-
Notifications
You must be signed in to change notification settings - Fork 33
fix(sdk)!: reclassify KAS 400 errors — distinguish tamper from misconfiguration #3166
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
12 commits
Select commit
Hold shift + click to select a range
e5144c5
fix(sdk): reclassify ErrRewrapBadRequest away from ErrTampered
marythought c968853
fix(sdk): wrap ErrRewrapForbidden under ErrKASRequestError
marythought 3464e5d
fix(sdk): distinguish policy binding tamper from KAS misconfiguration
marythought a3dbdae
Revert "fix(sdk): distinguish policy binding tamper from KAS misconfi…
marythought bdd77f0
fix(sdk): use descriptive KAS errors for misconfiguration, keep gener…
marythought 3dd9479
chore(docs): add security comments explaining generic vs descriptive …
marythought 3571082
fix(kas): keep generic error for corrupted policy and malformed binding
marythought 3a40427
chore(sdk): add shared constant for generic KAS error and expand tests
marythought 2b15967
docs(docs): add instructions for running xtests against feature branches
marythought 311f2db
fix(sdk): anchor tamper detection to gRPC desc prefix and harden erro…
marythought 48214c2
fix(kas): preserve per-KAO tamper signals on policy decode failure
marythought 8ec8182
fix(sdk): un-nest ErrRewrapForbidden from ErrKASRequestError
marythought File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.