-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
help wantedExtra attention is neededExtra attention is neededsecuritysystem security vulnerabilitiessystem security vulnerabilities
Description
- Description: The Locator service (
services/shieldx-gateway/locator/main.go) exposes/issuewithout any authentication. Anyone can POST arbitrarytenant/scopedata to mint valid locator tokens signed with the service key, bypassing downstream authorization. - Location:
handleIssueandRuninservices/shieldx-gateway/locator/main.go(no auth middleware before handler). - Recommendation: Gate
/issuebehind strong auth (mTLS + admission secret/JWT), enforce tenant allowlists, and log/alert on issuance. Consider separating public introspection from privileged issuance endpoints. - Done when: Unauthenticated issuance attempts fail, token minting restricted to authorized callers, and coverage tests verify the control path.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
help wantedExtra attention is neededExtra attention is neededsecuritysystem security vulnerabilitiessystem security vulnerabilities