Sitelet https://github.com/Altinity/altinity-oauth-helper/issues/71
Skip to content

security: make identity reservation and YAML policy parsing fail closed #71

Description

@BorisTyshkevich

Low-severity security hardening findings

1. Reserved-name matching uses a different Unicode equivalence rule

Identity matching uses strings.EqualFold, while denied_usernames uses strings.ToLower(strings.TrimSpace(...)). These are not equivalent Unicode relations.

Reproduction

With username_claim: sub and denied_usernames: [system], a signed token with sub=system is rejected when requested as system, but accepted as ſystem (U+017F long s).

Impact

The configured reserved-name policy is inconsistent for affected custom names. The review did not demonstrate a bypass of the chart's default reserved names or a ClickHouse local-account takeover.

Direction

Use one explicit identity-equivalence rule for matching and reservation, and test the resolved identity as well as the requested username where appropriate.

2. Production YAML accepts unknown security-policy fields

LoadConfig uses yaml.Unmarshal without KnownFields(true).

Reproduction

An otherwise valid configuration containing:

identity:
  allowed_email_domain:
    - example.com

starts successfully while allowed_email_domains remains empty.

Impact

An operator typo can silently disable an intended domain, role-filter, or deny-list policy. This requires configuration control and is not an independent remote bypass of correctly configured deployment.

Direction

Use strict production YAML decoding, reject trailing YAML documents, and report unknown fields before binding the listener.

Validation

Add regressions for the Unicode case and misspelled YAML fields, including the full production LoadConfig path.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggoPull requests that update go code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions