google / google/gae-secure-scaffold-python3

Scaffold websites require Cloud Datastore permissions, even when they don't use Cloud Datastore

Abierto
#24 4 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Python
Estrellas
35
Forks
19
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

If you deploy a basic scaffold App Engine app, on startup it _always_ attempts to connect to Cloud Datastore using the default service account credentials. This happens even if nothing in the app uses Cloud Datastore.

On a new App Engine project, this causes a 500 error. In the application log, you can see a message `google.api_core.exceptions.PermissionDenied: 403 Missing or insufficient permissions` that is emitted as part of the NDB datastore library.

A quick fix is to grant the default App Engine service account the required permissions.

The default App Engine service account normally gets the editor role, but this can be changed per-organization. If the GCP organization changes the default role, or removes all permissions for the service account by default, then your scaffold app can fail.

https://cloud.google.com/appengine/docs/standard/configure-service-accounts#default_service_account

The scaffold connects to the datastore in order to set/get a secret that is used by Flask for signing cookies and stuff. If the app doesn't need to do that, then we should make it so the app doesn't require access to the datastore , and avoid this error.

https://flask.palletsprojects.com/en/3.0.x/config/#SECRET_KEY

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza rastreando el inicio del scaffold y el acceso al datastore NDB que se usa para establecer u obtener el SECRET_KEY de Flask. Verifica la ruta básica de despliegue de App Engine y confirma que una app que no usa Datastore ya no falla con un 403 o 500 cuando la cuenta de servicio predeterminada carece de permisos de Datastore.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
flask, google-cloud, python
Área
backend, cloud, databases
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
42/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.