Repository navigation
Send the common agent headers on all cloud requests - #751
Conversation
| "X-Agent-IP-Address": _UNKNOWN if ip_address == _UNRESOLVED_IP else ip_address, | ||
| "X-Agent-Session-Id": get_agent_session_id(), |
There was a problem hiding this comment.
🟡 Medium - Custom HTTP endpoints receive internal host metadata
A deployment that configures AIKIDO_ENDPOINT or AIKIDO_REALTIME_ENDPOINT to an HTTP, proxy, or other non-Aikido service now sends the host name, DNS-resolved machine IP, and persistent session identifier on every request. The endpoint overrides accept arbitrary destinations and do not require HTTPS, so that service or a network observer can collect internal infrastructure details that were not present on the firewall/config/SSE requests before this PR.
Show fix
Only attach these metadata headers when the destination is an authenticated Aikido endpoint or an explicitly trusted HTTPS endpoint, or require HTTPS and provide an opt-out/redaction path for custom endpoints. Do not send the session identifier and private host metadata to arbitrary HTTP overrides.
More info - Reply on this comment to give feedback or ignore the issue.
There was a problem hiding this comment.
Should not matter if we also send the same data to operator-overridden endpoints.
| agent_headers.append({ | ||
| name.lower(): value for name, value in request.headers.items() | ||
| if name.lower().startswith('x-agent-') | ||
| }) |
There was a problem hiding this comment.
perhaps cleaner to store the headers as part of events and pass flag to the GET events to include headers? See AikidoSec/firewall-tester-action#195
So that you can see the headers are being sent for every type of event etc
| value.encode("latin-1") | ||
| except UnicodeEncodeError: | ||
| return _UNKNOWN | ||
| return value or _UNKNOWN |
There was a problem hiding this comment.
do we really need a constant for "unknown" hehe?
| """Contains package versions""" | ||
|
|
||
| PKG_VERSION = "1.0-REPLACE-VERSION" | ||
| LIBRARY_NAME = "firewall-python" |
There was a problem hiding this comment.
a constant for this feels a bit overkill sometimes but fine to me! ^^
Every agent-to-cloud request now carries the platform, the library name and version, the instance hostname and IP address, and a session id generated once per application run. The hostname, IP and library name are read through the same helpers and constant the event payloads use, so a request and an event always report the same instance. Resolving the instance IP queries DNS, and it is now needed twice per event report and once per config poll and stream connect, so it and the hostname are read once per run instead.