Skip to content

Dev jiangxiaofeng - #2

Merged
yu199195 merged 9 commits into
devfrom
dev-jiangxiaofeng
Jul 26, 2018
Merged

yu199195 merged 9 commits into
devfrom
dev-jiangxiaofeng

Conversation

@yu199195

Copy link
Copy Markdown
Member

No description provided.

@yu199195
yu199195 merged commit b419bc8 into dev Jul 26, 2018
yu199195 pushed a commit that referenced this pull request Aug 5, 2019
Aias00 added a commit that referenced this pull request Jun 16, 2026
…ermission, revert unrelated LICENSE changes

- Change /appAuth/updateSk to accept UpdateSkDTO as @RequestBody instead
  of @RequestParam, preventing appSecret from appearing in URLs, browser
  history, and server access logs (Copilot review comment #1)
- Change /sandbox/proxyGateway permission from system:authen:list to
  system:authen:modify — a write/signing endpoint should not be guarded
  by a read permission (Copilot review comment #3)
- Revert unrelated LICENSE file changes that were accidentally included
  (Copilot review comment #2 — re2j license issue is pre-existing)

Co-Authored-By: Claude <noreply@anthropic.com>
Aias00 added a commit that referenced this pull request Jul 7, 2026
…ndbox/proxyGateway (#6388)

* goalx: snapshot before shenyu-analysis

* chore(ci): optimize workflow build cache and mvnd parallelism

* chore: update LICENSE with new dependencies and versions

* [fix] Add missing permission annotations to /appAuth/updateSk and /sandbox/proxyGateway

- Add @RequiresPermissions("system:authen:edit") to AppAuthController.updateSk()
  This endpoint was the only one in the controller without a permission check,
  allowing any authenticated user to rotate arbitrary appAuth secrets.
- Change /appAuth/updateSk from GET to POST to prevent appSecret from
  appearing in URLs, browser history, and server access logs.
- Add @RequiresPermissions("system:authen:list") to SandboxController.proxyGateway()
  This endpoint generates server-side signed requests using stored appSecrets.
  Without permission checks, any authenticated user could abuse it to forge
  signed requests after compromising an appKey via the updateSk vulnerability.

These fixes address an authorization bypass where a low-privileged dashboard
user could chain updateSk + proxyGateway to impersonate arbitrary application
identities and send authenticated requests to allowlisted internal services.

Co-Authored-By: Claude <noreply@anthropic.com>

* [fix] Address PR review: use request body for updateSk, fix sandbox permission, revert unrelated LICENSE changes

- Change /appAuth/updateSk to accept UpdateSkDTO as @RequestBody instead
  of @RequestParam, preventing appSecret from appearing in URLs, browser
  history, and server access logs (Copilot review comment #1)
- Change /sandbox/proxyGateway permission from system:authen:list to
  system:authen:modify — a write/signing endpoint should not be guarded
  by a read permission (Copilot review comment #3)
- Revert unrelated LICENSE file changes that were accidentally included
  (Copilot review comment #2 — re2j license issue is pre-existing)

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: xiaoyu <xiaoyu@apache.org>
im47cn added a commit to im47cn/shenyu that referenced this pull request Aug 4, 2026
…ative test cases

Should-fix apache#1: Add Javadoc security warning on IV reuse in CBC mode,
including cross-reference to AesUtils key format divergence (nit apache#3).

Should-fix apache#2: Add CryptorStrategyFactorySpiTest that loads strategies
via CryptorStrategyFactory.newInstance() (exercising META-INF SPI +
ExtensionLoader.getJoin), not just direct instantiation.

Nit apache#4: Add negative tests for wrong byte-length keys (15-byte AES,
18-byte SM4) and non-base64 content.

apache#6531
im47cn added a commit to im47cn/shenyu that referenced this pull request Aug 6, 2026
…ative test cases

Should-fix apache#1: Add Javadoc security warning on IV reuse in CBC mode,
including cross-reference to AesUtils key format divergence (nit apache#3).

Should-fix apache#2: Add CryptorStrategyFactorySpiTest that loads strategies
via CryptorStrategyFactory.newInstance() (exercising META-INF SPI +
ExtensionLoader.getJoin), not just direct instantiation.

Nit apache#4: Add negative tests for wrong byte-length keys (15-byte AES,
18-byte SM4) and non-base64 content.

apache#6531
eye-gu pushed a commit to eye-gu/shenyu that referenced this pull request Sep 30, 2026
…ndbox/proxyGateway (apache#6388)

* goalx: snapshot before shenyu-analysis

* chore(ci): optimize workflow build cache and mvnd parallelism

* chore: update LICENSE with new dependencies and versions

* [fix] Add missing permission annotations to /appAuth/updateSk and /sandbox/proxyGateway

- Add @RequiresPermissions("system:authen:edit") to AppAuthController.updateSk()
  This endpoint was the only one in the controller without a permission check,
  allowing any authenticated user to rotate arbitrary appAuth secrets.
- Change /appAuth/updateSk from GET to POST to prevent appSecret from
  appearing in URLs, browser history, and server access logs.
- Add @RequiresPermissions("system:authen:list") to SandboxController.proxyGateway()
  This endpoint generates server-side signed requests using stored appSecrets.
  Without permission checks, any authenticated user could abuse it to forge
  signed requests after compromising an appKey via the updateSk vulnerability.

These fixes address an authorization bypass where a low-privileged dashboard
user could chain updateSk + proxyGateway to impersonate arbitrary application
identities and send authenticated requests to allowlisted internal services.

Co-Authored-By: Claude <noreply@anthropic.com>

* [fix] Address PR review: use request body for updateSk, fix sandbox permission, revert unrelated LICENSE changes

- Change /appAuth/updateSk to accept UpdateSkDTO as @RequestBody instead
  of @RequestParam, preventing appSecret from appearing in URLs, browser
  history, and server access logs (Copilot review comment #1)
- Change /sandbox/proxyGateway permission from system:authen:list to
  system:authen:modify — a write/signing endpoint should not be guarded
  by a read permission (Copilot review comment apache#3)
- Revert unrelated LICENSE file changes that were accidentally included
  (Copilot review comment apache#2 — re2j license issue is pre-existing)

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: xiaoyu <xiaoyu@apache.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants