test: prove DWH credential leak detection
This commit is contained in:
@@ -557,6 +557,7 @@ git commit -m "docs: explain per-installation DWH access"
|
||||
bash scripts/test-dwh-auth-build-contract.sh
|
||||
bash scripts/test-dwh-auth-nginx-contract.sh
|
||||
bash scripts/test-dwh-auth-nginx-integration.sh
|
||||
bash scripts/test-dwh-auth-secret-scan-contract.sh
|
||||
bash scripts/test-dwh-auth-secret-scan.sh
|
||||
bash scripts/test-verify-dwh-auth-docs.sh
|
||||
```
|
||||
|
||||
+58
@@ -0,0 +1,58 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
|
||||
scanner="$repo_root/scripts/test-dwh-auth-secret-scan.sh"
|
||||
tmp_parent=${TMPDIR:-/tmp}
|
||||
fixture_parent=$(mktemp -d "$tmp_parent/thothii-dwh-auth-secret-scan-contract.XXXXXX")
|
||||
fixture_root="$fixture_parent/root"
|
||||
outside_root="$fixture_parent/outside"
|
||||
|
||||
cleanup() {
|
||||
case "$fixture_parent" in
|
||||
"$tmp_parent"/thothii-dwh-auth-secret-scan-contract.*) rm -rf -- "$fixture_parent" ;;
|
||||
*) printf '%s\n' 'secret scan contract cleanup refused' >&2; return 1 ;;
|
||||
esac
|
||||
}
|
||||
trap cleanup EXIT HUP INT TERM
|
||||
|
||||
fail() {
|
||||
printf 'case=%s status=FAIL\n' "$1" >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
run_scanner() {
|
||||
local root=$1 stdout=$2 stderr=$3
|
||||
set +e
|
||||
"$scanner" --root "$root" >"$stdout" 2>"$stderr"
|
||||
scan_status=$?
|
||||
set -e
|
||||
}
|
||||
|
||||
mkdir -p "$fixture_root" "$outside_root" || fail fixture_directories
|
||||
chmod 0700 "$fixture_parent" "$fixture_root" "$outside_root" || fail fixture_directories
|
||||
|
||||
credential="$(printf 'thtdwh_v1.%s.%s' "$(printf 'A%.0s' {1..16})" "$(printf 'B%.0s' {1..43})")"
|
||||
printf '%s\n' "$credential" >"$fixture_root/full-format-fixture.txt"
|
||||
printf '%s\n' "$credential" >"$outside_root/outside-fixture.txt"
|
||||
|
||||
run_scanner "$fixture_root" "$fixture_root/negative.stdout" "$fixture_root/negative.stderr"
|
||||
[[ "$scan_status" -eq 1 ]] || fail detects_full_format
|
||||
[[ ! -s "$fixture_root/negative.stdout" ]] || fail detects_full_format
|
||||
[[ "$(<"$fixture_root/negative.stderr")" == 'dwh-auth credential literal scan failed' ]] || fail detects_full_format
|
||||
! grep -Fq -- "$credential" "$fixture_root/negative.stdout" "$fixture_root/negative.stderr" || fail detects_full_format
|
||||
printf 'case=detects_full_format status=PASS\n'
|
||||
|
||||
rm -f -- "$fixture_root/full-format-fixture.txt"
|
||||
run_scanner "$fixture_root" "$fixture_root/clean.stdout" "$fixture_root/clean.stderr"
|
||||
[[ "$scan_status" -eq 0 ]] || fail clean_fixture
|
||||
[[ "$(<"$fixture_root/clean.stdout")" == 'dwh-auth credential literal scan passed' ]] || fail clean_fixture
|
||||
[[ ! -s "$fixture_root/clean.stderr" ]] || fail clean_fixture
|
||||
printf 'case=clean_fixture status=PASS\n'
|
||||
|
||||
run_scanner "$fixture_parent/missing" "$fixture_root/error.stdout" "$fixture_root/error.stderr"
|
||||
[[ "$scan_status" -ne 0 ]] || fail invalid_root
|
||||
! grep -Fq -- "$credential" "$fixture_root/error.stdout" "$fixture_root/error.stderr" || fail invalid_root
|
||||
printf 'case=invalid_root status=PASS\n'
|
||||
|
||||
printf 'case=summary status=PASS\n'
|
||||
@@ -3,9 +3,18 @@ set -euo pipefail
|
||||
|
||||
repo_root=$(cd "$(dirname "$0")/.." && pwd -P)
|
||||
pattern='thtdwh_v1\.[A-Za-z0-9_-]{16}\.[A-Za-z0-9_-]{43}'
|
||||
scan_root=$repo_root
|
||||
|
||||
if [[ $# -ne 0 ]]; then
|
||||
[[ $# -eq 2 && $1 == --root && $2 == /* && -d $2 && ! -L $2 ]] || {
|
||||
printf '%s\n' 'dwh-auth credential literal scan failed (invalid root)' >&2
|
||||
exit 2
|
||||
}
|
||||
scan_root=$(cd "$2" && pwd -P)
|
||||
fi
|
||||
|
||||
set +e
|
||||
rg --quiet --hidden --glob '!.git/**' -P -- "$pattern" "$repo_root"
|
||||
rg --quiet --hidden --glob '!.git/**' -P -- "$pattern" "$scan_root"
|
||||
scan_status=$?
|
||||
set -e
|
||||
|
||||
|
||||
Reference in New Issue
Block a user