Skip to content

Send the common agent headers on all cloud requests - #751

Merged
hansott merged 4 commits into
mainfrom
agent-request-headers
Oct 9, 2026
Merged

hansott merged 4 commits into
mainfrom
agent-request-headers

Conversation

@iacobdaniel

@iacobdaniel iacobdaniel commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Every agent-to-cloud request now carries the platform, the library name and version, the instance hostname and IP address, and a session id generated once per application run. The hostname, IP and library name are read through the same helpers and constant the event payloads use, so a request and an event always report the same instance. Resolving the instance IP queries DNS, and it is now needed twice per event report and once per config poll and stream connect, so it and the hostname are read once per run instead.

Comment thread aikido_zen/background_process/requests/make_request.py Outdated
Comment on lines +16 to +17
"X-Agent-IP-Address": _UNKNOWN if ip_address == _UNRESOLVED_IP else ip_address,
"X-Agent-Session-Id": get_agent_session_id(),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium - Custom HTTP endpoints receive internal host metadata

A deployment that configures AIKIDO_ENDPOINT or AIKIDO_REALTIME_ENDPOINT to an HTTP, proxy, or other non-Aikido service now sends the host name, DNS-resolved machine IP, and persistent session identifier on every request. The endpoint overrides accept arbitrary destinations and do not require HTTPS, so that service or a network observer can collect internal infrastructure details that were not present on the firewall/config/SSE requests before this PR.

Show fix

Only attach these metadata headers when the destination is an authenticated Aikido endpoint or an explicitly trusted HTTPS endpoint, or require HTTPS and provide an opt-out/redaction path for custom endpoints. Do not send the session identifier and private host metadata to arbitrary HTTP overrides.

More info - Reply on this comment to give feedback or ignore the issue.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should not matter if we also send the same data to operator-overridden endpoints.

agent_headers.append({
name.lower(): value for name, value in request.headers.items()
if name.lower().startswith('x-agent-')
})

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

perhaps cleaner to store the headers as part of events and pass flag to the GET events to include headers? See AikidoSec/firewall-tester-action#195

So that you can see the headers are being sent for every type of event etc

value.encode("latin-1")
except UnicodeEncodeError:
return _UNKNOWN
return value or _UNKNOWN

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we really need a constant for "unknown" hehe?

Comment thread aikido_zen/config.py
"""Contains package versions"""

PKG_VERSION = "1.0-REPLACE-VERSION"
LIBRARY_NAME = "firewall-python"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a constant for this feels a bit overkill sometimes but fine to me! ^^

@hansott
hansott merged commit 06f4615 into main Oct 9, 2026
200 of 201 checks passed
@hansott
hansott deleted the agent-request-headers branch October 9, 2026 11:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants