Problem: enabling addhoc queries reveal tx data
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
Research direction
Start by tracing the chain.block RPC entry point and the ad hoc query configuration discussed in the issue. Determine the intended scope with the Kwil team before changing anything. Done would mean a block-header-only query path is clearly specified and does not expose raw transaction data when ad hoc queries are disabled.
Written by the indexing model from the issue text.
Description
actually... I'm still not sure it's the right move yet, I'm asking to the kwil team. I'll open a new issue about this. If the risk is only data exposure of transactions, it might be minor in this phase.
Originally posted by @outerlook in https://github.com/trufnetwork/node/issues/932#issuecomment-2883723790
from @brennanjl
Yes, disabling ad hoc queries also disables chain.block. This is because chain.block returns the entirety of the block data (all of the raw transactions). If this was not the case, then attackers could use chain.block as a workaround to read sensitive network information when queries are disabled
This is actually a perfect case where an rpc endpoint for querying a block header only would be ideal. It does not have the security concerns mentioned above because it doesn’t return the raw transaction data for a block
and I raised a point if it's as sensitive as enabling public direct access to 8484 endpoints from nodes
- Dominant language
- Go
- Stars
- 7
- Forks
- 3
- Avg merge
- 3h 2m
- Merged PRs (30d)
- 13
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from trufnetwork/node
-
type: goal
Difficulty 5/5 Over a week Newbie friendliness 35/100
trufnetwork/node#1436 ·
Maintainers usually reply within 1 day
-
Problem: settlement can't tell a capture was taken too earlyPossibly taken @MicBun claimed this 8 days ago. Open
trufnetwork/node#1435 · 1 assignee ·
Maintainers usually reply within 1 day
-
Goal: SDK call for market volume over a time periodPossibly taken @vinarmani claimed this 9 days ago. Open
trufnetwork/node#1429 · 2 comments · 1 assignee ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
trufnetwork/node#1313 · 2 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
trufnetwork/node#1200 · 1 comment ·
Maintainers usually reply within 1 day
All issues in trufnetwork/node
Similar issues
-
area/proxy kind/bug priority/backlog triage/accepted
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
lexfrei/cloudflare-tunnel-gateway-controller#840 ·
Maintainers usually reply within 1 day
-
area:chat bug sev:papercut
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Agent-Field/CodeAF#1592 ·
Maintainers usually reply within 1 day
-
kind/bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 7 days
-
bug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug P2 reliability
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
afreidah/s3-orchestrator#1564 ·
Maintainers usually reply within 1 day