forgejo: authorized integrations accept any issuer domain, on an open-registration instance #313
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#313
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Found while evaluating Authorized Integrations for #80. Independent of whether we adopt that feature —
it is reachable today.
The finding
[authorized_integration]is not configured inroles/forgejo/templates/app.ini.j2at all, so everyvalue is the upstream default. Forgejo's own v16.0.1 example config says what that means for
ALLOWED_DOMAINS:And creating an integration is not an admin-only action, despite the admin CLI being the documented
path. In v16.0.1
routers/web/web.gothe routes live under user settings:Why it matters here specifically
Registration is open (ADR 0029). So any account anyone creates can add an authorized integration
naming an arbitrary HTTPS issuer, and Forgejo will fetch that issuer's discovery document and JWKS. That
turns a signed-in stranger into someone who can make our server issue outbound HTTPS requests to a host
of their choosing.
ALLOW_LOCALNETWORKSblocks the worst version of this — it is not a route to our internal network. Whatremains is outbound request generation on demand, attributable to our IP.
Suggested
Set
ALLOWED_DOMAINSto the issuers we actually intend to trust. If Authorized Integrations is adopted atall, the only issuer in the #80 evaluation's GO column is our own Actions issuer, so a single-entry
allowlist covers it and denies everything else — least privilege, and cheap.
Verify before applying: it was not established whether the local Actions issuer is itself subject to
ALLOWED_DOMAINSor exempt from it. If it is subject, it must be listed or the two GO consumers in #80break. Check that on the
local/16.0.1 preview rather than on production — the change restarts Forgejo,so it is not worth two attempts.
Also worth setting
REQUEST_TIMEOUTdeliberately rather than inheriting 10s, and reviewing the blocklistknob, while the section is being added.
Note if #80 is ever adopted
ID tokens, unlike Actions secrets, are available to fork pull-request runs. So any claim rule must pin
event_name=pushplus an exact ref. A rule matchingpull_requeston a public repository would let afork's workflow authenticate as our bot.