Skip to content

Backport of [Security] Secvuln 8633 Consul configuration allowed repeated keys into release/1.20.x#21943

Merged
sarahalsmiller merged 15 commits into
release/1.20.xfrom
backport/SECVULN-8633-TOB-CONSUL24-17-Consul-configuration-allows-repeated-keys/publicly-deciding-hookworm
Nov 27, 2024
Merged

Backport of [Security] Secvuln 8633 Consul configuration allowed repeated keys into release/1.20.x#21943
sarahalsmiller merged 15 commits into
release/1.20.xfrom
backport/SECVULN-8633-TOB-CONSUL24-17-Consul-configuration-allows-repeated-keys/publicly-deciding-hookworm

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #21908 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Description

  • Due to a known issue in hcl v1,
  • There is a potential for old unparsed rules to be in the cache, so I added an optional route to replicate the old behavior to maintain backwards compatibility when reading unparsed policies from the cache.

Testing & Reproduction steps

  • New tests pass

Links

hashicorp/hcl#704 Original HCL PR

PR Checklist

  • [ X] updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core requested a review from a team as a code owner November 14, 2024 15:58
@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/SECVULN-8633-TOB-CONSUL24-17-Consul-configuration-allows-repeated-keys/publicly-deciding-hookworm branch from fd5b3c3 to a23a6c0 Compare November 14, 2024 15:58
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions Bot added theme/acls ACL and token generation pr/dependencies PR specifically updates dependencies of project labels Nov 14, 2024
@sarahalsmiller sarahalsmiller force-pushed the backport/SECVULN-8633-TOB-CONSUL24-17-Consul-configuration-allows-repeated-keys/publicly-deciding-hookworm branch from a23a6c0 to 4e21fa8 Compare November 25, 2024 16:54
@sarahalsmiller sarahalsmiller merged commit 297ca6b into release/1.20.x Nov 27, 2024
@sarahalsmiller sarahalsmiller deleted the backport/SECVULN-8633-TOB-CONSUL24-17-Consul-configuration-allows-repeated-keys/publicly-deciding-hookworm branch November 27, 2024 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependencies PR specifically updates dependencies of project theme/acls ACL and token generation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants