* update to release version v7.15.5
* Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>
* Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
* Merge commit from fork
* fix: validate trusted IP proxy headers
Respect trusted proxy boundaries before using real-client-IP headers for authentication bypass decisions and safely traverse X-Forwarded-For chains.
Signed-off-by: Jan Larwig <jan@larwig.com>
* fix: trusted-ip header bypass
Signed-off-by: Jan Larwig <jan@larwig.com>
* docs: add changelog entry
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* docs: changelog for v7.15.5
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* docs: update order of owners for prow
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* ci: make the linter happy again
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
* fix: #3428 bybitbucket auth failure by changing token n validation flow to use Authentication header instead of query param
Co-authored-by: aviralgarg05 <gargaviral99@gmail.com>
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* fix: added changelog entry and added tests to verify bitbucket auth header fix
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
* fix(bitbucket): aded support for limiting login for workspace members and handled deprecated team api and added test cases
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
* docs(bitbucket): applied missing docs changes
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
---------
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: aviralgarg05 <gargaviral99@gmail.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
* fix: handle Unix socket RemoteAddr in IP resolution
When oauth2-proxy listens on a Unix socket, Go sets RemoteAddr to "@"
instead of the usual "host:port" format. This caused net.SplitHostPort
to fail on every request, flooding logs with errors:
Error obtaining real IP for trusted IP list: unable to get ip and
port from http.RemoteAddr (@)
Fix by handling the "@" RemoteAddr at the source in getRemoteIP,
returning nil without error since Unix sockets have no meaningful
client IP. Also simplify the isTrustedIP guard and add a nil check
in GetClientString to prevent calling String() on nil net.IP.
Fixes#3373
Signed-off-by: h1net <ben@freshdevs.com>
* docs: add changelog entry and Unix socket trusted IPs documentation
Add changelog entry for #3374. Document that trusted IPs cannot match
against RemoteAddr for Unix socket listeners since Go sets it to "@",
and that IP-based trust still works via X-Forwarded-For with reverse-proxy.
Signed-off-by: Ben Newbery <ben.newbery@gmail.com>
Signed-off-by: h1net <ben@freshdevs.com>
* doc: fix changelog entry for #3374
Signed-off-by: Jan Larwig <jan@larwig.com>
* doc: add trusted ip a section to versioned docs as well
Signed-off-by: Jan Larwig <jan@larwig.com>
---------
Signed-off-by: h1net <ben@freshdevs.com>
Signed-off-by: Ben Newbery <ben.newbery@gmail.com>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
* add new docs version 7.15.x
* update to release version v7.15.0
* doc: changelog for v7.15.0 and extended docs for additional claims
* ci: fix trivy failure for release PR
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>