- Shipped
- September 28, 2026 at 10:15 AM UTC
- Author
- Kamo
- Commit
- 96bebee
The javadoc said /api/internal/dav/sign-in was reached over ClusterIP, as if that were the only way in. It is not: klusterservices **************** routes internal.<domain>/desktop-ws/* to kamowssecurity-service with the prefix stripped, so **************** reaches this method from the internet (a read-only GET there today gets SecurityService's own 404 for the stripped path). The code already holds: X-Internal-Auth is compared in constant time before any credential is checked. The javadoc now says so, names both paths, and forbids relaxing the gate on where a request seems to come from. Two tests send a request shaped as the edge route delivers it (Traefik's cluster remote address, X-Forwarded-Prefix, client-chosen forwarded headers) with no secret and with wrong ones: 403, and the check is never called. A mutation that trusts a 10.* remote address fails exactly these two tests.
