Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Broken Trino impersonation

オープン
#371 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
typescript

調査の方向性

Start with the input: false setting on user.additionalFields.username, and trace why parseAdditionalUserInputFromProviderProfile drops the username that mapProfileToUser returns during OAuth user creation. Then check the Trino API routes that fall back to locals.user?.username ?? 'anonymous'. Done means the username survives OAuth signup, impersonation works again, the update-user restriction from #330 still holds, and regression tests cover both cases.

索引モデルが issue の本文から書いたものです。

説明

In #330 I set input: false on user.additionalFields.username to stop users from changing it through /api/auth/update-user.
But better-auth also applies input: false to the OAuth provider profile: parseAdditionalUserInputFromProviderProfile skips such fields, so the username returned by mapProfileToUser is dropped when the user is created.

Without a username, the Trino API routes fall back to locals.user?.username ?? 'anonymous', which hides the error and breaks impersonation.

  • Fix and restore old behavior
  • While also ensuring that the Issue in #330 can not be exploited
  • Add regression tests
主要言語
TypeScript
スター
1
フォーク
0
平均マージ
3日 20時間
マージ済み PR(30日)
14

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

stackabletech/cockpit のほかの issue

stackabletech/cockpit の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。