Sitelet https://github.com/Altinity/altinity-oauth-helper/issues/68
Skip to content

security: bound verification-cache memory for oversized username aliases #68

Description

@BorisTyshkevich

Security finding

The verification cache caps entry count but not retained bytes. Identity matching accepts whitespace-padded aliases while the cache and successful-Bind logging retain the raw requested username.

Evidence

  • identity.Policy.matches trims Unicode whitespace for lowercase_equal.
  • Successful identity binding retains the raw requested username.
  • The cache key includes that raw username and the token.
  • cacheMaxEntries is 10,000 entries without a byte budget.

Reproduction

One 565-byte valid JWT was accepted under 512 distinct whitespace-padded aliases and retained 16,654,336 bytes of usernames alone in the positive cache. A real TCP LDAP Bind accepted a 60,017-byte username alias in a 60,661-byte request using a 590-byte JWT.

At roughly 60 KB per retained username, 10,000 entries could retain about 600 MB of usernames alone, above the chart's default 128 MiB memory limit. This is an extrapolation; the review did not intentionally OOM a process.

Impact

An authenticated caller can cause disproportionate cache and logging memory/volume pressure using one valid token. Expired entries are not eagerly deleted and the command's reaper interval is five minutes.

Proposed direction

  1. Bound accepted usernames before verification.
  2. Bound cache and retained-claim bytes, not only entry count.
  3. Canonicalize identity only if that preserves the cache's identity-binding security invariant.
  4. Bound logged successful usernames.
  5. Eagerly remove expired entries when observed.

Validation

Add regressions for Unicode-whitespace aliases, cache byte accounting, bounded successful-Bind logs, and cache-key isolation in both directions.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggoPull requests that update go code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions