airbytehq / airbytehq/airbyte-python-cdk

Security: Implement RestrictedPython for safer custom code execution

オープン
#235 コメント 0 件 リアクション 2 件 担当者 1 名 @aaronsteers が担当を希望しています GitHub で見る
主要言語
Python
スター
26
フォーク
53
平均マージ
2日 6時間
マージ済み PR(30日)
10

説明

## Background

Currently, the custom code compiler uses raw `exec()` to execute user-provided Python code, which could potentially be unsafe as it has unrestricted access to Python builtins and the global namespace.

## Proposed Solution

Implement [RestrictedPython](https://restrictedpython.readthedocs.io/) to provide a safer execution environment for custom code. This will:

1. Restrict access to potentially dangerous builtins
2. Run code in an isolated namespace
3. Prevent access to sensitive operations

## References

- Original PR discussion: https://github.com/airbytehq/airbyte-python-cdk/pull/174#discussion_r1917458832

## Implementation Notes

- Add RestrictedPython as a dependency
- Replace current `exec()` implementation with RestrictedPython's secure execution
- Add tests to verify security restrictions are working as expected

## Security Considerations

This enhancement will improve the security posture of the custom code execution feature by preventing potentially malicious code from accessing sensitive operations or resources.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。