fix: fail closed thothctl secret sources

This commit is contained in:
2026-08-04 17:17:39 +02:00
parent 4158990c10
commit 35a000222c
7 changed files with 366 additions and 49 deletions
+3 -12
View File
@@ -3,11 +3,11 @@ package output
import (
"errors"
"io"
"os"
"regexp"
"sort"
"strings"
"github.com/aritmolab/thothii/tools/thothctl/internal/safeio"
)
var credentialField = regexp.MustCompile(`(?im)(\b[\w.-]*(?:password|token|key)[\w.-]*\s*[:=]\s*)(?:"[^"\r\n]*"|'[^'\r\n]*'|[^\s,;]+)`)
@@ -48,18 +48,9 @@ func SecretValuesFromFiles(paths []string) ([]string, error) {
}
func readSecretFile(path string) (string, error) {
info, err := os.Lstat(path)
if err != nil || !info.Mode().IsRegular() || info.Size() > maxSecretFileBytes {
return "", errors.New("declared secret file could not be read")
}
file, err := os.Open(path)
contents, err := safeio.ReadCanonicalRegular(path, maxSecretFileBytes)
if err != nil {
return "", errors.New("declared secret file could not be read")
}
defer file.Close()
contents, err := io.ReadAll(io.LimitReader(file, maxSecretFileBytes+1))
if err != nil || len(contents) > maxSecretFileBytes {
return "", errors.New("declared secret file could not be read")
}
return strings.TrimRight(string(contents), "\r\n"), nil
}