llnl / llnl/remote-mirror-security
Better handling of external organization clients
- Dominant language
- Ruby
- Stars
- 4
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
A major limitation currently is that policy enforcement is restricted to a single organization since privileged organization credentials are required to inspect a repository. I'd like to use this issue to discuss the most flexible way of enabling "alternative" organization clients. As a first pass it would be great to consolidate the current [`alt_clients` into just `clients`](https://github.com/LLNL/remote-mirror-security/blob/main/lib/secure_mirror/mirror_client.rb#L22).
Contributor guide
No contributing guide indexed for this repository
Research direction
Start in lib/secure_mirror/mirror_client.rb around the alt_clients definition at line 22, then trace how policy enforcement inspects repositories with organization credentials. Clarify the supported alternative organization-client behavior before changing the structure. Done means the client configuration is consolidated under clients and external organization repositories can be handled as agreed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ruby
- Domain
- backend, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100