Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

The value of hashed-password can be used to open CodeServer directly, which has security problem

未關閉
#7,696 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
35/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
停滯
技術堆疊
typescript

研究方向

先追蹤 ~/.config/code-server/config.yaml 中的 auth 設定如何被讀取,以及登入頁面之後如何驗證 code-server-session cookie。使用列出的 code-server 指令和 jupyter_server_proxy URL 重現該行為,然後確認 hashed-password 值本身無法驗證工作階段。

由索引模型根據 Issue 內容生成。

描述

bug security triage
Is there an existing issue for this?
  • I have searched the existing issues
OS/Web Information
  • Web Browser: Chrome 143.0.7499.170
  • Local OS: windows
  • Remote OS: ubuntu 22.04, jupyterlab service
  • Remote Architecture: x86
  • code-server --version: v4.108.0
Steps to Reproduce
  1. prepare "hashed-password" using command echo -n "xxx" | npx argon2-cli -e
  2. edit ~/.config/code-server/config.yaml,auth: password, hashed-password:"$argon2i$v=19$m=4096,t=3,p=1$xxx$xxx"
  3. start code-server using command code-server --port 7756
  4. using jupyter_server_proxy to visit code-server service, concatenate a URL as https://base_url/proxy/7756/
  5. when the code-server login page occurs, skip input the xxx into the password area. F12 edit the application cookie, set key=code-server-session, value="$argon2i$v=19$m=4096,t=3,p=1$xxx$xxx", refresh the browser
Expected

Failed to login into the code-server. The hashed-password in the config.yaml should not be the plain credentials

Actual

successfully login into the code-server

主要語言
TypeScript
星號
79.4k
分支
6.9k
平均合併
2 天 13 小時
30 天內合併 PR
39

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

coder/code-server 的其他 Issue

查看 coder/code-server 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。