* update to release version v7.15.5
* Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>
* Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
* Merge commit from fork
* fix: validate trusted IP proxy headers
Respect trusted proxy boundaries before using real-client-IP headers for authentication bypass decisions and safely traverse X-Forwarded-For chains.
Signed-off-by: Jan Larwig <jan@larwig.com>
* fix: trusted-ip header bypass
Signed-off-by: Jan Larwig <jan@larwig.com>
* docs: add changelog entry
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* docs: changelog for v7.15.5
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* docs: update order of owners for prow
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* ci: make the linter happy again
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
* fix(encryption): return an error instead of panicking on a short GCM ciphertext
gcmCipher.Decrypt slices ciphertext[:nonceSize] without first checking the
length, so a ciphertext shorter than the 12-byte GCM nonce triggers a
slice-bounds-out-of-range panic instead of returning an error. The sibling
cfbCipher.Decrypt already guards its IV length and returns a descriptive error;
mirror that guard for GCM so decrypting a malformed (e.g. truncated) cookie
fails cleanly. Adds a test covering both ciphers.
Signed-off-by: Madan Kumar <winklemad@outlook.com>
* docs(changelog): add entry for the GCM short-ciphertext fix
Signed-off-by: Madan Kumar <winklemad@outlook.com>
---------
Signed-off-by: Madan Kumar <winklemad@outlook.com>
* Propagate Microsoft Graph errors during Entra group overage
When a session hit AAD group overage, addGraphGroupsToSession logged a
failed Graph request and returned nil, so EnrichSession's error handling
never ran and the session kept the overage placeholder instead of the
real groups. Return the error like the rest of the file does, and add a
regression test using the existing 401 Graph mock.
Signed-off-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>
* Tighten the Graph-error test and wrap the error, add a changelog entry
Wrap the Graph error with %w so callers can errors.Is through
EnrichSession. Pin the test to the Graph path with ErrorContains and
assert the session's groups are left untouched after the failed call, so
the test fails if the fix regresses rather than on any error. Add the
behaviour change to the changelog since a Graph outage during overage now
fails the login instead of proceeding with the overage placeholder.
Signed-off-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>
---------
Signed-off-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>
* fix: #3428 bybitbucket auth failure by changing token n validation flow to use Authentication header instead of query param
Co-authored-by: aviralgarg05 <gargaviral99@gmail.com>
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
* fix: added changelog entry and added tests to verify bitbucket auth header fix
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
* fix(bitbucket): aded support for limiting login for workspace members and handled deprecated team api and added test cases
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
* docs(bitbucket): applied missing docs changes
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
---------
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: aviralgarg05 <gargaviral99@gmail.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
AdditionalClaims were only extracted during the initial login. On
cookie refresh, buildSessionFromClaims did extract them into a new
session, but redeemRefreshToken only copied Email, User, Groups and
PreferredUsername back to the existing session, discarding the
AdditionalClaims.
This affects OIDC and MS Entra ID providers. Any header
injection relying on additional claims goes stale until the user
re-authenticates.
Signed-off-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
Co-authored-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
* Strip the port from the request host when matching cookie domains
GetCookieDomain suffix-matches the request host against each configured
cookie domain. When a reverse proxy rewrites the Host header to the
upstream's address, that host arrives as "host:port" and never matches,
so the request falls through to the "did not match any of the specific
cookie domains" warning and the shortest configured domain is used.
One way to hit this is Traefik's Errors middleware: it fetches a page
from a Service on port 443 with passHostHeader disabled, and forwards
the Host as "<host>:443". The request reaches oauth2-proxy correctly and
the resulting cookie is still usable, but every such request logs an
error that suggests a misconfiguration when none exists.
warnInvalidDomain, a few lines below in the same file, already calls
net.SplitHostPort on the host before comparing it to the cookie domain.
This makes GetCookieDomain consistent with it.
Tests cover a Host header with a port, an X-Forwarded-Host header with a
port, a non-standard port, and a host with a port that matches no
configured domain.
Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
* chore: add changelog entry for #3546
Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
* test: keep the new port entries at the end of the table
The port cases were inserted between the Host and X-Forwarded-Host
variants of the existing suffix-match case, which split a pair that
reads as one. Move them after the last existing entry instead.
Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
* test: pin that a port part can no longer match a cookie domain
SplitHostPort does not require the port to be numeric, so a host such as
"evil.com:.cookies.test" used to suffix-match a configured cookie domain
through its port part, and the cookie was then set for that domain. Matching
now runs against the host alone, so it does not.
Covers both the Host header and X-Forwarded-Host, since GetRequestHost
returns one or the other into the same comparison.
A Host of this shape cannot be expressed through the request URL, because
http.NewRequest rejects it as an invalid port, so the table gains a rawHost
field that assigns req.Host after the request is built. That is how a server
populates it from the wire, and pkg/upstream and pkg/middleware already set
req.Host the same way in their tests.
Thanks to @Lrifton92 for spotting this.
Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
---------
Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
Drop use of k8s.io/apimachinery/pkg/util/errors.NewAggregate and replace
to with errors.Join which is available in stdlib since Go 1.20.
This allows to drop one dependency (which itself brings its own
contraints in its go.mod) and use more standard behavior from stdlib.
Co-authored-by: Olivier Mengué <dolmen@cpan.org>
* update to release version v7.15.4
* docs: add changelog for v7.15.4
Signed-off-by: Jan Larwig <jan@larwig.com>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
* update to release version v7.15.3
* docs: changelog for v7.15.3
Signed-off-by: Jan Larwig <jan@larwig.com>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
* update to release version v7.15.2
* doc: add changelog entry for v7.15.2
Signed-off-by: Jan Larwig <jan@larwig.com>
* fix(deps): override webpackbar to v7 for webpack 5.106.0 compatibility
As outlined in https://github.com/facebook/docusaurus/issues/11923
Signed-off-by: Jan Larwig <jan@larwig.com>
* chore: fix local test files for nginx setup
Signed-off-by: Jan Larwig <jan@larwig.com>
---------
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>