Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Ipykernel replacement of `getpass` not fully compatible with it

未关闭
#1,123 3 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
35/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
jupyter, python
领域
security

调研方向

未指定文件、测试或入口点。首先将 ipykernel 的 getpass 替代实现与 Python 的标准 getpass API 进行比较,重点关注何时发出 GetPassWarning;完成的标准是调用方能够在请求密码之前检测到不安全的提示。

由索引模型根据 Issue 内容生成。

描述

The getpass API requires that the GetPassWarning is generated in case a password cannot be asked to the user in a secure way.

This is an important piece of the API, because it lets the programmer turn the warning into an error to handle the case when the terminal is not suited to securely prompt for a password before the user is asked for a password. In turn this is important because most users will carelessly type in a password regardless of any warning and is particularly bad for interfaces where the password will remain available for view via scrollback. Being able to handle the condition will let the program try different ways to get the password rather than prompting the user in an insecure way.

The problem here is that ipykernel replaces getpass with its own version that does not issue the GetPassWarning, so resulting in a different API from the standard getpass that ends up with the code prompting the user for a password insecurely without even realizing it.

At present time the workaround is clearly for the code to check if getpass comes from ipykernel and deal with this case specially.

主要语言
Python
星标
734
派生
411
平均合并
1 天 2 小时
30 天内合并 PR
9

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

ipython/ipykernel 的其他 Issue

查看 ipython/ipykernel 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。