fix(runtime): bind tokens to exact agent placement - #190
Merged
KIDA-MNESIA merged 1 commit intoSep 4, 2026
Conversation
KIDA-MNESIA
marked this pull request as ready for review
September 4, 2026 17:58
This was referenced Sep 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Runtime JWTs were revalidated against the Agent's current workspace and active participant row, but not its exact Computer assignment. A removed host could therefore keep using an already minted token after same-workspace reassignment or Computer revocation. Binding only the Computer id would still allow a move-away/move-back replay.
What
runtime_assignment_idthat rotates whenever workspace, Computer, participant kind, or departure state changes.computerIdandassignmentId, reject legacy tokens without placement claims, and compare the complete identity with live participant/Computer rows on every request and wake-stream delivery.Verification
npm run lintnpm run typechecknpm run server:typechecknpm run buildnpm run guard:big-brainnpm run guard:llm-trackednpm run guard:engine-registrynpm test(1118 passed, 4 skipped, 0 failed)npm run test:integrationagainstpgvector/pgvector:pg16and Redis (297 passed, 5 skipped, 0 failed)