nextcloud / nextcloud/notifications
Test-push command should verify user keys
Open
Nobody has claimed this yet.
0. Needs triage
enhancement
- Dominant language
- JavaScript
- Stars
- 153
- Forks
- 67
- Avg merge
- 15h 3m
- Merged PRs (30d)
- 96
Description
How to use GitHub
- Please use the 👍 reaction to show that you are interested into the same feature.
- Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
- Subscribe to receive notifications on status change and new comments.
Feature request
When executing occ notification:test-push we should verify that the stored keypair for the user is correct. Due to race condition it can happen, that the stored private key does not match the stored public key.
- Ref implementation in server: https://github.com/nextcloud/server/pull/43646
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at the implementation of the occ notification:test-push command and compare its key handling with the referenced server pull request #43646. Trace where the user's stored private and public keys are loaded; done means the command verifies that the pair matches before attempting the test push.
Written by the indexing model from the issue text.
Assessment
- Domain
- cli, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100