Skip to content

Session-ID hardening: no workspace-derived fallback ids upstream - #16

Merged
rjcloudsigma merged 1 commit into
mainfrom
fix/session-id-hardening-20260724
Jul 24, 2026
Merged

Session-ID hardening: no workspace-derived fallback ids upstream#16
rjcloudsigma merged 1 commit into
mainfrom
fix/session-id-hardening-20260724

Conversation

@rjcloudsigma

Copy link
Copy Markdown
Collaborator

New AAS/OpenClaw conversations without a fresh ctx.sessionId previously fell back to a workspace-hash session id — identical to the previous closed session in that workspace — and injected it as X-Session-Id, which taas-api Phase-0 honours. This PR (1) stops header injection entirely when no conversation-scoped id exists, (2) boot-salts internal fallback ids, (3) updates the smoke test to the hardened contract. Typecheck/build/tests green locally.

- resolveTransportTurnState: skip X-Session-Id/X-OpenClaw-Session-Id header
  injection entirely when no conversation-scoped ctx.sessionId is present,
  so a new conversation can never resume a previous (closed) session bound
  to the same workspace.
- resolveSessionId: salt the internal workspaceDir/stateDir fallback ids
  with a per-process boot salt so they can never collide with ids from a
  prior process lifetime.
- smoke test updated to assert the hardened contract.
@rjcloudsigma
rjcloudsigma merged commit 8fc3e55 into main Jul 24, 2026
@rjcloudsigma
rjcloudsigma deleted the fix/session-id-hardening-20260724 branch July 24, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant