Skip to content

chore(objectstore): temporarily disable proxy endpoint in s4s2#115031

Merged
matt-codecov merged 1 commit intomasterfrom
matth/objectstore-s4s2-proxy-disable
May 7, 2026
Merged

chore(objectstore): temporarily disable proxy endpoint in s4s2#115031
matt-codecov merged 1 commit intomasterfrom
matth/objectstore-s4s2-proxy-disable

Conversation

@matt-codecov
Copy link
Copy Markdown
Contributor

Ref FS-354
Ref FS-300

we need to temporarily disable objectstore auth enforcement in s4s2 to address an issue with the secrets in that region. this endpoint needs to be disabled while that fix is deployed as otherwise we would be introducing a totally unauthenticated IDOR vuln.

Legal Boilerplate

Look, I get it. The entity doing business as "Sentry" was incorporated in the State of Delaware in 2015 as Functional Software, Inc. and is gonna need some rights from me in order to utilize my contributions in this here PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Sentry can use, modify, copy, and redistribute my contributions, under Sentry's choice of terms.

@matt-codecov matt-codecov requested a review from a team as a code owner May 6, 2026 22:22
@linear-code
Copy link
Copy Markdown

linear-code Bot commented May 6, 2026

@github-actions github-actions Bot added the Scope: Backend Automatically applied to PRs that change backend components label May 6, 2026
@chromy
Copy link
Copy Markdown
Contributor

chromy commented May 7, 2026

lgtm for size analysis & snapshots

@matt-codecov matt-codecov merged commit 39da2f2 into master May 7, 2026
62 checks passed
@matt-codecov matt-codecov deleted the matth/objectstore-s4s2-proxy-disable branch May 7, 2026 19:10
matt-codecov added a commit that referenced this pull request May 7, 2026
…2" (#115138)

Reverts #115031

Depends on k8s revert that re-enables auth enforcement

auth enforcement has been re-enabled in S4S2 so we can re-enable this
endpoint
constantinius pushed a commit that referenced this pull request May 8, 2026
Ref FS-354
Ref FS-300

we need to temporarily disable objectstore auth enforcement in s4s2 to
address an issue with the secrets in that region. this endpoint needs to
be disabled while that fix is deployed as otherwise we would be
introducing a totally unauthenticated IDOR vuln.

### Legal Boilerplate

Look, I get it. The entity doing business as "Sentry" was incorporated
in the State of Delaware in 2015 as Functional Software, Inc. and is
gonna need some rights from me in order to utilize my contributions in
this here PR. So here's the deal: I retain all rights, title and
interest in and to my contributions, and by keeping this boilerplate
intact I confirm that Sentry can use, modify, copy, and redistribute my
contributions, under Sentry's choice of terms.
constantinius pushed a commit that referenced this pull request May 8, 2026
…2" (#115138)

Reverts #115031

Depends on k8s revert that re-enables auth enforcement

auth enforcement has been re-enabled in S4S2 so we can re-enable this
endpoint
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Scope: Backend Automatically applied to PRs that change backend components

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants