Consolidate homework answer encryption on the shared package
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 45/100
- Issue 类型
- 重构
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- python
- 领域
- backend, security, testing-qa
调研方向
Start with the import and patch-target inventory, then compare courses/homework_answer_crypto.py with community_base.coursework.answer_crypto at v0.5.10. Review courses/homework_answer_checks.py, courses/homework_answer_resolution.py, and their tests, including the deterministic envelope vector. Done means the duplicate is removed, callers share the package classes, focused tests and the documented selective verification pass, and crypto and scoring behavior remain unchanged.
由索引模型根据 Issue 内容生成。
描述
Consolidate homework answer encryption on the shared package
Status: pending
Tags: courses, security, enhancement, P1
Depends on: None
Blocks: —
Reporter context
The owner asks to unify and simplify community-base, AISL and DTC while preserving every feature and the current UX, with no visible UI changes. Use focused changes in an isolated DTC worktree because shared checkouts have other owners. The cross-repository inventory identified the 490-line courses/homework_answer_crypto.py as a duplicate of the shared answer-crypto owner already present in DTC's pinned community-base release.
Normative references
_docs/specs/04-courses-and-cohorts.md, especially preserved learner homework behavior and the rule to characterize scoring behavior before deduplication._docs/specs/07-security-privacy-operations.mdfor bounded failures and privacy._docs/architecture/app-boundaries.mdandAGENTS.mdfor direct domain ownership and the prohibition on legacy runtime shims._docs/ci/change-selective-ci.mdand_docs/specs/10-verification-strategy.mdfor versioned, change-selective verification.community-basev0.5.10community_base.coursework.answer_cryptofor the existing implementation contract.
Scope
Delete the duplicated courses/homework_answer_crypto.py implementation. Retarget all proven live and test imports directly to community_base.coursework.answer_crypto, including courses/homework_answer_checks.py, courses/homework_answer_resolution.py, and their tests. The existing DTC pyproject.toml and uv.lock pin community-base to v0.5.10, whose crypto module has the same implementation plus validate_source_envelope; this issue needs no package release or dependency bump. Before deleting, inventory all repository Python import forms, aliases, test imports, patch targets, and literal/dynamic references, then repeat the check on the final diff. Do not leave a compatibility facade or copy classes/exceptions locally.
Keep the DTC keyring configuration lookup, answer-resolution boundary, source option-ID mapping, free-form answer conversion, answer-check handling, homework models, and persisted envelopes in place. Preserve exact object identity for HomeworkAnswerKeyring, HomeworkAnswerCryptoError and its validation, unavailable-key, and decryption subclasses across every remaining caller. Change the deterministic test patch from the deleted site's secrets.token_bytes path to the shared module's path; keep its known AES-GCM/HKDF envelope vector meaningful. Existing encrypted answers must decrypt with the shared implementation, and newly encrypted answers must remain compatible with the prior implementation.
Characterize and preserve strict keyring parsing and rotation, canonical authenticated context, scalar and choice payloads, envelope validation and size bounds, malformed/tampered ciphertext failures, unknown key IDs, context mismatch, redacted error text, and failure handling in scoring. Do not compare independently randomized ciphertext for equality. If the existing tests leave a specific behavior gap, add one authoritative behavior test before changing the import owner and prove it passes before and after.
Non-goals
- No visible UI, template, route, API, access, scoring-policy, feature, or schema change.
- No model migration, stored-data rewrite, keyring configuration change, or new crypto algorithm/version.
- No package-code change, new abstraction, legacy runtime shim, or unrelated dependency pin update.
- No shared-main edit, commit, merge, push, or pull request in this grooming/implementation-review stage.
Acceptance criteria
- A final-revision caller inventory covers all three Python import forms, aliases, tests, scripts, patch targets, and dynamic references; no use of the deleted site module remains.
-
courses/homework_answer_crypto.pyis deleted, all callers use the package owner directly, and the report measures actual net application lines removed separately from tests or moved code. - Class and exception identity is single-owner: DTC resolution/checks and package encrypt/decrypt paths use the same
HomeworkAnswerKeyringand crypto exception classes. - Existing and new scalar/choice envelopes interoperate across old and shared implementations; the deterministic envelope vector, key rotation, malformed/oversized envelope rejection, unknown-key behavior, authenticated-context mismatch, and tamper failures retain their exact contract.
- DTC's configured keyring source, answer-resolution mapping, scoring behavior and safe failure handling stay unchanged; no secret or answer value is added to logs or error output.
- The authoritative crypto and answer-resolution tests pass before and after; the old
secrets.token_bytespatch is retargeted to the shared owner without weakening the vector assertion. - No page, API, template, route, model, migration, stored envelope, feature, or visible UX changes.
-
make lint,make lint-advisory, focused tests, and the versioned_docs/ci/change-selective-ci.mdverification plan pass. Engineer and Tester report exact base/head, graph and plan digests, every component'srerun/reused/skipped/not_applicabledisposition, exact commands/counts, and the graph-selected backend browser tier (smoke when the focused backend profile applies); any full-profile fallback follows the plan. - Independent Tester verifies the uncommitted isolated worktree and records screenshot evidence as
not_applicableif the graph confirms no render impact. Shared main remains untouched; no commit, merge, push, or PR occurs before the owner-authorized handoff.
Browser regression scenario
Scenario: learner submits source-managed homework with an encrypted answer
Given: an enrolled learner sees a homework question whose answer is stored as an encrypted source envelope
When: the learner submits an answer through the existing homework flow
Then: the response and score follow the same existing policy, and the learner sees no plaintext source answer, key detail, or new error message
The cryptographic boundary cases belong in focused unit/service tests. This backend-only ownership change introduces no new page or browser behavior.
Repository and operations scenarios
- A previously stored envelope decrypts with the shared owner using the existing configured keyring and the exact course/homework/question context.
- An envelope with a wrong context, unavailable key, malformed fields, or tampered ciphertext fails in the same bounded class and does not leak its secret input.
Blocked by: (none)
- 主要语言
- Python
- 星标
- 0
- 派生
- 0
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
DataTalksClub/website 的其他 Issue
-
bug infra operations P1 testing
难度 2/5 1-3 小时 新手友好度 72/100
DataTalksClub/website#329 ·
-
bug content data-migration documentation events operations P1
难度 2/5 1-3 小时 新手友好度 84/100
DataTalksClub/website#327 ·
-
bug frontend P0 testing
难度 2/5 1-3 小时 新手友好度 90/100
DataTalksClub/website#300 · 7 条评论 ·
-
bug data-migration events P0 testing
难度 2/5 1-3 小时 新手友好度 72/100
DataTalksClub/website#295 · 6 条评论 ·
-
courses enhancement P1
难度 5/5 一周以上 新手友好度 25/100
DataTalksClub/website#446 · 1 条评论 ·
查看 DataTalksClub/website 的全部 Issue
相似的 Issue
-
customer-reported
难度 2/5 1-3 小时 新手友好度 68/100
Azure/azure-cli#34150 · 1 条评论 ·
维护者通常 1 天内回复
-
community-request
难度 1/5 1 小时以内 新手友好度 95/100
NVIDIA-NeMo/Curator#2464 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
WeblateOrg/translation-finder#1099 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
trezor/trezor-firmware#7997 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复