Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[docs-scanner] Unclear relationship between sandbox:use PAT permission and granular account permissions

オープン 初心者向け
#26,225 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
1/5
見積もり時間
1時間未満
初心者へのやさしさ
88/100
issue の種類
ドキュメント
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
docker
領域
documentation

調査の方向性

content/manuals/ai/sandboxes-api/authentication.md を開き、「Authenticate automation with a PAT」および「Resource access and permissions」セクションを読んでください。PAT スコープの sandbox:use と sandboxesCreate、sandboxesRead、sandboxesDelete の関係を明確にしてください。両方のチェックが各リクエストに影響することも含めてください。ドキュメントで権限エラーの診断方法が説明されていることを確認してください。

索引モデルが issue の本文から書いたものです。

説明

File: content/manuals/ai/sandboxes-api/authentication.md

Issue

The authentication documentation describes two different permission concepts without explaining their relationship:

  1. PAT scope: "When creating the token, select the sandbox:use permission in your Docker account's personal access token settings."

  2. Account permissions: "Each request also checks whether you have permission for the action on the target resource. For example, creating a sandbox requires sandboxesCreate, reading it requires sandboxesRead, and deleting it requires sandboxesDelete."

The document never clarifies:

  • Does the sandbox:use PAT scope grant all the granular permissions (sandboxesCreate, sandboxesRead, etc.)?
  • Are the granular permissions separate account-level settings that must also be configured?
  • If a PAT has sandbox:use but the account lacks sandboxesCreate, what happens?
Why this matters

A reader setting up authentication needs to know:

  • Whether selecting sandbox:use is sufficient for all sandbox operations
  • Whether additional account configuration is required beyond creating the PAT
  • How to diagnose permission errors (is it the PAT scope or the account permission?)

The current text suggests these are related but doesn't explain the relationship, leaving readers uncertain whether they've completed the setup correctly.

Suggested fix

Add a clarifying sentence in the "Authenticate automation with a PAT" section:

When creating the token, select the sandbox:use permission in your Docker account's personal access token settings. This scope grants access to all sandbox operations, subject to your account's permissions. The API checks both the PAT scope and your account permissions for each request.

Or add a subsection under "Resource access and permissions" that explicitly states:

The sandbox:use PAT scope authorizes your application to act on your behalf. Your account's permissions (sandboxesCreate, sandboxesRead, etc.) then determine which operations succeed. Both the PAT scope and the account permission must allow the action.


Found by nightly documentation quality scanner

主要言語
Markdown
スター
4.7k
フォーク
8.5k
平均マージ
1日 18時間
マージ済み PR(30日)
127

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

docker/docs のほかの issue

docker/docs の issue をすべて見る

似ている issue

Documentation の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。