fix: pin workspace agent API client to intended agent (#26600) - #26612
Conversation
1f5cc36 to
18ac7d5
Compare
|
This backport required a fairly involved manual conflict resolution: #26600 was built on a separate request-context refactor of @codex review |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Backport of #26600 to release/2.32. The workspace agent API client followed HTTP redirects and trusted the redirected host, letting a malicious agent bounce a coderd request onto a different agent's unauthenticated port-4 API (cross-tenant file read/write and RCE). apiClient now refuses redirects and pins every dial to the intended agent address, and the task app / scaletest clients share AppHTTPClient, which blocks redirects too. The upstream change was built on a separate request-context refactor of apiClient that is not present on this release branch, so the redirect block and agent-address pinning are applied to the existing apiClient() here and the request-context-bounded dial test is omitted. (cherry picked from commit eeb2624)
18ac7d5 to
7768ac0
Compare
Backport of #26600 to
release/2.32.Original PR: #26600 - fix: pin workspace agent API client to intended agent
Merge commit: eeb2624
Requested by: @ethanndickson
What this fixes
The workspace agent API client followed HTTP redirects and trusted the redirected host, letting a malicious agent bounce a coderd request onto a different agent's unauthenticated port-4 API (cross-tenant file read/write and RCE, Cure53 CODAGT-668).
apiClientnow refuses redirects and pins every dial to the intended agent address, and the task-app / scaletest clients shareAppHTTPClient, which blocks redirects too.Conflict resolution
The automatic cherry-pick conflicted because #26600 was built on a separate request-context refactor of
apiClientthat is not present on this release branch. The redirect block and agent-address pinning are applied to the existingapiClient()here, and the request-context-bounded dial test (which depends on that refactor) is omitted. This branch had noagentconn_test.go, so the redirect tests are added as a newagentconn_test.go. The two redirect regression tests added by #26600 are included.