nextcloud / nextcloud/server

Let apps define list of sensitive config values instead of hardcoding in the server.

Open
#32,804 1 comment 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

0. Needs triage developer experience enhancement feature: apps management feature: logging
Dominant language
PHP
Stars
36.9k
Forks
5.2k
Avg merge
2d 3h
Merged PRs (30d)
713

Description

How to use GitHub
  • Please use the 👍 reaction to show that you are interested into the same feature.
  • Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
  • Subscribe to receive notifications on status change and new comments.

Is your feature request related to a problem? Please describe.
Currenty a list of sensitive config values is hardcoded in https://github.com/nextcloud/server/blob/8541707f3286e34b8ec24c5399776f61ec8fbb9d/lib/private/AppConfig.php#L47

Whenever an app defines a new sensitive config value, this list must be updated in the server and the value is visible until a potential PR is merged in the server and the server has been updated.

Describe the solution you'd like
It would be better if each app could define a list of config values that should be filtered.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading lib/private/AppConfig.php around line 47 and trace where the hardcoded sensitive-value list is consumed. Then identify how apps currently define configuration and where an app-provided list could be integrated. Done means an app can declare sensitive config names and those values are filtered without updating the server’s hardcoded list.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.