Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Make the anonymous-operator audit gate config-driven: add `compliance.allow_anonymous_operator` beside `FORGELM_ALLOW_ANONYMOUS_OPERATOR`

Aperta
#913 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
Mezza giornata
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
python
Ambito
security

Direzione di ricerca

Start with the environment check in AuditLogger.__init__, then the same FORGELM_ALLOW_ANONYMOUS_OPERATOR reads in doctor and approve. Do not start until #706 is settled, since it may close this row instead. If the field is added, thread compliance.allow_anonymous_operator through those call sites with YAML taking precedence, and cover the precedence in a test. Done means the field is documented in EN and TR, the template is updated, and the row is removed from docs/roadmap/risks-and-decisions.md with its ID named in the CHANGELOG.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

area: config severity: low source: roadmap wave: 4

Deferred work · F-PR29-A6-14 · severity Low · cost ~30 min (more in practice) · recorded in docs/roadmap/risks-and-decisions.md:87

Summary

Whether the audit logger refuses to start when no operator identity resolves is decided only by the FORGELM_ALLOW_ANONYMOUS_OPERATOR=1 environment variable (read in AuditLogger.__init__, and again in doctor and approve). The config-driven principle keeps behaviour gates in validated YAML and environment variables for secrets. The PR #29 plan adds compliance.allow_anonymous_operator: bool = False, with YAML taking precedence and the variable kept as a CI fallback.

Condition or budget

None recorded. Settle #706 first: it proposes the opposite fix (documenting identity variables as permitted), which would make this row moot.

State today (re-checked 2026-10-09)

No allow_anonymous_operator field exists; AuditLogger takes no config, so the field has to be threaded through its call sites.

Related

#706 (CR-A13-063) — the competing fix; #714 (CR-A04-086) asks for one shared operator-identity helper.

Acceptance criteria

  • Either the field exists (description, template entry, EN/TR docs, precedence tested) or #706's position is adopted and this row is closed with that reason.
  • The row is removed from the deferral table and the CHANGELOG names its ID (the table's removal contract).

Recorded in docs/roadmap/risks-and-decisions.md (read at f94595f) and re-checked against the code on 2026-10-09. The row leaves that table only when the fix is on main, the CHANGELOG names its ID and any promised guard exists.

Lingua principale
Python
Stelle
9
Fork
1
Merge medio
4h 3m
PR unite (30g)
3

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di HodeTech/ForgeLM

Tutte le issue di HodeTech/ForgeLM

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.