adobe / adobe/aio-cli-plugin-app-dev

isolate action code

Abierto
#32 3 comentarios 0 reacciones 0 asignados Ver en GitHub
enhancement
Lenguaje dominante
JavaScript
Estrellas
2
Forks
5
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Right now all action code that is run, has access to the host's node environment -- which is the developer's machine.
This includes the filesystem, running processes, etc. This will not be representative of a true serverless system which we are simulating.

Explore code isolation via the node `vm` module: https://nodejs.org/docs/latest-v18.x/api/vm.html
Take note that if the code to run uses `require` we will need to pass in the `require` loader, which may or may not be secure. In general this should not be a problem since we webpack the code.

Related:
1. https://github.com/node-inspector/node-inspector/issues/284
2. https://www.rocket.chat/blog/node-js-vm
3. https://github.com/laverdet/isolated-vm
4. https://github.com/Richienb/node-polyfill-webpack-plugin (note fs is not in there, since browsers do have this now, but we can easily add the fs fallback in)
5. https://blog.logrocket.com/how-to-protect-your-node-js-applications-from-malicious-dependencies-5f2e60ea08f9/
6. https://github.com/tschaub/mock-fs

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Empieza por localizar el punto de entrada de la ejecución de acciones en este repositorio; el issue no indica ningún archivo ni prueba. Lee la documentación de Node's vm y las referencias enlazadas sobre aislamiento, y luego define un enfoque de aislamiento que tenga en cuenta require y el acceso al sistema de archivos; el issue no especifica criterios concretos de finalización.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
javascript, node.js, webpack
Área
cli, security
Tipo de issue
Nueva funcionalidad
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Estancado
Claridad
Necesita aclaración
Aptitud para principiantes
25/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.