Affected by GO-2024-3325
and 4 other vulnerabilities
GO-2024-3325: kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp
GO-2025-3538: kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp
GO-2025-3985: kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
GO-2026-5088: kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
GO-2026-6517: kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
Random256BitsString is a convenience function for calling RandomBitsString(256).
Callers that need a random string should use this function unless they have a
very good reason to need a different amount of entropy.
RandomBits returns a random byte slice with at least the requested bits of entropy.
Callers should avoid using a value less than 256 unless they have a very good reason.
RandomBitsString returns a random string with at least the requested bits of entropy.
It uses RawURLEncoding to ensure we do not get / characters or trailing ='s.