Add authentication
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- r
- Domain
- authentication, cli, security
Research direction
The issue names dispatchr-authenticato.r and dispatch.r and identifies source() as the execution path. Start by reviewing how dispatch.r receives requests and how source() is reached; the work is done when the authentication option, credential handling, and behavior for authenticated and unauthenticated invocations are clearly defined and verified.
Written by the indexing model from the issue text.
Description
I'm not a security expert, but I'm pretty sure this application runs the risk of enabling remote code execution. It will only execute code via source(), so any malicious code would need to be written to the server, and the dispatchr server would need to have read access on that location. It seems unlikely that this is actually a vulnerability, but I feel like it's probably a good idea to be concerned.
A simple way to add a little more safety would be to add user authentication. This wouldn't necessarily need to be required, but it should at least be an option. so something like:
Rscript dispatchr-authenticato.r -u userName -p passWord
Rscript dispatch.r do/some/thing.r arg0
Rscript dispatch.r do/some/thingelse.r arg1
- Dominant language
- R
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dmarx/dispatchr
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Difficulty 5/5 Over a week Newbie friendliness 15/100
-
Switch to POST?Open
Difficulty 5/5 Over a week Newbie friendliness 20/100
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
rstudio/reticulate#1933 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 62/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
lrberge/fixest#686 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100