Let apps define list of sensitive config values instead of hardcoding in the server.
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 36.9k
- Forks
- 5.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 713
Description
How to use GitHub
- Please use the 👍 reaction to show that you are interested into the same feature.
- Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
- Subscribe to receive notifications on status change and new comments.
Is your feature request related to a problem? Please describe.
Currenty a list of sensitive config values is hardcoded in https://github.com/nextcloud/server/blob/8541707f3286e34b8ec24c5399776f61ec8fbb9d/lib/private/AppConfig.php#L47
Whenever an app defines a new sensitive config value, this list must be updated in the server and the value is visible until a potential PR is merged in the server and the server has been updated.
Describe the solution you'd like
It would be better if each app could define a list of config values that should be filtered.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading lib/private/AppConfig.php around line 47 and trace where the hardcoded sensitive-value list is consumed. Then identify how apps currently define configuration and where an app-provided list could be integrated. Done means an app can declare sensitive config names and those values are filtered without updating the server’s hardcoded list.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- backend, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100