Edge-home-orchestration-go: [ν† λ‘ ] SecurityMgr을 μˆ˜μ •ν•΄μ•Ό ν•˜λ‚˜μš”? (λ―Όκ°ν•œ 데이터 μ·¨κΈ‰)

에 λ§Œλ“  2020λ…„ 09μ›” 14일  Β·  6μ½”λ©˜νŠΈ  Β·  좜처: lf-edge/edge-home-orchestration-go

개인적으둜 λ―Όκ°ν•œ λ°μ΄ν„°λŠ” passPhraseJWTPath 에 λŒ€ν•œ μ•‘μ„ΈμŠ€λ‘œ λ°˜ν™˜λœλ‹€κ³  μƒκ°ν•©λ‹ˆλ‹€. μ–΄λ–»κ²Œ μƒκ°ν•˜λ‚˜μš”? @tdrozdovsky

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/controller/securemgr/authenticator/authenticator.go#L70

이것은 λ‹€μŒκ³Ό λ™μΌν•œ 잠재적 λ³΄μ•ˆ μœ„ν—˜μΌ 수 μžˆμŠ΅λ‹ˆλ‹€.

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/controller/securemgr/authenticator/authenticator.go#L84

enhancement question

κ°€μž₯ μœ μš©ν•œ λŒ“κΈ€

@tdrozdovsky Plus, err 이 ν”Œλž«νΌμ—μ„œ μ‚¬μš©λ˜λŠ” 경우 μˆ˜μ •ν•  수 μžˆμŠ΅λ‹ˆκΉŒ?

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/orchestrationapi/orchestration_api.go#L180

err λ³€μˆ˜λ₯Ό μ‚¬μš©ν•˜μ—¬ μ‘°μ‚¬ν–ˆμŠ΅λ‹ˆλ‹€. 였λ₯˜ μ²˜λ¦¬λŠ” μ•„λž˜μ—μ„œ μˆ˜ν–‰λ©λ‹ˆλ‹€.

if len(deviceScores) <= 0 {
        return errorResp
} else if deviceScores[0].score == scoringmgr.INVALID_SCORE {
    return errorResp
}

μΆ”κ°€ μ²˜λ¦¬λŠ” μ½”λ“œλ₯Ό 더 λ³΅μž‘ν•˜κ²Œ λ§Œλ“­λ‹ˆλ‹€.

λ”°λΌμ„œ err λ³€μˆ˜λ₯Ό λ¬΄μ‹œν•˜λŠ” 것이 μ’‹μŠ΅λ‹ˆλ‹€.

    deviceResources[i].score, _ = orcheEngine.GetScoreWithResource(dev.resource)

λͺ¨λ“  6 λŒ“κΈ€

@tdrozdovsky Plus, err 이 ν”Œλž«νΌμ—μ„œ μ‚¬μš©λ˜λŠ” 경우 μˆ˜μ •ν•  수 μžˆμŠ΅λ‹ˆκΉŒ?

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/orchestrationapi/orchestration_api.go#L180

@tdrozdovsky 이것은 λ‹€μŒκ³Ό 같이 lgtm 도ꡬλ₯Ό μ‚¬μš©ν•œ 지속적인 뢄석 λ•Œλ¬Έμž…λ‹ˆλ‹€.

https://lgtm.com/projects/g/lf-edge/edge-home-orchestration-go/alerts/?mode=list

개인적으둜 λ―Όκ°ν•œ λ°μ΄ν„°λŠ” passPhraseJWTPath 에 λŒ€ν•œ μ•‘μ„ΈμŠ€λ‘œ λ°˜ν™˜λœλ‹€κ³  μƒκ°ν•©λ‹ˆλ‹€. μ–΄λ–»κ²Œ μƒκ°ν•˜λ‚˜μš”? @tdrozdovsky

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/controller/securemgr/authenticator/authenticator.go#L70

이것은 λ‹€μŒκ³Ό λ™μΌν•œ 잠재적 λ³΄μ•ˆ μœ„ν—˜μΌ 수 μžˆμŠ΅λ‹ˆλ‹€.

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/controller/securemgr/authenticator/authenticator.go#L84

쒋은 점, μ €λŠ” 이 λ³΄μ•ˆ 문제λ₯Ό μ•Œκ³  κΈ°μ–΅ν•˜κ³  μžˆμŠ΅λ‹ˆλ‹€.

passPhraseJWTFilePath 파일 생성 μ‹œλ„ μ‹€νŒ¨μ— λŒ€ν•΄μ„œλ§Œ μ•Œλ €μ€λ‹ˆλ‹€.
κ·ΈλŸ¬λ‚˜ λ¬Όλ‘  μ΄λŸ¬ν•œ 정보λ₯Ό 파일(passPhrase, edge-orchestration.key λ“±)에 μ €μž₯ν•˜λŠ” 것은 λ³΄μ•ˆ μœ„ν—˜μž…λ‹ˆλ‹€.
λ―Έλž˜μ—λŠ” λ³΄μ•ˆ μŠ€ν† λ¦¬μ§€λ‚˜ SeLinux, SMACK λ“±κ³Ό 같은 μ•‘μ„ΈμŠ€ μ œμ–΄ μ‹œμŠ€ν…œμœΌλ‘œ 이 문제λ₯Ό ν•΄κ²°ν•΄μ•Ό ν•œλ‹€κ³  μƒκ°ν•©λ‹ˆλ‹€.

μƒκΈ°μ‹œμΌœμ£Όμ…”μ„œ κ°μ‚¬ν•©λ‹ˆλ‹€

@tdrozdovsky 제 μ œμ•ˆμ„ λ°›μ•„μ£Όμ…”μ„œ κ°μ‚¬ν•©λ‹ˆλ‹€. λ‚˜λŠ” λ‹Ήμ‹ μ—κ²Œ 이 문제λ₯Ό 방금 ν• λ‹Ήν–ˆμŠ΅λ‹ˆλ‹€. μš°λ¦¬λŠ” 곧 또 λ‹€λ₯Έ κ·€μ€‘ν•œ κΈ°μ—¬λ₯Ό λ³Ό 수 있기λ₯Ό κΈ°λŒ€ν•©λ‹ˆλ‹€!

@tdrozdovsky Plus, err 이 ν”Œλž«νΌμ—μ„œ μ‚¬μš©λ˜λŠ” 경우 μˆ˜μ •ν•  수 μžˆμŠ΅λ‹ˆκΉŒ?

https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/orchestrationapi/orchestration_api.go#L180

err λ³€μˆ˜λ₯Ό μ‚¬μš©ν•˜μ—¬ μ‘°μ‚¬ν–ˆμŠ΅λ‹ˆλ‹€. 였λ₯˜ μ²˜λ¦¬λŠ” μ•„λž˜μ—μ„œ μˆ˜ν–‰λ©λ‹ˆλ‹€.

if len(deviceScores) <= 0 {
        return errorResp
} else if deviceScores[0].score == scoringmgr.INVALID_SCORE {
    return errorResp
}

μΆ”κ°€ μ²˜λ¦¬λŠ” μ½”λ“œλ₯Ό 더 λ³΅μž‘ν•˜κ²Œ λ§Œλ“­λ‹ˆλ‹€.

λ”°λΌμ„œ err λ³€μˆ˜λ₯Ό λ¬΄μ‹œν•˜λŠ” 것이 μ’‹μŠ΅λ‹ˆλ‹€.

    deviceResources[i].score, _ = orcheEngine.GetScoreWithResource(dev.resource)

@tdrozdovsky Plus, err 이 ν”Œλž«νΌμ—μ„œ μ‚¬μš©λ˜λŠ” 경우 μˆ˜μ •ν•  수 μžˆμŠ΅λ‹ˆκΉŒ?
https://github.com/lf-edge/edge-home-orchestration-go/blob/22ce49b4b76ae78dfb75e14ef64399e5805c7d02/src/orchestrationapi/orchestration_api.go#L180

err λ³€μˆ˜λ₯Ό μ‚¬μš©ν•˜μ—¬ μ‘°μ‚¬ν–ˆμŠ΅λ‹ˆλ‹€. 였λ₯˜ μ²˜λ¦¬λŠ” μ•„λž˜μ—μ„œ μˆ˜ν–‰λ©λ‹ˆλ‹€.

if len(deviceScores) <= 0 {
      return errorResp
} else if deviceScores[0].score == scoringmgr.INVALID_SCORE {
  return errorResp
}

μΆ”κ°€ μ²˜λ¦¬λŠ” μ½”λ“œλ₯Ό 더 λ³΅μž‘ν•˜κ²Œ λ§Œλ“­λ‹ˆλ‹€.

λ”°λΌμ„œ err λ³€μˆ˜λ₯Ό λ¬΄μ‹œν•˜λŠ” 것이 μ’‹μŠ΅λ‹ˆλ‹€.

  deviceResources[i].score, _ = orcheEngine.GetScoreWithResource(dev.resource)

@tdrozdovsky ν•©λ¦¬μ μž…λ‹ˆλ‹€. ^^ 이에 λŒ€ν•œ 홍보λ₯Ό μ œμ•ˆν•΄ μ£Όμ‹œκ² μŠ΅λ‹ˆκΉŒ?

이 νŽ˜μ΄μ§€κ°€ 도움이 λ˜μ—ˆλ‚˜μš”?
0 / 5 - 0 λ“±κΈ‰