security: remove blind TypeAccessPolicy bypass from access checkers

Removed the code that bypassed authorization for TypeAccessPolicy identities.
All identities now go through proper permission verification via the inner
access checker, which will validate permissions from ServiceIdentityClaims.

This addresses the security concern where TypeAccessPolicy was being trusted
blindly without verifying whether the identity came from the wire or in-process.
This commit is contained in:
Roberto Jimenez Sanchez
2025-12-17 20:55:07 +01:00
parent 10825c242d
commit b2d861f01d
4 changed files with 0 additions and 22 deletions
@@ -45,11 +45,6 @@ func (c *sessionAccessChecker) Check(ctx context.Context, req authlib.CheckReque
return apierrors.NewUnauthorized(fmt.Sprintf("failed to get requester: %v", err))
}
// AccessPolicy identities are trusted internal callers
if authlib.IsIdentityType(requester.GetIdentityType(), authlib.TypeAccessPolicy) {
return nil
}
// Fill in namespace from identity if not provided
if req.Namespace == "" {
req.Namespace = requester.GetNamespace()
@@ -108,12 +108,6 @@ func TestSessionAccessChecker_Check(t *testing.T) {
requester: &mockRequester{orgRole: identity.RoleAdmin, identityType: authlib.TypeUser},
expectAllow: false,
},
{
name: "AccessPolicy identity is always allowed",
innerResponse: authlib.CheckResponse{Allowed: false},
requester: &mockRequester{orgRole: identity.RoleViewer, identityType: authlib.TypeAccessPolicy},
expectAllow: true,
},
}
for _, tt := range tests {
@@ -36,11 +36,6 @@ func (c *tokenAccessChecker) Check(ctx context.Context, req authlib.CheckRequest
return apierrors.NewUnauthorized("no auth info in context")
}
// AccessPolicy identities are trusted internal callers
if authlib.IsIdentityType(id.GetIdentityType(), authlib.TypeAccessPolicy) {
return nil
}
// Fill in namespace from identity if not provided
if req.Namespace == "" {
req.Namespace = id.GetNamespace()
@@ -47,12 +47,6 @@ func TestTokenAccessChecker_Check(t *testing.T) {
authInfo: &identity.StaticRequester{Type: authlib.TypeUser},
expectAllow: false,
},
{
name: "AccessPolicy identity is always allowed",
innerResponse: authlib.CheckResponse{Allowed: false},
authInfo: &identity.StaticRequester{Type: authlib.TypeAccessPolicy},
expectAllow: true,
},
}
for _, tt := range tests {