Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Support scoped Bugzilla access for agents via a capability-token proxy

Aperta
#6,694 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@suhaibmujahid ci sta già lavorando.

Dal 24/8/2026.

  • #6740 di @suhaibmujahid — aperta

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

hackbot

Agents currently reach Bugzilla through a broker sidecar holding a static BMO API key. That key gives every run of an agent the same standing access.

What we need is a shared service holding the upstream credential, and replace the broker's key with a per-run capability token minted by hackbot-api. The token states what the run may read; the proxy enforces it, filters results, and logs every decision.

This is inspired by proxsy, the authorization-proxy prototype @choller built, and borrows its rule-evaluation and content-filtering approach. The main departure is that authorization comes from a signed per-run token rather than static YAML client keys, which is what lets the scope be derived server-side per run.

Lingua principale
Python
Stelle
571
Fork
355
Merge medio
2g 6h
PR unite (30g)
69

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di mozilla/bugbug

Tutte le issue di mozilla/bugbug

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.