From bcc07443b71a452b237a1c35dc0c7c2126c992b6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Leon=20K=C3=B6nig?= Date: Fri, 26 Jan 2024 11:20:36 +0100 Subject: [PATCH] remove fallback to default sa --- server/auth/gatekeeper.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/server/auth/gatekeeper.go b/server/auth/gatekeeper.go index 4574717456f9..653629806922 100644 --- a/server/auth/gatekeeper.go +++ b/server/auth/gatekeeper.go @@ -307,7 +307,8 @@ func (s *gatekeeper) rbacAuthorization(ctx context.Context, claims *types.Claims namespaceAccount, err := s.getServiceAccount(claims, getNamespace(req)) if err != nil { log.WithError(err).Info("Error while SSO Delegation") - } else if precedence(namespaceAccount) > precedence(loginAccount) { + return nil, err + } else { delegatedAccount = namespaceAccount ssoDelegated = true }