diff --git a/pkg/plugins/plugins.go b/pkg/plugins/plugins.go index b83cac210e9..444af0bd8d5 100644 --- a/pkg/plugins/plugins.go +++ b/pkg/plugins/plugins.go @@ -374,12 +374,6 @@ func (scanner *PluginScanner) IsBackendOnlyPlugin(pluginType string) bool { // validateSignature validates a plugin's signature. func (s *PluginScanner) validateSignature(plugin *PluginBase) *PluginError { - // For the time being, we choose to only require back-end plugins to be signed - // NOTE: the state is calculated again when setting metadata on the object - if !plugin.Backend || !s.requireSigned { - return nil - } - if plugin.Signature == PluginSignatureValid { s.log.Debug("Plugin has valid signature", "id", plugin.Id) return nil @@ -404,6 +398,12 @@ func (s *PluginScanner) validateSignature(plugin *PluginBase) *PluginError { "state", plugin.Signature) } + // For the time being, we choose to only require back-end plugins to be signed + // NOTE: the state is calculated again when setting metadata on the object + if !plugin.Backend || !s.requireSigned { + return nil + } + switch plugin.Signature { case PluginSignatureUnsigned: allowUnsigned := false