Store access token in env variable CF_ACCESS_TOKEN alternatively to ~/.cf/config.json
メンテナーはふだん 3 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 48/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- go
- 領域
- authentication, cli, security
調査の方向性
まず cf login と cf oauth-token コマンドのフローから始め、その後のコマンドで ~/.cf/config.json がどのように読み込まれるかを追跡します。環境からアクセストークンを指定できる場所と、ログインオプションがどのように解析されるかを確認します。既存のトークン保存動作を壊さずに、要求された代替手段として CF_ACCESS_TOKEN がサポートされれば完了です。
索引モデルが issue の本文から書いたものです。
説明
What's the user value of this feature request?
User will get the option to store access code only in current session rather then writing it to the filesystem.
Who is the functionality for?
Any cf user be it an end user or an operator.
How often will this functionality be used by the user?
When logging in from an unsafe environment e.g. using a shared account on a jump host.
Who else is affected by the change?
No. It should be implemented as an alternative to how it is handled currently.
Is your feature request related to a problem? Please describe.
In some cases we use shared environments like a jump host where in some cases shared accounts are used to login e.g. emergency user. If cf cli writes my access token to disk it can be seen and used by any other user logged in with the same account.
Same issue exists if you ssh into a container and use cf or if you use a webshell like jupyter notebook.
Describe the solution you'd like
cf login command should support an option e.g. --token-to-env which exports the access token to the environment e.g. variable CF_ACCESS_TOKEN . Subsequent cf commands would respect the env veriable if no access token is stored in .cf/config.json
Describe alternatives you've considered
cf login could also have a flag -oauth-token the would just return the access token like in cf oauth-token . So the user could store it in CF_ACCESS_TOKEN which would then need to be respected by other cf commands.
Additional context
n.a.
- 主要言語
- Go
- スター
- 1.9k
- フォーク
- 989
- 平均マージ
- 4日 15時間
- マージ済み PR(30日)
- 8
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
cloudfoundry/cli のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 52/100
cloudfoundry/cli#3866 ·
メンテナーはふだん 3 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
cloudfoundry/cli#3863 · コメント 2 件 · リアクション 1 件 ·
メンテナーはふだん 3 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 45/100
cloudfoundry/cli#3851 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 3 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
cloudfoundry/cli#3794 ·
メンテナーはふだん 3 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 48/100
cloudfoundry/cli#3787 · コメント 1 件 ·
メンテナーはふだん 3 日以内に返信
cloudfoundry/cli の issue をすべて見る
似ている issue
-
flaky-test
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
SocialGouv/iterion#2108 ·
メンテナーはふだん 1 日以内に返信