Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Bound OAuth state and LDAP cache growth

Đang mở
#95 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
50/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
authentication, backend

Hướng nghiên cứu

Bắt đầu trong src/asfquart/generics.py, quanh dòng 40 và các dòng 87-93, để theo dõi cách các trạng thái OAuth đang chờ được lưu trữ và xóa trong các callback. Xem xét các phương án cleanup trong issue, sau đó thêm một cơ chế cleanup định kỳ và các unit test để xác minh rằng các mục đã hết hạn được xóa. Được xem là hoàn tất khi các trạng thái bị bỏ dở không còn tích lũy và các tiến trình chạy lâu dài duy trì mức sử dụng bộ nhớ ổn định.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

ASVS bug priority

Issue: FINDING-276 - No Expiry Cleanup for Stale OAuth State Entries (Memory Leak)

Labels: bug, security, priority:low, asvs-level:L2

ASVS Level(s): L2

Description:

Summary

Expired state entries are only cleaned up when specifically looked up during a callback. If a user initiates an OAuth flow but never completes the callback, the state entry remains in the dictionary indefinitely until process restart, causing gradual memory growth. With ~200 bytes per entry, 1000 abandoned flows would leak ~200 KB. This is a resource leak rather than a security vulnerability, but could impact long-running processes in high-traffic scenarios.

Details

In src/asfquart/generics.py at line 40 and lines 87-93, expired state entries are only cleaned up on lookup, not proactively.

Recommended Remediation

Implement periodic cleanup mechanism.

Option 1: Add async background task that runs every 5 minutes to clean expired states:

async def _cleanup_expired_states():
    current_time = time.time()
    expired = [s for s, d in pending_states.items() if d['timestamp'] < (current_time - workflow_timeout)]
    for state in expired:
        pending_states.pop(state, None)

Option 2: Probabilistic cleanup on each request (e.g., 10% of requests trigger cleanup).

Option 3: Migrate to Redis with automatic TTL-based expiry.

Acceptance Criteria
  • Periodic cleanup mechanism implemented
  • Memory leak eliminated
  • Long-running processes maintain stable memory usage
  • Unit tests verify cleanup logic
References
  • Source reports: L2:10.4.7.md
  • Related findings: FINDING-272
  • ASVS sections: 10.4.7
Priority

Low


The LDAP_CACHE dictionary is a module-level in-memory cache with no size limit, no eviction policy, and no background cleanup. Entries are only overwritten when the same userid is looked up again. The TTL (3600s) is checked for staleness (to determine if a re-query is needed) but expired entries are never removed from memory. Over the lifetime of the process, the cache grows monotonically as new users are encountered.

Ngôn ngữ chính
Python
Star
7
Fork
13
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của apache/infrastructure-asfquart

Tất cả issue của apache/infrastructure-asfquart

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.