Skip to content

[Security/Http] fix parsing X509 emailAddress #33759

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Sep 30, 2019

Conversation

nicolas-grekas
Copy link
Member

Q A
Branch? 3.4
Bug fix? yes
New feature? no
Deprecations? no
Tickets Fix #33636
License MIT
Doc PR -

@fabpot
Copy link
Member

fabpot commented Sep 30, 2019

Thank you @nicolas-grekas.

fabpot added a commit that referenced this pull request Sep 30, 2019
…kas)

This PR was merged into the 3.4 branch.

Discussion
----------

[Security/Http] fix parsing X509 emailAddress

| Q             | A
| ------------- | ---
| Branch?       | 3.4
| Bug fix?      | yes
| New feature?  | no
| Deprecations? | no
| Tickets       | Fix #33636
| License       | MIT
| Doc PR        | -

Commits
-------

fceb86b [Security/Http] fix parsing X509 emailAddress
@fabpot fabpot merged commit fceb86b into symfony:3.4 Sep 30, 2019
This was referenced Oct 7, 2019
@nicolas-grekas nicolas-grekas deleted the sec-x509 branch October 8, 2019 11:49
fabpot added a commit that referenced this pull request Dec 18, 2022
…nticator (Spomky)

This PR was squashed before being merged into the 6.3 branch.

Discussion
----------

[Security] Allow custom user identifier for X509 authenticator

| Q             | A
| ------------- | ---
| Branch?       | 6.3
| Bug fix?      | no
| New feature?  | yes
| Deprecations? | no
| Tickets       | Fix #47354
| License       | MIT
| Doc PR        | **to be created**

This PR allows defining a custom user identifier instead of the hardcoded `emailAddress`.
It also adds a new option for the firewall configuration:

```yaml
# config/packages/security.yaml
security:
    # ...

    firewalls:
        main:
            # ...
            x509:
                provider: your_user_provider
                user_identifier: CN # default to emailAddress
```

**💬 Discussion**: user identifier regex changed
Note that the regex is changed. The previous one was able to find an email address as expected, but now that the common name may not contain a `@` (or may contain more than one), it is required to update this part.
It does not impact the previously merged PR #33759, but I prefer highlight the fact that it can now catch invalid email addresses set in `emailAddress`.

Commits
-------

6479653 [Security] Allow custom user identifier for X509 authenticator
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants