Skip to content

broker: don't bind literal routes as tenancy resource ids - #123

Merged
TeoSlayer merged 2 commits into
mainfrom
fix/broker-literal-route-tenancy
Oct 1, 2026
Merged

TeoSlayer merged 2 commits into
mainfrom
fix/broker-literal-route-tenancy

Conversation

@Alexgodoroja

Copy link
Copy Markdown
Collaborator

Problem

agentphone.list_voices returns 404 {"error":"not found"} for every caller, on every platform.

GET /v1/agents/voices is a literal allow entry that sits beside the template GET /v1/agents/{agent_id}. pathParams matches both patterns and binds agent_id="voices". Nobody owns an agent with that id, so tenancy refuses the request before it reaches AgentPhone.

Fix

When a request hits a literal allow entry, tenancy binds no path params (AppEntry.tenancyPatterns). Query-string and body refs are still ownership-checked, and templated routes are unchanged.

Tests

  • New TestTenancy_LiteralRouteBesideTemplateIsNotAnID: the literal route reaches the partner once, and an unowned /v1/agents/{id} is still refused and never forwarded.
  • It fails without the fix and passes with it. go test ./internal/broker/ is green.

Rollout

Needs a broker redeploy on pilot-publish. No registry change.

Found during the app-store audit.

🤖 Generated with Claude Code

Alexgodoroja and others added 2 commits September 24, 2026 19:58
GET /v1/agents/voices is a literal allow entry next to the template
GET /v1/agents/{agent_id}. pathParams matched both and bound
agent_id="voices", which no caller owns, so tenancy refused the route with
a 404 for everyone (io.pilot.agentphone's list_voices). A request that hits a
literal allow entry now binds no path params; query and body refs are still
ownership-checked, and templated routes are unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@TeoSlayer
TeoSlayer merged commit 1d178ad into main Oct 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants