Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Problem: enabling addhoc queries reveal tx data

Abierto
#943 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
25/100
Tipo de issue
Nueva funcionalidad
Claridad
Necesita aclaración
Estado de actividad
Estancado
Stack tecnológico
go
Área
api, backend, security

Línea de trabajo

Start by tracing the chain.block RPC entry point and the ad hoc query configuration discussed in the issue. Determine the intended scope with the Kwil team before changing anything. Done would mean a block-header-only query path is clearly specified and does not expose raw transaction data when ad hoc queries are disabled.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

actually... I'm still not sure it's the right move yet, I'm asking to the kwil team. I'll open a new issue about this. If the risk is only data exposure of transactions, it might be minor in this phase.

Originally posted by @outerlook in https://github.com/trufnetwork/node/issues/932#issuecomment-2883723790

from @brennanjl

Yes, disabling ad hoc queries also disables chain.block. This is because chain.block returns the entirety of the block data (all of the raw transactions). If this was not the case, then attackers could use chain.block as a workaround to read sensitive network information when queries are disabled

This is actually a perfect case where an rpc endpoint for querying a block header only would be ideal. It does not have the security concerns mentioned above because it doesn’t return the raw transaction data for a block

and I raised a point if it's as sensitive as enabling public direct access to 8484 endpoints from nodes

Lenguaje dominante
Go
Estrellas
7
Forks
3
Merge medio
3 h 2 min
PR fusionados (30 d)
13

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de trufnetwork/node

Todos los issues de trufnetwork/node

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.