keybase / keybase/keybase-issues
API: I can add a key with a userid@keybase.io (packet) that doesn't match my username
未关闭
- 主要语言
- 没有语言数据
- 星标
- 899
- 派生
- 40
- PR 合并指标
- 30 天内没有已合并 PR
描述
This is probably ok since its ignored if not matching, but might be a good idea to add a check to make sure and userid@keybase.io user id packet (if included) in key also matches the keybase username associated with an account (if only as a sanity check).
(Yeah, I am testing wierd scenarios.)
贡献指南
这个仓库没有索引到贡献指南
调研方向
首先跟踪接受包含 userid@keybase.io 数据包的密钥的 API 路径,并确定数据包与账户用户名进行比较的位置。确认不匹配时的预期行为,然后添加覆盖,证明不一致的数据包会按决定被拒绝或忽略。完成标准是:在不破坏有效密钥的情况下强制执行健全性检查。
由索引模型根据 Issue 内容生成。
评估
- 领域
- api, authentication, security
- Issue 类型
- 功能
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100