fix(rpc): allow global agent secret across server owners

Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
This commit is contained in:
naiba
2026-05-19 01:58:53 +00:00
co-authored by naiba/CloudCode
parent 43624792a3
commit fa31ba402e
2 changed files with 17 additions and 0 deletions
+5
View File
@@ -101,6 +101,11 @@ func authorizeAgentForUUID(userId uint64, clientUUID string) (clientID uint64, h
// Treat as unknown (registration path) rather than impersonation. // Treat as unknown (registration path) rather than impersonation.
return 0, false, nil return 0, false, nil
} }
if userId == 0 {
// The legacy global agent secret maps to user 0. It predates per-user
// agent secrets, so keep it compatible by allowing any existing UUID.
return cid, true, nil
}
if server.UserID != userId { if server.UserID != userId {
return 0, false, fmt.Errorf("client UUID does not belong to the agent secret owner") return 0, false, fmt.Errorf("client UUID does not belong to the agent secret owner")
} }
+12
View File
@@ -73,6 +73,18 @@ func TestAuthorizeAgentForUUIDRejectsForeignServerUUID(t *testing.T) {
} }
} }
func TestAuthorizeAgentForUUIDAllowsGlobalDefaultSecret(t *testing.T) {
defer setupAuthAgentFixture(t)()
cid, hasID, err := authorizeAgentForUUID(0, "uuid-bob")
if err != nil {
t.Fatalf("global default secret must be allowed to use existing UUIDs, got %v", err)
}
if !hasID || cid != 2 {
t.Fatalf("expected (cid=2, hasID=true), got (cid=%d, hasID=%v)", cid, hasID)
}
}
// An unknown UUID must NOT be treated as an impersonation attempt — it is // An unknown UUID must NOT be treated as an impersonation attempt — it is
// the normal first-time registration path and the caller (Check) creates a // the normal first-time registration path and the caller (Check) creates a
// new server bound to the secret owner. // new server bound to the secret owner.