Skip to content

fix[backend](federation_server): applying public route bypass to /v1/… - #2808

Merged
osmontero merged 1 commit into
v11from
backlog/v11_federation_mode
Oct 1, 2026
Merged

osmontero merged 1 commit into
v11from
backlog/v11_federation_mode

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit
AlexSanchez-bit requested a review from a team October 1, 2026 15:52
@osmontero
osmontero merged commit a310ff0 into v11 Oct 1, 2026
5 checks passed
@osmontero
osmontero deleted the backlog/v11_federation_mode branch October 1, 2026 15:53
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./utmstack-collector:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.0
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/inputs:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/modules-config:
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.0
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/config:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400/updater:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🛑 AI review — Engineer review required

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. @Kbayero @osmontero please review.

🛑 architecture (silas-1.7-pro) — blocking — must fix before merge

Summary: Security config adds an unauthenticated route for /api/v1/mode, creating an auth bypass risk and requiring senior review.

  • high backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java:109 — Adding permitAll for /api/v1/mode bypasses authentication for a potentially sensitive endpoint. If this endpoint exposes mode, configuration, or operational state, it should not be publicly accessible. Alternative: require authentication by default and only add it to permitAll if the endpoint is explicitly designed as public, with a documented risk review.

⚠️ bugs (silas-1.7-pro) — non-blocking warnings

Summary: Adds public access to /api/v1/mode; verify this endpoint is intended to be unauthenticated and read-only.

  • medium backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java:109 — This permits all unauthenticated requests to /api/v1/mode. If that endpoint returns sensitive deployment/configuration data or accepts mutating operations, this is an authorization bypass. If public access is intended, consider restricting to the required HTTP method only.

🛑 security (silas-1.7-pro) — blocking — must fix before merge

Summary: Diff permits unauthenticated access to /api/v1/mode, which may disclose or alter system mode.

  • high backend/src/main/java/com/park/utmstack/config/SecurityConfiguration.java:109 — Adding /api/v1/mode to permitAll removes authentication for that endpoint. If it exposes deployment mode, configuration state, or allows mode changes, this is an authentication bypass and information disclosure risk. Mitigate by requiring authentication for /api/v1/mode or restricting the endpoint to internal callers.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants