Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Consolidate homework answer encryption on the shared package

Open
#438 10 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Refactor
Clarity
Clearly specified
Activity status
Active
Tech stack
python

Research direction

Start with the import and patch-target inventory, then compare courses/homework_answer_crypto.py with community_base.coursework.answer_crypto at v0.5.10. Review courses/homework_answer_checks.py, courses/homework_answer_resolution.py, and their tests, including the deterministic envelope vector. Done means the duplicate is removed, callers share the package classes, focused tests and the documented selective verification pass, and crypto and scoring behavior remain unchanged.

Written by the indexing model from the issue text.

Description

courses enhancement P1 security

Consolidate homework answer encryption on the shared package

Status: pending
Tags: courses, security, enhancement, P1
Depends on: None
Blocks: —

Reporter context

The owner asks to unify and simplify community-base, AISL and DTC while preserving every feature and the current UX, with no visible UI changes. Use focused changes in an isolated DTC worktree because shared checkouts have other owners. The cross-repository inventory identified the 490-line courses/homework_answer_crypto.py as a duplicate of the shared answer-crypto owner already present in DTC's pinned community-base release.

Normative references

  • _docs/specs/04-courses-and-cohorts.md, especially preserved learner homework behavior and the rule to characterize scoring behavior before deduplication.
  • _docs/specs/07-security-privacy-operations.md for bounded failures and privacy.
  • _docs/architecture/app-boundaries.md and AGENTS.md for direct domain ownership and the prohibition on legacy runtime shims.
  • _docs/ci/change-selective-ci.md and _docs/specs/10-verification-strategy.md for versioned, change-selective verification.
  • community-base v0.5.10 community_base.coursework.answer_crypto for the existing implementation contract.

Scope

Delete the duplicated courses/homework_answer_crypto.py implementation. Retarget all proven live and test imports directly to community_base.coursework.answer_crypto, including courses/homework_answer_checks.py, courses/homework_answer_resolution.py, and their tests. The existing DTC pyproject.toml and uv.lock pin community-base to v0.5.10, whose crypto module has the same implementation plus validate_source_envelope; this issue needs no package release or dependency bump. Before deleting, inventory all repository Python import forms, aliases, test imports, patch targets, and literal/dynamic references, then repeat the check on the final diff. Do not leave a compatibility facade or copy classes/exceptions locally.

Keep the DTC keyring configuration lookup, answer-resolution boundary, source option-ID mapping, free-form answer conversion, answer-check handling, homework models, and persisted envelopes in place. Preserve exact object identity for HomeworkAnswerKeyring, HomeworkAnswerCryptoError and its validation, unavailable-key, and decryption subclasses across every remaining caller. Change the deterministic test patch from the deleted site's secrets.token_bytes path to the shared module's path; keep its known AES-GCM/HKDF envelope vector meaningful. Existing encrypted answers must decrypt with the shared implementation, and newly encrypted answers must remain compatible with the prior implementation.

Characterize and preserve strict keyring parsing and rotation, canonical authenticated context, scalar and choice payloads, envelope validation and size bounds, malformed/tampered ciphertext failures, unknown key IDs, context mismatch, redacted error text, and failure handling in scoring. Do not compare independently randomized ciphertext for equality. If the existing tests leave a specific behavior gap, add one authoritative behavior test before changing the import owner and prove it passes before and after.

Non-goals

  • No visible UI, template, route, API, access, scoring-policy, feature, or schema change.
  • No model migration, stored-data rewrite, keyring configuration change, or new crypto algorithm/version.
  • No package-code change, new abstraction, legacy runtime shim, or unrelated dependency pin update.
  • No shared-main edit, commit, merge, push, or pull request in this grooming/implementation-review stage.

Acceptance criteria

  • A final-revision caller inventory covers all three Python import forms, aliases, tests, scripts, patch targets, and dynamic references; no use of the deleted site module remains.
  • courses/homework_answer_crypto.py is deleted, all callers use the package owner directly, and the report measures actual net application lines removed separately from tests or moved code.
  • Class and exception identity is single-owner: DTC resolution/checks and package encrypt/decrypt paths use the same HomeworkAnswerKeyring and crypto exception classes.
  • Existing and new scalar/choice envelopes interoperate across old and shared implementations; the deterministic envelope vector, key rotation, malformed/oversized envelope rejection, unknown-key behavior, authenticated-context mismatch, and tamper failures retain their exact contract.
  • DTC's configured keyring source, answer-resolution mapping, scoring behavior and safe failure handling stay unchanged; no secret or answer value is added to logs or error output.
  • The authoritative crypto and answer-resolution tests pass before and after; the old secrets.token_bytes patch is retargeted to the shared owner without weakening the vector assertion.
  • No page, API, template, route, model, migration, stored envelope, feature, or visible UX changes.
  • make lint, make lint-advisory, focused tests, and the versioned _docs/ci/change-selective-ci.md verification plan pass. Engineer and Tester report exact base/head, graph and plan digests, every component's rerun/reused/skipped/not_applicable disposition, exact commands/counts, and the graph-selected backend browser tier (smoke when the focused backend profile applies); any full-profile fallback follows the plan.
  • Independent Tester verifies the uncommitted isolated worktree and records screenshot evidence as not_applicable if the graph confirms no render impact. Shared main remains untouched; no commit, merge, push, or PR occurs before the owner-authorized handoff.

Browser regression scenario

Scenario: learner submits source-managed homework with an encrypted answer

Given: an enrolled learner sees a homework question whose answer is stored as an encrypted source envelope
When: the learner submits an answer through the existing homework flow
Then: the response and score follow the same existing policy, and the learner sees no plaintext source answer, key detail, or new error message

The cryptographic boundary cases belong in focused unit/service tests. This backend-only ownership change introduces no new page or browser behavior.

Repository and operations scenarios

  • A previously stored envelope decrypts with the shared owner using the existing configured keyring and the exact course/homework/question context.
  • An envelope with a wrong context, unavailable key, malformed fields, or tampered ciphertext fails in the same bounded class and does not leak its secret input.

Blocked by: (none)

Dominant language
Python
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

  • Ships a Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from DataTalksClub/website

All issues in DataTalksClub/website

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.