Stop treating caller attribution as a session ownership key by default#322
Open
damilolaedwards wants to merge 1 commit into
Open
Conversation
Sandbox session get/destroy/list ownership was keyed off the X-Panda-On-Behalf-Of header whenever the server had no authenticated user for a request. That header is client-supplied and unauthenticated by design, meant only for audit logging, so any caller that could reach the server could set it to someone else's value and read, destroy, or enumerate their sandbox sessions. With no header at all the ownership check was skipped entirely. Gate that fallback behind an explicit opt-in, server.attribution_session_scoping, off by default. A deployment that wants session isolation on an unauthenticated server despite the header being spoofable (an automated test harness isolating its own worker sessions, for example) can turn it on deliberately. Update the CI eval workflow and the harden loop's scratch server config to opt in, since both rely on it for per-worker session cleanup between concurrent runs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Sandbox session get/destroy/list ownership was keyed off the
X-Panda-On-Behalf-Of header whenever the server had no authenticated user
for a request. That header is client-supplied and unauthenticated by
design, meant only for audit logging, so any caller that could reach the
server could set it to someone else's value and read, destroy, or
enumerate their sandbox sessions. With no header at all the ownership
check was skipped entirely.
Gates that fallback behind an explicit opt-in, server.attribution_session_scoping,
off by default. A deployment that wants session isolation on an
unauthenticated server despite the header being spoofable, such as an
automated test harness isolating its own worker sessions, can turn it on
deliberately. Updates the CI eval workflow and the harden loop's scratch
server config to opt in, since both rely on it for per-worker session
cleanup between concurrent runs.
Test plan
go test -race ./pkg/server/... ./pkg/config/...go build ./...,go vet ./...