fix: scope Socket.IO event-caller to the requesting user's own session

get_event_call() routed execute:python / execute:tool events to a client-supplied session_id after only checking the session was connected, not that it belonged to the requester. Verify the target session is owned by the requesting user (metadata user_id) before delivering, so a client cannot route code/tool execution into another user's session.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Classic298 2026-06-06 16:45:06 +02:00
parent 1a97751e37
commit b147b33ee2

View file

@ -1015,9 +1015,10 @@ async def get_event_call(request_info):
async def __event_caller__(event_data):
session_id = request_info['session_id']
# Fast-fail if the client has disconnected.
if session_id not in SESSION_POOL:
log.warning(f'Event caller: session {session_id} no longer connected')
# session_id is client-supplied; only the requesting user's own live session may be targeted.
session = SESSION_POOL.get(session_id)
if session is None or session.get('id') != request_info.get('user_id'):
log.warning(f'Event caller: session {session_id} not owned by requesting user or disconnected')
return {'error': 'Client session disconnected.'}
try: