fix(security): validate bundle and clean runtime secrets

This commit is contained in:
2026-07-12 11:52:02 +02:00
parent 385646d574
commit 449a333365
5 changed files with 94 additions and 20 deletions
+21 -6
View File
@@ -36,8 +36,23 @@ cleanup_secret_tmp() {
}
trap cleanup_secret_tmp EXIT HUP INT TERM
run_child() {
"$@" &
child_pid=$!
forward_signal() { kill -TERM "$child_pid" 2>/dev/null || true; }
trap forward_signal HUP INT TERM
wait "$child_pid"
status=$?
trap - HUP INT TERM
return "$status"
}
bundle=${THT_SECRETS_FILE:-}
if [ -n "$bundle" ] && [ -r "$bundle" ]; then
if [ -n "$bundle" ]; then
if ! validate_bundle "$bundle" >/dev/null 2>&1; then
echo "THT_SECRETS_FILE points to an invalid secret bundle" >&2
exit 2
fi
# REST adapters consume these values while the harness is running. They are
# loaded here (before `tht` starts), not only in the backend/Pi process.
load_bundle_env() {
@@ -76,21 +91,21 @@ fi
case "${1:-server}" in
server)
shift || true
exec node /app/backend/dist/server.js "$@"
run_child node /app/backend/dist/server.js "$@"
;;
doctor)
shift
exec tht doctor "$@"
run_child tht doctor "$@"
;;
preprocess)
shift
exec tht preprocess "$@"
run_child tht preprocess "$@"
;;
tht)
shift
exec tht "$@"
run_child tht "$@"
;;
*)
exec tht "$@"
run_child tht "$@"
;;
esac