[sup] ACM cookie-auth session: URL cluster/node context + temp-credential lifecycle
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- sql, typescript
- 领域
- api, authentication, frontend
调研方向
首先跟踪现有的 ChCtx/session 流程和 ACM URL 上下文,然后检查 /api/account 和 /api/cluster/{id}/support/credentials 入口点。验证仅使用 cookie 的请求、401 时的 ACM 重定向、engineer-email 归属,以及针对每种已记录响应形态的 single-flight 凭证签发;完成的标准是所有列出的验收检查均通过。
由索引模型根据 Issue 内容生成。
描述
Part of #352. Heavily simplified by the cookie-auth model (was: #user login + pasted ACM key).
A dedicated ACM-mode ChCtx/session — no login form, no token, no key persistence.
Scope
- Read context from URL:
clusterandnodequery params (supplied by the ACM console link). No cluster URL→id resolution. - Cookie auth: all
/apicallscredentials:'same-origin', no auth header. A 401 = ACM session lost → redirect to ACM login (standard), not our concern to refresh. - Identity:
GET /api/account→ engineer email, used as CHuser=forquery_logattribution. Model engineer-identity (from/account) separately from CH transport login (may be a returnedlogin, else the email) and never assume they're the same. - Temp CH credential lifecycle: mint via
GET /api/cluster/{id}/support/credentials; read TTL from the response (don't hardcode); keep alive via/support/refreshor re-mint; single-flight so concurrent schema/dashboard requests don't mint in parallel. Handle both documented shapes ({password,ttl}/ bare string /{login,password}).
Removed vs. original
— there is no key in JS anymore.#usersentinel, ACM key in a password field, Chrome-password-store, no-localStorage/share-link/export rules for the key
Acceptance
- Loads cluster/node from URL;
currentUser()is the engineer email. - No credential stored in JS; cookie-only; 401 → ACM login redirect.
- Temp creds mint + refresh (single-flight), TTL from response, all response shapes handled.
- 主要语言
- TypeScript
- 星标
- 8
- 派生
- 2
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Altinity/altinity-sql-browser 的其他 Issue
-
inbox
难度 2/5 1-3 小时 新手友好度 76/100
Altinity/altinity-sql-browser#605 ·
-
inbox
难度 2/5 1-3 小时 新手友好度 78/100
Altinity/altinity-sql-browser#509 ·
-
inbox
难度 2/5 1-3 小时 新手友好度 78/100
Altinity/altinity-sql-browser#489 ·
-
flamegraph未关闭enhancement
难度 5/5 一周以上 新手友好度 25/100
Altinity/altinity-sql-browser#684 ·
-
bug
难度 4/5 3-5 天 新手友好度 68/100
Altinity/altinity-sql-browser#680 · 2 条评论 ·
查看 Altinity/altinity-sql-browser 的全部 Issue
相似的 Issue
-
enhancement
难度 2/5 1-3 小时 新手友好度 88/100
Small-tailqwq/dsh-deep-whale#187 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
melgarafael/DeskcommCRM#2503 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 74/100
0x80/isolate-package#218 ·
-
bug via-triage
难度 2/5 1-3 小时 新手友好度 82/100
pingdotgg/t3code#16859 · 1 条评论 ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 1 天内回复