Skip to content

Backport of [NET-1151 NET-11228] security: Add request normalization and header match options to prevent L7 intentions bypass into release/1.20.x#21839

Merged
zalimeni merged 1 commit into
release/1.20.xfrom
backport/zalimeni/feature/net-1151-l7-intentions-security-fixes/ghastly-grand-fawn
Oct 16, 2024
Merged

Backport of [NET-1151 NET-11228] security: Add request normalization and header match options to prevent L7 intentions bypass into release/1.20.x#21839
zalimeni merged 1 commit into
release/1.20.xfrom
backport/zalimeni/feature/net-1151-l7-intentions-security-fixes/ghastly-grand-fawn

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #21816 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Description

This PR brings in all previously reviewed changes from the zalimeni/feature/net-1151-l7-intentions-security-fixes feature branch into main and release branches. All changes were previously approved as part of Enterprise reviews except for the changelog added in this PR.

Changes include:

I'll squash and rebase these commits prior to merge to make backports more manageable.

Once this PR is merged, I'll cut api across active release branches, which will allow for hashicorp/consul-k8s#4385 to be updated and merged as well, completing the cross-repo changeset.

Testing & Reproduction steps

See previous PRs for testing details. All unit and integration tests are expected to pass.

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/zalimeni/feature/net-1151-l7-intentions-security-fixes/ghastly-grand-fawn branch from 91036cd to 6434641 Compare October 16, 2024 16:24
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions Bot added type/docs Documentation needs to be created/updated/clarified theme/api Relating to the HTTP API interface theme/cli Flags and documentation for the CLI interface theme/ui Anything related to the UI theme/envoy/xds Related to Envoy support labels Oct 16, 2024
@zalimeni zalimeni enabled auto-merge (squash) October 16, 2024 16:26
@zalimeni zalimeni merged commit 424f5a8 into release/1.20.x Oct 16, 2024
@zalimeni zalimeni deleted the backport/zalimeni/feature/net-1151-l7-intentions-security-fixes/ghastly-grand-fawn branch October 16, 2024 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

theme/api Relating to the HTTP API interface theme/cli Flags and documentation for the CLI interface theme/envoy/xds Related to Envoy support theme/ui Anything related to the UI type/docs Documentation needs to be created/updated/clarified

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants