Commit Graph
2386 Commits
Author SHA1 Message Date
renovate[bot] f4abcac865 chore(deps): update github/codeql-action action to v4.38.2 2026-10-01 09:02:54 +00:00
bea3f04bf8 release: v7.15.5 (#3553)
* update to release version v7.15.5

* Merge commit from fork

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>

* Merge commit from fork

Signed-off-by: Jan Larwig <jan@larwig.com>

* Merge commit from fork

* fix: validate trusted IP proxy headers

Respect trusted proxy boundaries before using real-client-IP headers for authentication bypass decisions and safely traverse X-Forwarded-For chains.

Signed-off-by: Jan Larwig <jan@larwig.com>

* fix: trusted-ip header bypass

Signed-off-by: Jan Larwig <jan@larwig.com>

* docs: add changelog entry

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* docs: changelog for v7.15.5

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* docs: update order of owners for prow

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* ci: make the linter happy again

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
Co-authored-by: blakeroberts-wk <blake.roberts@workiva.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
v7.15.5
2026-10-01 11:01:25 +02:00
Madan Kumar e05f04ef08 fix(encryption): return an error instead of panicking on a short GCM ciphertext (#3527)
* fix(encryption): return an error instead of panicking on a short GCM ciphertext

gcmCipher.Decrypt slices ciphertext[:nonceSize] without first checking the
length, so a ciphertext shorter than the 12-byte GCM nonce triggers a
slice-bounds-out-of-range panic instead of returning an error. The sibling
cfbCipher.Decrypt already guards its IV length and returns a descriptive error;
mirror that guard for GCM so decrypting a malformed (e.g. truncated) cookie
fails cleanly. Adds a test covering both ciphers.

Signed-off-by: Madan Kumar <winklemad@outlook.com>

* docs(changelog): add entry for the GCM short-ciphertext fix

Signed-off-by: Madan Kumar <winklemad@outlook.com>

---------

Signed-off-by: Madan Kumar <winklemad@outlook.com>
2026-10-01 09:18:17 +02:00
shauryaandIshan Shaurya Jaiswal 4b94ed869b fix: surface Microsoft Graph errors during Entra group overage instead of logging in with an incomplete group set (#3535)
* Propagate Microsoft Graph errors during Entra group overage

When a session hit AAD group overage, addGraphGroupsToSession logged a
failed Graph request and returned nil, so EnrichSession's error handling
never ran and the session kept the overage placeholder instead of the
real groups. Return the error like the rest of the file does, and add a
regression test using the existing 401 Graph mock.

Signed-off-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>

* Tighten the Graph-error test and wrap the error, add a changelog entry

Wrap the Graph error with %w so callers can errors.Is through
EnrichSession. Pin the test to the Graph path with ErrorContains and
assert the session's groups are left untouched after the failed call, so
the test fails if the fix regresses rather than on any error. Add the
behaviour change to the changelog since a Graph outage during overage now
fails the login instead of proceeding with the overage placeholder.

Signed-off-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>

---------

Signed-off-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>
Co-authored-by: Ishan Shaurya Jaiswal <19599684+no-hup@users.noreply.github.com>
2026-10-01 09:07:31 +02:00
bde7f9eee1 fix(bitbucket): auth failure due to Bitbucket API changes (#3477)
* fix: #3428 bybitbucket auth failure by changing token n validation flow to use Authentication header instead of query param

Co-authored-by: aviralgarg05 <gargaviral99@gmail.com>
Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

* fix: added changelog entry and added tests to verify bitbucket auth header fix

Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>

* fix(bitbucket): aded support for limiting login for workspace members and handled deprecated team api and added test cases

Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>

* docs(bitbucket): applied missing docs changes

Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>

---------

Signed-off-by: Mohammad Hassan <m8fouad@gmail.com>
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
Co-authored-by: aviralgarg05 <gargaviral99@gmail.com>
Co-authored-by: Jan Larwig <jan.larwig@digits.schwarz>
2026-10-01 09:00:53 +02:00
Apollo3zehnandApollo3zehn b0d87093a8 fix: propagate AdditionalClaims on session refresh (#3547)
AdditionalClaims were only extracted during the initial login. On
cookie refresh, buildSessionFromClaims did extract them into a new
session, but redeemRefreshToken only copied Email, User, Groups and
PreferredUsername back to the existing session, discarding the
AdditionalClaims.

This affects OIDC and MS Entra ID providers. Any header
injection relying on additional claims goes stale until the user
re-authenticates.

Signed-off-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
Co-authored-by: Apollo3zehn <Apollo3zehn@users.noreply.github.com>
2026-09-30 17:40:17 +02:00
kirilju 8f8d1f4eb3 fix: strip the port from the request host when matching cookie domains (#3546)
* Strip the port from the request host when matching cookie domains

GetCookieDomain suffix-matches the request host against each configured
cookie domain. When a reverse proxy rewrites the Host header to the
upstream's address, that host arrives as "host:port" and never matches,
so the request falls through to the "did not match any of the specific
cookie domains" warning and the shortest configured domain is used.

One way to hit this is Traefik's Errors middleware: it fetches a page
from a Service on port 443 with passHostHeader disabled, and forwards
the Host as "<host>:443". The request reaches oauth2-proxy correctly and
the resulting cookie is still usable, but every such request logs an
error that suggests a misconfiguration when none exists.

warnInvalidDomain, a few lines below in the same file, already calls
net.SplitHostPort on the host before comparing it to the cookie domain.
This makes GetCookieDomain consistent with it.

Tests cover a Host header with a port, an X-Forwarded-Host header with a
port, a non-standard port, and a host with a port that matches no
configured domain.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* chore: add changelog entry for #3546

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: keep the new port entries at the end of the table

The port cases were inserted between the Host and X-Forwarded-Host
variants of the existing suffix-match case, which split a pair that
reads as one. Move them after the last existing entry instead.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

* test: pin that a port part can no longer match a cookie domain

SplitHostPort does not require the port to be numeric, so a host such as
"evil.com:.cookies.test" used to suffix-match a configured cookie domain
through its port part, and the cookie was then set for that domain. Matching
now runs against the host alone, so it does not.

Covers both the Host header and X-Forwarded-Host, since GetRequestHost
returns one or the other into the same comparison.

A Host of this shape cannot be expressed through the request URL, because
http.NewRequest rejects it as an invalid port, so the table gains a rawHost
field that assigns req.Host after the request is built. That is how a server
populates it from the wire, and pkg/upstream and pkg/middleware already set
req.Host the same way in their tests.

Thanks to @Lrifton92 for spotting this.

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>

---------

Signed-off-by: Kiril Jurbinsky <kiril@instaffo.com>
2026-09-30 17:31:29 +02:00
Jan LarwigandOlivier Mengué 61db1188cf chore(deps): replace k8s.io/apimachinery/pkg/util/errors with errors.Join (#3552)
Drop use of k8s.io/apimachinery/pkg/util/errors.NewAggregate and replace
to with errors.Join which is available in stdlib since Go 1.20.

This allows to drop one dependency (which itself brings its own
contraints in its go.mod) and use more standard behavior from stdlib.

Co-authored-by: Olivier Mengué <dolmen@cpan.org>
2026-09-30 17:26:31 +02:00
renovate[bot] 94b5f340c4 chore(deps): update qltysh/qlty-action action to v2.4.0 (#3550)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-30 17:05:18 +02:00
renovate[bot] a769636b5f chore(deps): update gomod (#3511)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-30 16:56:06 +02:00
Ahmad Srour 86adcc6c9e docs: fix nginx API 401 example (#3549)
Signed-off-by: Ahmad Srour <asrour@live.com>
2026-09-30 16:55:20 +02:00
Jan Larwig 55824eb0e3 ci: use upstream cncf/prow-github-actions; fix needs-kind label issue; consolidate prow workflow files
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-09-28 17:18:26 +02:00
Jan Larwig 4238ee1b32 ci: introducing cncf/prow-github-actions (#3536)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-09-24 08:18:51 +02:00
Jan Larwig 6420aae790 docs: update and consolidate security disclosure process notice (#3537)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-09-13 15:22:39 +02:00
Jan Larwig 33c2eb92de docs: remove support issues and redirect to slack instead
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
2026-09-03 15:51:12 +02:00
Jan Larwig 0a83bffdb0 docs: remove support issues and redirect to slack instead
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
2026-09-03 15:47:51 +02:00
Jan Larwig c5529b42b7 docs: ai policy
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-24 11:39:04 +02:00
github-actions[bot]andJan Larwig 81ff034fe2 release v7.15.4 (#3508)
* update to release version v7.15.4

* docs: add changelog for v7.15.4

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
v7.15.4
2026-08-20 08:06:19 +02:00
Lee Seonghyeon · 이성현andihopenre-eng 61caa9ed01 docs: clarify the default nginx split-cookie example (#3474)
Signed-off-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
Co-authored-by: ihopenre-eng <247072151+ihopenre-eng@users.noreply.github.com>
2026-08-20 07:37:44 +02:00
nightcityblade 061685fed3 docs: clarify structured claim header serialization (#3501)
Signed-off-by: nightcityblade <jackchen@haloailabs.com>
2026-08-20 07:33:54 +02:00
nightcitybladeandnightcityblade d122f0c28e docs: clarify alpha upstream path syntax (#3504)
Signed-off-by: nightcityblade <nightcityblade@gmail.com>
Co-authored-by: nightcityblade <nightcityblade@gmail.com>
2026-08-20 07:32:33 +02:00
Jan Larwig f7ae0ae81e test: update traefik setup and use in-memory for all dex instances instead of etcd
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 10:38:26 +02:00
renovate[bot] ff9b942a84 chore(deps): update docker-compose 2026-08-18 10:38:26 +02:00
renovate[bot] aa9690aa46 chore(deps): update helm release dex to v0.24.1 (#3446)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-18 09:33:57 +02:00
renovate[bot] 5aeb458a7f chore(deps): update docker-compose (#3460)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-18 09:33:47 +02:00
renovate[bot] aad15f3f89 chore(deps): update alpine docker tag to v3.24.1 (#3421)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-18 09:33:31 +02:00
Jan Larwig c4043233cf ci: hardening by replacing all tags using immutable commit hashes (#3507)
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:31:56 +02:00
Jan Larwig d707a36a4c test: fix expected error message wording
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
Jan Larwig 304077498d ci: use go tool for running golangci-lint
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
renovate[bot] 09aa14acf4 chore(deps): update gomod
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-08-18 09:23:29 +02:00
Josh SorefandJan Larwig 1f049e5ebd docs: update inviter link (#3500)
* Update inviter link

---------

Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
2026-08-12 19:13:44 +02:00
renovate[bot] 14af2951e5 chore(deps): update actions/checkout action to v7 (#3462)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-30 21:28:21 +02:00
renovate[bot] d2a4782f6a chore(deps): update gomod (#3461)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-07-30 21:24:21 +02:00
Joel Speed 10b68716e5 Merge pull request #3425 from oauth2-proxy/renovate/actions-upload-pages-artifact-5.x
chore(deps): update actions/upload-pages-artifact action to v5
2026-06-14 17:15:04 +01:00
renovate[bot] 3d011d978d chore(deps): update actions/upload-pages-artifact action to v5 2026-06-14 16:10:13 +00:00
Joel Speed 127f087464 Merge pull request #3407 from oauth2-proxy/renovate/docker-compose
chore(deps): update docker-compose
2026-06-14 17:08:33 +01:00
renovate[bot] 077cd9f9cc chore(deps): update docker-compose 2026-06-14 15:42:56 +00:00
Joel Speed 807931cda5 Merge pull request #3424 from oauth2-proxy/renovate/gomod
chore(deps): update gomod
2026-06-14 16:42:14 +01:00
renovate[bot] 2479410598 chore(deps): update gomod 2026-06-13 19:57:08 +00:00
Jan Larwig 09979d458a docs: update slack reference for CNCF
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-09 13:50:16 +02:00
github-actions[bot]andJan Larwig 66b3a17db0 release v7.15.3 (#3450)
* update to release version v7.15.3

* docs: changelog for v7.15.3

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
v7.15.3
2026-06-09 13:28:24 +02:00
Jan Larwig 61151b4869 Merge pull request #3447 from oauth2-proxy/chore/bump-go-to-1.26-and-migrate-of-reverse-proxy-handling
chore(dep): bump go to 1.26 and migrate of reverse proxy handling
2026-06-09 12:20:57 +02:00
Jan Larwig 0de18825f6 chore(deps): bump Go to 1.26 and migrate upstream reverse proxies to Rewrite
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-08 14:12:56 +02:00
Jan Larwig 9a14186a26 chore(goconsts): use proper constants for http methods
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-06-08 12:54:58 +02:00
Jan Larwig 65037b086c change affiliation 2026-04-17 10:56:42 +02:00
github-actions[bot]andJan Larwig 5961fd99b4 release v7.15.2 (#3413)
* update to release version v7.15.2

* doc: add changelog entry for v7.15.2

Signed-off-by: Jan Larwig <jan@larwig.com>

* fix(deps): override webpackbar to v7 for webpack 5.106.0 compatibility

As outlined in https://github.com/facebook/docusaurus/issues/11923

Signed-off-by: Jan Larwig <jan@larwig.com>

* chore: fix local test files for nginx setup

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
v7.15.2
2026-04-14 13:12:28 +02:00
Jan Larwig bdfde725c6 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:29:01 +02:00
Jan Larwig cc0e0335ea Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:24:51 +02:00
Jan Larwig aff369dfa3 Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:22:56 +02:00
Jan Larwig 43596a7bab Merge commit from fork
Signed-off-by: Jan Larwig <jan@larwig.com>
2026-04-13 18:20:36 +02:00