Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

User able to surpass LDAP group requirement with a cookie #10

Closed
Dom-nik opened this issue Apr 26, 2016 · 1 comment
Closed

User able to surpass LDAP group requirement with a cookie #10

Dom-nik opened this issue Apr 26, 2016 · 1 comment

Comments

@Dom-nik
Copy link

Dom-nik commented Apr 26, 2016

I've just noted that after enabling LDAPAuthenticator.allowed_groups, one user who was not included in the application group was still able to login, probably based on a cookie/browser cache. When the user tried to login from within a private window it didn't succeed, but with a regular browser window login was not required. It seems to be a (minor) security breach.

@yuvipanda
Copy link
Collaborator

Yep - all cookies signed prior to enabling this would probably still be valid. I think rotating the secret key (jupyterhub_cookie_secret file) should fix it.

Thanks for reporting it! I'll add this to the README!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants