Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport of [Security] Secvuln 8633 Consul configuration allowed repeated keys into release/1.20.x #21943

Open
wants to merge 14 commits into
base: release/1.20.x
Choose a base branch
from

Conversation

hc-github-team-consul-core
Copy link
Collaborator

Backport

This PR is auto-generated from #21908 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Description

  • Due to a known issue in hcl v1,
  • There is a potential for old unparsed rules to be in the cache, so I added an optional route to replicate the old behavior to maintain backwards compatibility when reading unparsed policies from the cache.

Testing & Reproduction steps

  • New tests pass

Links

hashicorp/hcl#704 Original HCL PR

PR Checklist

  • [ X] updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/SECVULN-8633-TOB-CONSUL24-17-Consul-configuration-allows-repeated-keys/publicly-deciding-hookworm branch from fd5b3c3 to a23a6c0 Compare November 14, 2024 15:58
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions bot added theme/acls ACL and token generation pr/dependencies PR specifically updates dependencies of project labels Nov 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pr/dependencies PR specifically updates dependencies of project theme/acls ACL and token generation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants