Skip to content

Fixes #29113: Security improvements for OIDC config#974

Open
clarktsiory wants to merge 1 commit into
Normation:branches/rudder/9.0from
clarktsiory:bug_29113/_
Open

Fixes #29113: Security improvements for OIDC config#974
clarktsiory wants to merge 1 commit into
Normation:branches/rudder/9.0from
clarktsiory:bug_29113/_

Conversation

@clarktsiory

@clarktsiory clarktsiory commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

https://issues.rudder.io/issues/29113

  • follow the documented "restrict mapping as true" by default as in the doc
  • add tests against cached API opaque token cache to take API account status into consideration

Upmerge will be complicated 😅 (ApiAccount model has changed in 9.1, and we need a special PR in 9.2)

@clarktsiory clarktsiory requested a review from fanf June 25, 2026 15:17

@fanf fanf left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM ! Good luck with the upmerge

@Normation-Quality-Assistant

Copy link
Copy Markdown
Contributor

This PR is not mergeable to upper versions.
Since it is "Ready for merge" you must merge it by yourself using the following command:
rudder-dev merge https://github.com/Normation/rudder-plugins/pull/974
If necessary please resolve conflicts. Then check the state of higher version branches and run rudder-dev merge all if needed.
-- Your faithful QA
Kant merge: "Two things awe me most, the starry sky above me and the moral law within me."
(https://ci.normation.com/jenkins/job/merge-accepted-pr/120069/console)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants