Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Security Feature Request and Issues

Đang mở
#7,104 0 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
typescript
Lĩnh vực
documentation, security

Hướng nghiên cứu

Không có tệp hoặc kiểm thử nào được nêu tên. Hãy bắt đầu bằng cách xác định mục FAQ và đường dẫn tạo tệp cấu hình, sau đó xác định những mối lo ngại bảo mật được yêu cầu nào nằm trong phạm vi. Phần hoàn tất cần làm rõ hành vi của giới hạn tốc độ đăng nhập và xử lý việc lộ tệp cấu hình, trong đó mọi công việc tùy chỉnh hoặc liên quan đến fail2ban phải được xác định riêng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement
Issue 1: Ambiguity in Login Rate Limits

The code-server FAQ states:

code-server supports setting a single password and limits logins to two per minute plus an additional twelve per hour.

This language is somewhat ambiguous and leaves room for interpretation. For example:

  1. Are successful logins also part of the rate limit?
  2. Are failed logins excluded from the rate limit?
Proposed Solution

To clarify, the FAQ could be revised as follows:

code-server supports setting a single password and limits all logins (successful or unsuccessful) to two per minute plus an additional twelve per hour.

Issue 2: Configuration File Permissions

When starting code-server, the generated configuration file is created with permissions that allow other users on the system to view the file. This can potentially expose the user’s password.

Proposed Solution
  • Ensure that the configuration file is created with stricter permissions, making it readable and writable only by the user running code-server.
  • Alternatively, provide a clear warning in the documentation about this behavior so users can manually adjust permissions.
Additional Feature Suggestion

As someone who prioritizes tight security but does not want to limit successful logins, it would be ideal to:

  • Customize rate limit settings.
  • Configure integration with fail2ban for more comprehensive security.

These enhancements would provide significant benefits for users who require fine-grained control over security policies.

Ngôn ngữ chính
TypeScript
Star
79.4k
Fork
6.9k
Merge trung bình
2 ngày 13 giờ
Pull request đã merge (30 ngày)
39

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của coder/code-server

Tất cả issue của coder/code-server

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.