Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

The remote cache exposes credentials to tasks and env value hashes to the server

Abierto
#781 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
35/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
rust
Área
security

Línea de trabajo

Start with the remote cache configuration described in issue #727 and the key format in issue #755. Trace how credentials reach task processes and how tracked environment values are included in keys; done means credentials are supplied separately from the URL without reaching tasks, and the server cannot recover individual environment values.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

remote cache

Credentials. The remote cache URL is the only place to put credentials, so tokens end up in its query string or user info. To keep the token out of vite.config.*, the URL comes from VP_REMOTE_CACHE_URL, and vp run passes every VP_* variable through to the processes tasks spawn. Every tool and script a task runs can read the token.

Env value hashes. Each tracked env value is hashed on its own with unsalted SHA-256, and those hashes are part of the key sent to the server. Anyone who can read the remote cache can recover short or guessable values, such as short tokens or passwords, by brute force.

Expected: credentials can be supplied separately from the URL, for example as a token sent in an Authorization header, and aren't passed to task processes. The server can't recover individual env values from what it stores.

Affects remote cache configuration (#727) and the key format (#755).

Lenguaje dominante
Rust
Estrellas
468
Forks
42
Merge medio
1 d 18 h
PR fusionados (30 d)
46

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de voidzero-dev/vite-task

Todos los issues de voidzero-dev/vite-task

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.