Skip to content

fix: restrict default OPA policy to path-based admin protection#221

Merged
alecthomas merged 1 commit intomainfrom
aat/opa-path-based-policy
Mar 24, 2026
Merged

fix: restrict default OPA policy to path-based admin protection#221
alecthomas merged 1 commit intomainfrom
aat/opa-path-based-policy

Conversation

@alecthomas
Copy link
Copy Markdown
Collaborator

Allow all methods on strategy paths (git, gomod, etc.) from any
source, and restrict remote access to admin paths (/api/, /admin/).

Co-Authored-By: Claude Opus 4.6 (1M context) noreply@anthropic.com

Allow all methods on strategy paths (git, gomod, etc.) from any
source, and restrict remote access to admin paths (/api/*, /admin/*).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@alecthomas alecthomas requested a review from a team as a code owner March 24, 2026 00:50
@alecthomas alecthomas requested review from joshfriend and removed request for a team March 24, 2026 00:50
@alecthomas alecthomas enabled auto-merge (squash) March 24, 2026 00:50
@alecthomas alecthomas merged commit 05ddf3f into main Mar 24, 2026
6 checks passed
@alecthomas alecthomas deleted the aat/opa-path-based-policy branch March 24, 2026 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant