llnl / llnl/remote-mirror-security

Better handling of external organization clients

Open
#6 0 comments 0 reactions 0 assignees View on GitHub
important
Dominant language
Ruby
Stars
4
Forks
2
PR merge metrics
No merged PRs in 30d

Description

A major limitation currently is that policy enforcement is restricted to a single organization since privileged organization credentials are required to inspect a repository. I'd like to use this issue to discuss the most flexible way of enabling "alternative" organization clients. As a first pass it would be great to consolidate the current [`alt_clients` into just `clients`](https://github.com/LLNL/remote-mirror-security/blob/main/lib/secure_mirror/mirror_client.rb#L22).

Contributor guide

No contributing guide indexed for this repository

Research direction

Start in lib/secure_mirror/mirror_client.rb around the alt_clients definition at line 22, then trace how policy enforcement inspects repositories with organization credentials. Clarify the supported alternative organization-client behavior before changing the structure. Done means the client configuration is consolidated under clients and external organization repositories can be handled as agreed.

Written by the indexing model from the issue text.

Assessment

Tech stack
ruby
Domain
backend, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.