From f8bcdbb1f30742c8cd7c6226204a4dc694b85e6b Mon Sep 17 00:00:00 2001 From: chen21019 <19357113+chen21019@users.noreply.github.com> Date: Mon, 21 Sep 2026 10:22:03 +0800 Subject: [PATCH] Keep built-in OIDC identity types upgrade-safe --- .github/workflows/codeql-verification.yml | 6 +++++- COMPATIBILITY.md | 16 +++++++++++++--- README.md | 16 ++++++++++++---- code/framework/api-pub-sub-jetty/pom.xml | 2 +- code/framework/api-pub-sub/pom.xml | 2 +- code/framework/api/pom.xml | 2 +- code/framework/archaius/pom.xml | 2 +- code/framework/async/pom.xml | 2 +- code/framework/auditing/pom.xml | 2 +- code/framework/db-loader/pom.xml | 2 +- code/framework/deferred/pom.xml | 2 +- code/framework/encryption/pom.xml | 2 +- code/framework/engine/pom.xml | 2 +- code/framework/eventing/pom.xml | 2 +- code/framework/events/pom.xml | 2 +- code/framework/extension-spring/pom.xml | 2 +- code/framework/extension/pom.xml | 2 +- code/framework/java-server/pom.xml | 2 +- code/framework/jmx/pom.xml | 2 +- code/framework/jooq/pom.xml | 2 +- code/framework/json/pom.xml | 2 +- code/framework/launcher/pom.xml | 2 +- code/framework/lock/pom.xml | 2 +- code/framework/logback/pom.xml | 2 +- code/framework/managed-context/pom.xml | 2 +- code/framework/metrics/pom.xml | 2 +- code/framework/module/pom.xml | 2 +- code/framework/object/pom.xml | 2 +- code/framework/pool/pom.xml | 2 +- code/framework/resource-monitor/pom.xml | 2 +- code/framework/schema/pom.xml | 2 +- .../AuthSchemaAdditionsPostProcessor.java | 7 +++++++ .../AuthSchemaAdditionsPostProcessorTest.java | 2 +- code/framework/server/pom.xml | 2 +- code/framework/spring/pom.xml | 2 +- code/framework/system-task/pom.xml | 2 +- code/framework/token/pom.xml | 2 +- code/framework/utils/pom.xml | 2 +- code/iaas/agent-instance/pom.xml | 2 +- code/iaas/agent-server/pom.xml | 2 +- code/iaas/agent/pom.xml | 2 +- code/iaas/allocator/pom.xml | 2 +- code/iaas/api-logic/pom.xml | 2 +- code/iaas/archaius-management/pom.xml | 2 +- code/iaas/auth-logic/pom.xml | 2 +- .../api/auth/identity/IdentityManager.java | 13 ++++++++++++- .../IdentityManagerExternalTypeTest.java | 12 ++++++++++++ code/iaas/bootstrap/pom.xml | 2 +- code/iaas/config-item/api/pom.xml | 2 +- code/iaas/config-item/common/pom.xml | 2 +- code/iaas/config-item/server/pom.xml | 2 +- code/iaas/engine-jooq/pom.xml | 2 +- code/iaas/events/pom.xml | 2 +- code/iaas/external-handler/pom.xml | 2 +- code/iaas/ha/pom.xml | 2 +- code/iaas/healthcheck/pom.xml | 2 +- code/iaas/labels/pom.xml | 2 +- code/iaas/logic-common/pom.xml | 2 +- code/iaas/logic/pom.xml | 2 +- code/iaas/metadata/pom.xml | 2 +- code/iaas/model/pom.xml | 2 +- code/iaas/resource-pool/pom.xml | 2 +- code/iaas/service-discovery/api/pom.xml | 2 +- code/iaas/service-discovery/server/pom.xml | 2 +- code/iaas/ssh-common/pom.xml | 2 +- code/iaas/storage-service/pom.xml | 2 +- code/iaas/task-jooq/pom.xml | 2 +- code/implementation/activity-log/pom.xml | 2 +- .../implementation/agent-instance-impl/pom.xml | 2 +- code/implementation/docker/api/pom.xml | 2 +- code/implementation/docker/common/pom.xml | 2 +- code/implementation/docker/compute/pom.xml | 2 +- code/implementation/docker/machine/pom.xml | 2 +- code/implementation/docker/storage/pom.xml | 6 +++--- code/implementation/extension-api/pom.xml | 2 +- code/implementation/hazelcast/common/pom.xml | 2 +- code/implementation/hazelcast/eventing/pom.xml | 2 +- code/implementation/hazelcast/lock/pom.xml | 2 +- code/implementation/host-api/pom.xml | 2 +- code/implementation/host-stats/pom.xml | 2 +- code/implementation/register/pom.xml | 2 +- code/implementation/sample-setup/pom.xml | 2 +- code/implementation/settings-api/pom.xml | 2 +- .../simulator/agent-connection/pom.xml | 2 +- code/implementation/simulator/storage/pom.xml | 2 +- code/implementation/system-stack/pom.xml | 2 +- code/implementation/vm/pom.xml | 2 +- code/meta-parent/pom.xml | 2 +- code/packaging/app-config/pom.xml | 2 +- code/packaging/app/pom.xml | 2 +- code/packaging/bundle/pom.xml | 2 +- code/packaging/dev/pom.xml | 2 +- code/packaging/meta/pom.xml | 2 +- code/parent/pom.xml | 2 +- .../releases/orchestration-engine-0.183.310.md | 18 ++++++++++++++++++ pom.xml | 2 +- resources/pom.xml | 2 +- scripts/build | 2 +- scripts/check-pasturestack-source | 6 +++--- scripts/check-release-artifact | 2 +- 100 files changed, 176 insertions(+), 106 deletions(-) create mode 100644 docs/releases/orchestration-engine-0.183.310.md diff --git a/.github/workflows/codeql-verification.yml b/.github/workflows/codeql-verification.yml index 2e4a95b510..1a8f0601fb 100644 --- a/.github/workflows/codeql-verification.yml +++ b/.github/workflows/codeql-verification.yml @@ -31,7 +31,11 @@ jobs: test -z "$(git status --porcelain)" git merge-base --is-ancestor origin/main HEAD test "$(git rev-list --count origin/main..HEAD)" -eq 1 - grep -Fxq ' 0.183.300' code/meta-parent/pom.xml + project_version="$(sed -n 's/^[[:space:]]*\([^<]*\)<\/version>[[:space:]]*$/\1/p' code/meta-parent/pom.xml | head -n 1)" + build_version="$(sed -n 's/^ENGINE_VERSION=${ENGINE_VERSION:-\([^}]*\)}$/\1/p' scripts/build)" + [[ "$project_version" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]] + test "$build_version" = "$project_version" + test -f "docs/releases/orchestration-engine-${project_version}.md" - name: Initialize CodeQL uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 diff --git a/COMPATIBILITY.md b/COMPATIBILITY.md index 872c76a41d..7a174317bf 100644 --- a/COMPATIBILITY.md +++ b/COMPATIBILITY.md @@ -6,7 +6,7 @@ New operator-facing names use PastureStack and `PASTURESTACK_*`. Compatibility i ## Docker host policy -Release `0.183.309` preserves the Docker host policy introduced in `0.183.299`, +Release `0.183.310` preserves the Docker host policy introduced in `0.183.299`, which adds Docker Engine `29.8.0` as an exact supported version alongside the preserved legacy ranges, `24.0.9`, and the existing `29.4.1` through `29.7.2` interval. It does not widen the interval to admit @@ -23,6 +23,15 @@ modifying another backend. Each of those modes needs runtime acceptance on the relevant host before a Server release that consumes this Engine is published as fully supported. +## External identity type upgrades + +`oidc_user` and `oidc_group` are built-in OpenID Connect identity types. An +older database setting may replace the packaged external-type list and omit +them, so release `0.183.310` always unions these two reviewed types into API +schema options and Engine validation. Other configured provider types remain +dynamic, unknown identity types remain rejected, and the external provider +must still be configured before any external identity can be transformed. + ## Browser token session ownership Web Console `1.6.117` and newer supplies a high-entropy client session @@ -71,8 +80,9 @@ cover both the dynamic overlay and the deserialized frozen snapshots. The reviewed external identity list includes `oidc_user` and `oidc_group` in addition to the established GitHub, Shibboleth, and LDAP types. The same dynamic setting drives project-member schema options and Engine validation; -environment overrides may replace the list for compatible deployments, but an -active external provider does not authorize arbitrary identity type strings. +environment overrides may extend or narrow provider-specific compatibility +types, but cannot remove the two built-in OIDC types. An active external +provider still does not authorize arbitrary identity type strings. The reviewed default list must be present in a `META-INF/cattle` defaults file that production Archaius startup actually loads; the installer-facing root `cattle-global.properties` alone is not a Java runtime configuration source. diff --git a/README.md b/README.md index d5aa0f4308..d538c63130 100644 --- a/README.md +++ b/README.md @@ -9,8 +9,8 @@ PastureStack is an independent community effort to preserve, audit, and moderniz ## Project status The current public GitHub Release -[`v0.183.309`](https://github.com/PastureStack/orchestration-engine/releases/tag/v0.183.309) -produces engine version `0.183.309`. It retains the existing Java 25, Ubuntu +[`v0.183.310`](https://github.com/PastureStack/orchestration-engine/releases/tag/v0.183.310) +produces engine version `0.183.310`. It retains the existing Java 25, Ubuntu 26.04, Maven, Liquibase, MariaDB/MySQL, WebSocket, dependency, concurrency, and runtime-hardening work from the maintained compatibility line. Release builds consume the exact `5.7.4` runtime JAR published by @@ -21,6 +21,14 @@ product identity and provenance are carried by the artifact name, metadata, SBOM, and release evidence. Provenance and scope are documented in [`third-party/HAZELCAST.md`](third-party/HAZELCAST.md). +Release `0.183.310` makes the two built-in OpenID Connect identity types +upgrade-safe. An older database can override the packaged external-type list +without `oidc_user` or `oidc_group`; token creation and project membership then +fail after the provider has already authenticated the user. Engine validation +and both API schema generations now union those two reviewed built-in types +with the dynamic list. Unknown types are still rejected, and no external +identity is accepted unless the external provider is configured. + Release `0.183.309` preserves the authenticated PastureStack operator credential when an administrator posts `/v1-auth/config`. Earlier releases replaced that credential with the external identity provider's access token; @@ -119,7 +127,7 @@ dependency line. The existing platform JSON surface remains on `com.fasterxml.jackson` 2.22. Packaging gates admit only the reviewed, version-pinned pair and verify that their class namespaces are disjoint. -Host compatibility is evidence-based. Release `0.183.309` preserves the legacy ranges and Docker Engine `24.0.9`, retains the bounded `29.4.1` through `29.7.2` interval, and supports exactly `29.8.0`. It does not admit unverified `29.7.3` or `29.8.1`, or Docker 25 through 28. The frontend marks versions above the configured newest version as *untested*, not *supported*. Every Server release that consumes this policy must still pass its Ubuntu 26.04 host and installed firewall-backend runtime acceptance gate. +Host compatibility is evidence-based. Release `0.183.310` preserves the legacy ranges and Docker Engine `24.0.9`, retains the bounded `29.4.1` through `29.7.2` interval, and supports exactly `29.8.0`. It does not admit unverified `29.7.3` or `29.8.1`, or Docker 25 through 28. The frontend marks versions above the configured newest version as *untested*, not *supported*. Every Server release that consumes this policy must still pass its Ubuntu 26.04 host and installed firewall-backend runtime acceptance gate. The build and Dapper images still compile the Docker `29.7.2` CLI from the pinned official tag commit with Go `1.27.0`; the CLI tool version is separate from the Docker daemon host support setting. They do not import Docker's precompiled Go `1.26.5` binary. The source