Portal dev auth: replace mkcert CA install with leaf-only localhost trust
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- docker, docker-compose, shell
- Ambito
- authentication, devops, security
Direzione di ricerca
Start with scripts/ensure-dev-certs.sh and the entra-local and entra-local-certs-init services in docker-compose.yml, tracing the existing certificate generation, trust installation, and DEV_CERT_DIR handling. Verify direct leaf trust and the one-command entra-local flow on the target platform(s), including the browser/MSAL TLS handshake. Done means the leaf is localhost-scoped and trusted without the root-CA installation path, with the shared certificate directory and validity requirements covered.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Original author: @manekinekko
Follow-up from PR #1243 review (finding 🟡, by @cedricvidal_microsoft).
Context
The one-command local dev auth flow (entra-local served over HTTPS) currently uses mkcert -install, which adds a root CA to the OS/browser trust store. That CA can sign a cert for any hostname and forces a one-time admin/sudo prompt. For a dev emulator that only ever needs to be trusted for localhost, this is a heavier trust grant than the feature requires.
Proposal
Drop mkcert -install and trust only the leaf cert (already CA:FALSE, SAN-scoped to localhost / 127.0.0.1 / ::1). Trusting the leaf directly (e.g. security add-trusted-cert -r trustAsRoot into the login keychain on macOS, no sudo) caps the trust blast radius to localhost and can't vouch for any other domain. MSAL only needs the TLS handshake to https://localhost:<port> to succeed.
Scope / considerations
- Cross-platform trust plumbing is the main cost:
mkcert -installhides the macOS/Linux/Windows trust stores behind one command; leaf-only means doing it per-OS ourselves (security add-trusted-certon macOS, plus Linux and Windows equivalents). Landing macOS first and staging Linux/Windows as follow-ups may be acceptable. - Validity cap: directly-trusted leaves can hit the browser 398-day server-cert cap (mkcert's leaf is ~823 days). Mint a =398-day leaf to sidestep it.
- Shared cert dir: parameterize the compose mount to
${DEV_CERT_DIR:-./.certs}:/certs-src:ro(the script already honorsDEV_CERT_DIR) so a dev can setDEV_CERT_DIR=$HOME/.scope-dev-certsonce and share a single leaf + a single trust action across all worktrees and ports. - Verify before committing: confirm browsers/MSAL accept a directly-trusted leaf on each target platform (untested as of the PR review).
Not in scope
The rootless/UID-remapped container permission issue (finding F1) was already fixed in PR #1243 (f886e348) independently, without loosening the key, via an ownership-fixing init service. If we adopt leaf-only later, the in-volume key handling can be revisited then.
Relevant files: scripts/ensure-dev-certs.sh, docker-compose.yml (the entra-local / entra-local-certs-init services).
- Lingua principale
- TypeScript
- Stelle
- 7
- Fork
- 13
- Merge medio
- 3g 16h
- PR unite (30g)
- 29
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoft/scope
-
type: worker-update
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 2 giorni
-
type: worker-update
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
I maintainer di solito rispondono entro 2 giorni
-
type: worker-update
Difficoltà 1/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 2 giorni
-
Clarify that prompt features only categorize prompts, don't impact runsForse già presa @DerrickUnleashed l’ha presa 4 giorni fa. Apertaauthor: JaGord documentation good first issue UI
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 2 giorni
-
Submit Run task prompt picker should only search requirement promptsForse già presa @cedricvidal l’ha presa 70 giorni fa. Apertaauthor: cedricvidal bug portal
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di microsoft/scope
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
kind/chore priority/must
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
sidereal-io/sidereal#380 ·
I maintainer di solito rispondono entro 1 giorno
-
Mend: dependency security vulnerability
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
opfab/operatorfabric-core#10653 ·
I maintainer di solito rispondono entro 1 giorno
-
backend bug size:sm
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
chrisbenincasa/tunarr#2237 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 2/5 Mezza giornata Idoneità per principianti 69/100
Lam30ne/regulate-app#39 ·