-
Notifications
You must be signed in to change notification settings - Fork 8.1k
[release-1.4] authz: fix the validation for request.headers #21284
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
/retest |
It seems the lint is failing for unrelated issues?
@istio/release-managers-1-4 Is this an existing issue in 1.4 or do you have any ideas of this? Thank you. |
/retest |
781ba84
to
85b738d
Compare
/retest |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
@istio/release-managers-1-4 Could someone take a look at this? Thank you. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please link to the original master PRs/issue
@@ -285,3 +285,51 @@ func TestV1beta1_WorkloadSelector(t *testing.T) { | |||
rbacUtil.RunRBACTest(t, cases) | |||
}) | |||
} | |||
|
|||
// TestV1beta1_RequestHeaders tests v1beta1 authorization with "request.headers". | |||
func TestV1beta1_RequestHeaders(t *testing.T) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why do we have a special case for this? This seems like just a normal case, should this be added as a case in an existing test rather than a whole new test?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I didn't find a good existing test case to add this one, I will try do refactor this a little bit with more tests in master.
* authz: fix the validation for request.headers (istio#21284) * manual backport of 21513 (istio#21514) Signed-off-by: Rama Chavali <rama.rao@salesforce.com> * Fix PSP sample file to allow NET_RAW. (istio#21533) * [release-1.4] remove use_downstream_protocol for gateway (istio#21727) * remove use_downstream_protocol for gateway * comment * writing Co-authored-by: Yan Xue <3491507+yxue@users.noreply.github.com> * Update dependencies (istio#21765) * Make iptables script and output consistent with golang (istio#21871) Co-authored-by: knrc <knrc@users.noreply.github.com> * [release-1.4] resign certificate (istio#22131) * resign certificate * test Co-authored-by: xuzhonghu <xuzhonghu@huawei.com> * Stop linting links of 1.4 branch (istio#22132) This is going to continue to break as istio.io changes. We already disabled this on 1.5/master. * [release-1.4] Build: Honor GOBUILDFLAGS variable also in test mode (istio#22171) We already honor it in `go build`, we should do the same in `go test`. Manual backport of istio#22163 * Update base image for release 1.4 (istio#22165) * Fix GOBUILDFLAGS usage in codecov scripts (istio#22182) This variable needs to be set before used (set -u) and must not be quoted, otherwise it will become an empty arg for go test if it's empty. Co-authored-by: Jonh Wendell <jonh.wendell@redhat.com> * Update proxy to pickup fixes for ISTIO-SECURITY-2020-003. (istio#22257) * Fix extra .Value in deployment file for stackdriver tracing vars (istio#22506) Co-authored-by: gargnupur <gargnupur@google.com> * Update operator SHA (istio#22523) * clone LbEndpoint to prevent data race (istio#22023) (istio#22528) (cherry picked from commit fdc6dd4) Co-authored-by: Zhonghu Xu <xuzhonghu@huawei.com> * cni: update SHA (istio#22569) Signed-off-by: Yuchen Dai <silentdai@gmail.com> * Make sure to use CNI 1.4 image when running tests under CNI (istio#23035) * Make sure to use CNI 1.4 image when running tests under CNI * Fix lint * [release-1.4] Update dependencies with update_deps.sh (istio#23010) * Update deps with update_deps.sh * Dep updates again * [release-1.4] Run update_deps.sh (istio#23051) * Run update_deps.sh Had to do go get istio.io/operator@5f8ecc70a0f4059bfd4d0f7867d4dc76407f2f08 since update_deps.sh was not updating it. * Run go mod tidy * Update with another cni change (istio#23061) * [release-1.4] Fix Gateway helm chart for helm 3 (istio#23077) * Fix Gateway helm chart for helm 3 Helm 3 threw an error that `$spec.sds` is not a function. Removing the parentheses led to the next problem: the and evaluates eager so `spec.sds.enabled` resulted in a `nil` exception. By nesting the if, the problem is resolved * Also fix the role Co-authored-by: Alex Nederlof <alex@nederlof.com> Co-authored-by: Yangmin Zhu <ymzhu@google.com> Co-authored-by: Rama Chavali <rama.rao@salesforce.com> Co-authored-by: Oliver Liu <yonggangl@google.com> Co-authored-by: Istio Automation <istio.testing@gmail.com> Co-authored-by: Yan Xue <3491507+yxue@users.noreply.github.com> Co-authored-by: Jonh Wendell <jonh.wendell@redhat.com> Co-authored-by: knrc <knrc@users.noreply.github.com> Co-authored-by: xuzhonghu <xuzhonghu@huawei.com> Co-authored-by: John Howard <howardjohn@google.com> Co-authored-by: Eric Van Norman <ericvn@us.ibm.com> Co-authored-by: Joshua Blatt <jblatt@google.com> Co-authored-by: gargnupur <gargnupur@google.com> Co-authored-by: Yuchen Dai <silentdai@gmail.com> Co-authored-by: jacob-delgado <38300436+jacob-delgado@users.noreply.github.com> Co-authored-by: Alex Nederlof <alex@nederlof.com>
* authz: fix the validation for request.headers (istio#21284) * manual backport of 21513 (istio#21514) Signed-off-by: Rama Chavali <rama.rao@salesforce.com> * Fix PSP sample file to allow NET_RAW. (istio#21533) * [release-1.4] remove use_downstream_protocol for gateway (istio#21727) * remove use_downstream_protocol for gateway * comment * writing Co-authored-by: Yan Xue <3491507+yxue@users.noreply.github.com> * Update dependencies (istio#21765) * Make iptables script and output consistent with golang (istio#21871) Co-authored-by: knrc <knrc@users.noreply.github.com> * [release-1.4] resign certificate (istio#22131) * resign certificate * test Co-authored-by: xuzhonghu <xuzhonghu@huawei.com> * Stop linting links of 1.4 branch (istio#22132) This is going to continue to break as istio.io changes. We already disabled this on 1.5/master. * [release-1.4] Build: Honor GOBUILDFLAGS variable also in test mode (istio#22171) We already honor it in `go build`, we should do the same in `go test`. Manual backport of istio#22163 * Update base image for release 1.4 (istio#22165) * Fix GOBUILDFLAGS usage in codecov scripts (istio#22182) This variable needs to be set before used (set -u) and must not be quoted, otherwise it will become an empty arg for go test if it's empty. Co-authored-by: Jonh Wendell <jonh.wendell@redhat.com> * Update proxy to pickup fixes for ISTIO-SECURITY-2020-003. (istio#22257) * Fix extra .Value in deployment file for stackdriver tracing vars (istio#22506) Co-authored-by: gargnupur <gargnupur@google.com> * Update operator SHA (istio#22523) * clone LbEndpoint to prevent data race (istio#22023) (istio#22528) (cherry picked from commit fdc6dd4) Co-authored-by: Zhonghu Xu <xuzhonghu@huawei.com> * cni: update SHA (istio#22569) Signed-off-by: Yuchen Dai <silentdai@gmail.com> * Make sure to use CNI 1.4 image when running tests under CNI (istio#23035) * Make sure to use CNI 1.4 image when running tests under CNI * Fix lint * [release-1.4] Update dependencies with update_deps.sh (istio#23010) * Update deps with update_deps.sh * Dep updates again * [release-1.4] Run update_deps.sh (istio#23051) * Run update_deps.sh Had to do go get istio.io/operator@5f8ecc70a0f4059bfd4d0f7867d4dc76407f2f08 since update_deps.sh was not updating it. * Run go mod tidy * Update with another cni change (istio#23061) * [release-1.4] Fix Gateway helm chart for helm 3 (istio#23077) * Fix Gateway helm chart for helm 3 Helm 3 threw an error that `$spec.sds` is not a function. Removing the parentheses led to the next problem: the and evaluates eager so `spec.sds.enabled` resulted in a `nil` exception. By nesting the if, the problem is resolved * Also fix the role Co-authored-by: Alex Nederlof <alex@nederlof.com> * Citadel completely ignores namespaces opted out. (istio#23223) * Add Kiali fix to Helm (istio#23445) * Update operator for istio/operator#777 (istio#23540) * bump base (istio#23655) * Update cni sha for release-1.4 branch (istio#24216) * [release-1.4] Update jquery and nodejs (istio#24407) * Add files from cherrypick * Update yaml files to pull 1.15.1 images Co-authored-by: Brian Avery <bavery@redhat.com> * Update proxy sha (istio#24721) * Bump bookinfo images * Update vendor Co-authored-by: Yangmin Zhu <ymzhu@google.com> Co-authored-by: Rama Chavali <rama.rao@salesforce.com> Co-authored-by: Oliver Liu <yonggangl@google.com> Co-authored-by: Istio Automation <istio.testing@gmail.com> Co-authored-by: Yan Xue <3491507+yxue@users.noreply.github.com> Co-authored-by: knrc <knrc@users.noreply.github.com> Co-authored-by: xuzhonghu <xuzhonghu@huawei.com> Co-authored-by: John Howard <howardjohn@google.com> Co-authored-by: Eric Van Norman <ericvn@us.ibm.com> Co-authored-by: Joshua Blatt <jblatt@google.com> Co-authored-by: gargnupur <gargnupur@google.com> Co-authored-by: Yuchen Dai <silentdai@gmail.com> Co-authored-by: jacob-delgado <38300436+jacob-delgado@users.noreply.github.com> Co-authored-by: Alex Nederlof <alex@nederlof.com> Co-authored-by: Brian Avery <bavery@redhat.com> Co-authored-by: Martin Ostrowski <mostrowski@google.com> Co-authored-by: stewartbutler <stewartbutler@google.com> Co-authored-by: Istio Automation <istio-testing-bot@google.com> Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
This fixes the validation for the "request.headers" to correctly generate the filter config. Note the bug has already been fixed in master and release-1.5 in a separate PR (https://github.com/istio/istio/pull/20442/files#diff-4fa38d71f05c2090c15c94f43f3e248cR77) before.