Low-severity security hardening findings
1. Reserved-name matching uses a different Unicode equivalence rule
Identity matching uses strings.EqualFold, while denied_usernames uses strings.ToLower(strings.TrimSpace(...)). These are not equivalent Unicode relations.
Reproduction
With username_claim: sub and denied_usernames: [system], a signed token with sub=system is rejected when requested as system, but accepted as ſystem (U+017F long s).
Impact
The configured reserved-name policy is inconsistent for affected custom names. The review did not demonstrate a bypass of the chart's default reserved names or a ClickHouse local-account takeover.
Direction
Use one explicit identity-equivalence rule for matching and reservation, and test the resolved identity as well as the requested username where appropriate.
2. Production YAML accepts unknown security-policy fields
LoadConfig uses yaml.Unmarshal without KnownFields(true).
Reproduction
An otherwise valid configuration containing:
identity:
allowed_email_domain:
- example.com
starts successfully while allowed_email_domains remains empty.
Impact
An operator typo can silently disable an intended domain, role-filter, or deny-list policy. This requires configuration control and is not an independent remote bypass of correctly configured deployment.
Direction
Use strict production YAML decoding, reject trailing YAML documents, and report unknown fields before binding the listener.
Validation
Add regressions for the Unicode case and misspelled YAML fields, including the full production LoadConfig path.
Low-severity security hardening findings
1. Reserved-name matching uses a different Unicode equivalence rule
Identity matching uses
strings.EqualFold, whiledenied_usernamesusesstrings.ToLower(strings.TrimSpace(...)). These are not equivalent Unicode relations.Reproduction
With
username_claim: subanddenied_usernames: [system], a signed token withsub=systemis rejected when requested assystem, but accepted asſystem(U+017F long s).Impact
The configured reserved-name policy is inconsistent for affected custom names. The review did not demonstrate a bypass of the chart's default reserved names or a ClickHouse local-account takeover.
Direction
Use one explicit identity-equivalence rule for matching and reservation, and test the resolved identity as well as the requested username where appropriate.
2. Production YAML accepts unknown security-policy fields
LoadConfigusesyaml.UnmarshalwithoutKnownFields(true).Reproduction
An otherwise valid configuration containing:
starts successfully while
allowed_email_domainsremains empty.Impact
An operator typo can silently disable an intended domain, role-filter, or deny-list policy. This requires configuration control and is not an independent remote bypass of correctly configured deployment.
Direction
Use strict production YAML decoding, reject trailing YAML documents, and report unknown fields before binding the listener.
Validation
Add regressions for the Unicode case and misspelled YAML fields, including the full production
LoadConfigpath.