smolnar82 opened a new pull request, #1438:
URL: https://github.com/apache/knox/pull/1438

   [KNOX-3498](https://issues.apache.org/jira/browse/KNOX-3498) - Reject 
IP-literal OIDC issuer registration via topology-configurable flag
   
   ## What changes were proposed in this pull request?
   
   Complements the reactive IP-literal JWKS logging (PR #1437) with a 
preventive, fail-fast check at **issuer registration time** so a bare-IP issuer 
never enters the trust store in the first place.
   
   - New topology-level flag `knoxidf.allow.ip.literal.issuer.url` on the 
`KNOXIDF_ADMIN` service, read in `TrustedOidcIssuersResource.init()`. Default 
is `true` (permissive) for backward compatibility.
   - When set to `false`, `registerIssuer` rejects an `issuerUrl` whose host is 
an IP literal (IPv4 or bracketed IPv6) with `400 invalid_request`, audited as 
`FAILURE`. Being per-topology lets a single deployment accept IP issuers for 
some admin topologies while rejecting them for a stricter one.
   - Extracted the IP-literal host detection (previously duplicated in 
`DefaultTokenAuthorityService` and the new resource check) into a shared 
`HttpUtils.isIpLiteralHost(String)` in `gateway-util-common`, backed by Guava 
`InetAddresses.isUriInetAddress`. Both call sites now delegate to it.
   - Enforcement is registration-only by design; the discovery/verification 
path runs off the gateway-wide singleton and stays covered by PR #1437's 
warning.
   
   ## How was this patch tested?
   
   Automated unit tests (all green):
   - `HttpUtilsTest.testIsIpLiteralHost` — IPv4, bracketed IPv6, DNS names, and 
null/host-less/unparseable inputs.
   - `TrustedOidcIssuersResourceTest` (29) — reject-when-disabled, 
allow-by-default, and `init()` param wiring.
   - `DefaultTokenAuthorityServiceTest` (13) — unchanged behavior after the 
refactor.
   
   ## Integration Tests
   
   Added `test_ip_literal_issuer_registration_rejected` to 
`.github/workflows/tests/test_k8s_delegation.py`: the `knoxidf-admin` topology 
now sets `knoxidf.allow.ip.literal.issuer.url=false`, and the test registers a 
bare-IP issuer (`https://203.0.113.5:6443`), asserting `400 invalid_request` 
and that it never lands in the registry. Existing lifecycle/unregistered-issuer 
cases are unaffected (they use the DNS issuer `https://k3s:6443`).
   ```
   tests-1  | ------------------------------------
   tests-1  | Your code has been rated at 10.00/10
   tests-1  | 
   tests-1  | Waiting for knox...
   tests-1  | ============================= test session starts 
==============================
   tests-1  | platform linux -- Python 3.10.20, pytest-9.0.3, pluggy-1.6.0
   tests-1  | rootdir: /tests
   tests-1  | plugins: platformdirs-4.12.2
   tests-1  | collected 125 items
   tests-1  | 
   tests-1  | test_clientid_credentials.py .......                              
       [  5%]
   tests-1  | test_delegation.py .........                                      
       [ 12%]
   tests-1  | test_health.py .....                                              
       [ 16%]
   tests-1  | test_k8s_delegation.py ........                                   
       [ 23%]
   tests-1  | test_k8s_serviceaccount_validation.py ......                      
       [ 28%]
   tests-1  | test_knox_admin_path_traversal.py ...                             
       [ 30%]
   tests-1  | test_knox_auth_service_and_ldap.py ...                            
       [ 32%]
   tests-1  | test_knox_configs.py .                                            
       [ 33%]
   tests-1  | test_knox_ldap_cache.py ...                                       
       [ 36%]
   tests-1  | test_knox_ldap_injection.py .......                               
       [ 41%]
   tests-1  | test_knox_ldap_proxy_search.py .........                          
       [ 48%]
   tests-1  | test_knoxauth_preauth_and_paths.py ......                         
       [ 53%]
   tests-1  | test_knoxauth_token_forwarding.py ...........                     
       [ 62%]
   tests-1  | test_knoxidf.py .......                                           
       [ 68%]
   tests-1  | test_knoxsso_redirect.py .                                        
       [ 68%]
   tests-1  | test_knoxtoken_jwt.py ....................                        
       [ 84%]
   tests-1  | test_remote_auth.py ...                                           
       [ 87%]
   tests-1  | test_remoteauth_extauthz_additional_path.py ....                  
       [ 90%]
   tests-1  | test_token_exchange.py ............                               
       [100%]
   tests-1  | 
   tests-1  | =============================== warnings summary 
===============================
   ...
   tests-1  | ----------------- generated xml file: /tests/test-results.xml 
------------------
   tests-1  | ====================== 125 passed, 117 warnings in 31.02s 
======================
   tests-1 exited with code 0
   Aborting on container exit...
   Container compose-tests-1 Stopping 
   Container compose-tests-1 Stopped Config   w Enable Watch   d Detach
   
   ```


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to