Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

The remote cache exposes credentials to tasks and env value hashes to the server

Đang mở
#781 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
rust
Lĩnh vực
security

Hướng nghiên cứu

Start with the remote cache configuration described in issue #727 and the key format in issue #755. Trace how credentials reach task processes and how tracked environment values are included in keys; done means credentials are supplied separately from the URL without reaching tasks, and the server cannot recover individual environment values.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

remote cache

Credentials. The remote cache URL is the only place to put credentials, so tokens end up in its query string or user info. To keep the token out of vite.config.*, the URL comes from VP_REMOTE_CACHE_URL, and vp run passes every VP_* variable through to the processes tasks spawn. Every tool and script a task runs can read the token.

Env value hashes. Each tracked env value is hashed on its own with unsalted SHA-256, and those hashes are part of the key sent to the server. Anyone who can read the remote cache can recover short or guessable values, such as short tokens or passwords, by brute force.

Expected: credentials can be supplied separately from the URL, for example as a token sent in an Authorization header, and aren't passed to task processes. The server can't recover individual env values from what it stores.

Affects remote cache configuration (#727) and the key format (#755).

Ngôn ngữ chính
Rust
Star
468
Fork
42
Merge trung bình
1 ngày 3 giờ
Pull request đã merge (30 ngày)
41

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của voidzero-dev/vite-task

Tất cả issue của voidzero-dev/vite-task

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.