From 3069d764f8c50b220dabea9926b792589fe9b95d Mon Sep 17 00:00:00 2001 From: "Grot (@grafanabot)" <43478413+grafanabot@users.noreply.github.com> Date: Thu, 29 Oct 2020 19:58:20 +0530 Subject: [PATCH] Plugins: Fix descendent frontend plugin signature validation (#28638) (#28662) * move plugin root check to earlier in validation process * remove comment * only check root if necessary (cherry picked from commit b9d71f5cddd88a150c3655e5f578e30001617feb) Co-authored-by: Will Browne --- pkg/plugins/plugins.go | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkg/plugins/plugins.go b/pkg/plugins/plugins.go index b83cac210e9..444af0bd8d5 100644 --- a/pkg/plugins/plugins.go +++ b/pkg/plugins/plugins.go @@ -374,12 +374,6 @@ func (scanner *PluginScanner) IsBackendOnlyPlugin(pluginType string) bool { // validateSignature validates a plugin's signature. func (s *PluginScanner) validateSignature(plugin *PluginBase) *PluginError { - // For the time being, we choose to only require back-end plugins to be signed - // NOTE: the state is calculated again when setting metadata on the object - if !plugin.Backend || !s.requireSigned { - return nil - } - if plugin.Signature == PluginSignatureValid { s.log.Debug("Plugin has valid signature", "id", plugin.Id) return nil @@ -404,6 +398,12 @@ func (s *PluginScanner) validateSignature(plugin *PluginBase) *PluginError { "state", plugin.Signature) } + // For the time being, we choose to only require back-end plugins to be signed + // NOTE: the state is calculated again when setting metadata on the object + if !plugin.Backend || !s.requireSigned { + return nil + } + switch plugin.Signature { case PluginSignatureUnsigned: allowUnsigned := false