feat(kanidm): detect OAuth2 scope-map drift #281
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!281
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/275-oauth2-drift-gate"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Part of #275 — the hardening that would have caught #278 shipping half-fixed.
The problem it closes
kanidm-provision applies scope maps additively with no removal logic (#279). So a group removed from a client's declaration stays live forever, and the converge still reports success. #278 added
forgejo_adminstobitborg-web-dev, leftforgejo_usersin place, and the dev client stayed visible to every user — with a clean apply and a PR body claiming the opposite.Scope maps decide who sees an application on their Kanidm landing page and which groups can obtain tokens for it. An additive-only mismatch is a visibility/authorisation defect, and nothing surfaced it.
Verified against production, both paths
Detection — reports the real leak, stays silent on the client that matches:
Enforcement — with
-e kanidm_oauth2_drift_fail=true, exit 2:Why it warns rather than fails by default
The drift it detects is currently real and unfixed. A hard gate would abort every unrelated apply until someone runs
delete-scope-mapby hand — the same reasoning as the account-policy gate in #277: a gate that breaks unrelated applies is worse than no gate.Recommended sequence: run the manual
delete-scope-mapforbitborg-web-dev/forgejo_users, confirm this task goes quiet, then setkanidm_oauth2_drift_fail: trueso any future leak aborts instead of printing.Properties
check_mode: false, so a dry-run exercises the gate instead of skipping it.group@domain: {scopes}rendering by taking everything before the first@.Not covered
Claim-map drift at group level inside a declared claim — relevant to #280, where
ent_lfs/ent_lfs_largemay survive. Same shape of problem; worth extending this gate once #280's behaviour is observed on a real apply.76297b9aae6985c82a7d6985c82a7d054a7ad1d3