From b2d861f01d004efa7a6f16ba1464bf467d35e61a Mon Sep 17 00:00:00 2001 From: Roberto Jimenez Sanchez Date: Wed, 17 Dec 2025 20:55:07 +0100 Subject: [PATCH] security: remove blind TypeAccessPolicy bypass from access checkers Removed the code that bypassed authorization for TypeAccessPolicy identities. All identities now go through proper permission verification via the inner access checker, which will validate permissions from ServiceIdentityClaims. This addresses the security concern where TypeAccessPolicy was being trusted blindly without verifying whether the identity came from the wire or in-process. --- apps/provisioning/pkg/auth/session_access_checker.go | 5 ----- apps/provisioning/pkg/auth/session_access_checker_test.go | 6 ------ apps/provisioning/pkg/auth/token_access_checker.go | 5 ----- apps/provisioning/pkg/auth/token_access_checker_test.go | 6 ------ 4 files changed, 22 deletions(-) diff --git a/apps/provisioning/pkg/auth/session_access_checker.go b/apps/provisioning/pkg/auth/session_access_checker.go index 27ea420959e..00348ef8e59 100644 --- a/apps/provisioning/pkg/auth/session_access_checker.go +++ b/apps/provisioning/pkg/auth/session_access_checker.go @@ -45,11 +45,6 @@ func (c *sessionAccessChecker) Check(ctx context.Context, req authlib.CheckReque return apierrors.NewUnauthorized(fmt.Sprintf("failed to get requester: %v", err)) } - // AccessPolicy identities are trusted internal callers - if authlib.IsIdentityType(requester.GetIdentityType(), authlib.TypeAccessPolicy) { - return nil - } - // Fill in namespace from identity if not provided if req.Namespace == "" { req.Namespace = requester.GetNamespace() diff --git a/apps/provisioning/pkg/auth/session_access_checker_test.go b/apps/provisioning/pkg/auth/session_access_checker_test.go index 2375fcf7b5d..1e99a6e46db 100644 --- a/apps/provisioning/pkg/auth/session_access_checker_test.go +++ b/apps/provisioning/pkg/auth/session_access_checker_test.go @@ -108,12 +108,6 @@ func TestSessionAccessChecker_Check(t *testing.T) { requester: &mockRequester{orgRole: identity.RoleAdmin, identityType: authlib.TypeUser}, expectAllow: false, }, - { - name: "AccessPolicy identity is always allowed", - innerResponse: authlib.CheckResponse{Allowed: false}, - requester: &mockRequester{orgRole: identity.RoleViewer, identityType: authlib.TypeAccessPolicy}, - expectAllow: true, - }, } for _, tt := range tests { diff --git a/apps/provisioning/pkg/auth/token_access_checker.go b/apps/provisioning/pkg/auth/token_access_checker.go index 8339074468a..d2c6f9e1c5b 100644 --- a/apps/provisioning/pkg/auth/token_access_checker.go +++ b/apps/provisioning/pkg/auth/token_access_checker.go @@ -36,11 +36,6 @@ func (c *tokenAccessChecker) Check(ctx context.Context, req authlib.CheckRequest return apierrors.NewUnauthorized("no auth info in context") } - // AccessPolicy identities are trusted internal callers - if authlib.IsIdentityType(id.GetIdentityType(), authlib.TypeAccessPolicy) { - return nil - } - // Fill in namespace from identity if not provided if req.Namespace == "" { req.Namespace = id.GetNamespace() diff --git a/apps/provisioning/pkg/auth/token_access_checker_test.go b/apps/provisioning/pkg/auth/token_access_checker_test.go index aa6184b3a0a..bce0d3a77a0 100644 --- a/apps/provisioning/pkg/auth/token_access_checker_test.go +++ b/apps/provisioning/pkg/auth/token_access_checker_test.go @@ -47,12 +47,6 @@ func TestTokenAccessChecker_Check(t *testing.T) { authInfo: &identity.StaticRequester{Type: authlib.TypeUser}, expectAllow: false, }, - { - name: "AccessPolicy identity is always allowed", - innerResponse: authlib.CheckResponse{Allowed: false}, - authInfo: &identity.StaticRequester{Type: authlib.TypeAccessPolicy}, - expectAllow: true, - }, } for _, tt := range tests {