createTerminal and createFM correctly check server ownership before
issuing a stream UUID, but terminalStream and fmStream only verified
that the UUID existed. Any authenticated user holding a valid stream
UUID could attach to it, gaining the original creator's live shell or
file-manager session — and the UUID is exposed via URL path (referer
leaks, access logs, browser history, frontend error reporters).
Bind the creator user ID into ioStreamContext at CreateStream time,
expose StreamOwnership and IsStreamAuthorizedForUser, and check
ownership in terminalStream/fmStream before the WebSocket upgrade so a
rejected attempt does not tear down the legitimate stream via defer.
NAT streams are also routed through CreateStream(_, 0); they are not
reachable from /ws/terminal or /ws/file so a sentinel user ID is fine.
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
* test(deps): use self admin-frontend
* feat: separate real ip header of frontend/agent
* test(ci): test
* Revert "test(ci): test"
This reverts commit 1634c7e7d7bca2873c13955abb582ea88645844f.
* test(ci): test
* test(ci): test
* test(ci): test
* Revert "test(ci): test"
This reverts commit 8fce20a07e5a9503f665937337050d4373ca7e78.
* Revert "test(ci): test"
This reverts commit 3267cccbfb81776a711e8cb34e676536f0852d1c.
* Revert "test(ci): test"
This reverts commit 566660c0c6a9875864aa46537bcc6788769337eb.
* Revert "test(deps): use self admin-frontend"
This reverts commit 16a838b374ff040800b2c1c5f8e5ede577645669.
* feat: support listening https
* refactor
* modernize
* support snake case in config
* more precise control of config fields
* update goreleaser config
* remove kubeyaml
* fix: expose agent_secret
* chore