Skip to content
This repository has been archived by the owner on Dec 4, 2024. It is now read-only.

[release/3][BACKPORT] chore: bump dex #1115

Merged
merged 1 commit into from
May 12, 2021

Conversation

d2iq-mergebot
Copy link
Contributor

This is a backport of the following PR:

#1109

What type of PR is this?
Chore

What this PR does/ why we need it:
Bump dex to include a change that defers creation of AuthRequest objects to avoid Denial of Service.

Which issue(s) this PR fixes:
https://jira.d2iq.com/browse/COPS-6867
https://jira.d2iq.com/browse/D2IQ-75146

Special notes for your reviewer:

Tested in https://github.com/mesosphere/yakcl/pull/425

Does this PR introduce a user-facing change?:

Defer AuthRequest creation until after initial login page to avoid too many objects.

Checklist

  • The commit message explains the changes and why are needed.
  • The code builds and passes lint/style checks locally.
  • The relevant subset of integration tests pass locally.
  • The core changes are covered by tests.
  • The documentation is updated where needed.

Signed-off-by: Jonathan Giddy <[email protected]>
@d2iq-mergebot
Copy link
Contributor Author

This repo has @mesosphere-mergebot integration. You can perform the following commands by submitting a comment. Submit a comment with content "@mesosphere-mergebot help" to view more detailed help text and examples. Be sure the have a look at the mergebot documentation, too.

@mesosphere-mergebot backport  

@d2iq-mergebot d2iq-mergebot mentioned this pull request May 5, 2021
5 tasks
@joejulian joejulian added this to the release/3.5 milestone May 5, 2021
@armandgrillet armandgrillet merged commit 26162d7 into release/3 May 12, 2021
@armandgrillet armandgrillet deleted the backport/release/3/master-1109 branch May 12, 2021 06:59
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants