mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: GET /api/v2/agent-firewall/sessions/{id} (#24814)
Add a GET endpoint at `/api/v2/agent-firewall/sessions/{id}` that
returns agent firewall session metadata (`id`, `workspace_id`,
`owner_id`, `confined_process`, `started_at`). The handler authorizes
against the `boundary_log` resource with `ActionRead` via dbauthz.
The endpoint is enterprise-only, gated behind the `FeatureBoundary`
entitlement.
The `GetBoundarySessionByID` SQL query JOINs through `workspace_agents`
→ `workspace_resources` → `workspace_builds` → `workspaces` to return
`workspace_id` and `workspace_owner_id` directly, avoiding a separate
query.
Also adds an `owner_id` column to the `boundary_logs` table (migration
000526) with a FK to `users(id)` and a backfill from
`boundary_sessions`. This enables user-scoped RBAC authorization for
`InsertBoundaryLogs` via `.WithOwner()`, ensuring workspace agents can
only insert logs for their own owner.
Depends on #24810
**RBAC behaviour:**
| Role | Result |
|---------|--------|
| Owner | read |
| Auditor | read |
| Member | 404 |
> [!NOTE]
> This PR was authored by Coder Agents.
This commit is contained in:
@@ -16,12 +16,28 @@ INSERT INTO boundary_sessions (
|
||||
) RETURNING *;
|
||||
|
||||
-- name: GetBoundarySessionByID :one
|
||||
SELECT * FROM boundary_sessions WHERE id = @id;
|
||||
SELECT
|
||||
bs.*,
|
||||
w.id AS workspace_id,
|
||||
w.owner_id AS workspace_owner_id
|
||||
FROM
|
||||
boundary_sessions bs
|
||||
JOIN
|
||||
workspace_agents wa ON wa.id = bs.workspace_agent_id
|
||||
JOIN
|
||||
workspace_resources wr ON wr.id = wa.resource_id
|
||||
JOIN
|
||||
workspace_builds wb ON wb.job_id = wr.job_id
|
||||
JOIN
|
||||
workspaces w ON w.id = wb.workspace_id
|
||||
WHERE
|
||||
bs.id = @id;
|
||||
|
||||
-- name: InsertBoundaryLogs :many
|
||||
INSERT INTO boundary_logs (
|
||||
id,
|
||||
session_id,
|
||||
owner_id,
|
||||
sequence_number,
|
||||
captured_at,
|
||||
created_at,
|
||||
@@ -33,6 +49,7 @@ INSERT INTO boundary_logs (
|
||||
SELECT
|
||||
unnest(@id :: uuid[]),
|
||||
@session_id :: uuid,
|
||||
@owner_id :: uuid,
|
||||
unnest(@sequence_number :: int[]),
|
||||
unnest(@captured_at :: timestamptz[]),
|
||||
unnest(@created_at :: timestamptz[]),
|
||||
|
||||
Reference in New Issue
Block a user