The code in question reminds me a lot of my favorite Kubernetes bug: if (request.authenticationData) { ok := validate(etc); if (!ok) { return authenticationFailure; } } Turns out the same meme spans decades.
Where can I read about the bug? And what is the bug? If there is no authenticationData it is authenticated by default or what?
Link to the patch fixing it: https://github.com/kubernetes/kubernetes/commit/7fef0a4f6a44...
Of course, we'd already fixed other issues like Kubelet listening on a secondary debug port with no authentication. Those problems stemmed from its origins as a make-it-possible hacker project and it took a while to pivot it to something usable in an enterprise.