Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

BReg acceptance: statistics profiles admit any token of the project

Open Beginner friendly
#1,941 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
rust
Domain
authorization

Research direction

Start at products/breg/acceptance/facility/registry.yaml: compare the statistics-publisher and statistics-reader profiles against other profiles that declare requiredScopes/requiredPurposes. Check dev-clients.yaml for the scopes already granted (registry:facility:statistics:publish / :read) and docs/site/src/content/docs/configure/breg-access.mdx for admission semantics. Done means bregctl check no longer emits access.profile.no_required_scope for these profiles and the statistics tests plus workflow script still pass with the existing dev-client scopes.

Written by the indexing model from the issue text.

Description

agent-ready area:breg bug criticality:p3 triage:needs-implementation

In products/breg/acceptance/facility/registry.yaml, statistics-publisher and statistics-reader declare only principalClaim: registry_principal: no requiredScopes and no requiredPurposes. Every other profile in the project uses the same principal claim, and a request is admitted against whichever profile the application selects (docs/site/src/content/docs/configure/breg-access.mdx, "One profile per request"). So a token issued for any task in this project can select statistics-publisher.

statistics-publisher lists and counts permits and discharge reports in every district (rowBoundaries: [], allowCount: true), filterable by permit type, validity dates, boundary and the derived flags. That is required for it to publish releases, but it means any caller with a token for this registry can obtain exact counts, including the small cells a release suppresses (1 to 4) and rounds.

The intent looks clear from dev-clients.yaml, which gives the publisher client registry:facility:statistics:publish and the reader client registry:facility:statistics:read; the profiles never require those scopes. bregctl check already warns (access.profile.no_required_scope: "any authenticated" caller), but the acceptance project is the example adopters copy for statistics.

Expected. Both statistics profiles require their scope (and the project's purpose if that fits), and the statistics tests and workflow script keep passing with the dev clients' existing scopes.

Dominant language
Rust
Stars
2
Forks
0
Avg merge
9h 5m
Merged PRs (30d)
248

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from registrystack/registry-stack

All issues in registrystack/registry-stack

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.