fix: fail closed thothctl secret sources
This commit is contained in:
@@ -3,11 +3,11 @@ package output
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"io"
|
||||
"os"
|
||||
"regexp"
|
||||
"sort"
|
||||
"strings"
|
||||
|
||||
"github.com/aritmolab/thothii/tools/thothctl/internal/safeio"
|
||||
)
|
||||
|
||||
var credentialField = regexp.MustCompile(`(?im)(\b[\w.-]*(?:password|token|key)[\w.-]*\s*[:=]\s*)(?:"[^"\r\n]*"|'[^'\r\n]*'|[^\s,;]+)`)
|
||||
@@ -48,18 +48,9 @@ func SecretValuesFromFiles(paths []string) ([]string, error) {
|
||||
}
|
||||
|
||||
func readSecretFile(path string) (string, error) {
|
||||
info, err := os.Lstat(path)
|
||||
if err != nil || !info.Mode().IsRegular() || info.Size() > maxSecretFileBytes {
|
||||
return "", errors.New("declared secret file could not be read")
|
||||
}
|
||||
file, err := os.Open(path)
|
||||
contents, err := safeio.ReadCanonicalRegular(path, maxSecretFileBytes)
|
||||
if err != nil {
|
||||
return "", errors.New("declared secret file could not be read")
|
||||
}
|
||||
defer file.Close()
|
||||
contents, err := io.ReadAll(io.LimitReader(file, maxSecretFileBytes+1))
|
||||
if err != nil || len(contents) > maxSecretFileBytes {
|
||||
return "", errors.New("declared secret file could not be read")
|
||||
}
|
||||
return strings.TrimRight(string(contents), "\r\n"), nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user