Skip to content

Jlc/saml security backport - #98

Merged
johanseto merged 3 commits into
open-release/teak.nelpfrom
jlc/saml-security-backport
Oct 1, 2026
Merged

johanseto merged 3 commits into
open-release/teak.nelpfrom
jlc/saml-security-backport

Conversation

@johanseto

Copy link
Copy Markdown

Description

Backports the SAML metadata URL validation fix from openedx/openedx-platform@70a5624 to address GHSA-328g-7h4g-r2m9.

The backport prevents SSRF when retrieving SAML metadata by validating user-supplied URLs and adds request timeouts. It also includes a compatibility commit that defines the required settings in both LMS and CMS configuration.

This affects Operators and users who configure third-party SAML authentication providers.

Supporting information

• Upstream fix: openedx@70a5624
• Security advisory: GHSA-328g-7h4g-r2m9

Testing instructions

  1. Configure a SAML provider with a valid HTTPS metadata URL and verify that metadata can be fetched successfully.
  2. Attempt to use loopback, link-local, reserved, or private-network metadata URLs and verify that they are rejected according to the configured settings.
  3. Run the third-party authentication utility tests:
    pytest common/djangoapps/third_party_auth/tests/test_utils.py

Deadline

None.

Other information

The compatibility commit adds the new SAML metadata URL settings to both  lms/envs/common.py  and  cms/envs/common.py .

@johanseto
johanseto requested a review from andrey-canon October 1, 2026 20:09
@johanseto
johanseto force-pushed the jlc/saml-security-backport branch from f5d8299 to 15a7d1f Compare October 1, 2026 20:42
@andrey-canon
andrey-canon force-pushed the open-release/teak.nelp branch from fa870d0 to e57b2e4 Compare October 1, 2026 20:57
feanil and others added 3 commits October 1, 2026 16:03
Adds `validate_saml_metadata_url()` to `third_party_auth/utils.py` which
enforces HTTPS and blocks requests to loopback, link-local, and reserved
addresses unconditionally, and RFC 1918 private ranges by default
(configurable via `SAML_METADATA_URL_ALLOW_PRIVATE_IPS`).

The validator is called in three places where user-supplied metadata URLs
are fetched: `fetch_metadata_xml()` in utils.py, the inline fetch in
`tasks.py::fetch_saml_metadata`, and `sync_provider_data` in the
SAMLProviderDataViewSet. A 30-second timeout is also added to all
`requests.get()` calls that were previously unbounded.

Fixes GHSA-328g-7h4g-r2m9.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
E7670: setting annotation (SAML_METADATA_URL_ALLOW_PRIVATE_IPS) cannot have a boolean value (setting-boolean-default-value) pylint
@johanseto
johanseto force-pushed the jlc/saml-security-backport branch from 15a7d1f to 48d006a Compare October 1, 2026 21:03
@johanseto
johanseto merged commit 74a6592 into open-release/teak.nelp Oct 1, 2026
47 checks passed
@johanseto
johanseto deployed to open-release/teak.nelp October 1, 2026 21:48 — with GitHub Actions Active
@johanseto
johanseto deployed to open-release/teak.nelp October 1, 2026 21:48 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
open-release/teak.nelp — 48d006a7 Deployed Oct 1, 2026 by johanseto via create-jira-issue / create_jira_issue #36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants