`masterKey` function is not called on server start
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 78/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- node.js, typescript
- 領域
- backend
調査の方向性
src/ParseServer.ts の ParseServer.start() から始め、起動タスクが Config.put() から返されたオプションにアクセスする方法を追跡します。拒否する masterKey 関数を使って問題を再現し、その後、起動処理がそれを呼び出し、リクエストを受け付ける前に拒否することを確認します。
索引モデルが issue の本文から書いたものです。
説明
New Issue Checklist
- Report security issues confidentially.
- Any contribution is under this license.
- Before posting search existing issues.
Issue Description
If the Parse Server option masterKey is set to a function, the function is supposed to be called when Parse Server starts; ParseServer.start() in src/ParseServer.ts adds this.config.loadMasterKey?.() to the startup tasks. However, this.config is the plain options object returned by Config.put(), not a Config instance. It has no loadMasterKey method, so the optional call does nothing. This has been the case since setting masterKey to a function was added in #9582 (Parse Server 8.0.0).
As a result, the function is only called on the first request. If it fails, for example because a secret store is unavailable, Parse Server starts nonetheless and responds to every request with status 500, including the /health endpoint. Other startup tasks, such as the migration of the schema option or the connection of the cache adapter, make the start fail instead.
Steps to reproduce
- Start Parse Server with
masterKey: () => Promise.reject(new Error('secret store unavailable')), and awaitParseServer.start(). - Send any request, for example
GET /parse/health.
Actual Outcome
ParseServer.start() resolves; the masterKey function has not been called. The request fails with status 500 and {"code":1,"message":"Internal server error."}, and so does every following request.
Expected Outcome
The masterKey function is called when Parse Server starts, and ParseServer.start() rejects if the function fails.
Environment
Server
- Parse Server version:
9.10.2-alpha.4(alphabranch); since8.0.0 - Operating system: any
- Local or remote host: any
Database
- System: any
- Database version: any
- Local or remote host: any
Client
- SDK: any
- SDK version: any
Logs
Not applicable
- 主要言語
- JavaScript
- スター
- 21.4k
- フォーク
- 4.8k
- 平均マージ
- 1日 22時間
- マージ済み PR(30日)
- 49
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
parse-community/parse-server のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
parse-community/parse-server#10720 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
parse-community/parse-server#10699 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
parse-community/parse-server#10634 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 84/100
parse-community/parse-server#10631 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
/installations and /audiences reject a find sent as POST + _method=GET with "Invalid key name: 0"オープン
難易度 2/5 半日 初心者へのやさしさ 65/100
parse-community/parse-server#10626 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
parse-community/parse-server の issue をすべて見る
似ている issue
-
Add google analyticsオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
NCAR/music-box-interactive#628 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
remotion-dev/remotion#11847 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
phoenixframework/phoenix_live_view#4456 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
AllTheMods/ATM-10#4436 ·
メンテナーはふだん 5 日以内に返信