Skip to content

Commit e588be5

Browse files
committed
Added: release notes for #11689
1 parent 543bc7c commit e588be5

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
## Security improvements for `api-bearer-auth-use-builtin-user-on-id-match`
2+
3+
We’ve strengthened the security of the `api-bearer-auth-use-builtin-user-on-id-match` feature flag. It will now only work when the provided bearer token includes an `idp` claim that matches the Keycloak Service Provider identifier.
4+
5+
By enforcing this check, the risk of impersonation from other identity providers is significantly reduced, since they would need to be explicitly configured with this specific, non-standard identifier.
6+
7+
See:
8+
- [#11622 (comment)](https://github.com/IQSS/dataverse/pull/11622#discussion_r2216017175)
9+
- [#11689](https://github.com/IQSS/dataverse/issues/11689)

0 commit comments

Comments
 (0)