[FIXED] LeafNode: Publish permissions checked against pre-transform subject
A shadow subscription created by a stream import delivers the import's post-transform subject to the leafnode. The publish permission check in deliverMsg() was performed against the exporting account's subject instead, which is never sent on the wire. As a result, the pre-transform subject had to be added to the allow list for messages to be delivered at all, which grants the leafnode publish permissions beyond what is intended to travel over the connection. Extract the remap that msgHeaderForRouteOrLeaf() already performs into importTargetSubject() and use it for the permission check, so that both call sites derive the delivered subject the same way. The extracted logic is unchanged. Resolves #4608 Signed-off-by: Florian Barth <florian.barth@foerstergroup.com>
F
Florian Barth committed
0ba71b452eb9ec4c6fdb3cccff46974dac0bb1ba
Parent: 2efc8a4