Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

BReg acceptance: statistics profiles admit any token of the project

オープン 初心者向け
#1,941 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
78/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
rust
領域
authorization

調査の方向性

products/breg/acceptance/facility/registry.yaml から始める: statistics-publisher と statistics-reader のプロファイルを、requiredScopes/requiredPurposes を宣言している他のプロファイルと比較する。付与済みのスコープ(registry:facility:statistics:publish / :read)については dev-clients.yaml を、受理(admission)のセマンティクスについては docs/site/src/content/docs/configure/breg-access.mdx を確認する。完了の条件は、bregctl check がこれらのプロファイルに対して access.profile.no_required_scope をもう出力しなくなり、statistics のテストとワークフロースクリプトが既存の dev-client スコープのまま引き続き通ることである。

索引モデルが issue の本文から書いたものです。

説明

agent-ready area:breg bug criticality:p3 triage:needs-implementation

In products/breg/acceptance/facility/registry.yaml, statistics-publisher and statistics-reader declare only principalClaim: registry_principal: no requiredScopes and no requiredPurposes. Every other profile in the project uses the same principal claim, and a request is admitted against whichever profile the application selects (docs/site/src/content/docs/configure/breg-access.mdx, "One profile per request"). So a token issued for any task in this project can select statistics-publisher.

statistics-publisher lists and counts permits and discharge reports in every district (rowBoundaries: [], allowCount: true), filterable by permit type, validity dates, boundary and the derived flags. That is required for it to publish releases, but it means any caller with a token for this registry can obtain exact counts, including the small cells a release suppresses (1 to 4) and rounds.

The intent looks clear from dev-clients.yaml, which gives the publisher client registry:facility:statistics:publish and the reader client registry:facility:statistics:read; the profiles never require those scopes. bregctl check already warns (access.profile.no_required_scope: "any authenticated" caller), but the acceptance project is the example adopters copy for statistics.

Expected. Both statistics profiles require their scope (and the project's purpose if that fits), and the statistics tests and workflow script keep passing with the dev clients' existing scopes.

主要言語
Rust
スター
2
フォーク
0
平均マージ
9時間 5分
マージ済み PR(30日)
248

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

registrystack/registry-stack のほかの issue

registrystack/registry-stack の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。