Confine agent re-registration to the owner's tenant - #290
Open
jameshoweee wants to merge 1 commit into
Open
Conversation
Agent names are global and any user can mint a registration token, so register_agent(overwrite=True) let anyone re-register another user's agent by name: the caller got a live API key for the victim's agent (owner_id unchanged) and the victim's key was deleted (cross-tenant takeover + DoS). Reject overwrite when the existing agent has a different owner. Same-owner re-register is unchanged. Adds a regression test.
jameshoweee
requested review from
amaudruz and
christian-mcdermott
as code owners
August 25, 2026 15:41
|
All contributors have signed the CLA. ✅ |
Author
|
I have read the CLA Document and I hereby sign the CLA |
Collaborator
|
recheck |
1 similar comment
Collaborator
|
recheck |
Author
|
recheck |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Agent names are global and any user can mint a registration token, so
register_agent(overwrite=True)let anyone re-register another user's agent by name: the caller got a live API key for the victim's agent (owner_id left unchanged) and the victim's key was deleted. Cross-tenant takeover + DoS of the owner.Fix: reject overwrite when the existing agent has a different owner, using the same "already exists" error so ownership isn't leaked. Same-owner re-register (connector restart, server rediscovery) is unchanged. Adds a regression test.