This is an automated email from the ASF dual-hosted git repository.
smolnar82 pushed a change to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git
discard 5e64d708c KNOX-3390: Moved gateway-level config to GatewayConfig and
implemented the missing methods (#1322)
discard cb879e552 KNOX-3390 - Address comments in PR 1315 (#1320)
omit 33c51e855 KNOX-3355 - Add OIDCDiscoveryHelper,
JdbcTrustedOidcIssuerService, and TrustedOidcIssuerServiceFactory (#1315)
omit ea39545cf KNOX-3355 - Add TrustedOidcIssuerService schema and
interface (#1311)
omit 8a5cec704 KnoxIDF - Fixed pylint and test issues in Docker-based tests
omit a023563db Knox as OIDC Provider (#1215)
add 08b1f90b5 KNOX-3383: Bump Jackson to 2.18.9 due to CVEs (#1310)
add a5dfbcaca KNOX-3382: Bump Netty to 1.135.Final due to CVEs (#1309)
add 94f394a73 Add Project Security Threat Model Document (#1312)
add b438768cd KNOX-3381: Fix HaDispatch unnecessary failover due to
IOException during writeOutboundResponse (#1308)
add fcab7e2f8 KNOX-3385: Ldap Proxy accepts search using either proxy or
remote base dn (#1314)
add 9f4b8e7fb KNOX-3388: Improve alias creation during EKU mode testing
(#1316)
add 76fa85b5c KNOX-3389: Embedded LDAP getUserGroups drops roles-lookup
roles that have no backing group (#1318)
new be0c4edca Knox as OIDC Provider (#1215)
new ca62c98fc KnoxIDF - Fixed pylint and test issues in Docker-based tests
new 11acc7e60 KNOX-3355 - Add TrustedOidcIssuerService schema and
interface (#1311)
new 0ac3eca9f KNOX-3355 - Add OIDCDiscoveryHelper,
JdbcTrustedOidcIssuerService, and TrustedOidcIssuerServiceFactory (#1315)
new dfdd98f0d KNOX-3390 - Address comments in PR 1315 (#1320)
new c0eb9b583 KNOX-3390: Moved gateway-level config to GatewayConfig and
implemented the missing methods (#1322)
This update added new revisions after undoing existing revisions.
That is to say, some revisions that were in the old version of the
branch are not in the new version. This situation occurs
when a user --force pushes a change and generates a repository
containing something like this:
* -- * -- B -- O -- O -- O (5e64d708c)
\
N -- N -- N refs/heads/knox_idf (c0eb9b583)
You should already have received notification emails for all of the O
revisions, and so the following emails describe only the N revisions
from the common base, B.
Any revisions marked "omit" are not gone; other references still
refer to them. Any revisions marked "discard" are gone forever.
The 6 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.
Summary of changes:
.../workflows/build/conf/topologies/knoxldap.xml | 2 +-
.github/workflows/build/gateway-site.xml | 2 +-
.../compose/single-eku-no-mtls/gateway-site.xml | 2 +-
.../compose/single-eku/gateway-single-eku.sh | 19 +-
.../workflows/compose/single-eku/gateway-site.xml | 2 +-
.../workflows/tests/test_knox_ldap_proxy_search.py | 26 +
AGENTS.md | 29 +
SECURITY.md | 35 ++
THREAT_MODEL.md | 661 +++++++++++++++++++++
.../gateway/ha/dispatch/AtlasApiHaDispatch.java | 4 +-
.../dispatch/AtlasApiTrustedProxyHaDispatch.java | 4 +-
.../knox/gateway/ha/dispatch/AtlasHaDispatch.java | 4 +-
.../ha/dispatch/AtlasTrustedProxyHaDispatch.java | 4 +-
.../ha/dispatch/ConfigurableHADispatch.java | 3 +-
.../ha/dispatch/ConfigurableHADispatchTest.java | 86 +++
.../gateway/ha/dispatch/DefaultHaDispatchTest.java | 26 +-
.../services/ldap/KnoxLDAPServerManager.java | 19 +-
.../gateway/services/ldap/backend/FileBackend.java | 11 +-
.../gateway/services/ldap/backend/LdapBackend.java | 7 +
.../services/ldap/backend/LdapProxyBackend.java | 14 +
.../ldap/interceptor/UserSearchInterceptor.java | 12 +-
.../services/ldap/KnoxLDAPServerManagerTest.java | 70 +++
.../ldap/backend/LdapProxyBackendTest.java | 22 +
.../knox/gateway/dispatch/NiFiHaDispatch.java | 3 +-
knox-site/docs/service_ldap_server.md | 2 +-
pom.xml | 4 +-
26 files changed, 1018 insertions(+), 55 deletions(-)
create mode 100644 AGENTS.md
create mode 100644 SECURITY.md
create mode 100644 THREAT_MODEL.md