fix(rpc): allow global agent secret across server owners

Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
This commit is contained in:
naiba
2026-05-19 01:58:53 +00:00
co-authored by naiba/CloudCode
parent 9d67134148
commit 1efe2bf053
2 changed files with 17 additions and 0 deletions
+5
View File
@@ -101,6 +101,11 @@ func authorizeAgentForUUID(userId uint64, clientUUID string) (clientID uint64, h
// Treat as unknown (registration path) rather than impersonation.
return 0, false, nil
}
if userId == 0 {
// The legacy global agent secret maps to user 0. It predates per-user
// agent secrets, so keep it compatible by allowing any existing UUID.
return cid, true, nil
}
if server.UserID != userId {
return 0, false, fmt.Errorf("client UUID does not belong to the agent secret owner")
}