Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Add WordPress adversarial adapter and vulnerable runtime campaigns

Đang mở
#2,017 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Ít trao đổi
Công nghệ
php, typescript

Hướng nghiên cứu

Bắt đầu bằng việc đọc các contract chung được tham chiếu trong #2014 và ánh xạ các surface WordPress, oracle adapter, lỗi vận chuyển, clock, signal và fixture được liệt kê vào phạm vi adapter được yêu cầu. Công việc được xem là hoàn tất khi các campaign dùng một lần với quyền truy cập mạng bị từ chối bao phủ các tiêu chí chấp nhận, bao gồm replay xác định, journey được tối giản, fingerprint ổn định và các provenance bundle được niêm phong, đã ẩn thông tin, mà không có policy dành riêng cho WordPress trong runtime-core.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Problem

The generic #2014 contracts deliberately do not embed WordPress grammars, policies, hooks, or transport special cases. A WordPress extension adapter is still required to turn them into end-to-end security and correctness campaigns inside disposable WP Codebox runtimes.

Scope

  • Register WordPress-owned mutators for REST, AJAX, XML-RPC, blocks, shortcodes, serialized values, options/meta, files, cron, CLI, roles/capabilities, and multisite membership.
  • Register generic-oracle adapters for authorization/nonce/tenant isolation, injection/execution indicators, transactional consistency, duplicate effects, fail-open behavior, filesystem escape, and secret leakage.
  • Intercept WordPress HTTP transports using the generic transport-fault model and publish exact/emulated/unsupported fidelity.
  • Add faithful PHP/WordPress and cron clock controls; report database clock support independently.
  • Emit bounded hook, route, query, filesystem, cache, lock, memory, CPU, and duration novelty signals.
  • Add intentionally vulnerable neutral plugin and theme fixtures for authorization, injection, state corruption, true races, external-service failure, and UI-state defects.
  • Run disposable integration/E2E campaigns that automatically discover and minimize every fixture defect and replay stable findings.

Acceptance criteria

  • Fixtures run only inside disposable runtimes with network denied by default.
  • Campaigns prove deterministic concurrent replay, service failure/recovery, minimized browser journeys, and stable fingerprints.
  • Every finding has a sealed, redacted replay bundle with exact runtime/component provenance.
  • No WordPress-specific name or policy enters runtime-core.

Refs #2014

Ngôn ngữ chính
TypeScript
Star
17
Fork
4
Merge trung bình
43 phút
Pull request đã merge (30 ngày)
70

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của Automattic/wp-codebox

Tất cả issue của Automattic/wp-codebox

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.