Skip to content

upgrade stac-auth-proxy to v1.1.1#191

Merged
szabozoltan69 merged 2 commits into
developfrom
upgrade-stac-auth-proxy
Jun 2, 2026
Merged

upgrade stac-auth-proxy to v1.1.1#191
szabozoltan69 merged 2 commits into
developfrom
upgrade-stac-auth-proxy

Conversation

@batpad

@batpad batpad commented May 28, 2026

Copy link
Copy Markdown
Contributor

We need to upgrade stac-auth-proxy to v1.1.1 as it includes a fix for a recent vulnerability in Starlette.

I think we should just be able to bump this version for now and have things work, but would be good to deploy and test.

I was unable to create a working PoC of bypassing authentication for our current setup, but I have been able to get a PoC working locally against unpatched versions of stac-auth-proxy.

@pantierra - I think we should eventually change how we are setting up stac-auth-proxy? I think there's a better way to do it now that it's packaged with eoapi-k8s? But I think we can treat that separately and for now just apply the version bump patch?

cc @emmanuelmathot @thenav56

@thenav56

Copy link
Copy Markdown
Member

Hey @batpad,

I had to update some other values because of the remote changes: developmentseed/stac-auth-proxy@v1.0.3...v1.1.1

It is deployed on the alpha instance: https://montandon-eoapi-3-auth-proxy.ifrc-go.dev.togglecorp.com/stac/
Everything looks okay, but could you please check it as well?

@batpad

batpad commented May 29, 2026

Copy link
Copy Markdown
Contributor Author

Thanks much for the fixes @thenav56 !

@pantierra

Copy link
Copy Markdown

Looks good to me. Yes, in a separate step we can use stac-auth-proxy packaged with eoapi-k8s.

@szabozoltan69 szabozoltan69 merged commit 2c0bafd into develop Jun 2, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants