OpenFn / OpenFn/lightning

Log access control events

Open
#365 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Elixir
Stars
296
Forks
86
Avg merge
1d 13h
Merged PRs (30d)
50

Description

User story

As a Lightning administrator, I would like to see a log of access control events (especially access control failures), so that I can identify when a malicious user is probing the application for vulnerabilities

https://owasp-top-10-proactive-controls-2018.readthedocs.io/en/latest/c7-enforce-access-controls.html#log-all-access-control-events

Details
Implementation notes
Release notes
Tests

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked OWASP access-control logging guidance, then locate Lightning's access-control checks and determine where events are currently handled. Confirm the expected event coverage with maintainers, especially for access-control failures; done means the requested access-control events are logged and covered by appropriate tests, but the issue names no files or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
elixir
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.