Commit da36bab
authored
Check where an agent address redirects to, not just where it starts (#38)
* Check where an agent address redirects to, not just where it starts
`checkAgentEndpoint` decides whether this deployment is willing to talk to an
address, and then the request was handed to a fetch that follows redirects. The
address that was checked and the address that was dialled were therefore only the
same address while nobody redirected. A registrable agent at
`https://agent.example.com/ag-ui` answering `307 Location:
http://169.254.169.254/latest/meta-data/` put the server on its own cloud metadata
endpoint, which the check refuses under every configuration.
Both places that dial an agent are affected, and the second is the worse one. The
connection test runs once at registration; the runtime dials the stored endpoint on
every single run, carrying whatever auth header the registration supplied, so a
redirect added after approval is an ongoing exposure rather than a one-off.
`createAgentFetch` applies the check to each hop. Redirects are followed rather than
refused, because a deployment that puts its agent behind one has done nothing wrong
and `http` to `https` is the ordinary case; each destination goes through
`checkAgentEndpoint` first, so following one can only reach somewhere registering it
directly would have reached. Three hops, then it gives up.
Method and body are carried across hops. A browser turns a redirected POST into a
GET, and doing that here would only ever produce a confusing "that is not an AG-UI
endpoint" from an agent that is one.
The stall guard already accepted an inner fetch, so the two compose: a deployment
with a timeout configured gets the watch and the redirect check rather than
whichever was wired last.
* Stop a redirect carrying the credentials on to the next host
A hop that leaves the host the request was authorised for now arrives with
nothing that proves who we are. The customer's key was given to us for their
host, and the signed run assertion is this deployment's own capability: whatever
holds it can call back as that Bot, for that person, and it rides in the body, so
dropping headers alone would leave the more valuable of the two travelling. Only
the two protocol headers survive the hop, and the run is taken out of the body.
Once dropped they stay dropped, so a chain that wanders off and comes back does
not collect them again. A scheme upgrade on the same host is not a different
party and keeps both, which is the shape a deployment behind a redirect actually
has; the downgrade is treated as one.
The stored address is checked before it is dialled, not only the hops after it.
A row written before this guard existed is dialled on every run, and that was the
one address a check reading only Location headers never looked at.
`EndpointRedirectError` is now `EndpointNotAllowedError`, because it answers for
the stored address as well as the hops.
* Put a refused agent dial on the audit trail, and say what changed in the changelog
A refused hop threw and nothing else happened. The person whose run failed found
out immediately and the deployment found out nothing, which is the wrong way
round for this particular failure: a registration is one person at one moment,
but a stored agent that has quietly begun redirecting somewhere it should not is
a fact about an endpoint, happening on every run, with nobody watching. It reads
as an agent being flaky until somebody can count it.
`createAgentFetch` now reports refusals to its caller and `index.ts` turns that
into an `agent.dial_refused` row naming the address and the reason. The callback
rather than an audit store keeps `endpoint.ts` deciding and nothing else, which
is the same reason it reuses the navigation target check instead of growing a
second one.
Reporting cannot take a refusal down with it. A reporter that throws is
swallowed and a row that cannot be written is logged, because the request is
already refused by the time either runs and the alternative is trading a lost
record for a dialled request.
All four refusal paths report: the stored address, a redirect destination, a body
that cannot be stripped for a cross-host hop, and the redirect cap. The last is
not a trust decision and is counted anyway, since an endpoint that loops is
another thing only the trail can show is happening repeatedly.
Three tests, and the negative one earns its place: removing the report turns two
red, and reporting on a permitted hop turns the third red, so neither direction
is vacuous.1 parent 140919b commit da36bab
9 files changed
Lines changed: 787 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
58 | 80 | | |
59 | 81 | | |
60 | 82 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
2 | 6 | | |
3 | 7 | | |
4 | 8 | | |
| |||
97 | 101 | | |
98 | 102 | | |
99 | 103 | | |
100 | | - | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
101 | 112 | | |
102 | 113 | | |
103 | 114 | | |
| |||
111 | 122 | | |
112 | 123 | | |
113 | 124 | | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
114 | 130 | | |
115 | 131 | | |
116 | 132 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
54 | 68 | | |
55 | 69 | | |
56 | 70 | | |
| |||
0 commit comments