Make it impossible to accidentally define a nonfunctional secret extension
Mantenedores costumam responder em até 2 dias
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 38/100
Direção de pesquisa
Start by inspecting the JSON Schema rules for extension manifests and the process_secret_args function. Compare enforcing one name argument with appending the secret name at runtime, including the optional vault argument. Done means non-functional secret definitions are prevented or clearly handled, with the limitation surfaced through dsc extension list or trace messages.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary of the new feature / enhancement
As an extension developer,
I want a clear contract for defining a secret extension that prevents defining a non-functional extension,
so that I can correctly define my extension without reading the implementation code in the DSC engine library.
In the current implementation:
- The
secret.argsfield for an extension manifest is optional. - The
secret.argsfield doesn't require exactly one instance of the name argument (like{"nameArg": "--secret-name"}). This makes it possible to define an extension that can't lookup specific secrets. Presumably, it will always return the same secret regardless of name, which seems counter to the spirit of thesecret(<name>[, <vault>])function. - The
secret.argsfield doesn't limit the inclusion of name and vault arguments to a single instance. - The
process_secret_argsfunction doesn't have any way to pass the secret name to an extension except with the name argument - no handling for ifnamewasn't processed in args. - The implementation doesn't signal to the user that no name can be provided. There's no surfacing of this information either in the representation for
dsc extension listor through trace messages.
Proposed technical implementation details (optional)
There are two different paths we can take:
- Update the JSON Schema to explicitly require
argsand to require a single name argument and optionally allow a single vault argument. - Update the implementation to append the secret name as the final argument to the executable when
argsisn't defined or is defined without a name argument.
The current implementation allows for non-functional extension manifest definitions. While it could be considered a breaking change to make the schema modifications, since they only exclude non-functional definitions this may be acceptable.
- Linguagem predominante
- Rust
- Estrelas
- 526
- Forks
- 76
- Merge médio
- 4d 20h
- PRs com merge (30d)
- 24
Preparar o ambiente
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de PowerShell/DSC
-
Feature Request: Support dsc functions in executable argsTalvez já em andamento @SteveL-MSFT assumiu há 5 dias. AbertaIssue-Enhancement
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 62/100
PowerShell/DSC#1722 · 4 comentários · 1 responsável ·
Mantenedores costumam responder em até 2 dias
-
Dev-UX Needs Triage
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
PowerShell/DSC#1694 ·
Mantenedores costumam responder em até 2 dias
-
Issue-Enhancement Needs Triage
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 38/100
PowerShell/DSC#1683 · 5 comentários ·
Mantenedores costumam responder em até 2 dias
-
Issue-Enhancement Needs Triage
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
PowerShell/DSC#1673 ·
Mantenedores costumam responder em até 2 dias
-
Issue-Enhancement Needs Triage
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
PowerShell/DSC#1669 · 1 reação ·
Mantenedores costumam responder em até 2 dias
Todas as issues de PowerShell/DSC
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
trezor/trezor-firmware#7997 ·
Mantenedores costumam responder em até 2 dias
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
smol-machines/smolvm#1489 · 1 comentário · 1 reação ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
Mantenedores costumam responder em até 1 dia