apache / apache/answer-plugins
New plugin use-case/type of plugin: Credentials Guard
- Ngôn ngữ chính
- Go
- Star
- 131
- Fork
- 75
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
Hi 👋,
First of all, thanks for providing _Answer_ and congrats for joining Apache 👍
I'm having a plugin use-case in mind I'd like to work on, that is - as far as I'm able to see - [currently not supported](https://answer.apache.org/docs/plugins/#plugin-type).
**Idea/Use-Case**
I'd like to implement a plugin that checks user submitted content for security sensitive information like credentials and asks
the user if the content really should be submitted as is.
Submitting such kind of information if fairly easy especially if you're copy & pasting code snippets (totally unrelated to Answer itself obviously).
This would allow to not even persist sensitive data in case it's not intended by the user. Persisiting sensitive information is an issue as Answer keeps the content history - which is really great in general (I really like the diff functionality ❤️) but not in case you submit something that better shouldn't have been.
To detect credentials potentially, I was thinking about using something like e.g. [DeepPass](https://github.com/GhostPack/DeepPass).
_Additional thoughts_
* it potentially involves both frontend and backend functionality
* needs to intervene (optionally with user consent) before data gets persisted
* should involve scanning user questions, answers and comments, basically all user submitted content
Looking forward for feedback 😃
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Hướng nghiên cứu
Bắt đầu với tài liệu về loại plugin được liên kết trong issue và kiểm tra các loại plugin cũng như các điểm mở rộng hiện có trong repository. Xác định phạm vi quét câu hỏi, câu trả lời và bình luận trước khi lưu trữ, bao gồm cả sự đồng ý tùy chọn của người dùng và lịch sử nội dung; công việc được xem là hoàn tất khi đã thống nhất loại plugin và phạm vi triển khai.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Lĩnh vực
- backend, frontend, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 25/100