fix: harden evidence secret file handoff
This commit is contained in:
@@ -60,18 +60,18 @@ function isInside(path: string, root: string): boolean {
|
||||
return pathRelative !== "" && !pathRelative.startsWith("..") && !isAbsolute(pathRelative);
|
||||
}
|
||||
|
||||
function isSafeSecretFile(path: string, secretRoots: readonly string[]): boolean {
|
||||
if (!isAbsolute(path)) return false;
|
||||
function safeSecretFilePath(path: string, secretRoots: readonly string[]): string | undefined {
|
||||
if (!isAbsolute(path)) return undefined;
|
||||
|
||||
try {
|
||||
const resolvedPath = realpathSync(path);
|
||||
const resolvedRoots = secretRoots.map((root) => realpathSync(root));
|
||||
if (!resolvedRoots.some((root) => isInside(resolvedPath, root))) return false;
|
||||
if (!statSync(resolvedPath).isFile()) return false;
|
||||
if (!resolvedRoots.some((root) => isInside(resolvedPath, root))) return undefined;
|
||||
if (!statSync(resolvedPath).isFile()) return undefined;
|
||||
accessSync(resolvedPath, constants.R_OK);
|
||||
return true;
|
||||
return resolvedPath;
|
||||
} catch {
|
||||
return false;
|
||||
return undefined;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -132,11 +132,12 @@ export function resolveBinding(
|
||||
|
||||
const value = env[variable.name];
|
||||
const present = value !== undefined && value.trim() !== "";
|
||||
const safe = !variable.secret || (present && isSafeSecretFile(value, secretRoots));
|
||||
const safePath = variable.secret && present ? safeSecretFilePath(value, secretRoots) : undefined;
|
||||
const safe = !variable.secret || safePath !== undefined;
|
||||
if ((required.has(variable.suffix) && !present) || (present && !safe)) {
|
||||
missing.push(variable.name);
|
||||
}
|
||||
if (present && safe) values[variable.name] = value;
|
||||
if (present && safe) values[variable.name] = variable.secret ? safePath! : value;
|
||||
}
|
||||
|
||||
return { transport: selectedTransport, values, missing };
|
||||
@@ -166,11 +167,11 @@ export function resolveEvidenceBinding(
|
||||
for (const variable of variables) {
|
||||
const value = env[variable.name];
|
||||
const present = value !== undefined && value.trim() !== "";
|
||||
const safe = present && isSafeSecretFile(value, secretRoots);
|
||||
if ((required.has(variable.suffix) && !present) || (present && !safe)) {
|
||||
const safePath = present ? safeSecretFilePath(value, secretRoots) : undefined;
|
||||
if ((required.has(variable.suffix) && !present) || (present && safePath === undefined)) {
|
||||
missing.push(variable.name);
|
||||
}
|
||||
if (safe) values[variable.name] = value;
|
||||
if (safePath !== undefined) values[variable.name] = safePath;
|
||||
}
|
||||
return { values, missing };
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { chmodSync, mkdirSync, mkdtempSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
|
||||
import { chmodSync, mkdirSync, mkdtempSync, realpathSync, rmSync, symlinkSync, writeFileSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
import { join } from "node:path";
|
||||
import { afterEach, expect, test } from "vitest";
|
||||
@@ -153,7 +153,7 @@ test("resolves direct bindings from the stable workspace namespace", () => {
|
||||
values: {
|
||||
THT_WS_PSD_CLINICAL_DWH_HOST: "dwh.internal",
|
||||
THT_WS_PSD_CLINICAL_DWH_PORT: "5432",
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: password.path,
|
||||
THT_WS_PSD_CLINICAL_DWH_PASSWORD_FILE: realpathSync(password.path),
|
||||
},
|
||||
});
|
||||
});
|
||||
@@ -304,10 +304,26 @@ test("requires only a safe HTTP signed-URL file and never reads its contents", (
|
||||
[variable]: signed.path,
|
||||
[evidenceVariable("ACCESS_KEY_FILE")]: signed.path,
|
||||
}, [signed.root]);
|
||||
expect(resolved).toEqual({ values: { [variable]: signed.path }, missing: [] });
|
||||
expect(resolved).toEqual({ values: { [variable]: realpathSync(signed.path) }, missing: [] });
|
||||
expect(JSON.stringify(resolved)).not.toContain("CANARY-SIGNED-URL-CONTENT");
|
||||
});
|
||||
|
||||
test("canonicalizes an in-root Evidence symlink before passing it to the harness", () => {
|
||||
const signed = secretPath("evidence-signed-target");
|
||||
const link = join(signed.root, "signed-urls-link");
|
||||
symlinkSync(signed.path, link);
|
||||
const source = withEvidence({
|
||||
type: "http",
|
||||
uris: ["https://evidence.example.test/guide.md"],
|
||||
authentication: "signed_urls_file",
|
||||
});
|
||||
const variable = evidenceVariable("SIGNED_URLS_FILE");
|
||||
|
||||
expect(resolveEvidenceBinding(source, { [variable]: link }, [signed.root])).toEqual({
|
||||
values: { [variable]: realpathSync(signed.path) }, missing: [],
|
||||
});
|
||||
});
|
||||
|
||||
test("requires S3 access and secret files together while accepting an optional safe session token", () => {
|
||||
const access = secretPath("evidence-access");
|
||||
const secret = secretPath("evidence-secret");
|
||||
@@ -327,9 +343,9 @@ test("requires S3 access and secret files together while accepting an optional s
|
||||
}, [access.root]).missing).toEqual([evidenceVariable("SECRET_KEY_FILE")]);
|
||||
expect(resolveEvidenceBinding(source, env, [access.root, secret.root, token.root])).toEqual({
|
||||
values: {
|
||||
[evidenceVariable("ACCESS_KEY_FILE")]: access.path,
|
||||
[evidenceVariable("SECRET_KEY_FILE")]: secret.path,
|
||||
[evidenceVariable("SESSION_TOKEN_FILE")]: token.path,
|
||||
[evidenceVariable("ACCESS_KEY_FILE")]: realpathSync(access.path),
|
||||
[evidenceVariable("SECRET_KEY_FILE")]: realpathSync(secret.path),
|
||||
[evidenceVariable("SESSION_TOKEN_FILE")]: realpathSync(token.path),
|
||||
},
|
||||
missing: [],
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user