Skip to content

Conversation

akagami-harsh
Copy link
Contributor

@akagami-harsh akagami-harsh commented Sep 4, 2025

Description of your changes:

Copy link

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign chensun for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@akagami-harsh
Copy link
Contributor Author

working on adding a test for it.

@akagami-harsh akagami-harsh changed the title fix(frontend): Fix bypass namespace authorization by manipulating URL parameters in artifact requests. fix(frontend): Prevent namespace authorization bypass in artifact requests Sep 4, 2025
Signed-off-by: Harshvir Potpose <[email protected]>
Signed-off-by: Harshvir Potpose <[email protected]>
Signed-off-by: Harshvir Potpose <[email protected]>
@google-oss-prow google-oss-prow bot added size/L and removed size/M labels Sep 5, 2025
@juliusvonkohout
Copy link
Member

Do you mean to write a function is_authorized? Because I do not know what authorizeFN is supposed to mean. Please align with @HumairAK and @hbelmiro for the coding style.

@juliusvonkohout
Copy link
Member

And it is a wonderful effort that we also need for graduatioon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[backend] Security exploit in mlpipeline-UI
2 participants