Bound OAuth state and LDAP cache growth
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 50/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- python
- Lĩnh vực
- authentication, backend
Hướng nghiên cứu
Bắt đầu trong src/asfquart/generics.py, quanh dòng 40 và các dòng 87-93, để theo dõi cách các trạng thái OAuth đang chờ được lưu trữ và xóa trong các callback. Xem xét các phương án cleanup trong issue, sau đó thêm một cơ chế cleanup định kỳ và các unit test để xác minh rằng các mục đã hết hạn được xóa. Được xem là hoàn tất khi các trạng thái bị bỏ dở không còn tích lũy và các tiến trình chạy lâu dài duy trì mức sử dụng bộ nhớ ổn định.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Issue: FINDING-276 - No Expiry Cleanup for Stale OAuth State Entries (Memory Leak)
Labels: bug, security, priority:low, asvs-level:L2
ASVS Level(s): L2
Description:
Summary
Expired state entries are only cleaned up when specifically looked up during a callback. If a user initiates an OAuth flow but never completes the callback, the state entry remains in the dictionary indefinitely until process restart, causing gradual memory growth. With ~200 bytes per entry, 1000 abandoned flows would leak ~200 KB. This is a resource leak rather than a security vulnerability, but could impact long-running processes in high-traffic scenarios.
Details
In src/asfquart/generics.py at line 40 and lines 87-93, expired state entries are only cleaned up on lookup, not proactively.
Recommended Remediation
Implement periodic cleanup mechanism.
Option 1: Add async background task that runs every 5 minutes to clean expired states:
async def _cleanup_expired_states():
current_time = time.time()
expired = [s for s, d in pending_states.items() if d['timestamp'] < (current_time - workflow_timeout)]
for state in expired:
pending_states.pop(state, None)
Option 2: Probabilistic cleanup on each request (e.g., 10% of requests trigger cleanup).
Option 3: Migrate to Redis with automatic TTL-based expiry.
Acceptance Criteria
- Periodic cleanup mechanism implemented
- Memory leak eliminated
- Long-running processes maintain stable memory usage
- Unit tests verify cleanup logic
References
- Source reports: L2:10.4.7.md
- Related findings: FINDING-272
- ASVS sections: 10.4.7
Priority
Low
The LDAP_CACHE dictionary is a module-level in-memory cache with no size limit, no eviction policy, and no background cleanup. Entries are only overwritten when the same userid is looked up again. The TTL (3600s) is checked for staleness (to determine if a re-query is needed) but expired entries are never removed from memory. Over the lifetime of the process, the cache grows monotonically as new users are encountered.
- Ngôn ngữ chính
- Python
- Star
- 7
- Fork
- 13
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của apache/infrastructure-asfquart
-
bug priority
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
Document OAuth callback consistency rulesCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởdocumentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
apache/infrastructure-asfquart#126 · 1 bình luận ·
-
ASVS priority
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
apache/infrastructure-asfquart#85 · 1 bình luận ·
-
Triage and track asfquart issuesCó thể đã có người làm @sbp đã nhận 1 ngày trước. Đang mở
apache/infrastructure-asfquart#134 · 1 người được giao ·
Tất cả issue của apache/infrastructure-asfquart
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
-
Harmony OPeNDAP SubSetter (HOSS) Geographic LARC_CLOUD PREFIRE_SAT2_AUX-SAT R01 production
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
nasa/harmony-autotester#245 ·
-
[FEATURE] - Add UTVD supportĐang mởenhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Deltares/imod-python#1928 ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100