Teams SSH doesn't update existing users' SSH keys
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- github, typescript
调研方向
首先定位 teams-ssh 的更新循环,以及读取 Github 团队成员关系和用户 SSH 密钥的代码。确认现有用户在 authorized_keys 中的表示方式,然后将完成条件定义为:能够检测并添加新增加的密钥,而不需要更改团队成员关系;密钥移除明确留作设计问题。
由索引模型根据 Issue 内容生成。
描述
If someone is added to the Sudo or SSH teams in the HacKSU org, and later adds SSH key(s) to their account in order to log in to a server, the new keys will not be added to their .ssh/authorized_keys file, since that file is only updated when the user account is initially added to the server.
This can be worked around by removing a user from both the SSH and, if necessary, the Sudo team, waiting for teams-ssh to update, and then re-adding them and waiting for teams-ssh to update again.
Fixing this would require pulling each user's SSH keys along with their team membership from Github every 60 seconds, checking if each key is already present in the authorized_keys file or not, and adding it if it isn't already there.
Automatically removing keys when they're removed from a user's Github profile could be more problematic. It would increase the security of the system by providing a quick way to remove keys if they're compromised, but it could also lead to unexpected lockouts if the user uses an SSH key for their server account without even realizing it's also saved in their Github account.
- 主要语言
- TypeScript
- 星标
- 0
- 派生
- 0
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
相似的 Issue
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs 未关闭
难度 2/5 1-3 小时 新手友好度 70/100
-
Crush 未关闭
难度 1/5 1 小时以内 新手友好度 85/100
catppuccin/catppuccin#3125 ·
-
难度 1/5 1 小时以内 新手友好度 90/100
ElementsProject/cln-application#167 · 1 条评论 · 1 个 reaction ·
-
难度 2/5 1-3 小时 新手友好度 75/100
Quantco/pnpm-licenses#17 ·
-
难度 2/5 1-3 小时 新手友好度 75/100