-
Notifications
You must be signed in to change notification settings - Fork 103
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Revert "update file permissions to read/write (#751)" #755
Conversation
This reverts commit 022150f.
the file should be 0600, not 0700
I also removed most of the constants like |
Co-authored-by: James Belleau <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Tested Locally and file permissions match as expected. Great catch on the screaming snake case.
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [common-fate/granted](https://github.com/common-fate/granted) | minor | `v0.33.0` -> `v0.35.1` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>common-fate/granted (common-fate/granted)</summary> ### [`v0.35.1`](https://github.com/common-fate/granted/releases/tag/v0.35.1) [Compare Source](common-fate/granted@v0.35.0...v0.35.1) This release includes bug fixes for the RDS plugin. #### What's Changed - Remove Grant is activated message, use new Grant Output API by [@​JoshuaWilkes](https://github.com/JoshuaWilkes) in common-fate/granted#769 - Improve how RDS proxy command handles grant expiry and proxy connection errors by [@​JoshuaWilkes](https://github.com/JoshuaWilkes) in common-fate/granted#770 **Full Changelog**: common-fate/granted@v0.35.0...v0.35.1 ### [`v0.35.0`](https://github.com/common-fate/granted/releases/tag/v0.35.0) [Compare Source](common-fate/granted@v0.34.1...v0.35.0) #### AWS IAM Identity Center phishing protection ![Frame 13](https://github.com/user-attachments/assets/4e315c6c-694f-45bf-84bc-7f56f1df47d2) This release adds support for the new [Granted browser extension for Chrome](https://chromewebstore.google.com/detail/granted/cjjieeldgoohbkifkogalkmfpddeafcm), which confirms the user code automatically when logging in to AWS IAM Identity Center. This makes authenticating faster and protects against being phished for your AWS credentials. [Read more in our announcement blog post here.](https://www.commonfate.io/blog/granted-mitigates-aws-phishing). [Follow our install guide here to get set up with Granted.](https://docs.commonfate.io/granted/getting-started) #### What's Changed - add fixes to setting custom browser by [@​meyerjrr](https://github.com/meyerjrr) in common-fate/granted#760 - Fix the version output when running `assume -v` by [@​chrnorm](https://github.com/chrnorm) in common-fate/granted#762 - Added support for manual setting of PassDir to avoid pass password pollution in default location by [@​VigneshSelvaraj96](https://github.com/VigneshSelvaraj96) in common-fate/granted#761 - Add apigw -> apigateway service shortcut by [@​alexjurkiewicz](https://github.com/alexjurkiewicz) in common-fate/granted#763 - Add AWS IAM Identity Center device code flow automation by [@​chrnorm](https://github.com/chrnorm) in common-fate/granted#765 #### New Contributors - [@​VigneshSelvaraj96](https://github.com/VigneshSelvaraj96) made their first contribution in common-fate/granted#761 **Full Changelog**: common-fate/granted@v0.34.2...v0.35.0 ### [`v0.34.1`](https://github.com/common-fate/granted/releases/tag/v0.34.1) [Compare Source](common-fate/granted@v0.34.0...v0.34.1) This release fixes a folder permissions issue introduced in v0.34.0, and fixes an issue with using `assume -s ram` to open Resource Access Manager. A big thankyou to contributors [@​jpbelleau](https://github.com/jpbelleau) and [@​wayne-folkes](https://github.com/wayne-folkes). #### What's Changed - Add RAM (Resource Access Manager) by [@​wayne-folkes](https://github.com/wayne-folkes) in common-fate/granted#757 - Revert "update file permissions to read/write ([#​751](common-fate/granted#751))" by [@​chrnorm](https://github.com/chrnorm) and [@​jpbelleau](https://github.com/jpbelleau) in common-fate/granted#755 **Full Changelog**: common-fate/granted@v0.34.0...v0.34.1 ### [`v0.34.0`](https://github.com/common-fate/granted/releases/tag/v0.34.0) [Compare Source](common-fate/granted@v0.33.0...v0.34.0) #### What's Changed - Sort sso profiles by profile name by [@​shwethaumashanker](https://github.com/shwethaumashanker) in common-fate/granted#733 - Fix using default duration on auto approved requests by [@​meyerjrr](https://github.com/meyerjrr) in common-fate/granted#748 - Update file permissions to read/write by [@​meyerjrr](https://github.com/meyerjrr) in common-fate/granted#751 - Implement custom templated launch for sso browser option by [@​meyerjrr](https://github.com/meyerjrr) in common-fate/granted#750 **Full Changelog**: common-fate/granted@v0.33.0...v0.34.0 </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40NDAuNyIsInVwZGF0ZWRJblZlciI6IjM3LjQ0MC43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiXX0=-->
What changed?
Reverts the change made in #751.
Why?
#751 incorrectly removed the executable flag on some of the directories created by Granted. The execute flag is required. Additionally, the PR relaxed some of the permissions from
0600
to0644
which allows users other than the current one to read the various config and frecency files. Given that we've never had a permissions issue opened due to a use case where0644
is required, I think this is too permissive.How did you test it?
Build the CLI locally:
Move the
~/.dgranted
folder:Run
dassume
, which will run through the onboarding wizard.Confirm that the
config
file is not executable and has the expected permissions:Potential risks
Low, as we are reverting a known issue in the new release.
Is patch release candidate?
Yes
Link to relevant docs PRs