Private repository tokens are propagated in browser and API URLs
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- python, typescript
Direzione di ricerca
Start by reading the token handling in src/app/page.tsx and src/components/CodeViewer.tsx, then trace where the token is actually consumed and how navigation state is maintained. Check the /codemap/file request and relevant tests; done means tokens are absent from browser and API URLs while still reaching the code that needs them. The issue says a fix is included in linked PR #600, so check that work before starting.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).
Summary
The repository entry form appends the private-repository access token to the client-side navigation URL's query string, and the Code Viewer forwards it again in /codemap/file's query string, a route that never reads a token parameter.
Details
// src/app/page.tsx
const params = new URLSearchParams();
if (accessToken) {
params.append('token', accessToken);
}
// src/components/CodeViewer.tsx
const params = new URLSearchParams({ repo_url: repoUrl, file_path: activeFile, type: repoType || 'github' });
if (token) params.set('token', token);
fetch(`${getApiBaseUrl()}/codemap/file?${params.toString()}`)
POC
(available upon request)
Impact
The token enters browser history and any copied/shared link, and is visible to same-origin scripts via the URL. The second occurrence additionally reaches proxy/access logs with no functional need, since /codemap/file never consumes it.
Suggested fix: keep tokens in ephemeral state, send them only where consumed, and scrub any URL that already carries one. A fix is included in the linked PR.
Fix: #600
- Lingua principale
- Python
- Stelle
- 18.1k
- Fork
- 2k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di AsyncFuncAI/deepwiki-open
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
AsyncFuncAI/deepwiki-open#608 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#602 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
AsyncFuncAI/deepwiki-open#589 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#539 · 1 commento ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 20/100
AsyncFuncAI/deepwiki-open#609 ·
Tutte le issue di AsyncFuncAI/deepwiki-open
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
pyjanitor-devs/pyjanitor#1758 ·
I maintainer di solito rispondono entro 1 giorno
-
bug ready for review
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
odysseus-dev/odysseus#6641 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
happypawspillaro/happypaws#78 ·
I maintainer di solito rispondono entro 4 giorni
-
pydanty:is-working
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
pydantic/pydantic-ai#10020 ·
I maintainer di solito rispondono entro 1 giorno
-
stdlib type-bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
python/cpython#159044 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno