Skip to content

Commit 65de3d2

Browse files
committed
fix(arm): compare GCP WIF reuse account/issuer for exact equality
The provider-reuse check on setup-gcp-wif.sh ran a single describe with --format='value(aws.accountId,oidc.issuerUri)' and tested the tab-joined result with a suffix glob (OIDC) or prefix glob (AWS). Both are substring tests standing in for equality: an existing OIDC provider whose issuer merely ENDS with the expected one (e.g. an attacker-hosted https://evil.example.com/<expected-issuer>, an ordinary HTTPS URL GCP would fetch /.well-known/openid-configuration from) passed the check, as did an AWS account ID merely STARTING with the expected one. That made the attribute-condition and attribute-mapping checks below it vacuous, since they only bind the identity this check was supposed to have already pinned. Split into two separate describe calls, one per field, each compared with exact !=. Pre-existing in the reuse path added by #1651, not introduced by this PR. This is the fifth substring-standing-in-for- equality defect found in this codebase.
1 parent 2602935 commit 65de3d2

1 file changed

Lines changed: 24 additions & 10 deletions

File tree

‎arm/CUDly-CrossSubscription/setup-gcp-wif.sh‎

Lines changed: 24 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -260,18 +260,32 @@ else
260260
--workload-identity-pool="$POOL_ID" \
261261
--format='value(attributeCondition)')
262262
# A provider of the other type would emit a credential config that does not
263-
# match it and mint an attribute the grant below never names.
264-
EXISTING_TYPE=$(gcloud iam workload-identity-pools providers describe "$PROVIDER_ID" \
265-
--project="$PROJECT" --location=global \
266-
--workload-identity-pool="$POOL_ID" \
267-
--format='value(aws.accountId,oidc.issuerUri)')
268-
if [[ "$PROVIDER_TYPE" == "aws" && "$EXISTING_TYPE" != "${AWS_ACCOUNT_ID}"* ]]; then
269-
die "provider '${PROVIDER_ID}' already exists but is not an AWS provider for account ${AWS_ACCOUNT_ID} (describe reports: ${EXISTING_TYPE}). Delete it and re-run:
263+
# match it and mint an attribute the grant below never names. Compared as an
264+
# exact match on the single relevant field, not a prefix/suffix test against
265+
# the account-id/issuer-uri pair gcloud tab-joins under `value(a,b)`: a
266+
# suffix test here would accept any issuer URI merely ENDING in the expected
267+
# one (e.g. an attacker-hosted https://evil.example.com/<expected-issuer>,
268+
# whose /.well-known/openid-configuration GCP would then fetch from the
269+
# attacker, who can mint a token with any subject), and a prefix test would
270+
# accept any account ID merely STARTING with the expected one.
271+
if [[ "$PROVIDER_TYPE" == "aws" ]]; then
272+
EXISTING_ACCOUNT_ID=$(gcloud iam workload-identity-pools providers describe "$PROVIDER_ID" \
273+
--project="$PROJECT" --location=global \
274+
--workload-identity-pool="$POOL_ID" \
275+
--format='value(aws.accountId)')
276+
if [[ "$EXISTING_ACCOUNT_ID" != "$AWS_ACCOUNT_ID" ]]; then
277+
die "provider '${PROVIDER_ID}' already exists but is not an AWS provider for account ${AWS_ACCOUNT_ID} (describe reports account: ${EXISTING_ACCOUNT_ID:-none}). Delete it and re-run:
270278
${DELETE_HINT}"
271-
fi
272-
if [[ "$PROVIDER_TYPE" == "oidc" && "$EXISTING_TYPE" != *"${ISSUER_URI}" ]]; then
273-
die "provider '${PROVIDER_ID}' already exists but is not an OIDC provider for issuer ${ISSUER_URI} (describe reports: ${EXISTING_TYPE}). Delete it and re-run:
279+
fi
280+
else
281+
EXISTING_ISSUER=$(gcloud iam workload-identity-pools providers describe "$PROVIDER_ID" \
282+
--project="$PROJECT" --location=global \
283+
--workload-identity-pool="$POOL_ID" \
284+
--format='value(oidc.issuerUri)')
285+
if [[ "$EXISTING_ISSUER" != "$ISSUER_URI" ]]; then
286+
die "provider '${PROVIDER_ID}' already exists but is not an OIDC provider for issuer ${ISSUER_URI} (describe reports issuer: ${EXISTING_ISSUER:-none}). Delete it and re-run:
274287
${DELETE_HINT}"
288+
fi
275289
fi
276290
if [[ "$EXISTING_CONDITION" != "$EXPECTED_CONDITION" ]]; then
277291
die "provider '${PROVIDER_ID}' already exists with a different attribute condition, so this script cannot vouch for which identities enter pool '${POOL_ID}'.

0 commit comments

Comments
 (0)