Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[sup] ACM cookie-auth session: URL cluster/node context + temp-credential lifecycle

未关闭
#354 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
35/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
冷清
技术栈
sql, typescript

调研方向

首先跟踪现有的 ChCtx/session 流程和 ACM URL 上下文,然后检查 /api/account 和 /api/cluster/{id}/support/credentials 入口点。验证仅使用 cookie 的请求、401 时的 ACM 重定向、engineer-email 归属,以及针对每种已记录响应形态的 single-flight 凭证签发;完成的标准是所有列出的验收检查均通过。

由索引模型根据 Issue 内容生成。

描述

enhancement sup

Part of #352. Heavily simplified by the cookie-auth model (was: #user login + pasted ACM key).

A dedicated ACM-mode ChCtx/session — no login form, no token, no key persistence.

Scope

  • Read context from URL: cluster and node query params (supplied by the ACM console link). No cluster URL→id resolution.
  • Cookie auth: all /api calls credentials:'same-origin', no auth header. A 401 = ACM session lost → redirect to ACM login (standard), not our concern to refresh.
  • Identity: GET /api/account → engineer email, used as CH user= for query_log attribution. Model engineer-identity (from /account) separately from CH transport login (may be a returned login, else the email) and never assume they're the same.
  • Temp CH credential lifecycle: mint via GET /api/cluster/{id}/support/credentials; read TTL from the response (don't hardcode); keep alive via /support/refresh or re-mint; single-flight so concurrent schema/dashboard requests don't mint in parallel. Handle both documented shapes ({password,ttl} / bare string / {login,password}).

Removed vs. original

  • #user sentinel, ACM key in a password field, Chrome-password-store, no-localStorage/share-link/export rules for the key — there is no key in JS anymore.

Acceptance

  • Loads cluster/node from URL; currentUser() is the engineer email.
  • No credential stored in JS; cookie-only; 401 → ACM login redirect.
  • Temp creds mint + refresh (single-flight), TTL from response, all response shapes handled.
主要语言
TypeScript
星标
8
派生
2
PR 合并指标
30 天内没有已合并 PR

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

Altinity/altinity-sql-browser 的其他 Issue

查看 Altinity/altinity-sql-browser 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。