mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-05 04:47:43 +00:00
468dcaef69
test(security): pin GHSA-m77q STS root-secret token signing (sec-7) GHSA-m77q-r63m-pj89 (intentionally UNFIXED) is that STS session tokens are signed with the shared root secret: crates/iam/src/root_credentials.rs token_signing_key() returns the root secret_key, so anyone holding the root secret can forge STS session tokens. No test named the advisory, and the existing test_created_sts_credentials_authorize_with_session_token_claims uses token_signing_key() for both signing and verifying, so it pins "same key signs and verifies" but not the m77q-specific "signing key IS the root secret" — a future fix that decouples the STS key from the root secret would pass it silently. Add a flow-level pin, test_ghsa_m77q_sts_session_token_signed_with_root_secret, that captures the advisory's exact signature: (1) token_signing_key() == the root secret; (2) an AssumeRole-style session token issued with that key decodes with the root secret and NOT with any other secret; (3) it authorizes through the STS path. All three assert CURRENT (by-design-vulnerable) behavior, so a real m77q fix (a dedicated STS signing key) turns them red and forces a red -> green regression update. Also GHSA-name the existing characterization test and token_signing_key() with doc comments and the advisory URL, and update the m77q row in docs/testing/security-regressions.md. No production behavior changes. Refs: backlog#1151 (sec-7) Co-authored-by: houseme <housemecn@gmail.com>
41 lines
1.5 KiB
Rust
41 lines
1.5 KiB
Rust
// Copyright 2024 RustFS Team
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
use rustfs_credentials::Credentials;
|
|
|
|
pub(crate) fn credentials() -> Option<Credentials> {
|
|
crate::runtime_sources::action_credentials()
|
|
}
|
|
|
|
pub(crate) fn credentials_or_default() -> Credentials {
|
|
credentials().unwrap_or_default()
|
|
}
|
|
|
|
/// The signing key for STS session tokens.
|
|
///
|
|
/// GHSA-m77q-r63m-pj89 (intentionally UNFIXED): this returns the root secret
|
|
/// key, so STS JWTs are signed with the shared root secret and anyone holding
|
|
/// it can forge session tokens. The behavior is pinned by
|
|
/// `test_ghsa_m77q_sts_session_token_signed_with_root_secret` in `sys.rs`;
|
|
/// fixing the advisory (a dedicated STS signing key distinct from the root
|
|
/// secret) must update that test red -> green. See
|
|
/// docs/testing/security-regressions.md.
|
|
pub(crate) fn token_signing_key() -> Option<String> {
|
|
credentials().map(|cred| cred.secret_key)
|
|
}
|
|
|
|
pub(crate) fn is_root_access_key(access_key: &str) -> bool {
|
|
credentials().is_some_and(|cred| cred.access_key == access_key)
|
|
}
|