Skip to content

smokeng v0.15.0

Choose a tag to compare

@github-actions github-actions released this 01 Sep 13:01
· 63 commits to main since this release

v0.15.0 — the client secret leaves the command line, and grants can be made to matter

Three things that were only visible from a deployment, not from the code.

The OIDC client secret was passed as --oidc-client-secret. A command line is
world-readable in /proc, so that hands the secret to every local user on the
host, and the systemd unit carrying it is mode 0644, which hands it out again.
It worked perfectly the whole time, which is the worst property a disclosure
can have. --oidc-client-secret-file reads it from a file instead, and warns
when that file is readable by anyone but its owner — a secret moved out of the
command line into a 0644 file has gained nothing, and nothing would have said
so. The two flags are mutually exclusive rather than one silently winning. The
irtt keyfile goes through the same reader and gains the same warning.

If you have ever passed --oidc-client-secret, treat it as disclosed and rotate
it. Moving it to a file afterwards does not un-publish it.

The Ansible role could not set --default-role at all, so every deployment ran
the viewer default: every authenticated user reads the whole tree, and a grant
can only add to that. You could write grants, see them listed, and have them
restrict nothing, with no way to change it short of editing the unit by hand.
smokeng_default_role fixes that, and the docs now state the corollary where it
is read rather than leaving it as a footnote — while default-role is viewer, a
grant is inert, and an installation in that state looks exactly like one that
is working.

A grant's role could be changed all along: the store upserts on (group,
target), so re-adding re-roles. But the grant list offered only Remove, so the
discoverable way to demote an editor was to delete the grant and rebuild it
from memory, through a state where the group has no access and with the path to
retype correctly. The role is now editable on the row. Group and path stay
fixed: they are what identifies a grant, so changing either is a different
grant, not an edit.