-
Notifications
You must be signed in to change notification settings - Fork 508
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Only use delegation passphrase env var for non-base roles #822
Conversation
@@ -234,7 +235,8 @@ func getPassphraseRetriever() notary.PassRetriever { | |||
// For delegation roles, we can also try the "delegation" alias if it is specified | |||
// Note that we don't check if the role name is for a delegation to allow for names like "user" | |||
// since delegation keys can be shared across repositories | |||
if v := env["delegation"]; v != "" { | |||
// This cannot be a base role or imported key, though. | |||
if v := env["delegation"]; !data.IsBaseRole(alias) && !strings.Contains(alias, "imported ") && v != "" { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍 Nice catch for if the base roles aren't provided but delegation roles are!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm wondering if we should should specify a constant or otherwise provide some kind of utility function for this, so we ensure that all imported keys have a similarly-formatted alias?
Edit: "this" = the word "imported"
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
totally agree, I've refactored "imported " into a constant 👍
Thanks for fixing this bug! I have one caveat about the word "imported" being special, but this LGTM other than that! |
Want to circle back on this once the import refactor is merged |
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
3373c40
to
06a12a8
Compare
@endophage: rebased, doesn't handle the |
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
06a12a8
to
7a98a07
Compare
LGTM pending CI |
Part of the issue noted in #820
Signed-off-by: Riyaz Faizullabhoy riyaz.faizullabhoy@docker.com