Skip to content

Should the specification restrict the format of rolenames listed in metadata? #456

Description

@vladimir-v-diaz

The specification does not set any restrictions on the rolenames listed in metadata. For example, these rolenames may include unicode and other special characters. We can leave it up to adopters to set these restrictions for their particular implementation, or we can require a set of restrictions by default for cases that we know can lead to problems.

Activity

  1. JustinCappos commented on Jun 3, 2017

    @JustinCappos
    Member
  2. jku commented on Feb 17, 2022

    @jku
    Member

    I'll document the current situation in python-tuf and then close this: I agree that the specification could be a lot better in this regard but that's not a python-tuf issue.

    python-tuf handles rolenames as follows:

    • any string is an acceptable rolename
    • rolenames are not expected to be valid parts of a file path: e.g. the client percent encodes the rolename before using it as a filename
    • as a clarification to those two points, the "ROLENAME.json" key in targets delegations is still expected to be the raw string with an extension added to the end (I consider this a specification bug, the key should be just "ROLENAME"). This means the key does not necessarily match the filename that is actually used to store the metadata.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationDocumentation of the project as well as procedural documentationenhancementsecurity

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions