Skip to content

Send X-Agent headers with requests to Aikido - #516

Merged
teta2k merged 1 commit into
mainfrom
send-x-agent-headers
Oct 9, 2026
Merged

teta2k merged 1 commit into
mainfrom
send-x-agent-headers

Conversation

@hansott

@hansott hansott commented Oct 9, 2026

Copy link
Copy Markdown
Member

No description provided.

Comment thread lib/agent/cloud/common.go
Comment on lines +39 to +46
func setAgentHeaders(req *http.Request, server *ServerData) {
req.Header.Set("X-Agent-Platform", "php")
req.Header.Set("X-Agent-Library", "firewall-php")
req.Header.Set("X-Agent-Version", constants.Version)
req.Header.Set("X-Agent-Hostname", cmp.Or(globals.Machine.HostName, "unknown"))
req.Header.Set("X-Agent-IP-Address", cmp.Or(globals.Machine.IPAddress, "unknown"))
req.Header.Set("X-Agent-Session-Id", server.SessionID)
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Low - Redirects disclose the new agent identity headers cross-host

When either configured Aikido endpoint returns a redirect to another host, the default HTTP clients follow it and retain these newly added X-Agent headers. The redirect destination can therefore receive the machine hostname, local IP address, and stable session identifier even though Go normally removes the Authorization header on a cross-host redirect.

Show fix

Disable cross-host redirects for cloud requests, or validate the final host and remove the X-Agent headers before following a redirect to a different origin.

More info - Reply on this comment to give feedback or ignore the issue.

@hansott
hansott force-pushed the send-x-agent-headers branch from c762f94 to bf39156 Compare October 9, 2026 09:48
Comment thread lib/agent/aikido_types/session_id.go Outdated
// The custom Go toolchain we use for Alpine has no uuid package
func newSessionID() string {
var b [16]byte
rand.Read(b[:])

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Low - Entropy failures produce colliding session IDs

If the system crypto source returns an error or partial read while a new ServerData is created, newSessionID ignores that failure and still returns an ID. The timestamp bytes are filled afterward but the random suffix can remain zero or partially filled, so sessions created in the same millisecond can share an identifier and be mis-correlated by the cloud.

Show fix

Check and propagate the error from crypto/rand.Read; do not create or transmit a session ID unless its random bytes were fully generated, or use a documented collision-safe fallback that preserves session separation.

More info - Reply on this comment to give feedback or ignore the issue.

@hansott
hansott force-pushed the send-x-agent-headers branch from bf39156 to eac0069 Compare October 9, 2026 09:59
func newSessionID() string {
var b [16]byte
if _, err := rand.Read(b[:]); err != nil {
return "unknown"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not reachable but fine to keep idiomatic go error checking

@teta2k
teta2k merged commit 0cfd2fd into main Oct 9, 2026
396 checks passed
@teta2k
teta2k deleted the send-x-agent-headers branch October 9, 2026 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants