Teams SSH doesn't update existing users' SSH keys
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 35/100
- Issue-Typ
- Bug
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Veraltet
- Tech-Stack
- github, typescript
- Bereich
- authentication, infrastructure, security
Rechercherichtung
Beginnen Sie damit, die teams-ssh-Aktualisierungsschleife und den Code zu lokalisieren, der die Github-Teammitgliedschaft und die SSH-Schlüssel der Benutzer liest. Bestätigen Sie, wie bestehende Benutzer in authorized_keys dargestellt werden, und definieren Sie anschließend die Fertigstellung so, dass neu hinzugefügte Schlüssel erkannt und hinzugefügt werden, ohne Änderungen an der Teammitgliedschaft zu erfordern; das Entfernen von Schlüsseln bleibt ausdrücklich eine Designfrage.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
If someone is added to the Sudo or SSH teams in the HacKSU org, and later adds SSH key(s) to their account in order to log in to a server, the new keys will not be added to their .ssh/authorized_keys file, since that file is only updated when the user account is initially added to the server.
This can be worked around by removing a user from both the SSH and, if necessary, the Sudo team, waiting for teams-ssh to update, and then re-adding them and waiting for teams-ssh to update again.
Fixing this would require pulling each user's SSH keys along with their team membership from Github every 60 seconds, checking if each key is already present in the authorized_keys file or not, and adding it if it isn't already there.
Automatically removing keys when they're removed from a user's Github profile could be more problematic. It would increase the security of the system by providing a quick way to remove keys if they're compromised, but it could also lead to unexpected lockouts if the user uses an SSH key for their server account without even realizing it's also saved in their Github account.
- Vorherrschende Sprache
- TypeScript
- Sterne
- 0
- Forks
- 0
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Ähnliche Issues
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
-
Crush Offen
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 85/100
catppuccin/catppuccin#3125 ·
-
Add a SECURITY.md Offen
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
ElementsProject/cln-application#167 · 1 Kommentar · 1 Reaktion ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
Quantco/pnpm-licenses#17 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100