BReg acceptance: statistics profiles admit any token of the project
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- rust
- Domain
- authorization
Research direction
Start at products/breg/acceptance/facility/registry.yaml: compare the statistics-publisher and statistics-reader profiles against other profiles that declare requiredScopes/requiredPurposes. Check dev-clients.yaml for the scopes already granted (registry:facility:statistics:publish / :read) and docs/site/src/content/docs/configure/breg-access.mdx for admission semantics. Done means bregctl check no longer emits access.profile.no_required_scope for these profiles and the statistics tests plus workflow script still pass with the existing dev-client scopes.
Written by the indexing model from the issue text.
Description
In products/breg/acceptance/facility/registry.yaml, statistics-publisher and statistics-reader declare only principalClaim: registry_principal: no requiredScopes and no requiredPurposes. Every other profile in the project uses the same principal claim, and a request is admitted against whichever profile the application selects (docs/site/src/content/docs/configure/breg-access.mdx, "One profile per request"). So a token issued for any task in this project can select statistics-publisher.
statistics-publisher lists and counts permits and discharge reports in every district (rowBoundaries: [], allowCount: true), filterable by permit type, validity dates, boundary and the derived flags. That is required for it to publish releases, but it means any caller with a token for this registry can obtain exact counts, including the small cells a release suppresses (1 to 4) and rounds.
The intent looks clear from dev-clients.yaml, which gives the publisher client registry:facility:statistics:publish and the reader client registry:facility:statistics:read; the profiles never require those scopes. bregctl check already warns (access.profile.no_required_scope: "any authenticated" caller), but the acceptance project is the example adopters copy for statistics.
Expected. Both statistics profiles require their scope (and the project's purpose if that fits), and the statistics tests and workflow script keep passing with the dev clients' existing scopes.
- Dominant language
- Rust
- Stars
- 2
- Forks
- 0
- Avg merge
- 9h 5m
- Merged PRs (30d)
- 248
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from registrystack/registry-stack
-
area:casework bug criticality:p2 rust
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
registrystack/registry-stack#1936 ·
Maintainers usually reply within 1 day
-
area:casework bug criticality:p3 rust
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
registrystack/registry-stack#1934 ·
Maintainers usually reply within 1 day
-
area:release area:scheduling bug criticality:p3 triage:needs-implementation
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
registrystack/registry-stack#1909 ·
Maintainers usually reply within 1 day
-
area:release bug
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
registrystack/registry-stack#1874 ·
Maintainers usually reply within 1 day
-
area:breg bug criticality:p3
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
registrystack/registry-stack#1851 ·
Maintainers usually reply within 1 day
All issues in registrystack/registry-stack
Similar issues
-
agent:triaged bug bughunt pm:npm priority:p1
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
SocketDev/socket-patch#1127 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
documentation enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
adorsys/status-list-server#619 ·
Maintainers usually reply within 2 days
-
batch-backport only backports the first 30 matching PRsPossibly taken @DvirDukhan claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 5 days
-
Configuration-level resource: `Allocate` rejects the kubelet's re-offer of the same device for a later container of the same Pod ("Unable to claim slot")Possibly taken @fang80913 claimed this 38 days ago. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
project-akri/akri#854 ·