archive SHA-256 and Go builder image digest are enforced by the source gate and the resulting images are scanned before release. @@ -167,7 +175,7 @@ The gate performs dependency-hygiene checks, builds every Maven module with JDK To create the complete release archive after the gate passes: ```sh -ENGINE_VERSION=0.183.309 bash scripts/build --release +ENGINE_VERSION=0.183.310 bash scripts/build --release bash scripts/check-release-artifact dist/artifacts/cattle.jar ``` diff --git a/code/framework/api-pub-sub-jetty/pom.xml b/code/framework/api-pub-sub-jetty/pom.xml index c527fa1033..22653d40b6 100644 --- a/code/framework/api-pub-sub-jetty/pom.xml +++ b/code/framework/api-pub-sub-jetty/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/api-pub-sub/pom.xml b/code/framework/api-pub-sub/pom.xml index e4eb8f25c8..1941c58f6b 100644 --- a/code/framework/api-pub-sub/pom.xml +++ b/code/framework/api-pub-sub/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/api/pom.xml b/code/framework/api/pom.xml index f46e4451a4..609cccb53b 100644 --- a/code/framework/api/pom.xml +++ b/code/framework/api/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/archaius/pom.xml b/code/framework/archaius/pom.xml index 88544227f7..f8e7b1b866 100644 --- a/code/framework/archaius/pom.xml +++ b/code/framework/archaius/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-meta-parent - 0.183.309 + 0.183.310 ../../meta-parent/pom.xml diff --git a/code/framework/async/pom.xml b/code/framework/async/pom.xml index bc1990ca6e..683d29dc11 100644 --- a/code/framework/async/pom.xml +++ b/code/framework/async/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/auditing/pom.xml b/code/framework/auditing/pom.xml index daf74f3226..1eaf741b60 100644 --- a/code/framework/auditing/pom.xml +++ b/code/framework/auditing/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/db-loader/pom.xml b/code/framework/db-loader/pom.xml index f6aff77c40..a75ba3fc76 100644 --- a/code/framework/db-loader/pom.xml +++ b/code/framework/db-loader/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/deferred/pom.xml b/code/framework/deferred/pom.xml index d63fcea093..702c544ea9 100644 --- a/code/framework/deferred/pom.xml +++ b/code/framework/deferred/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/encryption/pom.xml b/code/framework/encryption/pom.xml index fa497b4b9e..f87c096c41 100644 --- a/code/framework/encryption/pom.xml +++ b/code/framework/encryption/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/engine/pom.xml b/code/framework/engine/pom.xml index 0ffbf1f9e5..8ea3265ef7 100644 --- a/code/framework/engine/pom.xml +++ b/code/framework/engine/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/eventing/pom.xml b/code/framework/eventing/pom.xml index 299f43e0f7..26c51a9479 100644 --- a/code/framework/eventing/pom.xml +++ b/code/framework/eventing/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/events/pom.xml b/code/framework/events/pom.xml index 5e0a9b591b..af2d64dd6f 100644 --- a/code/framework/events/pom.xml +++ b/code/framework/events/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/extension-spring/pom.xml b/code/framework/extension-spring/pom.xml index ecbec48b13..7ed09b8d33 100644 --- a/code/framework/extension-spring/pom.xml +++ b/code/framework/extension-spring/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/extension/pom.xml b/code/framework/extension/pom.xml index 684188cdd6..def71632d8 100644 --- a/code/framework/extension/pom.xml +++ b/code/framework/extension/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/java-server/pom.xml b/code/framework/java-server/pom.xml index 54bfbe8bf7..0fdf849bc7 100644 --- a/code/framework/java-server/pom.xml +++ b/code/framework/java-server/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/jmx/pom.xml b/code/framework/jmx/pom.xml index bd71083c6e..788279516c 100644 --- a/code/framework/jmx/pom.xml +++ b/code/framework/jmx/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/jooq/pom.xml b/code/framework/jooq/pom.xml index b1e7804343..af51113d7a 100644 --- a/code/framework/jooq/pom.xml +++ b/code/framework/jooq/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/json/pom.xml b/code/framework/json/pom.xml index c9a2fbd143..bf0f839358 100644 --- a/code/framework/json/pom.xml +++ b/code/framework/json/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/launcher/pom.xml b/code/framework/launcher/pom.xml index ef272dc9cd..4ecfcced09 100644 --- a/code/framework/launcher/pom.xml +++ b/code/framework/launcher/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/lock/pom.xml b/code/framework/lock/pom.xml index b4068c3630..21e299b008 100644 --- a/code/framework/lock/pom.xml +++ b/code/framework/lock/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/logback/pom.xml b/code/framework/logback/pom.xml index b76460b0ed..59cc885d3f 100644 --- a/code/framework/logback/pom.xml +++ b/code/framework/logback/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-meta-parent - 0.183.309 + 0.183.310 ../../meta-parent/pom.xml diff --git a/code/framework/managed-context/pom.xml b/code/framework/managed-context/pom.xml index 1387e05dac..153ddb8e53 100644 --- a/code/framework/managed-context/pom.xml +++ b/code/framework/managed-context/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/metrics/pom.xml b/code/framework/metrics/pom.xml index eb6e138bbe..104b99f385 100644 --- a/code/framework/metrics/pom.xml +++ b/code/framework/metrics/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/module/pom.xml