Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

@SecureField add expression support #36804

Closed
Serkan80 opened this issue Oct 31, 2023 · 5 comments · Fixed by #37204
Closed

@SecureField add expression support #36804

Serkan80 opened this issue Oct 31, 2023 · 5 comments · Fixed by #37204
Labels
area/security kind/enhancement New feature or request
Milestone

Comments

@Serkan80
Copy link

Serkan80 commented Oct 31, 2023

Description

Currenty @SecureField only supports hardcoded roles and it would be nice if this could be aligned with how @RolesAllowed works, namely with expressions support.

This also causes problems in combination with @RolesAllowed when the latter uses expressions and when the app is deployed on certain environments then the dynamic role is not available in SecureField.

If implemented, then please make this also available on the LTS version.

Implementation ideas

This should be possible:

@SecureField(roles=‘${maintainer.role}’, ‘roleA’)

Copy link

quarkus-bot bot commented Oct 31, 2023

/cc @pedroigor (bearer-token)

@michalvavrik
Copy link
Member

If implemented, then please make this also available on the LTS version.

Sorry, probably not possible. I think new feature like this does not qualify for backports.

@geoand
Copy link
Contributor

geoand commented Nov 20, 2023

I think new feature like this does not qualify for backports.

I definitely agree

@quarkus-bot quarkus-bot bot added this to the 3.7 - main milestone Nov 20, 2023
@Serkan80
Copy link
Author

If implemented, then please make this also available on the LTS version.

Sorry, probably not possible. I think new feature like this does not qualify for backports.

I thought that security fixes & enhancements would also be backported to the LTS version ?

Anyways, thx for the effort for implementing this feature! Very appreciated !

@geoand
Copy link
Contributor

geoand commented Nov 21, 2023

This is a new feature, not a fix for a security issue

@gsmet gsmet modified the milestones: 3.7 - main, 3.6.0 Nov 21, 2023
benkard pushed a commit to benkard/mulkcms2 that referenced this issue Dec 2, 2023
This MR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [flow-bin](https://github.com/flowtype/flow-bin) ([changelog](https://github.com/facebook/flow/blob/master/Changelog.md)) | devDependencies | minor | [`^0.222.0` -> `^0.223.0`](https://renovatebot.com/diffs/npm/flow-bin/0.222.0/0.223.2) |
| [io.quarkus:quarkus-maven-plugin](https://github.com/quarkusio/quarkus) | build | minor | `3.5.3` -> `3.6.0` |
| [io.quarkus:quarkus-universe-bom](https://github.com/quarkusio/quarkus-platform) | import | minor | `3.5.3` -> `3.6.0` |

---

### Release Notes

<details>
<summary>flowtype/flow-bin</summary>

### [`v0.223.2`](flow/flow-bin@5bb7bcf...6e1e3f7)

[Compare Source](flow/flow-bin@5bb7bcf...6e1e3f7)

### [`v0.223.0`](flow/flow-bin@84a68f1...5bb7bcf)

[Compare Source](flow/flow-bin@84a68f1...5bb7bcf)

</details>

<details>
<summary>quarkusio/quarkus</summary>

### [`v3.6.0`](https://github.com/quarkusio/quarkus/releases/tag/3.6.0)

[Compare Source](quarkusio/quarkus@3.5.3...3.6.0)

##### Major changes

-   [#&#8203;37241](quarkusio/quarkus#37241) - Make improvements to REST Client SSE handling

##### Complete changelog

-   [#&#8203;37242](quarkusio/quarkus#37242) - Support Docker Desktop for building native executables
-   [#&#8203;37241](quarkusio/quarkus#37241) - Make improvements to REST Client SSE handling
-   [#&#8203;37240](quarkusio/quarkus#37240) - Updates Infinispan to 14.0.21.Final
-   [#&#8203;37238](quarkusio/quarkus#37238) - Build cache - Only store if the access key is around
-   [#&#8203;37236](quarkusio/quarkus#37236) - Api to read minimum and recommended Java versions from catalog metadata
-   [#&#8203;37221](quarkusio/quarkus#37221) - Image updates (including Java 21 base image)
-   [#&#8203;37218](quarkusio/quarkus#37218) - Fix OpenTelemetry trace exclusion of endpoints served from the management interface
-   [#&#8203;37213](quarkusio/quarkus#37213) - Add basic Range header support
-   [#&#8203;37205](quarkusio/quarkus#37205) - Resteasy-reactive Partial Content support (Range: bytes http header)
-   [#&#8203;37204](quarkusio/quarkus#37204) - Allow to define allowed roles as configuration expressions inside `@SecureField` annotation
-   [#&#8203;37201](quarkusio/quarkus#37201) - Fixed sample code for KotlinModule initialization
-   [#&#8203;37198](quarkusio/quarkus#37198) - Some minor refinements for build scans
-   [#&#8203;37193](quarkusio/quarkus#37193) - AccessDeniedException error with build using native image on linux with Docker Desktop
-   [#&#8203;37185](quarkusio/quarkus#37185) - Removed DependencyFlags.REMOVED
-   [#&#8203;37170](quarkusio/quarkus#37170) - Fix snapshots following a collision of pull requests
-   [#&#8203;37166](quarkusio/quarkus#37166) - Support custom Authorization schemes for OIDC bearer tokens
-   [#&#8203;37162](quarkusio/quarkus#37162) - Bump org.apache.commons:commons-text from 1.10.0 to 1.11.0
-   [#&#8203;37161](quarkusio/quarkus#37161) - Bump io.quarkus:quarkus-platform-bom-maven-plugin from 0.0.97 to 0.0.99
-   [#&#8203;37158](quarkusio/quarkus#37158) - Bump com.unboundid:unboundid-ldapsdk from 6.0.9 to 6.0.10
-   [#&#8203;37153](quarkusio/quarkus#37153) - Bump smallrye-jwt version to 4.4.0
-   [#&#8203;37149](quarkusio/quarkus#37149) - Bump com.squareup.okio:okio from 1.17.2 to 1.17.6 in /bom/application
-   [#&#8203;37107](quarkusio/quarkus#37107) - Rest client able to get full SSE event
-   [#&#8203;37101](quarkusio/quarkus#37101) - Remove `smallrye-opentracing` from native tests modules in CI
-   [#&#8203;37094](quarkusio/quarkus#37094) - Bump jakarta.json:jakarta.json-api from 2.1.2 to 2.1.3
-   [#&#8203;37092](quarkusio/quarkus#37092) - Bump mongo-client.version from 4.11.0 to 4.11.1
-   [#&#8203;37067](quarkusio/quarkus#37067) - SmallRye GraphQL 2.6 + custom scalar registration
-   [#&#8203;37053](quarkusio/quarkus#37053) - Clarify dynamic Environment Variables name conversion
-   [#&#8203;37004](quarkusio/quarkus#37004) - Move failsafe config to the root instead of in an execution
-   [#&#8203;36976](quarkusio/quarkus#36976) - Error in JBossLoggerFinder during integration test
-   [#&#8203;36804](quarkusio/quarkus#36804) - `@SecureField` add expression support
-   [#&#8203;36801](quarkusio/quarkus#36801) - Add note that endpointdisabled does not work native
-   [#&#8203;36746](quarkusio/quarkus#36746) - Allow using a random test port within Google Cloud Function tests
-   [#&#8203;35476](quarkusio/quarkus#35476) - Random test port does not work together with google-cloud-functions extensions

</details>

<details>
<summary>quarkusio/quarkus-platform</summary>

### [`v3.6.0`](quarkusio/quarkus-platform@3.5.3...3.6.0)

[Compare Source](quarkusio/quarkus-platform@3.5.3...3.6.0)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This MR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4yNC4wIiwidXBkYXRlZEluVmVyIjoiMzQuMjQuMCJ9-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/security kind/enhancement New feature or request
Projects
None yet
5 participants