BReg acceptance: statistics profiles admit any token of the project
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- rust
- Lĩnh vực
- authorization
Hướng nghiên cứu
Bắt đầu tại products/breg/acceptance/facility/registry.yaml: so sánh hai profile statistics-publisher và statistics-reader với các profile khác khai báo requiredScopes/requiredPurposes. Kiểm tra dev-clients.yaml để xem các scope đã được cấp (registry:facility:statistics:publish / :read) và docs/site/src/content/docs/configure/breg-access.mdx để nắm ngữ nghĩa admission. Hoàn thành nghĩa là bregctl check không còn phát ra access.profile.no_required_scope cho các profile này và các bài test statistics cùng script workflow vẫn vượt qua với các dev-client scope hiện có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
In products/breg/acceptance/facility/registry.yaml, statistics-publisher and statistics-reader declare only principalClaim: registry_principal: no requiredScopes and no requiredPurposes. Every other profile in the project uses the same principal claim, and a request is admitted against whichever profile the application selects (docs/site/src/content/docs/configure/breg-access.mdx, "One profile per request"). So a token issued for any task in this project can select statistics-publisher.
statistics-publisher lists and counts permits and discharge reports in every district (rowBoundaries: [], allowCount: true), filterable by permit type, validity dates, boundary and the derived flags. That is required for it to publish releases, but it means any caller with a token for this registry can obtain exact counts, including the small cells a release suppresses (1 to 4) and rounds.
The intent looks clear from dev-clients.yaml, which gives the publisher client registry:facility:statistics:publish and the reader client registry:facility:statistics:read; the profiles never require those scopes. bregctl check already warns (access.profile.no_required_scope: "any authenticated" caller), but the acceptance project is the example adopters copy for statistics.
Expected. Both statistics profiles require their scope (and the project's purpose if that fits), and the statistics tests and workflow script keep passing with the dev clients' existing scopes.
- Ngôn ngữ chính
- Rust
- Star
- 2
- Fork
- 0
- Merge trung bình
- 8 giờ 50 phút
- Pull request đã merge (30 ngày)
- 258
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của registrystack/registry-stack
-
area:casework bug criticality:p2 rust
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
registrystack/registry-stack#1936 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:casework bug criticality:p3 rust
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
registrystack/registry-stack#1934 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:release area:scheduling bug criticality:p3 triage:needs-implementation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
registrystack/registry-stack#1909 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:release bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
registrystack/registry-stack#1874 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:breg bug criticality:p3
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
registrystack/registry-stack#1851 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của registrystack/registry-stack
Issue tương tự
-
app enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 80/100
elodin-sys/elodin#890 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
guidance-ai/llguidance#391 ·
-
documentation
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
Verifiedz/Shimmer#144 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
点击设置提示`操作未能完成,详情请查看应用日志`Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Y-ASLant/ElegantClipboard#166 ·