fix(security): validate bundle and clean runtime secrets
This commit is contained in:
@@ -36,8 +36,23 @@ cleanup_secret_tmp() {
|
||||
}
|
||||
trap cleanup_secret_tmp EXIT HUP INT TERM
|
||||
|
||||
run_child() {
|
||||
"$@" &
|
||||
child_pid=$!
|
||||
forward_signal() { kill -TERM "$child_pid" 2>/dev/null || true; }
|
||||
trap forward_signal HUP INT TERM
|
||||
wait "$child_pid"
|
||||
status=$?
|
||||
trap - HUP INT TERM
|
||||
return "$status"
|
||||
}
|
||||
|
||||
bundle=${THT_SECRETS_FILE:-}
|
||||
if [ -n "$bundle" ] && [ -r "$bundle" ]; then
|
||||
if [ -n "$bundle" ]; then
|
||||
if ! validate_bundle "$bundle" >/dev/null 2>&1; then
|
||||
echo "THT_SECRETS_FILE points to an invalid secret bundle" >&2
|
||||
exit 2
|
||||
fi
|
||||
# REST adapters consume these values while the harness is running. They are
|
||||
# loaded here (before `tht` starts), not only in the backend/Pi process.
|
||||
load_bundle_env() {
|
||||
@@ -76,21 +91,21 @@ fi
|
||||
case "${1:-server}" in
|
||||
server)
|
||||
shift || true
|
||||
exec node /app/backend/dist/server.js "$@"
|
||||
run_child node /app/backend/dist/server.js "$@"
|
||||
;;
|
||||
doctor)
|
||||
shift
|
||||
exec tht doctor "$@"
|
||||
run_child tht doctor "$@"
|
||||
;;
|
||||
preprocess)
|
||||
shift
|
||||
exec tht preprocess "$@"
|
||||
run_child tht preprocess "$@"
|
||||
;;
|
||||
tht)
|
||||
shift
|
||||
exec tht "$@"
|
||||
run_child tht "$@"
|
||||
;;
|
||||
*)
|
||||
exec tht "$@"
|
||||
run_child tht "$@"
|
||||
;;
|
||||
esac
|
||||
|
||||
Reference in New Issue
Block a user