MagicStack / MagicStack/asyncpg
Support using pre-hashed passwords
未关闭
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 8.1k
- 派生
- 468
- PR 合并指标
- 30 天内没有已合并 PR
描述
Asyncpg should also support using HASH objects or pre-hashed strings. Also, I would suggest that once the authentication method has been identified (e.g. md5, sha, no-hash) then the password should be morphed. As it currently stands, the password can be retrieved in plain text by other libraries that have access to the Connection or Pool objects.
# malicious code can easily get away with this:
print(pool._connection_kwargs['password'])
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先追踪 asyncpg 的 Connection 和 Pool 如何处理密码,以及如何识别 md5、sha 和 no-hash 等 PostgreSQL 身份验证方法。完成的标准是支持预先哈希的字符串或 HASH 对象,并且密码处理不再通过 pool._connection_kwargs 暴露明文值。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- postgresql, python
- 领域
- authentication, databases, security
- Issue 类型
- 功能
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100