Repository navigation
fix(auth): never sign anyone in through OIDC without an allowlist - #15049
Merged
diegosouzapw merged 1 commit intoOct 6, 2026
Merged
diegosouzapw merged 1 commit into
diegosouzapw merged 1 commit into
Conversation
The OIDC callback treated an empty oidcAllowedSubjects as "let every account of the identity provider in", and it minted the dashboard admin session for whoever that was. The settings route was meant to prevent the empty state, but it only ran when the request body itself set oidcEnabled to true. With OIDC already on, a later update that sent oidcAllowedSubjects: [] (a key that needs no password confirmation) passed, and so did any state that did not come through that route. Check the state the update would produce instead: reject it when OIDC would be enabled and the allowlist would hold no non-blank entry, whether the request changes the switch, the list or both. The callback now also counts an allowlist without a usable entry as not configured, before it contacts the provider, so an instance already in that state stops admitting everybody. Password login is unaffected. Signed-off-by: Minxi Hou <houminxi@gmail.com>
diegosouzapw
changed the base branch from
release/v3.8.51
to
release/v3.8.52
September 29, 2026 11:17
Owner
|
Re-homed to |
diegosouzapw
merged commit Oct 6, 2026
3efc28e
into
diegosouzapw:release/v3.8.52
8 of 16 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The OIDC callback treated an empty oidcAllowedSubjects as "let every
account of the identity provider in", and it minted the dashboard admin
session for whoever that was. The settings route was meant to prevent the
empty state, but it only ran when the request body itself set
oidcEnabled to true. With OIDC already on, a later update that sent
oidcAllowedSubjects: [] (a key that needs no password confirmation)
passed, and so did any state that did not come through that route.
Check the state the update would produce instead: reject it when OIDC
would be enabled and the allowlist would hold no non-blank entry, whether
the request changes the switch, the list or both. The callback now also
counts an allowlist without a usable entry as not configured, before it
contacts the provider, so an instance already in that state stops
admitting everybody. Password login is unaffected.
Related Issues
Validation
tests/unit/oidc-callback.test.ts,tests/unit/oidc-settings-allowlist-guard.test.tsnpm run lintTests Added Or Updated
tests/unit/oidc-callback.test.tstests/unit/oidc-settings-allowlist-guard.test.tsCoverage Notes
Reviewer Notes