Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Make `HeaderValue::set_sensitive` available in const contexts

Đang mở
#807 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
45/100
Loại issue
Tính năng
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
rust
Lĩnh vực
api

Hướng nghiên cứu

Bắt đầu từ các định nghĩa của HeaderValue::set_sensitive và HeaderValue::from_static, đồng thời kiểm tra tài liệu và các bài kiểm thử xung quanh. Làm cho set_sensitive có thể được sử dụng trong các ngữ cảnh const, thêm cảnh báo được yêu cầu về việc nhúng bí mật nếu phù hợp, và xác minh rằng hành vi hiện có của HeaderValue vẫn được kiểm thử đầy đủ.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

A-headers E-easy S-feature

Hey, I'd like to use HeaderValue::set_sensitive when defining header value constants with HeaderValue::from_static.
In particular, I'd like to mark an OAuth client credential that's compiled into the application as sensitive.

I fully understand that a value that's compiled into the binary is trivial to dump and shouldn't be considered secure. Moreover, I fully understand that no amount of obfuscation will change this. However, many OAuth implementations (like GitHub or Forgejo) always issue client credentials, regardless of whether the client is public or confidential. This means clients are forced to use the credential, which effectively means the credential has to be embedded into the client.

I'd be willing to contribute a PR for this, but I wanted to open an issue to discuss first, as the idea of storing confidential header values as constants seems controversial. In addition to the const keyword, a note in the doc comment to discourage developers from embedding secrets might be warranted.


Thank you for creating Hyper and this crate!

Ngôn ngữ chính
Rust
Star
1.4k
Fork
378
Merge trung bình
1 ngày 21 giờ
Pull request đã merge (30 ngày)
5

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của hyperium/http

Tất cả issue của hyperium/http

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.