toolsrv: include session ID in bypass broker requests

The bypass broker requires a 'session' field in the JSON request
to identify which session is making the bypass request. The toolsrv
was sending requests without this field, causing 'denied (no session
identity)' errors.

Fix: Include OLLIE_SESSION_ID from environment in the bypass request.
This commit is contained in:
Levi Neely 2026-08-12 08:34:52 +02:00
parent 23b427f97b
commit 1814f82928
1 changed files with 6 additions and 5 deletions

View File

@ -272,11 +272,12 @@ func executeBypassDirect(ctx context.Context, cmd, cwd string, envExtra map[stri
defer conn.Close()
reqJSON, _ := json.Marshal(struct {
Cmd string `json:"cmd"`
Cwd string `json:"cwd"`
Env map[string]string `json:"env"`
Sudo bool `json:"sudo,omitempty"`
}{Cmd: cmd, Cwd: cwd, Env: envMap, Sudo: sudo})
Cmd string `json:"cmd"`
Cwd string `json:"cwd"`
Env map[string]string `json:"env"`
Session string `json:"session"`
Sudo bool `json:"sudo,omitempty"`
}{Cmd: cmd, Cwd: cwd, Env: envMap, Session: os.Getenv("OLLIE_SESSION_ID"), Sudo: sudo})
reqJSON = append(reqJSON, '\n')
if _, err := conn.Write(reqJSON); err != nil {