Skip to content

v3.6.2 - Profile-Based Access Control & Windows Compatibility

Latest

Choose a tag to compare

@xaspx xaspx released this 28 Jun 06:28
· 1 commit to main since this release

v3.6.2 — Profile-Based Access Control & Windows Compatibility

Release date: 2026-06-28

A maintenance release focusing on two community-contributed improvements: profile-based access isolation for multi-agent deployments, and Windows compatibility fixes.

✨ Feature: Profile-Based Access Control (PR #78 by @sfalsin)

What it does: Restricts which Hermes agent profiles each HCI user can see and manage. In multi-agent setups where you run multiple Hermes profiles (e.g. "jorah", "varys", "production"), this prevents users from accessing profiles they shouldn't.

Backend changes:

  • New allowed_profiles field on user records — an array of profile names, or ['*'] for unrestricted access
  • requireProfileAccess Express middleware applied to all profile-scoped endpoints: /api/gateway/:profile/*, /api/config/:profile, /api/keys/:profile
  • /api/profiles endpoint now filters results per-user — users only see profiles they're authorized for
  • /api/office/agent-states also filtered per-user
  • canAccessProfile(user, profileName) and updateUserProfiles() helper functions exported from auth module
  • POST /api/users accepts optional allowed_profiles array

Frontend changes:

  • Create User form now includes an "Agent Access" section with live-loaded checkboxes for each available profile
  • Admin role auto-sets full access (['*']) — no checkbox interaction needed
  • Files tab hidden for users without files.read permission
  • Maintenance tab hidden for non-admin users

Compatibility: Fully backward compatible. Existing users without allowed_profiles see all profiles (fallback to ['*'] behavior). No migration required.

🐛 Fix: Windows Compatibility (PR #79 by @jpntw-dotcom)

Problem: process.getuid() is a Unix-only API. On Windows, it throws TypeError: process.getuid is not a function at startup, preventing HCI from running entirely.

Changes in server.js:

  • const IS_ROOT = process.getuid === 0 → process.getuid ? process.getuid() === 0 : false (gracefully returns false on Windows, which is correct — Windows has no root concept)
  • XDG_RUNTIME_DIR auto-detection block now guarded with process.getuid check (Linux-only feature, safely skipped on Windows)

No functional impact on Linux/macOS — the guard is a no-op where process.getuid exists.

📦 Files changed since v3.6.1

File Changes
README.md +18 lines — Profile-Based Access Control documentation
auth.js +23 lines, -2 — new auth functions for profile access
server.js +46 lines, -23 — middleware + route guards + Windows fix
src/index.html +2 lines, -2 — id attributes for nav elements
src/js/core/auth.js +9 lines, -1 — nav visibility based on permissions
src/js/pages/users.js +32 lines, -3 — profile selection UI in Create User form
package.json version 3.6.1 → 3.6.2

🔗 PRs

  • #78 — feat: Profile-Based Access Control (per-agent user isolation)
  • #79 — fix: guard process.getuid() calls for Windows compatibility