option alongside plugin messaging, sockets, Redis, MQTT, and MySQL.
Changes:
- Introduces the secure HTTP transport implementation (proxy enrollment authority + backend connector + strict protocol framing + credential stores).
- Extends proxy vote-party durability to journal and safely retry proxy-side effects/reward deliveries under HTTP.
- Updates Control/config validation, default configs, commands, and adds extensive unit/integration/security tests plus documentation.
File summaries
| File | Description |
|---|---|
| VotingPlugin/src/test/java/com/bencodez/votingplugin/tests/VotingPluginProxyTestImpl.java | Extends proxy test harness to simulate HTTP vote envelope delivery and vote-party durability behaviors. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/tests/VotingPluginProxyTest.java | Adds tests for HTTP vote-party durability, authenticated backend envelope checks, and queue behavior. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/tests/BungeeMethodTest.java | Adds assertions for the new HTTP method behavior and name lookup. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/control/ProxyMethodConfigurationServiceTest.java | Adds validation coverage for required HTTP proxy settings and endpoint constraints. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/proxy/cache/VotePartyCacheDurabilityTest.java | Tests vote-party cache “save actually persisted” verification behavior. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/control/BackendConfigurationServiceTest.java | Adds quick-setup coverage for HTTP, redaction for ConnectionCode, and preflight validation cases. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/backendproxy/transport/HttpBackendProxyTransportTest.java | Verifies backend HTTP transport validation, replacement behavior, and non-blocking close semantics. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/backendproxy/http/HttpTransportSecurityTest.java | Tests protocol bounds, pins, code parsing, identity durability, enrollment/renewal/revocation invariants. |
| VotingPlugin/src/test/java/com/bencodez/votingplugin/backendproxy/BackendProxyHandlerLifecycleTest.java | Adds lifecycle tests for staged publication/rollback of plugin messaging and presence activation. |
| VotingPlugin/src/main/resources/BungeeSettings.yml | Documents HTTP as a backend method and adds HTTP.ConnectionCode placeholder. |
| VotingPlugin/src/main/resources/bungeeconfig.yml | Adds proxy-side HTTP listener settings and documents the required public endpoint. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/VotingPluginMain.java | Refactors backend proxy handler restart into prepare/validate/publish/abort phases; adjusts plugin message relay ownership handling. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/VotingPluginProxyConfig.java | Adds HTTP listener/public-endpoint config accessors for proxy implementations. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/VotingPluginProxyCommand.java | Adds /votingplugin httpcode and /votingplugin httprevoke proxy commands. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/velocity/VotingPluginVelocity.java | Implements new vote-party durability methods and durable save for Velocity. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/velocity/VelocityJsonVoteCache.java | Persists/loads pending vote-party rewards and proxy effects with encoded server keys. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/velocity/VelocityConfig.java | Reads proxy HTTP settings from Velocity config. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/control/ProxyMethodConfigurationService.java | Validates HTTP host/port and HTTPS public endpoint shape. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/cache/VotePartyCacheDurability.java | Adds post-save verification to ensure vote-party transactional state is actually persisted. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/cache/PendingVotePartyProxyEffects.java | Introduces a bounded durable representation of ordered proxy-side vote-party effects. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/cache/IVoteCache.java | Extends vote cache interface for pending vote-party rewards/effects persistence. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/BungeeMethod.java | Adds the new HTTP enum value and description. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/bungee/VotingPluginBungee.java | Implements new vote-party durability methods and durable save for Bungee. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/bungee/BungeeJsonVoteCache.java | Persists/loads pending vote-party rewards and proxy effects with encoded server keys. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/proxy/bungee/BungeeConfig.java | Reads proxy HTTP settings from Bungee config. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/listeners/VotiferEvent.java | Updates backend-side votifier bypass message/logic to include HTTP. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/control/BackendControlConnector.java | Refactors Control reload flow to validate HTTP enrollment off-thread and support abort/rollback sequencing. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/control/BackendConfigurationService.java | Adds HTTP method validation and redaction support for ConnectionCode. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/config/BungeeSettings.java | Adds managed config field for backend HTTP.ConnectionCode. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/transport/PluginMessagingBackendProxyTransport.java | Stages plugin messaging publication so shared state isn’t swapped before handler publication. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/transport/HttpBackendProxyTransport.java | Implements backend-side HTTP transport setup, enrollment, readiness validation, and bounded shutdown flushing. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/transport/BackendProxyTransportManager.java | Adds support for HTTP transport, publication staging, and HTTP-specific validate/rollback hooks. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/transport/BackendProxyTransport.java | Adds a publication boundary hook (activateAfterPublication). |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/presence/BackendPresenceManager.java | Ensures presence activation can fail atomically without partially publishing state. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpTransportSecrets.java | Adds minimal crypto helpers (random, SHA-256, HMAC) used by transport/enrollment. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpTransportProtocol.java | Defines strict, bounded, versioned JSON envelope/batch format for the HTTP transport. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpTlsIdentity.java | Implements durable proxy-side private CA and rotating server TLS identity generation. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpPinnedTls.java | Builds pinned TLS contexts for enrollment and normal mTLS operation. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpInboundDeliveryStore.java | Adds backend-side crash-durable inbound delivery fencing across callbacks. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpEnrollmentAuthority.java | Implements proxy-side enrollment tokens, certificate binding, renewal, and revocation persistence. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpConnectionCode.java | Implements the copy/paste connection code format, validation, and legacy compatibility. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpClientCredentialStore.java | Implements owner-only client credential persistence with generation staging/activation/rollback. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/http/HttpBackendTransportConnector.java | Implements backend long-poll client with bounded queues, acks, delivery journaling, and renewal. |
| VotingPlugin/src/main/java/com/bencodez/votingplugin/backendproxy/BackendProxyHandler.java | Stages presence + transport publication and adds replacement/rollback hooks. |
| VotingPlugin/pom.xml | Adds and shades BouncyCastle dependencies used for certificate issuance. |
| docs/http-transport.md | Documents quick setup, threat model, durability semantics, and operational guidance for HTTP transport. |
Review details
- Files reviewed: 49/49 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| com.bencodez.simpleapi.servercomm.pluginmessage.PluginMessage current = getPluginMessaging(); | ||
| if (backendPluginMessageRelayOwner != current) { | ||
| current.add(backendPluginMessageRelay); | ||
| backendPluginMessageRelayOwner = current; | ||
| } |
| public boolean prepareForReplacement(BungeeMethod replacementMethod) { | ||
| if (method == replacementMethod && method != BungeeMethod.PLUGINMESSAGING && method != BungeeMethod.REDIS) { | ||
| transportManager.prepareForReplacement(); | ||
| return method == BungeeMethod.HTTP; |
Summary
BungeeMethod: HTTPas a bidirectional, outbound-backend transport using one proxy HTTPS portdocs/http-transport.mdEasy setup
HTTPon the proxy and setHTTP.PublicEndpoint./votingpluginbungee httpcode <server>.HTTP.ConnectionCodeand restart it.Compromised or replaced nodes can be revoked with
/votingpluginbungee httprevoke <server>.Security
The application cannot by itself prevent volumetric link/TCP floods; the documentation recommends host/provider firewall protection for Internet exposure and requires direct TLS pass-through.
Performance
Verification
mvn -B -f VotingPlugin/pom.xml packagepassedgit diff --check: passingDelivery semantics