mirror of
https://github.com/jcreek/CosmicClash.git
synced 2026-09-11 00:14:00 +00:00
fix(multiplayer): bind signed workload tokens to allocation_id only
The just-landed signed workload token embedded (allocation_id, match_id, server_id) as claims. That doesn't actually work for its intended delivery channel: the token is meant to be requested as a GameServerAllocation annotation in the SAME request that asks Agones to pick a server, so at mint time the allocator knows allocation_id (it generates it) but not yet which server_id Agones will return -- server_id only exists in Agones's response, after the annotation request has already been sent. Embedding it was simply not possible for the real caller this was built for; only the (allocator -> signed_token) unit tests and hand-constructed integration tests happened to supply it directly, masking the gap. Fixes it by having the token bind only allocation_id (the one identifier actually known at mint time) plus expiry. match_id/server_id are resolved at verify time from the durable allocations table via the new store.AllocationBindingByAllocationID, keyed by allocation_id -- which the allocator already records immediately after Agones responds. This is strictly stronger, not just a workaround: a caller can no longer claim any match/server pairing at all, even one that happens to be internally consistent -- the binding returned is entirely durable-record-derived. Verified: server/workload's unit tests updated for the new two-field claim shape; server/api's Postgres integration suite gains TestWorkloadVerifierFromSignedTokenNeverTrustsCallerSuppliedBinding (two distinct real allocations each resolve to their own, and only their own, match/server pairing) replacing the now-inapplicable mismatched-triple test. Full `go build ./... && go vet ./... && gofmt -l . && go test ./... -race` and `go test -tags integration ./... -race` both clean; the api integration suite re-run 3x clean against a live postgres:17-alpine container.
This commit is contained in:
@@ -5,32 +5,33 @@ import (
|
||||
"database/sql"
|
||||
)
|
||||
|
||||
// AllocationBindingStillValidSQL cross-checks a signed workload token's
|
||||
// claims against the durable allocation record before trusting it. A
|
||||
// validly-signed, unexpired token alone is not proof the allocation it names
|
||||
// is still the live binding for that match/server pair -- this closes that
|
||||
// gap defense-in-depth. allocations rows are append-only and never leave
|
||||
// 'ALLOCATED' (see allocator_sql.go), so this is a simple existence check,
|
||||
// not a state-machine walk.
|
||||
const AllocationBindingStillValidSQL = `SELECT 1 FROM allocations
|
||||
WHERE allocation_id = $1 AND match_id = $2 AND server_id = $3 AND state = 'ALLOCATED'`
|
||||
// AllocationBindingByAllocationIDSQL resolves the durable match_id/server_id
|
||||
// pairing for an allocation_id. A signed workload token only ever names
|
||||
// allocation_id (see workload/signed_token.go for why match_id/server_id
|
||||
// aren't embedded in the token itself); this is what lets WorkloadVerify
|
||||
// return a binding whose match_id/server_id came from the durable allocator
|
||||
// record, not from anything the caller supplied. allocations rows are
|
||||
// append-only and never leave 'ALLOCATED' (see allocator_sql.go), so this is
|
||||
// a simple existence lookup, not a state-machine walk.
|
||||
const AllocationBindingByAllocationIDSQL = `SELECT match_id, server_id FROM allocations
|
||||
WHERE allocation_id = $1 AND state = 'ALLOCATED'`
|
||||
|
||||
// AllocationBindingStillValid reports whether the given (allocationID,
|
||||
// matchID, serverID) triple names a real, still-allocated row. db, and every
|
||||
// identifier, must be non-empty -- callers pass this an already-parsed and
|
||||
// signature-verified token's claims, so empty fields here indicate a caller
|
||||
// bug rather than a legitimate "not found".
|
||||
func AllocationBindingStillValid(ctx context.Context, db *sql.DB, allocationID, matchID, serverID string) (bool, error) {
|
||||
if db == nil || allocationID == "" || matchID == "" || serverID == "" {
|
||||
return false, sql.ErrNoRows
|
||||
// AllocationBindingByAllocationID returns the (matchID, serverID) durably
|
||||
// recorded for allocationID, and false if no such allocated row exists. db
|
||||
// and allocationID must be non-empty -- callers pass this an
|
||||
// already-parsed and signature-verified token's claims, so an empty
|
||||
// allocationID here indicates a caller bug rather than a legitimate
|
||||
// "not found".
|
||||
func AllocationBindingByAllocationID(ctx context.Context, db *sql.DB, allocationID string) (matchID, serverID string, ok bool, err error) {
|
||||
if db == nil || allocationID == "" {
|
||||
return "", "", false, sql.ErrNoRows
|
||||
}
|
||||
var one int
|
||||
err := db.QueryRowContext(ctx, AllocationBindingStillValidSQL, allocationID, matchID, serverID).Scan(&one)
|
||||
err = db.QueryRowContext(ctx, AllocationBindingByAllocationIDSQL, allocationID).Scan(&matchID, &serverID)
|
||||
if err == sql.ErrNoRows {
|
||||
return false, nil
|
||||
return "", "", false, nil
|
||||
}
|
||||
if err != nil {
|
||||
return false, err
|
||||
return "", "", false, err
|
||||
}
|
||||
return true, nil
|
||||
return matchID, serverID, true, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user