Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

auth: queue and task grants for inspect and admin tokens

Cerrado
#989 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Ya se ha fusionado un pull request relacionado.

  • #1012 de @stromanni — fusionado

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
35/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
rust

Línea de trabajo

Start with Grant::parse and Admin::scope, then compare the narrowed-access pattern in Producer::scope_narrowed and the #987 behavior for GetJob. Trace the listed queue, task, dead-letter, periodic-task, and listing methods to determine where resources are loaded and scopes are checked. Done means narrowed operator grants can be minted, permitted resources work, out-of-scope rows return *_NOT_FOUND, and spanning methods refuse safely with SCOPE_DENIED metadata.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

area/server area/wire P2 security

Follow-up to #839 / #987.

inspect and admin can only be granted whole: Grant::parse refuses a qualifier on them, and both Admin::scope and the auth layer require whole access. So an operator token reaches every queue, dead letter, schedule and override in its namespace.

Wanted: an operator token for one team's queues. For example, admin:queue=billing could pause or resume billing and replay its dead letters, and could touch nothing else.

Methods that name a resource:

  • PauseQueue / ResumeQueue (queue)
  • Set/ClearQueueOverride (queue)
  • Set/ClearTaskOverride (task_name)
  • PutPeriodicTask (task_name, queue)
  • PurgeDeadLetters (task_name arm)

Methods keyed by id: Get/Replay/DeleteDeadLetter and the periodic Get/Delete/Pause/Resume/Trigger need the row loaded first. A row outside the grants should read as *_NOT_FOUND, the same way GetJob answers since #987.

Methods that span queues: ListQueues, GetThroughput, ListDeadLetters, ListWorkers, ListPeriodicTasks and ListOverrides must follow the #987 rule: either the request names a reachable resource, or the method is refused. No post-filtering, because a short page leaks a count.

Pattern to reuse: the default Admin::scope stays closed. Each method opts in on purpose, as Producer::scope_narrowed does. Refusals reuse SCOPE_DENIED with queue / task metadata.

Until then: a narrowed operator grant stays unmintable.

Lenguaje dominante
Rust
Estrellas
20
Forks
2
Merge medio
7 h 19 min
PR fusionados (30 d)
89

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de ByteVeda/flexiq

Todos los issues de ByteVeda/flexiq

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.