b/code/framework/module/pom.xml index 20f3dfbe20..ea21ae9417 100644 --- a/code/framework/module/pom.xml +++ b/code/framework/module/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/object/pom.xml b/code/framework/object/pom.xml index 84f252227c..78724f5348 100644 --- a/code/framework/object/pom.xml +++ b/code/framework/object/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/pool/pom.xml b/code/framework/pool/pom.xml index c609efd5c3..088ac2c73f 100644 --- a/code/framework/pool/pom.xml +++ b/code/framework/pool/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/resource-monitor/pom.xml b/code/framework/resource-monitor/pom.xml index 44e7904640..52b07673a1 100644 --- a/code/framework/resource-monitor/pom.xml +++ b/code/framework/resource-monitor/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/schema/pom.xml b/code/framework/schema/pom.xml index f99f2b5fbf..e6bf12361f 100644 --- a/code/framework/schema/pom.xml +++ b/code/framework/schema/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/schema/src/main/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessor.java b/code/framework/schema/src/main/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessor.java index acf8d2af49..1e77e3817b 100644 --- a/code/framework/schema/src/main/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessor.java +++ b/code/framework/schema/src/main/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessor.java @@ -11,12 +11,14 @@ import io.github.ibuildthecloud.gdapi.model.impl.SchemaImpl; import java.util.ArrayList; +import java.util.Arrays; import java.util.LinkedHashSet; import java.util.List; public class AuthSchemaAdditionsPostProcessor extends AbstractSchemaPostProcessor implements SchemaPostProcessor, Priority { private static final ConfigListProperty AUTH_SERVICE_EXTERNAL_ID_TYPES = ArchaiusUtil.getStringListProperty("auth.service.external.id.types"); + private static final List REQUIRED_OIDC_IDENTITY_TYPES = Arrays.asList("oidc_user", "oidc_group"); @Override public SchemaImpl postProcess(SchemaImpl schema, SchemaFactory factory) { @@ -31,6 +33,11 @@ public SchemaImpl postProcess(SchemaImpl schema, SchemaFactory factory) { if (configured != null) { options.addAll(configured); } + // A database setting created by an older release can override + // the packaged Archaius default. OIDC is a built-in provider, + // so its reviewed identity types must remain available after + // an in-place upgrade even when that stale override exists. + options.addAll(REQUIRED_OIDC_IDENTITY_TYPES); field.setOptions(new ArrayList(options)); } } diff --git a/code/framework/schema/src/test/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessorTest.java b/code/framework/schema/src/test/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessorTest.java index 84ef0a541f..758afb4a58 100644 --- a/code/framework/schema/src/test/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessorTest.java +++ b/code/framework/schema/src/test/java/io/cattle/platform/schema/processor/AuthSchemaAdditionsPostProcessorTest.java @@ -49,7 +49,7 @@ public void externalIdTypesReadDynamicListThroughWrapper() { new AuthSchemaAdditionsPostProcessor().postProcess(schema, null); - assertEquals(Arrays.asList("rancher_id", "ldap", "github"), field.getOptions()); + assertEquals(Arrays.asList("rancher_id", "ldap", "github", "oidc_user", "oidc_group"), field.getOptions()); } finally { if (ConfigurationManager.getConfigInstance().containsKey(key)) { ConfigurationManager.getConfigInstance().clearProperty(key); diff --git a/code/framework/server/pom.xml b/code/framework/server/pom.xml index 401c448eb6..365170aed0 100644 --- a/code/framework/server/pom.xml +++ b/code/framework/server/pom.xml @@ -4,7 +4,7 @@ cattle-meta-parent io.cattle - 0.183.309 + 0.183.310 ../../meta-parent/pom.xml diff --git a/code/framework/spring/pom.xml b/code/framework/spring/pom.xml index a52e4eace0..2c54749cf5 100644 --- a/code/framework/spring/pom.xml +++ b/code/framework/spring/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/system-task/pom.xml b/code/framework/system-task/pom.xml index 2f07168625..410961003f 100644 --- a/code/framework/system-task/pom.xml +++ b/code/framework/system-task/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/token/pom.xml b/code/framework/token/pom.xml index fbce320a1d..5dea066f64 100644 --- a/code/framework/token/pom.xml +++ b/code/framework/token/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/framework/utils/pom.xml b/code/framework/utils/pom.xml index 0971bcac12..c94b8753da 100644 --- a/code/framework/utils/pom.xml +++ b/code/framework/utils/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/agent-instance/pom.xml b/code/iaas/agent-instance/pom.xml index 876d00a9e4..f857f38494 100644 --- a/code/iaas/agent-instance/pom.xml +++ b/code/iaas/agent-instance/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/agent-server/pom.xml b/code/iaas/agent-server/pom.xml index dd37d4f287..f654711ab1 100644 --- a/code/iaas/agent-server/pom.xml +++ b/code/iaas/agent-server/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/agent/pom.xml b/code/iaas/agent/pom.xml index 8e43a4dec6..77565b61f0 100644 --- a/code/iaas/agent/pom.xml +++ b/code/iaas/agent/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/allocator/pom.xml b/code/iaas/allocator/pom.xml index 0a53d13bec..14f3005291 100644 --- a/code/iaas/allocator/pom.xml +++ b/code/iaas/allocator/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/api-logic/pom.xml