feat: finish Pi and workspace management updates
This commit is contained in:
@@ -122,6 +122,12 @@ func extractSecretValues(contents []byte) ([]string, error) {
|
||||
if whole != "" {
|
||||
values = append(values, whole)
|
||||
}
|
||||
// PEM files (including OpenSSH private keys) can contain base64 lines that look
|
||||
// like dotenv assignments. Keep the complete document opaque instead of trying
|
||||
// to parse it as a dotenv bundle.
|
||||
if bytes.HasPrefix(trimmed, []byte("-----BEGIN ")) {
|
||||
return values, nil
|
||||
}
|
||||
|
||||
if trimmed[0] == '{' || trimmed[0] == '[' {
|
||||
var document any
|
||||
|
||||
@@ -105,6 +105,26 @@ func TestSecretValuesFromFilesRedactsEveryDotenvBundleValue(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestSecretValuesFromFilesAcceptsOpenSSHPrivateKey(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
secretFile := filepath.Join(physicalTempDir(t), "git-ssh-key")
|
||||
contents := "-----BEGIN OPENSSH PRIVATE KEY-----\n" +
|
||||
"ZmFrZS1rZXktcGF5bG9hZA==\n" +
|
||||
"-----END OPENSSH PRIVATE KEY-----\n"
|
||||
if err := os.WriteFile(secretFile, []byte(contents), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
secrets, err := SecretValuesFromFiles([]string{secretFile})
|
||||
if err != nil {
|
||||
t.Fatalf("SecretValuesFromFiles() error = %v, want OpenSSH key accepted", err)
|
||||
}
|
||||
if len(secrets) == 0 {
|
||||
t.Fatal("SecretValuesFromFiles() returned no values for OpenSSH key")
|
||||
}
|
||||
}
|
||||
|
||||
func TestSanitizeRecognizesQuotedCredentialKeys(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user