Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

auth scoperesolver uses offset pagination during cache reload — same root cause as #8586

Aperta
#8,588 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@petemoore ci sta già lavorando.

Dal 7/5/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

While auditing call sites for the offset-pagination bug class fixed by #8587, I found that services/auth/src/scoperesolver.js:193-200 uses the same dangerous pattern:

let offset = 0;
while (true) {
  const rows = await this.db.fns.get_clients(null, 1000, offset);
  if (rows.length === 0) {
    break;
  } else {
    offset += 1000;
  }
  // ... process clients
}

This loop walks the full clients table to rebuild the in-memory client cache used for scope resolution. Concurrent client inserts/deletes during the reload shift rows between pages, so a client can be silently skipped (or returned twice) — exactly the same offset-pagination race fixed in #8586/#8587 for the worker-scanner.

Severity

Lower than the worker-scanner case — this is an eventually-consistent cache, not a termination decision — but real:

  • A skipped client briefly fails authentication for that client until the next reload.
  • A duplicated client wastes work and slightly distorts the resolver's cache.
  • The race repeats every reload cycle whenever clients are being created/expired during the same window.

Fix

Same shape as #8587: add a keyset-paginated DB function get_clients_after (in DB version 0126), then migrate the scoperesolver scan loop to use it via paginatedIterator from @taskcluster/lib-postgres. The existing get_clients will be marked deprecated, and the auth API handler (auth/src/api.js) and static-clients.js migrated to the new function as well.

Audit context

The full audit found six internal full-set scan loops in services/. Five are already safe (keyset, self-terminating, or DB-side single-call). This is the only remaining one with the offset-pagination race.

A separate follow-up will add an ESLint rule banning the offset-loop pattern to prevent regressions.

References

  • Original bug: #8586
  • Original fix (worker-scanner / provisioner): #8587
Lingua principale
JavaScript
Stelle
436
Fork
307
Merge medio
1g 10h
PR unite (30g)
94

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di taskcluster/taskcluster

Tutte le issue di taskcluster/taskcluster

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.