Skip to content

NM-341: Multi-tenancy changes - #1349

Open
VishalDalwadi wants to merge 20 commits into
developfrom
NM-341
Open

NM-341: Multi-tenancy changes#1349
VishalDalwadi wants to merge 20 commits into
developfrom
NM-341

Conversation

@VishalDalwadi

Copy link
Copy Markdown
Contributor

Describe your changes

Provide Issue ticket number if applicable/not in title

Provide link to Netmaker PR if required

Provide testing steps

Checklist before requesting a review

  • My changes affect only 10 files or less.
  • I have performed a self-review of my code and tested it.
  • If it is a new feature, I have added thorough tests, my code is <= 1450 lines.
  • If it is a bugfix, my code is <= 200 lines.
  • My functions are <= 80 lines.
  • I have had my code reviewed by a peer.
  • My unit tests pass locally.
  • Netclient & Netmaker are awesome.

@tenki-reviewer

tenki-reviewer Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Review Complete
No issues found!

Risk: 🟠 High (78/100) — no findings · 23 LOC across 12 files


Critical JWT security flaw found: globally cached JWT tokens lack server affinity and signature verification is entirely disabled, enabling cross-tenant token reuse across multi-tenant deployments.

Files Reviewed (12 files)
auth/auth.go
flow/tracker/tracker.go
functions/auto_relay.go
functions/list.go
functions/mqhandlers.go
functions/mqpublish.go
functions/pull.go
functions/server.go
functions/uninstall.go
go.mod
networking/client-ping.go
posture/client.go

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant