feat: GET /api/v2/agent-firewall/sessions/{id} (#24814)

Add a GET endpoint at `/api/v2/agent-firewall/sessions/{id}` that
returns agent firewall session metadata (`id`, `workspace_id`,
`owner_id`, `confined_process`, `started_at`). The handler authorizes
against the `boundary_log` resource with `ActionRead` via dbauthz.

The endpoint is enterprise-only, gated behind the `FeatureBoundary`
entitlement.

The `GetBoundarySessionByID` SQL query JOINs through `workspace_agents`
→ `workspace_resources` → `workspace_builds` → `workspaces` to return
`workspace_id` and `workspace_owner_id` directly, avoiding a separate
query.

Also adds an `owner_id` column to the `boundary_logs` table (migration
000526) with a FK to `users(id)` and a backfill from
`boundary_sessions`. This enables user-scoped RBAC authorization for
`InsertBoundaryLogs` via `.WithOwner()`, ensuring workspace agents can
only insert logs for their own owner.

Depends on #24810

**RBAC behaviour:**

| Role    | Result |
|---------|--------|
| Owner   | read   |
| Auditor | read   |
| Member  | 404    |

> [!NOTE]
> This PR was authored by Coder Agents.
This commit is contained in:
Sas Swart
2026-06-18 20:50:17 +02:00
committed by GitHub
parent 20ed45cac7
commit 491a75294e
24 changed files with 649 additions and 20 deletions
+41
View File
@@ -84,6 +84,47 @@ curl -X GET http://coder-server:8080/.well-known/oauth-protected-resource \
|--------|---------------------------------------------------------|-------------|------------------------------------------------------------------------------------------------|
| 200 | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK | [codersdk.OAuth2ProtectedResourceMetadata](schemas.md#codersdkoauth2protectedresourcemetadata) |
## Get agent firewall session by ID
### Code samples
```shell
# Example request using curl
curl -X GET http://coder-server:8080/api/v2/agent-firewall/sessions/{id} \
-H 'Accept: application/json' \
-H 'Coder-Session-Token: API_KEY'
```
`GET /api/v2/agent-firewall/sessions/{id}`
### Parameters
| Name | In | Type | Required | Description |
|------|------|--------------|----------|---------------------------|
| `id` | path | string(uuid) | true | Agent firewall session ID |
### Example responses
> 200 Response
```json
{
"confined_process": "string",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"owner_id": "8826ee2e-7933-4665-aef2-2393f84a0d05",
"started_at": "2019-08-24T14:15:22Z",
"workspace_id": "0967198e-ec7b-4c6b-b4d3-f71244cadbe9"
}
```
### Responses
| Status | Meaning | Description | Schema |
|--------|---------------------------------------------------------|-------------|--------------------------------------------------------------------------|
| 200 | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK | [codersdk.AgentFirewallSession](schemas.md#codersdkagentfirewallsession) |
To perform this operation, you must be authenticated. [Learn more](authentication.md).
## List AI Gateway keys
### Code samples
+22
View File
@@ -1263,6 +1263,28 @@ None
|-----------------------------------------------|
| `always_collapsed`, `always_expanded`, `auto` |
## codersdk.AgentFirewallSession
```json
{
"confined_process": "string",
"id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
"owner_id": "8826ee2e-7933-4665-aef2-2393f84a0d05",
"started_at": "2019-08-24T14:15:22Z",
"workspace_id": "0967198e-ec7b-4c6b-b4d3-f71244cadbe9"
}
```
### Properties
| Name | Type | Required | Restrictions | Description |
|--------------------|--------|----------|--------------|-------------|
| `confined_process` | string | false | | |
| `id` | string | false | | |
| `owner_id` | string | false | | |
| `started_at` | string | false | | |
| `workspace_id` | string | false | | |
## codersdk.AgentScriptTiming
```json