Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Portal dev auth: replace mkcert CA install with leaf-only localhost trust

オープン
#1,298 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
48/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
docker, docker-compose, shell

調査の方向性

Start with scripts/ensure-dev-certs.sh and the entra-local and entra-local-certs-init services in docker-compose.yml, tracing the existing certificate generation, trust installation, and DEV_CERT_DIR handling. Verify direct leaf trust and the one-command entra-local flow on the target platform(s), including the browser/MSAL TLS handshake. Done means the leaf is localhost-scoped and trusted without the root-CA installation path, with the shared certificate directory and validity requirements covered.

索引モデルが issue の本文から書いたものです。

説明

Original author: @manekinekko

Follow-up from PR #1243 review (finding 🟡, by @cedricvidal_microsoft).

Context

The one-command local dev auth flow (entra-local served over HTTPS) currently uses mkcert -install, which adds a root CA to the OS/browser trust store. That CA can sign a cert for any hostname and forces a one-time admin/sudo prompt. For a dev emulator that only ever needs to be trusted for localhost, this is a heavier trust grant than the feature requires.

Proposal

Drop mkcert -install and trust only the leaf cert (already CA:FALSE, SAN-scoped to localhost / 127.0.0.1 / ::1). Trusting the leaf directly (e.g. security add-trusted-cert -r trustAsRoot into the login keychain on macOS, no sudo) caps the trust blast radius to localhost and can't vouch for any other domain. MSAL only needs the TLS handshake to https://localhost:<port> to succeed.

Scope / considerations

  • Cross-platform trust plumbing is the main cost: mkcert -install hides the macOS/Linux/Windows trust stores behind one command; leaf-only means doing it per-OS ourselves (security add-trusted-cert on macOS, plus Linux and Windows equivalents). Landing macOS first and staging Linux/Windows as follow-ups may be acceptable.
  • Validity cap: directly-trusted leaves can hit the browser 398-day server-cert cap (mkcert's leaf is ~823 days). Mint a =398-day leaf to sidestep it.
  • Shared cert dir: parameterize the compose mount to ${DEV_CERT_DIR:-./.certs}:/certs-src:ro (the script already honors DEV_CERT_DIR) so a dev can set DEV_CERT_DIR=$HOME/.scope-dev-certs once and share a single leaf + a single trust action across all worktrees and ports.
  • Verify before committing: confirm browsers/MSAL accept a directly-trusted leaf on each target platform (untested as of the PR review).

Not in scope

The rootless/UID-remapped container permission issue (finding F1) was already fixed in PR #1243 (f886e348) independently, without loosening the key, via an ownership-fixing init service. If we adopt leaf-only later, the in-volume key handling can be revisited then.

Relevant files: scripts/ensure-dev-certs.sh, docker-compose.yml (the entra-local / entra-local-certs-init services).

主要言語
TypeScript
スター
7
フォーク
13
平均マージ
3日 5時間
マージ済み PR(30日)
26

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

microsoft/scope のほかの issue

microsoft/scope の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。