fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -2,6 +2,11 @@ import {
|
||||
closeSync, constants, fstatSync, lstatSync, openSync, readFileSync,
|
||||
type Stats,
|
||||
} from "node:fs";
|
||||
import {
|
||||
AUTHENTICATION_SECRET_LIMITS,
|
||||
isAuthenticationSecretReference,
|
||||
isUsableAuthenticationSecret,
|
||||
} from "../auth/secret-policy.js";
|
||||
|
||||
/** Keys accepted by the deployment bundle. Keep this list intentionally explicit. */
|
||||
export const SECRET_BUNDLE_KEYS = Object.freeze([
|
||||
@@ -26,7 +31,10 @@ const LEGACY_FILES: Readonly<Record<string, string>> = {
|
||||
};
|
||||
|
||||
const MAX_BUNDLE_BYTES = 64 * 1024;
|
||||
const MAX_LINE_BYTES = 16 * 1024;
|
||||
const MAX_LINE_BYTES = Math.max(
|
||||
16 * 1024,
|
||||
...Object.entries(AUTHENTICATION_SECRET_LIMITS).map(([name, maximum]) => name.length + 1 + maximum),
|
||||
);
|
||||
|
||||
export interface SecretBundleConfig {
|
||||
secretsFile?: string;
|
||||
@@ -98,7 +106,8 @@ function parseBundle(text: string): ReadonlyMap<string, string> {
|
||||
const match = /^([A-Z][A-Z0-9_]*)=(.*)$/.exec(line);
|
||||
if (!match) throw unavailable();
|
||||
const [, key, value] = match;
|
||||
if (!ALLOWED.has(key) || values.has(key) || value.length === 0 || /[\r\n]/.test(value)) {
|
||||
if (!ALLOWED.has(key) || values.has(key) || value.length === 0 || /[\r\n]/.test(value)
|
||||
|| isAuthenticationSecretReference(key) && !isUsableAuthenticationSecret(key, value)) {
|
||||
throw unavailable();
|
||||
}
|
||||
values.set(key, value);
|
||||
|
||||
Reference in New Issue
Block a user