fix: scope Socket.IO event-caller to the requesting user's own session (#25763)

get_event_call() routed execute:python / execute:tool events to a client-supplied session_id after only checking the session was connected, not that it belonged to the requester. Verify the target session is owned by the requesting user (metadata user_id) before delivering, so a client cannot route code/tool execution into another user's session.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Classic298
2026-06-29 02:17:40 -05:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 914039ac81
commit 386ac95814
+4 -3
View File
@@ -1022,9 +1022,10 @@ async def get_event_call(request_info):
async def __event_caller__(event_data):
session_id = request_info['session_id']
# Fast-fail if the client has disconnected.
if session_id not in SESSION_POOL:
log.warning(f'Event caller: session {session_id} no longer connected')
# session_id is client-supplied; only the requesting user's own live session may be targeted.
session = SESSION_POOL.get(session_id)
if session is None or session.get('id') != request_info.get('user_id'):
log.warning(f'Event caller: session {session_id} not owned by requesting user or disconnected')
return {'error': 'Client session disconnected.'}
try: