smolnar82 opened a new pull request, #1438: URL: https://github.com/apache/knox/pull/1438
[KNOX-3498](https://issues.apache.org/jira/browse/KNOX-3498) - Reject IP-literal OIDC issuer registration via topology-configurable flag ## What changes were proposed in this pull request? Complements the reactive IP-literal JWKS logging (PR #1437) with a preventive, fail-fast check at **issuer registration time** so a bare-IP issuer never enters the trust store in the first place. - New topology-level flag `knoxidf.allow.ip.literal.issuer.url` on the `KNOXIDF_ADMIN` service, read in `TrustedOidcIssuersResource.init()`. Default is `true` (permissive) for backward compatibility. - When set to `false`, `registerIssuer` rejects an `issuerUrl` whose host is an IP literal (IPv4 or bracketed IPv6) with `400 invalid_request`, audited as `FAILURE`. Being per-topology lets a single deployment accept IP issuers for some admin topologies while rejecting them for a stricter one. - Extracted the IP-literal host detection (previously duplicated in `DefaultTokenAuthorityService` and the new resource check) into a shared `HttpUtils.isIpLiteralHost(String)` in `gateway-util-common`, backed by Guava `InetAddresses.isUriInetAddress`. Both call sites now delegate to it. - Enforcement is registration-only by design; the discovery/verification path runs off the gateway-wide singleton and stays covered by PR #1437's warning. ## How was this patch tested? Automated unit tests (all green): - `HttpUtilsTest.testIsIpLiteralHost` — IPv4, bracketed IPv6, DNS names, and null/host-less/unparseable inputs. - `TrustedOidcIssuersResourceTest` (29) — reject-when-disabled, allow-by-default, and `init()` param wiring. - `DefaultTokenAuthorityServiceTest` (13) — unchanged behavior after the refactor. ## Integration Tests Added `test_ip_literal_issuer_registration_rejected` to `.github/workflows/tests/test_k8s_delegation.py`: the `knoxidf-admin` topology now sets `knoxidf.allow.ip.literal.issuer.url=false`, and the test registers a bare-IP issuer (`https://203.0.113.5:6443`), asserting `400 invalid_request` and that it never lands in the registry. Existing lifecycle/unregistered-issuer cases are unaffected (they use the DNS issuer `https://k3s:6443`). ``` tests-1 | ------------------------------------ tests-1 | Your code has been rated at 10.00/10 tests-1 | tests-1 | Waiting for knox... tests-1 | ============================= test session starts ============================== tests-1 | platform linux -- Python 3.10.20, pytest-9.0.3, pluggy-1.6.0 tests-1 | rootdir: /tests tests-1 | plugins: platformdirs-4.12.2 tests-1 | collected 125 items tests-1 | tests-1 | test_clientid_credentials.py ....... [ 5%] tests-1 | test_delegation.py ......... [ 12%] tests-1 | test_health.py ..... [ 16%] tests-1 | test_k8s_delegation.py ........ [ 23%] tests-1 | test_k8s_serviceaccount_validation.py ...... [ 28%] tests-1 | test_knox_admin_path_traversal.py ... [ 30%] tests-1 | test_knox_auth_service_and_ldap.py ... [ 32%] tests-1 | test_knox_configs.py . [ 33%] tests-1 | test_knox_ldap_cache.py ... [ 36%] tests-1 | test_knox_ldap_injection.py ....... [ 41%] tests-1 | test_knox_ldap_proxy_search.py ......... [ 48%] tests-1 | test_knoxauth_preauth_and_paths.py ...... [ 53%] tests-1 | test_knoxauth_token_forwarding.py ........... [ 62%] tests-1 | test_knoxidf.py ....... [ 68%] tests-1 | test_knoxsso_redirect.py . [ 68%] tests-1 | test_knoxtoken_jwt.py .................... [ 84%] tests-1 | test_remote_auth.py ... [ 87%] tests-1 | test_remoteauth_extauthz_additional_path.py .... [ 90%] tests-1 | test_token_exchange.py ............ [100%] tests-1 | tests-1 | =============================== warnings summary =============================== ... tests-1 | ----------------- generated xml file: /tests/test-results.xml ------------------ tests-1 | ====================== 125 passed, 117 warnings in 31.02s ====================== tests-1 exited with code 0 Aborting on container exit... Container compose-tests-1 Stopping Container compose-tests-1 Stopped Config w Enable Watch d Detach ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
