Avoid exposing Git credentials in subprocess command-line arguments
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 56/100
Hướng nghiên cứu
Tìm đoạn mã xây dựng các đối số cho tiến trình con của Git và xử lý cấu hình chứa thông tin xác thực, sau đó lần theo việc xác thực các giá trị ủy quyền và URL kho lưu trữ của nó. Kiểm tra cách môi trường của tiến trình con được thiết lập, bao gồm các mục GIT_CONFIG_* hiện có và các số lượng bị sai định dạng. Công việc được xem là hoàn tất khi thông tin xác thực không xuất hiện trong các đối số của tiến trình con, đồng thời việc bảo toàn cấu hình, xác thực và hành vi ủy quyền theo phạm vi vẫn được các bài kiểm thử bao phủ.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Description
Cachew currently passes repository-scoped authorization credentials to Git using command-line configuration:
git -c credential.helper=<helper containing credential> ...
The credential is embedded as a literal in the helper definition, which exposes it in Git's process arguments. Command-line arguments may be visible through process inspection tools, /proc/<pid>/cmdline, diagnostic tooling, or process telemetry.
PR #321 also identified that credentials are embedded in the helper command, but addressed token refresh during long-running subprocesses. It was closed in favor of #322, which addressed token lifetime and LFS timeouts without removing credentials from process arguments.
Proposed change
Pass credential-bearing Git configuration through Git's environment-based configuration mechanism instead:
GIT_CONFIG_COUNT=<n>
GIT_CONFIG_KEY_<n>=http.<repository-scope>.extraHeader
GIT_CONFIG_VALUE_<n>=Authorization: <credential>
The implementation should:
- Preserve existing
GIT_CONFIG_COUNT,GIT_CONFIG_KEY_*, andGIT_CONFIG_VALUE_*entries. - Append the credential configuration at the next available index.
- Reject malformed, negative, or overflowing
GIT_CONFIG_COUNTvalues. - Continue validating the authorization value and repository URL scope.
- Restrict this change to credential-bearing configuration; ordinary non-sensitive Git configuration can remain in command-line arguments.
- Ensure credentials do not appear in the generated Git subprocess arguments.
Security impact
This reduces accidental credential disclosure through process listings and command-line capture. The credential remains in the child process environment, as required by Git, so access to process environments should still be restricted appropriately.
- Ngôn ngữ chính
- Go
- Star
- 41
- Fork
- 14
- Merge trung bình
- 19 giờ 28 phút
- Pull request đã merge (30 ngày)
- 3
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của block/cachew
-
etag-range-followup
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
Azure Blob as a storage backendĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 30/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 38/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
Issue tương tự
-
agentic-workflows
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
priority/4/normal status/needs-triage type/bug/unconfirmed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
authelia/authelia#13292 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
blinklabs-io/actions#138 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[UI] AlbumDetails collapses multi-genre list to single primary genre on viewports < lg breakpointĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày