Skip to content

Releases: gogatekeeper/gatekeeper

2.9.4

28 Jan 22:17
@p53 p53
e6f3e04
Compare
Choose a tag to compare

What's Changed

Full Changelog: 2.9.3...2.9.4

2.9.4-rc2

28 Jan 21:48
@p53 p53
e6f3e04
Compare
Choose a tag to compare
2.9.4-rc2 Pre-release
Pre-release

What's Changed

  • Update pkgs, go to 1.21 by @p53 in #408

Full Changelog: 2.9.4-rc1...2.9.4-rc2

2.9.4-rc1

26 Jan 23:07
@p53 p53
d914ec2
Compare
Choose a tag to compare
2.9.4-rc1 Pre-release
Pre-release

What's Changed

Full Changelog: 2.9.3...2.9.4-rc1

2.9.3

11 Dec 21:50
@p53 p53
266f841
Compare
Choose a tag to compare

SECURITY NOTICE:

As fork of louketo-proxy we inherited IMPERSONATION type security vulnerability. There are 2 levels of impact: 1. Unaffected 2. Affected (High Risk)

  1. Unaffected - if you use one of these options, you are not susceptible to this attack:
    • --enable-encrypted-token=true
    • --store-url=<redis-url>
    • --enable-idp-session-check=true
  2. High Risk - if you don't use one of above options

Quick migitation: Enable at least one of above mentioned options
Normal migitation: Upgrade to latest version >=2.9.3
Enhance security: additionally beside upgrade to >=2.9.3 enable one of mentioned options (encryption, store_url, enable-idp-session-check)

Short Description of vulnerability: existing user in your userbase might impersonate other user in your userbase
Detailed description will be provided in 1-2 months (from security reasons)

What's Changed

  • Update HMAC description docu by @p53
  • Refactor handlers by @p53, Pierre Bogossian bogossian@mail.com, Nikifor Georgiev
  • Generate UMA ticket when invalid UMA token but valid resource accessed by @p53
  • Enable to use openid-provider-proxy settings in all requests to keycloak by @p53
  • Update docu for 2.9.1 by @p53
  • Turn off issuer, client id check for refresh token by @p53
  • Turn off tok verif refresh by @p53
  • Update docu for 2.9.2 by @p53
  • Remove refresh token validation, add e2e tests by @p53
  • Add tests for skipopenidtlsverify by @p53
  • Fix resources-stringslice parsing after urfavecli to v2 upgrade by @p53
  • Update docs 2.9.3 by @p53

2.9.3-rc3

08 Dec 23:15
@p53 p53
46c342c
Compare
Choose a tag to compare
2.9.3-rc3 Pre-release
Pre-release

Changelog

  • fcd0e84 Add tests for skipopenidtlsverify (#401)
  • 46c342c Fix resources-stringslice parsing after urfavecli to v2 upgrade (#402)

2.9.3-rc2

08 Dec 11:58
@p53 p53
3457b4c
Compare
Choose a tag to compare
2.9.3-rc2 Pre-release
Pre-release

Changelog

  • 3457b4c Remove refresh token validation add e2e (#400)

2.9.3-rc1

08 Dec 01:10
@p53 p53
d91f905
Compare
Choose a tag to compare
2.9.3-rc1 Pre-release
Pre-release

Changelog

  • d91f905 Remove refresh token validation, add e2e tests (#399)

2.9.2-rc1

04 Dec 09:08
@p53 p53
6c66f9c
Compare
Choose a tag to compare
2.9.2-rc1 Pre-release
Pre-release

Changelog

  • 6c66f9c Turn off issuer, client id check for refresh token (#395)

2.9.1-rc2

29 Nov 22:52
@p53 p53
d1a210f
Compare
Choose a tag to compare
2.9.1-rc2 Pre-release
Pre-release

Changelog

  • d1a210f Enable to use openid-provider-proxy settings in all requests to keycloak (#389)

2.9.1-rc1

28 Nov 23:21
@p53 p53
122495a
Compare
Choose a tag to compare
2.9.1-rc1 Pre-release
Pre-release

Changelog