feat(grpc): resolve org from server record for agent RPCs
Two instances of the branch's recurring bug class remained in the agent path: a client-supplied ID accepted as data, then consumed by an unscoped query. - ListMonitorsForRunner filtered on `runner` alone, and `runner` is set by the client on monitor create/update. Org A could point a monitor at org B's server_id and org B's agent would fetch and execute the check. Now org-filtered, and `runner` is validated against the caller's org on create and update. - IngestResult resolved the monitor via the unfiltered getMonitorByID using a monitor_id from the agent's request body, letting org A's agent write state and incidents into org B's monitor and fire its channels. Now rejects on org mismatch and on a monitor not assigned to the reporting agent. The in-process scheduler passes an empty orgID as a documented sentinel for the cross-org server-run sweep. Install script still emits a single shared GRPC_HOST; the agent path resolves org from the server record, never from a hostname.
This commit is contained in:
@@ -112,7 +112,7 @@ func (s *vantageServer) SyncMonitors(ctx context.Context, req *pb.SyncMonitorsRe
|
||||
if err != nil {
|
||||
return nil, status.Errorf(codes.Unauthenticated, "invalid agent token")
|
||||
}
|
||||
monitors, err := services.ListMonitorsForRunner(srv.ServerID)
|
||||
monitors, err := services.ListMonitorsForRunner(srv.OrgID, srv.ServerID)
|
||||
if err != nil {
|
||||
return nil, status.Errorf(codes.Internal, "list monitors")
|
||||
}
|
||||
@@ -137,7 +137,8 @@ func (s *vantageServer) SyncMonitors(ctx context.Context, req *pb.SyncMonitorsRe
|
||||
}
|
||||
|
||||
func (s *vantageServer) ReportChecks(ctx context.Context, req *pb.ReportChecksRequest) (*pb.ReportChecksResponse, error) {
|
||||
if _, err := services.ValidateAgentToken(req.ServerId, req.AgentToken); err != nil {
|
||||
srv, err := services.ValidateAgentToken(req.ServerId, req.AgentToken)
|
||||
if err != nil {
|
||||
return nil, status.Errorf(codes.Unauthenticated, "invalid agent token")
|
||||
}
|
||||
for _, r := range req.Results {
|
||||
@@ -146,7 +147,9 @@ func (s *vantageServer) ReportChecks(ctx context.Context, req *pb.ReportChecksRe
|
||||
t := time.Unix(r.CertExpiryUnix, 0)
|
||||
res.CertExpiry = &t
|
||||
}
|
||||
if err := services.IngestResult(r.MonitorId, res); err != nil {
|
||||
// A rejected monitor (wrong org, or not run by this agent) is skipped,
|
||||
// not fatal — the rest of the batch is still legitimate.
|
||||
if err := services.IngestResult(srv.OrgID, srv.ServerID, r.MonitorId, res); err != nil {
|
||||
log.Printf("ingest check %s: %v", r.MonitorId, err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user