Skip to content

Conversation

@gergosimonyi
Copy link
Collaborator

@gergosimonyi gergosimonyi commented Apr 11, 2025

The goal of this is to prevent a brute force attack on a very high reputation (identifier, ip) tuple.

Note: reputation scores will stay the same when the tenant-wide limit is changed, so it is possible to temporarily have a score violating a newly set limit, until the score is first updated.

@gergosimonyi gergosimonyi requested review from a team as code owners April 11, 2025 10:44
@netlify
Copy link

netlify bot commented Apr 11, 2025

Deploy Preview for authentik-docs canceled.

Name Link
🔨 Latest commit 9b835d3
🔍 Latest deploy log https://app.netlify.com/sites/authentik-docs/deploys/67fd15198f21a500082aa297

@netlify
Copy link

netlify bot commented Apr 11, 2025

Deploy Preview for authentik-storybook ready!

Name Link
🔨 Latest commit 9b835d3
🔍 Latest deploy log https://app.netlify.com/sites/authentik-storybook/deploys/67fd15199175df000813cfd0
😎 Deploy Preview https://deploy-preview-14008--authentik-storybook.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@codecov
Copy link

codecov bot commented Apr 11, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 92.73%. Comparing base (ae36429) to head (9b835d3).
Report is 20 commits behind head on main.

✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #14008      +/-   ##
==========================================
+ Coverage   92.72%   92.73%   +0.01%     
==========================================
  Files         796      796              
  Lines       40927    40975      +48     
==========================================
+ Hits        37951    38000      +49     
+ Misses       2976     2975       -1     
Flag Coverage Δ
e2e 47.92% <37.14%> (-0.02%) ⬇️
integration 24.17% <20.00%> (-0.01%) ⬇️
unit 90.52% <100.00%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions
Copy link
Contributor

github-actions bot commented Apr 11, 2025

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-9b835d386bea867ecf834b1ae8f725d7b1be714d
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-9b835d386bea867ecf834b1ae8f725d7b1be714d

Afterwards, run the upgrade commands from the latest release notes.

@rissson rissson changed the title policies/reputation: limit reputaiton score policies/reputation: limit reputation score Apr 11, 2025
@gergosimonyi gergosimonyi force-pushed the policies/reputation/limit-reputaiton-score branch from e438f37 to 197f140 Compare April 11, 2025 11:38
@gergosimonyi gergosimonyi requested a review from rissson April 14, 2025 09:07
label=${msg("Reputation: lower limit")}
required
name="reputationLowerLimit"
value="${first(this._settings?.reputationLowerLimit, -5)}"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@gergosimonyi

Nit: this will set off a linter warning soon for “magic numbers”. Recommend moving it into a constant.

Is it too much to ask for a world in which I can just import these
straight from Python?
@gergosimonyi gergosimonyi enabled auto-merge (squash) April 14, 2025 14:02
@gergosimonyi gergosimonyi merged commit edf3300 into main Apr 14, 2025
86 checks passed
@gergosimonyi gergosimonyi deleted the policies/reputation/limit-reputaiton-score branch April 14, 2025 14:19
kensternberg-authentik added a commit that referenced this pull request Apr 15, 2025
* main: (1461 commits)
  core: bump google-auth from 2.38.0 to v2.39.0 (#14076)
  core: bump sentry-sdk from 2.25.1 to v2.26.1 (#14079)
  core: bump prompt-toolkit from 3.0.50 to v3.0.51 (#14078)
  core: bump boto3 from 1.37.33 to v1.37.34 (#14074)
  core: bump msgraph-sdk from 1.27.0 to v1.28.0 (#14077)
  website/docs: fix minor typo in working_with_policies.md (#14071)
  core, web: update translations (#14064)
  stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#14065)
  core: bump goauthentik.io/api/v3 from 3.2025024.4 to 3.2025024.6 (#14069)
  Small fix for Actual-Budget wiki guide (#14066)
  root: support db pool (#13534)
  rbac: add `InitialPermissions` (#13795)
  web: bump API Client version (#14058)
  core: Bump django from 5.0.14 to 5.1.8 (#14059)
  core: bump django-rest-framework from 3.14.0 to 3.16.0 (#14057)
  policies/reputation: limit reputation score (#14008)
  ci: fix api-py-publish by disabling poetry cache (#14010)
  core: bump goauthentik/fips-python from 3.12.9-slim-bookworm-fips to 3.12.10-slim-bookworm-fips (#14044)
  ci: add NPM packages publish (#13974)
  root: add packages/ to codeowners (#13975)
  ...
kensternberg-authentik added a commit that referenced this pull request Apr 25, 2025
* main: (93 commits)
  core: bump google-auth from 2.38.0 to v2.39.0 (#14076)
  core: bump sentry-sdk from 2.25.1 to v2.26.1 (#14079)
  core: bump prompt-toolkit from 3.0.50 to v3.0.51 (#14078)
  core: bump boto3 from 1.37.33 to v1.37.34 (#14074)
  core: bump msgraph-sdk from 1.27.0 to v1.28.0 (#14077)
  website/docs: fix minor typo in working_with_policies.md (#14071)
  core, web: update translations (#14064)
  stages/authenticator_webauthn: Update FIDO MDS3 & Passkey aaguid blobs (#14065)
  core: bump goauthentik.io/api/v3 from 3.2025024.4 to 3.2025024.6 (#14069)
  Small fix for Actual-Budget wiki guide (#14066)
  root: support db pool (#13534)
  rbac: add `InitialPermissions` (#13795)
  web: bump API Client version (#14058)
  core: Bump django from 5.0.14 to 5.1.8 (#14059)
  core: bump django-rest-framework from 3.14.0 to 3.16.0 (#14057)
  policies/reputation: limit reputation score (#14008)
  ci: fix api-py-publish by disabling poetry cache (#14010)
  core: bump goauthentik/fips-python from 3.12.9-slim-bookworm-fips to 3.12.10-slim-bookworm-fips (#14044)
  ci: add NPM packages publish (#13974)
  root: add packages/ to codeowners (#13975)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants