Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Should we allow creation of participants with uuids provided by the client?

Đang mở
#130 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
20/100
Loại issue
Tính năng
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Đình trệ
Công nghệ
elixir
Lĩnh vực
api, backend

Hướng nghiên cứu

Bắt đầu bằng việc đọc issue #128 và hành vi participant upsert hiện tại trong quá trình tạo ủy quyền và bỏ phiếu. Làm rõ liệu có nên chấp nhận các participant UUID do client cung cấp hay không, sau đó ghi lại các quyết định về bảo mật của mã định danh, các UUID chỉ-đọc và các mã định danh tạm thời.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

This has come up during investigation of #128, and needs further discussion:

One of the reasons we decided to use uuids as ids is to enable passing around of identifiers to/from clients and other services, and we're supporting for pre-existing resources in our system - votes, delegations and participants already persisted in the database.

Currently we support upserts of participants on delegation and voting creation based on emails provided by the client.

Another potential scenario is when the client already generates uuids for their participants (for which they're the source the truth), and submits that to us instead of an email. For instance, when creating a delegation, submitting delegator_id and delegate_id instead of a delegator_email and delegate_email. This could be a way to improve the privacy of the participant in our system. We'd only know their client-side id.

Questions raised so far:

  • YAGNI?
  • any security issues with passing around a direct db identifier like that?
  • in some instances clients will create a view-only uuid, and sometimes that's ephemeral. How do we handle that?
Ngôn ngữ chính
Elixir
Star
17
Fork
3
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của liquidvotingio/api

Tất cả issue của liquidvotingio/api

Issue tương tự

Thêm issue về Elixir

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.