-
Bug
-
Resolution: Done
-
Major
-
Logging 6.0.5, Logging 6.1.3, Logging 6.2.0, Logging 6.3.0
-
Incidents & Support
-
1
-
False
-
-
False
-
NEW
-
VERIFIED
-
-
Bug Fix
-
-
-
Logging - Sprint 275
-
Important
Through a Slack discussion we discovered that the current implementation of loki-gateway (observatorium/api) is not correctly enforcing authorization policies on the "/series" endpoint. Allowing to get stream metadata information from any log stream.
This is happens as the "/series" endpoint uses "match" instead of "query" to filter which series metadata should be returned to the request.
observatorium/api should fixed to have into consideration this difference and inherently correctly enforce authorization policies.
- clones
-
LOG-6892 loki-gateway does not enforce fine-grained authorization on /series endpoint
-
- Closed
-