The remote cache exposes credentials to tasks and env value hashes to the server
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
Línea de trabajo
Start with the remote cache configuration described in issue #727 and the key format in issue #755. Trace how credentials reach task processes and how tracked environment values are included in keys; done means credentials are supplied separately from the URL without reaching tasks, and the server cannot recover individual environment values.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Credentials. The remote cache URL is the only place to put credentials, so tokens end up in its query string or user info. To keep the token out of vite.config.*, the URL comes from VP_REMOTE_CACHE_URL, and vp run passes every VP_* variable through to the processes tasks spawn. Every tool and script a task runs can read the token.
Env value hashes. Each tracked env value is hashed on its own with unsalted SHA-256, and those hashes are part of the key sent to the server. Anyone who can read the remote cache can recover short or guessable values, such as short tokens or passwords, by brute force.
Expected: credentials can be supplied separately from the URL, for example as a token sent in an Authorization header, and aren't passed to task processes. The server can't recover individual env values from what it stores.
Affects remote cache configuration (#727) and the key format (#755).
- Lenguaje dominante
- Rust
- Estrellas
- 468
- Forks
- 42
- Merge medio
- 1 d 18 h
- PR fusionados (30 d)
- 46
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de voidzero-dev/vite-task
-
Dificultad 4/5 3-5 días Aptitud para principiantes 52/100
voidzero-dev/vite-task#791 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 67/100
voidzero-dev/vite-task#790 ·
Los mantenedores suelen responder en 1 día
-
vp run: output forwarding fails with EAGAIN when an inherited Node child sets stdout non-blockingAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
voidzero-dev/vite-task#782 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
remote cache
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
voidzero-dev/vite-task#779 ·
Los mantenedores suelen responder en 1 día
-
remote cache
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
voidzero-dev/vite-task#778 ·
Los mantenedores suelen responder en 1 día
Todos los issues de voidzero-dev/vite-task
Issues similares
-
area:release bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
registrystack/registry-stack#1874 ·
Los mantenedores suelen responder en 1 día
-
component:midnight-toolkit status:untriaged
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
midnightntwrk/midnight-node#2237 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día