Skip to content

Stop treating caller attribution as a session ownership key by default#322

Open
damilolaedwards wants to merge 1 commit into
ethpandaops:masterfrom
damilolaedwards:fix/session-owner-attribution-authz
Open

Stop treating caller attribution as a session ownership key by default#322
damilolaedwards wants to merge 1 commit into
ethpandaops:masterfrom
damilolaedwards:fix/session-owner-attribution-authz

Conversation

@damilolaedwards

Copy link
Copy Markdown

Summary

Sandbox session get/destroy/list ownership was keyed off the
X-Panda-On-Behalf-Of header whenever the server had no authenticated user
for a request. That header is client-supplied and unauthenticated by
design, meant only for audit logging, so any caller that could reach the
server could set it to someone else's value and read, destroy, or
enumerate their sandbox sessions. With no header at all the ownership
check was skipped entirely.

Gates that fallback behind an explicit opt-in, server.attribution_session_scoping,
off by default. A deployment that wants session isolation on an
unauthenticated server despite the header being spoofable, such as an
automated test harness isolating its own worker sessions, can turn it on
deliberately. Updates the CI eval workflow and the harden loop's scratch
server config to opt in, since both rely on it for per-worker session
cleanup between concurrent runs.

Test plan

  • go test -race ./pkg/server/... ./pkg/config/...
  • New tests cover both the default-off behavior and the opt-in behavior
  • go build ./..., go vet ./...

Sandbox session get/destroy/list ownership was keyed off the
X-Panda-On-Behalf-Of header whenever the server had no authenticated
user for a request. That header is client-supplied and unauthenticated
by design, meant only for audit logging, so any caller that could
reach the server could set it to someone else's value and read,
destroy, or enumerate their sandbox sessions. With no header at all
the ownership check was skipped entirely.

Gate that fallback behind an explicit opt-in, server.attribution_session_scoping,
off by default. A deployment that wants session isolation on an
unauthenticated server despite the header being spoofable (an
automated test harness isolating its own worker sessions, for example)
can turn it on deliberately. Update the CI eval workflow and the
harden loop's scratch server config to opt in, since both rely on it
for per-worker session cleanup between concurrent runs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant