[tahoe-lafs-trac-stream] [Tahoe-LAFS] #3642: Address the GBS spec "TODO" regarding placement of storage index in the URL

Tahoe-LAFS trac at tahoe-lafs.org
Fri Mar 19 18:53:57 UTC 2021


#3642: Address the GBS spec "TODO" regarding placement of storage index in the URL
---------------------+---------------------------
 Reporter:  exarkun  |          Owner:  exarkun
     Type:  defect   |         Status:  new
 Priority:  normal   |      Milestone:  undecided
Component:  unknown  |        Version:  n/a
 Keywords:           |  Launchpad Bug:
---------------------+---------------------------
 {{{
 We considered making this ``POST /v1/immutable`` instead.
 The motivation was to keep *storage index* out of the request URL.
 Request URLs have an elevated chance of being logged by something.
 We were concerned that having the *storage index* logged may increase some
 risks.
 However, we decided this does not matter because the *storage index* can
 only be used to read the share (which is ciphertext).
 TODO Verify this conclusion.
 }}}

 Update this with current thinking / conclusions / justifications and
 delete the TODO.

--
Ticket URL: <https://tahoe-lafs.org/trac/tahoe-lafs/ticket/3642>
Tahoe-LAFS <https://Tahoe-LAFS.org>
secure decentralized storage


More information about the tahoe-lafs-trac-stream mailing list