fix(auth): make diagnostics bounded and portable

This commit is contained in:
2026-08-17 12:19:19 +02:00
parent 7cfbee36fa
commit be1724890a
23 changed files with 1088 additions and 116 deletions
+11 -2
View File
@@ -2,6 +2,11 @@ import {
closeSync, constants, fstatSync, lstatSync, openSync, readFileSync,
type Stats,
} from "node:fs";
import {
AUTHENTICATION_SECRET_LIMITS,
isAuthenticationSecretReference,
isUsableAuthenticationSecret,
} from "../auth/secret-policy.js";
/** Keys accepted by the deployment bundle. Keep this list intentionally explicit. */
export const SECRET_BUNDLE_KEYS = Object.freeze([
@@ -26,7 +31,10 @@ const LEGACY_FILES: Readonly<Record<string, string>> = {
};
const MAX_BUNDLE_BYTES = 64 * 1024;
const MAX_LINE_BYTES = 16 * 1024;
const MAX_LINE_BYTES = Math.max(
16 * 1024,
...Object.entries(AUTHENTICATION_SECRET_LIMITS).map(([name, maximum]) => name.length + 1 + maximum),
);
export interface SecretBundleConfig {
secretsFile?: string;
@@ -98,7 +106,8 @@ function parseBundle(text: string): ReadonlyMap<string, string> {
const match = /^([A-Z][A-Z0-9_]*)=(.*)$/.exec(line);
if (!match) throw unavailable();
const [, key, value] = match;
if (!ALLOWED.has(key) || values.has(key) || value.length === 0 || /[\r\n]/.test(value)) {
if (!ALLOWED.has(key) || values.has(key) || value.length === 0 || /[\r\n]/.test(value)
|| isAuthenticationSecretReference(key) && !isUsableAuthenticationSecret(key, value)) {
throw unavailable();
}
values.set(key, value);