NVIDIA / NVIDIA/nvcf

Validate base64 encoded secret value with newlines in the request body by rejecting with 400/Bad Request

Open
#1,108 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
218
Forks
72
Avg merge
1d 12h
Merged PRs (30d)
427

Description

Description

Validate base64 encoded secret value provided for creating/updating registry credential for newlines. If the secret value contains a newline, then it must be rejected with 400 / Bad Request status.

Definition of Done

  • This should be done for all endpoints where a base64 encoded secret value is expected -- Create Account, Create Registry Credential, Update Registry Credential, etc.

By submitting this issue, you acknowledge that you are an assigned member of the NVCF development team and agree to follow our code of conduct and our contributing guidelines.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Create Account, Create Registry Credential, and Update Registry Credential entry points, then trace where their base64-encoded secret values are validated. Check all endpoints that accept this value and add coverage for newline-containing input; done means each rejects it with HTTP 400 / Bad Request.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
api, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.