From 54d367f695cacd3852687ad7259e362015344c52 Mon Sep 17 00:00:00 2001 From: ValentaTomas Date: Sat, 16 May 2026 01:17:40 -0700 Subject: [PATCH] fix(orchestrator): overwrite envID in sandbox logs too The /logs handler already overwrites instanceID and teamID from the authoritative sandbox map; envID was the only identity field still trusted from the envd payload. Take it from sbx.Runtime.TemplateID too so envd doesn't need to be trusted for any of them. --- packages/orchestrator/pkg/hyperloopserver/handlers/logs.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/packages/orchestrator/pkg/hyperloopserver/handlers/logs.go b/packages/orchestrator/pkg/hyperloopserver/handlers/logs.go index d9db476722..6e61fe764f 100644 --- a/packages/orchestrator/pkg/hyperloopserver/handlers/logs.go +++ b/packages/orchestrator/pkg/hyperloopserver/handlers/logs.go @@ -45,8 +45,9 @@ func (h *APIStore) Logs(c *gin.Context) { return } - // Overwrite instanceID and teamID to avoid spoofing + // Overwrite instanceID, envID, and teamID to avoid spoofing payload["instanceID"] = sbxID + payload["envID"] = sbx.Runtime.TemplateID payload["teamID"] = sbx.Runtime.TeamID logs, err := json.Marshal(payload)