Skip to content

Conversation

@matheuscscp
Copy link
Member

@matheuscscp matheuscscp commented Jan 20, 2026

Sanitize and validate the user and groups used for Kubernetes RBAC impersonation after evaluating the CEL expressions for extracting the info from OIDC claims.

Also make this validation consistent with Anonymous authentication.

@matheuscscp matheuscscp added bug Something isn't working area/cves CVE fixes related issues and pull requests area/security Security related issues and pull requests area/web-ui Flux Status Page related issues and pull requests labels Jan 20, 2026
Copy link
Member

@stefanprodan stefanprodan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@matheuscscp matheuscscp merged commit 0845404 into main Jan 20, 2026
9 of 10 checks passed
@matheuscscp matheuscscp deleted the auth-validation branch January 20, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/cves CVE fixes related issues and pull requests area/security Security related issues and pull requests area/web-ui Flux Status Page related issues and pull requests bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants