Validate base64 encoded secret value with newlines in the request body by rejecting with 400/Bad Request
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 218
- Forks
- 72
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 427
Description
Description
Validate base64 encoded secret value provided for creating/updating registry credential for newlines. If the secret value contains a newline, then it must be rejected with 400 / Bad Request status.
Definition of Done
- This should be done for all endpoints where a base64 encoded secret value is expected -- Create Account, Create Registry Credential, Update Registry Credential, etc.
By submitting this issue, you acknowledge that you are an assigned member of the NVCF development team and agree to follow our code of conduct and our contributing guidelines.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the Create Account, Create Registry Credential, and Update Registry Credential entry points, then trace where their base64-encoded secret values are validated. Check all endpoints that accept this value and add coverage for newline-containing input; done means each rejects it with HTTP 400 / Bad Request.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- api, backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100