security: remove blind TypeAccessPolicy bypass from access checkers
Removed the code that bypassed authorization for TypeAccessPolicy identities. All identities now go through proper permission verification via the inner access checker, which will validate permissions from ServiceIdentityClaims. This addresses the security concern where TypeAccessPolicy was being trusted blindly without verifying whether the identity came from the wire or in-process.
This commit is contained in:
@@ -45,11 +45,6 @@ func (c *sessionAccessChecker) Check(ctx context.Context, req authlib.CheckReque
|
||||
return apierrors.NewUnauthorized(fmt.Sprintf("failed to get requester: %v", err))
|
||||
}
|
||||
|
||||
// AccessPolicy identities are trusted internal callers
|
||||
if authlib.IsIdentityType(requester.GetIdentityType(), authlib.TypeAccessPolicy) {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Fill in namespace from identity if not provided
|
||||
if req.Namespace == "" {
|
||||
req.Namespace = requester.GetNamespace()
|
||||
|
||||
@@ -108,12 +108,6 @@ func TestSessionAccessChecker_Check(t *testing.T) {
|
||||
requester: &mockRequester{orgRole: identity.RoleAdmin, identityType: authlib.TypeUser},
|
||||
expectAllow: false,
|
||||
},
|
||||
{
|
||||
name: "AccessPolicy identity is always allowed",
|
||||
innerResponse: authlib.CheckResponse{Allowed: false},
|
||||
requester: &mockRequester{orgRole: identity.RoleViewer, identityType: authlib.TypeAccessPolicy},
|
||||
expectAllow: true,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
|
||||
@@ -36,11 +36,6 @@ func (c *tokenAccessChecker) Check(ctx context.Context, req authlib.CheckRequest
|
||||
return apierrors.NewUnauthorized("no auth info in context")
|
||||
}
|
||||
|
||||
// AccessPolicy identities are trusted internal callers
|
||||
if authlib.IsIdentityType(id.GetIdentityType(), authlib.TypeAccessPolicy) {
|
||||
return nil
|
||||
}
|
||||
|
||||
// Fill in namespace from identity if not provided
|
||||
if req.Namespace == "" {
|
||||
req.Namespace = id.GetNamespace()
|
||||
|
||||
@@ -47,12 +47,6 @@ func TestTokenAccessChecker_Check(t *testing.T) {
|
||||
authInfo: &identity.StaticRequester{Type: authlib.TypeUser},
|
||||
expectAllow: false,
|
||||
},
|
||||
{
|
||||
name: "AccessPolicy identity is always allowed",
|
||||
innerResponse: authlib.CheckResponse{Allowed: false},
|
||||
authInfo: &identity.StaticRequester{Type: authlib.TypeAccessPolicy},
|
||||
expectAllow: true,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
|
||||
Reference in New Issue
Block a user