Topic604 problems· 5 reviewed

Identity And Access

604 incident problems about Identity And Access. Start with the reviewed ones.

All problems (604)

SECURITY-1251An OIDC login loop persists after a successful callbackOne browser or hostname signs in successfully while another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1220Login throttling seems effective but API tokens still bypass itAn app reduces password spray on the browser login page but still sees abusive token requests continue unabated.SecurityIntermediate18 minProSECURITY-1225Login throttling works on the web form but API tokens still bypass itBrowser password spray drops quickly, but token-bearing API abuse continues through another path.SecurityIntermediate18 minProSECURITY-1256OIDC login succeeds at the provider but loops at the appOne login URL works while another hostname for the same app loops forever despite identical provider-side configuration.SecurityAdvanced18 minProSECURITY-1226OIDC login works in one browser but fails in anotherA login flow appears healthy in one hostname path or browser and fails with state or nonce errors in another.SecurityAdvanced18 minProK8S-1219ALB controller says permissions are correct but one action still failsAn ALB controller works enough to create some resources but repeatedly fails one reconciliation action.KubernetesAdvanced21 minProSECURITY-1206JWT validation fails after key rotationA signing key rotation succeeds for most services but one verifier keeps rejecting valid tokens.SecurityAdvanced21 minProK8S-1223IRSA works for most AWS calls but one SDK path still falls back to node credentialsA pod can access one AWS service through IRSA but another code path still appears to use the node role.KubernetesAdvanced22 minProK8S-1212IRSA annotation is present but STS still denies AssumeRoleA pod with the correct service account still gets access denied after an auth migration.KubernetesAdvanced23 minProLINUX-1593A sudo path cleanup is correct and one host still runs the old binaryOne host still runs the old binary after sudo path cleanup.LinuxIntermediate7 minProNETWORK-1573A Cloudflare Access route is fixed and one service token still bypassesOne service token still bypasses new Access rules after route fixes.NetworkIntermediate8 minProSECURITY-1576A JWKS cache is refreshed and one verifier still rejects new tokensOne verifier still rejects new tokens after JWKS refresh.SecurityIntermediate8 minProSECURITY-1586A JWKS refresh succeeds and one verifier still rejects new tokensOne verifier still rejects new tokens after JWKS refresh.SecurityIntermediate8 minProSECURITY-1596A JWKS refresh succeeds and one verifier still rejects new tokensOne verifier still rejects new tokens after JWKS refresh.SecurityIntermediate8 minProSECURITY-1608A PAM RADIUS realm fix is correct and one bastion still denies usersOne bastion still denies users after a PAM RADIUS realm fix.SecurityIntermediate8 minProLINUX-1563A sudo path is updated and one host still denies the commandOne host denies a deploy command after the binary path was standardized.LinuxIntermediate8 minProLINUX-1583A sudo rule is fixed and one command still resolves the old pathOne host still executes the old binary after a sudo rule fix.LinuxIntermediate8 minProLINUX-1573A sudoers cleanup lands and one deploy host still denies the commandOne deploy host still denies a command after sudoers cleanup.LinuxIntermediate8 minProLINUX-1601A tmpfiles cleanup rule is updated and one directory still comes back world-writableA hardened directory keeps returning world-writable after tmpfiles cleanup.LinuxIntermediate8 minProSECURITY-1582A Turnstile secret rotates and one worker still verifies with the old keyOne worker still verifies with the old Turnstile key after rotation.SecurityIntermediate8 minPro