Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport of [NET-1151 NET-11228] security: Add request normalization and header match options to prevent L7 intentions bypass into release/1.20.x #21839

Conversation

hc-github-team-consul-core
Copy link
Contributor

Backport

This PR is auto-generated from #21816 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Description

This PR brings in all previously reviewed changes from the zalimeni/feature/net-1151-l7-intentions-security-fixes feature branch into main and release branches. All changes were previously approved as part of Enterprise reviews except for the changelog added in this PR.

Changes include:

I'll squash and rebase these commits prior to merge to make backports more manageable.

Once this PR is merged, I'll cut api across active release branches, which will allow for hashicorp/consul-k8s#4385 to be updated and merged as well, completing the cross-repo changeset.

Testing & Reproduction steps

See previous PRs for testing details. All unit and integration tests are expected to pass.

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/zalimeni/feature/net-1151-l7-intentions-security-fixes/ghastly-grand-fawn branch from 91036cd to 6434641 Compare October 16, 2024 16:24
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions bot added type/docs Documentation needs to be created/updated/clarified theme/api Relating to the HTTP API interface theme/cli Flags and documentation for the CLI interface theme/ui Anything related to the UI theme/envoy/xds Related to Envoy support labels Oct 16, 2024
@zalimeni zalimeni enabled auto-merge (squash) October 16, 2024 16:26
@zalimeni zalimeni merged commit 424f5a8 into release/1.20.x Oct 16, 2024
103 checks passed
@zalimeni zalimeni deleted the backport/zalimeni/feature/net-1151-l7-intentions-security-fixes/ghastly-grand-fawn branch October 16, 2024 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
theme/api Relating to the HTTP API interface theme/cli Flags and documentation for the CLI interface theme/envoy/xds Related to Envoy support theme/ui Anything related to the UI type/docs Documentation needs to be created/updated/clarified
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants