Affected by GO-2023-1723
and 5 other vulnerabilities
GO-2023-1723: SpiceDB binding metrics port to untrusted networks and can leak command-line flags in github.com/authzed/spicedb
GO-2023-2166: SpiceDB leaks information in log files when URI cannot be parsed in github.com/authzed/spicedb
GO-2024-2597: Integer overflow in chunking helper causes dispatching to miss elements or panic in github.com/authzed/spicedb
GO-2024-2716: SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used in github.com/authzed/spicedb
GO-2024-2939: SpiceDB exclusions can result in no permission returned when permission expected in github.com/authzed/spicedb
GO-2024-3131: SpiceDB having multiple caveats on resources of the same type may improperly result in no permission in github.com/authzed/spicedb
package
Version:
v1.7.0
Opens a new window with list of versions in this module.
Published: Apr 27, 2022
License: Apache-2.0
Opens a new window with license information.
Imports: 17
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
Package gateway implements an HTTP server that forwards JSON requests to
an upstream SpiceDB gRPC server.
NewHandler creates an REST gateway HTTP Handler with the provided upstream
configuration.
OtelAnnotator propagates the OpenTelemetry tracing context to the outgoing
gRPC metadata.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.