b/code/iaas/api-logic/pom.xml index c1be61853d..378bcf59af 100644 --- a/code/iaas/api-logic/pom.xml +++ b/code/iaas/api-logic/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/archaius-management/pom.xml b/code/iaas/archaius-management/pom.xml index ddbde87c57..f828c774b0 100644 --- a/code/iaas/archaius-management/pom.xml +++ b/code/iaas/archaius-management/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/auth-logic/pom.xml b/code/iaas/auth-logic/pom.xml index f908b12672..6c03026bed 100644 --- a/code/iaas/auth-logic/pom.xml +++ b/code/iaas/auth-logic/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/identity/IdentityManager.java b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/identity/IdentityManager.java index e69ec3c667..94bc138468 100644 --- a/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/identity/IdentityManager.java +++ b/code/iaas/auth-logic/src/main/java/io/cattle/platform/iaas/api/auth/identity/IdentityManager.java @@ -24,6 +24,7 @@ import io.github.ibuildthecloud.gdapi.util.ResponseCodes; import java.util.ArrayList; +import java.util.Arrays; import java.util.Collection; import java.util.Collections; import java.util.HashSet; @@ -48,6 +49,8 @@ public class IdentityManager extends AbstractNoOpResourceManager { private static final Logger logger = LoggerFactory.getLogger(IdentityManager.class); private static final ConfigListProperty SUPPORTED_EXTERNAL_ID_TYPES = ArchaiusUtil.getStringListProperty("auth.service.external.id.types"); + private static final Set REQUIRED_OIDC_IDENTITY_TYPES = Collections.unmodifiableSet( + new HashSet(Arrays.asList("oidc_user", "oidc_group"))); private Map identityProviders; @@ -291,6 +294,14 @@ public Identity projectMemberToIdentity(Identity identity) { } protected boolean isSupportedExternalIdentityType(Identity identity) { - return identity != null && SUPPORTED_EXTERNAL_ID_TYPES.get().contains(identity.getExternalIdType()); + if (identity == null || identity.getExternalIdType() == null) { + return false; + } + String externalIdType = identity.getExternalIdType(); + if (REQUIRED_OIDC_IDENTITY_TYPES.contains(externalIdType)) { + return true; + } + List configured = SUPPORTED_EXTERNAL_ID_TYPES.get(); + return configured != null && configured.contains(externalIdType); } } diff --git a/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/identity/IdentityManagerExternalTypeTest.java b/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/identity/IdentityManagerExternalTypeTest.java index 9a81d3f43e..7f8885fa3d 100644 --- a/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/identity/IdentityManagerExternalTypeTest.java +++ b/code/iaas/auth-logic/src/test/java/io/cattle/platform/iaas/api/auth/identity/IdentityManagerExternalTypeTest.java @@ -53,6 +53,18 @@ public void acceptsSupportedOidcUserAndGroupTypes() { } } + @Test + public void acceptsOidcTypesWhenAnOlderDatabaseOverrideOmitsThem() { + ConfigurationManager.getConfigInstance().setProperty(TYPES, + "github_user,github_org,github_team,shibboleth_user,shibboleth_group,ldap_user,ldap_group"); + + for (String type : new String[] {"oidc_user", "oidc_group"}) { + Identity identity = new Identity(type, "subject"); + assertEquals(identity, manager.projectMemberToIdentity(identity)); + assertEquals(identity, manager.untransform(identity, true)); + } + } + @Test public void rejectsUnknownExternalTypeEvenWhenProviderIsConfigured() { Identity identity = new Identity("arbitrary_external_type", "subject"); diff --git a/code/iaas/bootstrap/pom.xml b/code/iaas/bootstrap/pom.xml index 043b9b1c57..bb610a4cdf 100644 --- a/code/iaas/bootstrap/pom.xml +++ b/code/iaas/bootstrap/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/config-item/api/pom.xml b/code/iaas/config-item/api/pom.xml index d88a8c6c8f..4acb58402e 100644 --- a/code/iaas/config-item/api/pom.xml +++ b/code/iaas/config-item/api/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/iaas/config-item/common/pom.xml b/code/iaas/config-item/common/pom.xml index c55e3b037c..7c7a75c04e 100644 --- a/code/iaas/config-item/common/pom.xml +++ b/code/iaas/config-item/common/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/iaas/config-item/server/pom.xml b/code/iaas/config-item/server/pom.xml index bc19322a43..f50f4b6f39 100644 --- a/code/iaas/config-item/server/pom.xml +++ b/code/iaas/config-item/server/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/iaas/engine-jooq/pom.xml b/code/iaas/engine-jooq/pom.xml index bf2e368945..e620d743af 100644 --- a/code/iaas/engine-jooq/pom.xml +++ b/code/iaas/engine-jooq/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/events/pom.xml b/code/iaas/events/pom.xml index 308c6c8d52..1a7f9d321c 100644 --- a/code/iaas/events/pom.xml +++ b/code/iaas/events/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/external-handler/pom.xml b/code/iaas/external-handler/pom.xml index 14f359046c..96ee56c5a0 100644 --- a/code/iaas/external-handler/pom.xml +++ b/code/iaas/external-handler/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/ha/pom.xml b/code/iaas/ha/pom.xml index 5a4cf22e32..c52f8181d0 100644 --- a/code/iaas/ha/pom.xml +++ b/code/iaas/ha/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/healthcheck/pom.xml b/code/iaas/healthcheck/pom.xml index d5099d2f0f..1e3217c682 100644 --- a/code/iaas/healthcheck/pom.xml +++ b/code/iaas/healthcheck/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/labels/pom.xml b/code/iaas/labels/pom.xml index 59d11fd775..dc3b9f9bb9 100644 --- a/code/iaas/labels/pom.xml +++ b/code/iaas/labels/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/logic-common/pom.xml b/code/iaas/logic-common/pom.xml index 9be0f3fb26..e6c050ead2 100644 --- a/code/iaas/logic-common/pom.xml +++ b/code/iaas/logic-common/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/logic/pom.xml b/code/iaas/logic/pom.xml index fd006629f3..3733d0b867 100644 --- a/code/iaas/logic/pom.xml +++ b/code/iaas/logic/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/metadata/pom.xml b/code/iaas/metadata/pom.xml index a6c186cd74..124c7188e8 100644 --- a/code/iaas/metadata/pom.xml +++ b/code/iaas/metadata/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/model/pom.xml b/code/iaas/model/pom.xml index 331c456999..432f2a4eae 100644 --- a/code/iaas/model/pom.xml +++ b/code/iaas/model/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/resource-pool/pom.xml b/code/iaas/resource-pool/pom.xml index 03710d5a5c..23a69c55da 100644 --- a/code/iaas/resource-pool/pom.xml +++ b/code/iaas/resource-pool/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/service-discovery/api/pom.xml b/code/iaas/service-discovery/api/pom.xml index 747b7aa329..181eac26a2 100644 --- a/code/iaas/service-discovery/api/pom.xml +++ b/code/iaas/service-discovery/api/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/iaas/service-discovery/server/pom.xml b/code/iaas/service-discovery/server/pom.xml index 649b274bcf..74e09a7125 100644 --- a/code/iaas/service-discovery/server/pom.xml +++ b/code/iaas/service-discovery/server/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/iaas/ssh-common/pom.xml b/code/iaas/ssh-common/pom.xml index a29d94d153..7701e319fd 100644 --- a/code/iaas/ssh-common/pom.xml +++ b/code/iaas/ssh-common/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/storage-service/pom.xml b/code/iaas/storage-service/pom.xml index 55c2b4d430..c0e2909cf6 100644 --- a/code/iaas/storage-service/pom.xml +++ b/code/iaas/storage-service/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/iaas/task-jooq/pom.xml b/code/iaas/task-jooq/pom.xml index 0172910764..d22a8e75a8 100644 --- a/code/iaas/task-jooq/pom.xml +++ b/code/iaas/task-jooq/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/activity-log/pom.xml b/code/implementation/activity-log/pom.xml index cc8f398015..1a1aba805e 100644 --- a/code/implementation/activity-log/pom.xml +++ b/code/implementation/activity-log/pom.xml @@ -5,7 +5,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/agent-instance-impl/pom.xml b/code/implementation/agent-instance-impl/pom.xml index d113cfd1bf..6766cf381b 100644 --- a/code/implementation/agent-instance-impl/pom.xml +++ b/code/implementation/agent-instance-impl/pom.xml @@ -3,7 +3,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml cattle-agent-instance-impl diff --git a/code/implementation/docker/api/pom.xml b/code/implementation/docker/api/pom.xml index 84df33f389..952a4a162d 100644 --- a/code/implementation/docker/api/pom.xml +++ b/code/implementation/docker/api/pom.xml @@ -5,7 +5,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/docker/common/pom.xml b/code/implementation/docker/common/pom.xml index 8c40a11533..8d609c189d 100644 --- a/code/implementation/docker/common/pom.xml +++ b/code/implementation/docker/common/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/docker/compute/pom.xml b/code/implementation/docker/compute/pom.xml index 1d9f7e0b07..bea4e4fca6 100644 --- a/code/implementation/docker/compute/pom.xml +++ b/code/implementation/docker/compute/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/docker/machine/pom.xml b/code/implementation/docker/machine/pom.xml index f80bd08e18..f75acda103 100644 --- a/code/implementation/docker/machine/pom.xml +++ b/code/implementation/docker/machine/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/docker/storage/pom.xml b/code/implementation/docker/storage/pom.xml index ba8e1c740b..3b50ae1c4c 100644 --- a/code/implementation/docker/storage/pom.xml +++ b/code/implementation/docker/storage/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml @@ -21,12 +21,12 @@ io.cattle cattle-docker-common - 0.183.309 + 0.183.310 io.cattle cattle-iaas-allocator - 0.183.309 + 0.183.310 diff --git a/code/implementation/extension-api/pom.xml b/code/implementation/extension-api/pom.xml index 06a6c3ca67..0a634e3308 100644 --- a/code/implementation/extension-api/pom.xml +++ b/code/implementation/extension-api/pom.xml @@ -3,7 +3,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml cattle-extension-api diff --git a/code/implementation/hazelcast/common/pom.xml b/code/implementation/hazelcast/common/pom.xml index e3fe0986c2..2f197b5b82 100644 --- a/code/implementation/hazelcast/common/pom.xml +++ b/code/implementation/hazelcast/common/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/hazelcast/eventing/pom.xml b/code/implementation/hazelcast/eventing/pom.xml index 3e9554fa7d..74feab69d5 100644 --- a/code/implementation/hazelcast/eventing/pom.xml +++ b/code/implementation/hazelcast/eventing/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/hazelcast/lock/pom.xml b/code/implementation/hazelcast/lock/pom.xml index cd8985a4ca..fb13473f8a 100644 --- a/code/implementation/hazelcast/lock/pom.xml +++ b/code/implementation/hazelcast/lock/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/host-api/pom.xml b/code/implementation/host-api/pom.xml index 03c70d472a..d710db94bc 100644 --- a/code/implementation/host-api/pom.xml +++ b/code/implementation/host-api/pom.xml @@ -5,7 +5,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/host-stats/pom.xml b/code/implementation/host-stats/pom.xml index 44cc2ec79c..79f6ddb6db 100644 --- a/code/implementation/host-stats/pom.xml +++ b/code/implementation/host-stats/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/register/pom.xml b/code/implementation/register/pom.xml index eee0f28eb6..b6337344a5 100644 --- a/code/implementation/register/pom.xml +++ b/code/implementation/register/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/sample-setup/pom.xml b/code/implementation/sample-setup/pom.xml index 073560ef00..8325308b3b 100644 --- a/code/implementation/sample-setup/pom.xml +++ b/code/implementation/sample-setup/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/settings-api/pom.xml b/code/implementation/settings-api/pom.xml index d0f73df000..bb51f586d0 100644 --- a/code/implementation/settings-api/pom.xml +++ b/code/implementation/settings-api/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/simulator/agent-connection/pom.xml b/code/implementation/simulator/agent-connection/pom.xml index afe3b732c5..842dd87b4b 100644 --- a/code/implementation/simulator/agent-connection/pom.xml +++ b/code/implementation/simulator/agent-connection/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/simulator/storage/pom.xml b/code/implementation/simulator/storage/pom.xml index de0b246356..4c51ee9428 100644 --- a/code/implementation/simulator/storage/pom.xml +++ b/code/implementation/simulator/storage/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../../parent/pom.xml diff --git a/code/implementation/system-stack/pom.xml b/code/implementation/system-stack/pom.xml index f46b4d68d9..6aeaa5de3a 100644 --- a/code/implementation/system-stack/pom.xml +++ b/code/implementation/system-stack/pom.xml @@ -5,7 +5,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/implementation/vm/pom.xml b/code/implementation/vm/pom.xml index af01a4554f..36f67c8615 100644 --- a/code/implementation/vm/pom.xml +++ b/code/implementation/vm/pom.xml @@ -3,7 +3,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml cattle-vm diff --git a/code/meta-parent/pom.xml b/code/meta-parent/pom.xml index 1ab09270e6..f781cd1535 100644 --- a/code/meta-parent/pom.xml +++ b/code/meta-parent/pom.xml @@ -9,7 +9,7 @@ 4.0.0 io.cattle cattle-meta-parent - 0.183.309 + 0.183.310 pom PastureStack Orchestration Engine Compatibility orchestration engine for the PastureStack server. diff --git a/code/packaging/app-config/pom.xml b/code/packaging/app-config/pom.xml index 3b18c02a11..cba14a3b55 100644 --- a/code/packaging/app-config/pom.xml +++ b/code/packaging/app-config/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml jar diff --git a/code/packaging/app/pom.xml b/code/packaging/app/pom.xml index 9b589eabdc..02ec43a4d4 100644 --- a/code/packaging/app/pom.xml +++ b/code/packaging/app/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml war diff --git a/code/packaging/bundle/pom.xml b/code/packaging/bundle/pom.xml index 7f5bc0bc91..b44d0240e1 100644 --- a/code/packaging/bundle/pom.xml +++ b/code/packaging/bundle/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/packaging/dev/pom.xml b/code/packaging/dev/pom.xml index dd97e17918..65b95985b9 100644 --- a/code/packaging/dev/pom.xml +++ b/code/packaging/dev/pom.xml @@ -4,7 +4,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/packaging/meta/pom.xml b/code/packaging/meta/pom.xml index c3527074ef..7dc1968fc4 100644 --- a/code/packaging/meta/pom.xml +++ b/code/packaging/meta/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../../parent/pom.xml diff --git a/code/parent/pom.xml b/code/parent/pom.xml index 7480b0c6b2..0813c81dd5 100644 --- a/code/parent/pom.xml +++ b/code/parent/pom.xml @@ -5,7 +5,7 @@ io.cattle cattle-meta-parent ../meta-parent/pom.xml - 0.183.309 + 0.183.310 pom diff --git a/docs/releases/orchestration-engine-0.183.310.md b/docs/releases/orchestration-engine-0.183.310.md new file mode 100644 index 0000000000..2a72e07731 --- /dev/null +++ b/docs/releases/orchestration-engine-0.183.310.md @@ -0,0 +1,18 @@ +# Orchestration Engine 0.183.310 + +- Treat `oidc_user` and `oidc_group` as reviewed built-in OpenID Connect + identity types even when an older database setting overrides the packaged + external identity list and omits them. +- Union the same built-in types into the `projectMember.externalIdType` options + published by both API generations, preserving stable order and eliminating + the runtime/schema mismatch. +- Retain the configured external-provider requirement and reject every unknown + external identity type. This is an upgrade compatibility repair, not a broad + identity-type bypass. +- Add focused tests for the stale-database override, normal OIDC identities, + unknown identity rejection, and schema option publication. + +Older database overrides that omit the built-in OIDC identity types are covered +by both the token/membership validation path and the public schema path. Server +consumers must also include Authentication Service `v0.4.42`, which reconciles +the non-secret provider contract before the final token exchange. diff --git a/pom.xml b/pom.xml index 2929d3f008..c4bdb81009 100644 --- a/pom.xml +++ b/pom.xml @@ -3,7 +3,7 @@ io.cattle cattle-parent - 0.183.309 + 0.183.310 code/parent/pom.xml cattle diff --git a/resources/pom.xml b/resources/pom.xml index 2172451729..b4f799a797 100644 --- a/resources/pom.xml +++ b/resources/pom.xml @@ -4,7 +4,7 @@ cattle-parent io.cattle - 0.183.309 + 0.183.310 ../code/parent/pom.xml diff --git a/scripts/build b/scripts/build index 006df0bfa7..ddb38e2965 100755 --- a/scripts/build +++ b/scripts/build @@ -16,7 +16,7 @@ fi SOURCE_REVISION=${SOURCE_REVISION:-$(git rev-parse HEAD)} SOURCE_DATE_EPOCH=${SOURCE_DATE_EPOCH:-$(git show -s --format=%ct HEAD)} -ENGINE_VERSION=${ENGINE_VERSION:-0.183.309} +ENGINE_VERSION=${ENGINE_VERSION:-0.183.310} case "$SOURCE_REVISION" in ''|*[!0-9a-f]*) diff --git a/scripts/check-pasturestack-source b/scripts/check-pasturestack-source index a5869d3282..777aed1d0c 100755 --- a/scripts/check-pasturestack-source +++ b/scripts/check-pasturestack-source @@ -51,7 +51,7 @@ fi project_version=$(sed -n 's/^[[:space:]]*\([^<]*\)<\/version>[[:space:]]*$/\1/p' code/meta-parent/pom.xml | head -n 1) [[ "$project_version" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]] || fail non_numeric_project_version -require_line code/meta-parent/pom.xml ' 0.183.309' +require_line code/meta-parent/pom.xml ' 0.183.310' require_line "$iaas_api_defaults" 'auth.service.external.id.types=github_user,github_org,github_team,shibboleth_user,shibboleth_group,ldap_user,ldap_group,oidc_user,oidc_group' require_line code/meta-parent/pom.xml ' https://github.com/PastureStack/orchestration-engine' require_line Dockerfile 'FROM ubuntu:26.04@sha256:2260313b31c8c011cd2eebe728008efac1b3982be73eb71348ea2648d2c0e09b' @@ -168,7 +168,7 @@ require_line code/packaging/app-config/src/main/java/io/cattle/platform/app/Type require_line code/framework/schema/src/test/java/io/cattle/platform/schema/processor/TokenSessionAuthOverlayTest.java ' public void clientSessionIdSurvivesAuthorizationAsCreateOnlyInput() throws Exception {' require_line resources/src/test/java/io/cattle/platform/resources/FrozenTokenSessionSchemaTest.java ' public void everyFrozenSchemaWithTokenAcceptsClientSessionIdOnlyOnCreate()' require_line resources/src/test/java/io/cattle/platform/resources/FrozenTokenSessionSchemaTest.java ' assertNotNull(schemaFile + " lacks token.clientSessionId", clientSessionId);' -require_line docs/releases/orchestration-engine-0.183.309.md 'Server consumers must verify a bound OIDC policy confirmation through the public' +require_line docs/releases/orchestration-engine-0.183.310.md 'Older database overrides that omit the built-in OIDC identity types are covered' require_line code/iaas/api-logic/src/main/java/io/cattle/platform/iaas/api/request/handler/GenericWhitelistedProxy.java ' return !("POST".equalsIgnoreCase(method) && "/v1-auth/config".equals(path));' require_line code/iaas/api-logic/src/test/java/io/cattle/platform/iaas/api/request/handler/GenericWhitelistedProxyTest.java ' public void preservesPlatformAuthorizationForAuthenticationConfigUpdates() {' require_line code/packaging/app-config/src/test/java/io/cattle/platform/app/TypesConfigTest.java ' public void coreSchemaWaitsForConfigurationAndPublishesOidcProjectMemberTypes() {' @@ -361,4 +361,4 @@ fi require_line README.md 'PastureStack is an independent community effort to preserve, audit, and modernize the Rancher 1.6 ecosystem. It is not affiliated with or endorsed by Rancher Labs or SUSE.' require_line ORIGIN.md '- Preserved upstream boundary: `82d154a53f4089fecfb9f320caad826bb4f6055f`' -printf 'PASTURESTACK_SOURCE_GATE_OK version=0.183.309 runtime_sources=github_release images=digest_pinned ubuntu=26.04 ubuntu_snapshot=20260826T000000Z jdk=25.0.4 maven=3.9.16 patched_hazelcast=5.7.4 docker_cli=29.7.2 docker_host_29_8_0=exact credential_secret_capacity=mediumtext port_preflight=authoritative volume_preflight=runtime_resolution_aligned volume_preflight_project_schema=authorized volume_preflight_type_set=registered v1_hardware_schema=container-and-launchConfig network_driver_rollback=launch-config-restored stack_driver_rollback=child-launch-config-restored auth_token_session_binding=authorized-create-only auth_token_transport=bare-or-bearer-normalized auth_token_frozen_v1_schema=base-superadmin-token oidc_external_types=packaged-runtime-defaults-startup-ordered-deduplicated-reviewed-allowlist mfa_policy_confirmation=actor-purpose-digest-single-use auth_config_proxy_identity=caller-platform-credential\n' +printf 'PASTURESTACK_SOURCE_GATE_OK version=0.183.310 runtime_sources=github_release images=digest_pinned ubuntu=26.04 ubuntu_snapshot=20260826T000000Z jdk=25.0.4 maven=3.9.16 patched_hazelcast=5.7.4 docker_cli=29.7.2 docker_host_29_8_0=exact credential_secret_capacity=mediumtext port_preflight=authoritative volume_preflight=runtime_resolution_aligned volume_preflight_project_schema=authorized volume_preflight_type_set=registered v1_hardware_schema=container-and-launchConfig network_driver_rollback=launch-config-restored stack_driver_rollback=child-launch-config-restored auth_token_session_binding=authorized-create-only auth_token_transport=bare-or-bearer-normalized auth_token_frozen_v1_schema=base-superadmin-token oidc_external_types=packaged-runtime-defaults-plus-builtins-upgrade-safe mfa_policy_confirmation=actor-purpose-digest-single-use auth_config_proxy_identity=caller-platform-credential\n' diff --git a/scripts/check-release-artifact b/scripts/check-release-artifact index b9ed846575..24360de9ac 100755 --- a/scripts/check-release-artifact +++ b/scripts/check-release-artifact @@ -4,7 +4,7 @@ set -euo pipefail cd "$(dirname "$0")/.." artifact=${1:-dist/artifacts/cattle.jar} -expected_version=${EXPECTED_ENGINE_VERSION:-0.183.309} +expected_version=${EXPECTED_ENGINE_VERSION:-0.183.310} test -f "$artifact" artifact=$(realpath "$artifact")