Repository navigation
Commit 65de3d2
committed
fix(arm): compare GCP WIF reuse account/issuer for exact equality
The provider-reuse check on setup-gcp-wif.sh ran a single describe with
--format='value(aws.accountId,oidc.issuerUri)' and tested the tab-joined
result with a suffix glob (OIDC) or prefix glob (AWS). Both are substring
tests standing in for equality: an existing OIDC provider whose issuer
merely ENDS with the expected one (e.g. an attacker-hosted
https://evil.example.com/<expected-issuer>, an ordinary HTTPS URL GCP
would fetch /.well-known/openid-configuration from) passed the check, as
did an AWS account ID merely STARTING with the expected one. That made
the attribute-condition and attribute-mapping checks below it vacuous,
since they only bind the identity this check was supposed to have
already pinned.
Split into two separate describe calls, one per field, each compared
with exact !=. Pre-existing in the reuse path added by #1651, not
introduced by this PR. This is the fifth substring-standing-in-for-
equality defect found in this codebase.1 parent 2602935 commit 65de3d2
1 file changed
Lines changed: 24 additions & 10 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
260 | 260 | | |
261 | 261 | | |
262 | 262 | | |
263 | | - | |
264 | | - | |
265 | | - | |
266 | | - | |
267 | | - | |
268 | | - | |
269 | | - | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
270 | 278 | | |
271 | | - | |
272 | | - | |
273 | | - | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
274 | 287 | | |
| 288 | + | |
275 | 289 | | |
276 | 290 | | |
277 | 291 | | |
| |||
0 commit comments