Scope PGCheckpointer queries by tenant GID
Each Save and Load now derives tenant_id from the run GID and pins it in the WHERE clause. A caller that supplies an ID from another tenant fails closed instead of silently reading or overwriting cross-tenant checkpoint data. Also rejects oversize checkpoints on load as a read-side guard against a tampered or migrated row exceeding MaxCheckpointBytes. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -15,7 +15,7 @@
|
||||
CREATE TABLE agent_runs (
|
||||
id TEXT NOT NULL PRIMARY KEY,
|
||||
tenant_id TEXT NOT NULL,
|
||||
organization_id TEXT NOT NULL,
|
||||
organization_id TEXT NOT NULL REFERENCES organizations(id) ON DELETE CASCADE,
|
||||
start_agent_name TEXT NOT NULL,
|
||||
status TEXT NOT NULL DEFAULT 'PENDING',
|
||||
checkpoint JSONB,
|
||||
@@ -29,8 +29,5 @@ CREATE TABLE agent_runs (
|
||||
updated_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
||||
);
|
||||
|
||||
CREATE INDEX idx_agent_runs_status ON agent_runs (status)
|
||||
WHERE status IN ('PENDING', 'RUNNING', 'SUSPENDED');
|
||||
CREATE INDEX idx_agent_runs_organization_status ON agent_runs (organization_id, status, created_at);
|
||||
CREATE INDEX idx_agent_runs_running_lease ON agent_runs (lease_expires_at)
|
||||
WHERE status = 'RUNNING';
|
||||
Reference in New Issue
Block a user