fix: close evidence credential disclosure gaps

This commit is contained in:
2026-08-09 19:15:00 +02:00
parent 7126b567b0
commit df8dc1e219
7 changed files with 100 additions and 13 deletions
+7 -3
View File
@@ -60,6 +60,8 @@ def _resolve_http_signed_url_files(value: Any) -> Any:
return resolved
if "urls" in resolved:
raise ConfigError("HTTP signed URL file cannot be combined with urls")
if "provenance_urls" not in resolved:
raise ConfigError("HTTP signed URL file requires provenance_urls")
path_value = resolved.pop("signed_urls_file")
if not isinstance(path_value, str):
raise ConfigError("Invalid signed URL file reference")
@@ -76,8 +78,8 @@ def _resolve_http_signed_url_files(value: Any) -> Any:
if len(payload) > _MAX_SIGNED_URL_FILE_BYTES:
raise OSError
parsed = json.loads(payload.decode("utf-8"))
except (OSError, UnicodeError, json.JSONDecodeError) as exc:
raise ConfigError("Cannot read signed URL file") from exc
except (OSError, UnicodeError, json.JSONDecodeError):
raise ConfigError("Cannot read signed URL file") from None
if (
not isinstance(parsed, list)
or not parsed
@@ -307,6 +309,8 @@ class HttpEvidenceSourceConfig(BaseModel):
):
raise ValueError("HTTP transport URL must use http or https")
if self.provenance_urls is None:
if canonical != transport_urls or len(set(canonical)) != len(canonical):
raise ValueError("Public HTTP URLs must be canonical query-free identities")
return self
try:
provenance = [canonical_provenance_uri(url) for url in self.provenance_urls]
@@ -532,7 +536,7 @@ def load_config(path: Path) -> Config:
cfg = Config.model_validate(translated)
except ValidationError as e:
details = _format_validation_error(e)
raise ConfigError(f"Configurazione non valida in {path}:\n{details}") from e
raise ConfigError(f"Configurazione non valida in {path}:\n{details}") from None
env_profile = os.environ.get("THT_PROFILE")
if env_profile is not None:
if env_profile not in ("server", "workstation"):