Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions charts/cofide-connect/templates/configmap-envoy.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -230,15 +230,15 @@ data:
- san_type: URI
matcher:
safe_regex:
regex: spiffe://[^/]*/ns/cofide/sa/cofide-agent
regex: spiffe://[^/]+/cluster/[\w-]+/ns/cofide/sa/cofide-agent

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The regex for matching the cluster name, [\w-]+, is quite permissive. It allows names that start or end with a hyphen or underscore (e.g., -cluster or cluster_), which can be problematic if these names are used in contexts with stricter validation like DNS. It's better to use a more restrictive regex that enforces a standard naming convention, disallowing leading or trailing separators.

                                regex: spiffe://[^/]+/cluster/[a-zA-Z0-9](?:[a-zA-Z0-9_-]*[a-zA-Z0-9])?/ns/cofide/sa/cofide-agent

- san_type: URI
matcher:
safe_regex:
regex: spiffe://[^/]*/spire/server
- san_type: URI
matcher:
safe_regex:
regex: spiffe://[^/]*/ns/cofide/sa/cofide-observer
regex: spiffe://[^/]+/cluster/[\w-]+/ns/cofide/sa/cofide-observer

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The regex for matching the cluster name, [\w-]+, is quite permissive. It allows names that start or end with a hyphen or underscore (e.g., -cluster or cluster_), which can be problematic if these names are used in contexts with stricter validation like DNS. It's better to use a more restrictive regex that enforces a standard naming convention, disallowing leading or trailing separators.

                                regex: spiffe://[^/]+/cluster/[a-zA-Z0-9](?:[a-zA-Z0-9_-]*[a-zA-Z0-9])?/ns/cofide/sa/cofide-observer

validation_context_sds_secret_config:
name: ALL
sds_config:
Expand Down
Loading