|
|
|
|
|
by theptip
1545 days ago
|
|
Thanks for doing the issue sleuthing. This is an excruciatingly bad look. You'd have thought with all the code-owner functionality that GL has, they would lock down the `/lib/gitlab/auth/` files to require a security engineer to give additional signoff on top of a normal review. It looks like anyone at Gitlab can approve changes to the auth code (except LDAP): https://gitlab.com/gitlab-org/gitlab/-/blob/master/.gitlab/C... which is terrifying if true. |
|
Like this?
> cc @gitlab-com/gl-security/appsec
https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318#...
I do so desperately hope it doesn't come across as throwing shade, because hindsight-2020-etc, but I do also think there was some kind of weird process breakdown here because this change somehow slipped past a "4 eyes" and an appsec review phase