fix: harden thothctl file access

This commit is contained in:
2026-08-04 17:34:46 +02:00
parent 35a000222c
commit f5468f0d36
9 changed files with 327 additions and 41 deletions
+16 -4
View File
@@ -14,6 +14,10 @@ var credentialField = regexp.MustCompile(`(?im)(\b[\w.-]*(?:password|token|key)[
const maxSecretFileBytes = 64 * 1024
const maxSecretSourceFiles = 32
const maxSecretSourceBytes = 256 * 1024
// Sanitize redacts common credential fields and every supplied secret value.
func Sanitize(text string, secretValues []string) string {
text = credentialField.ReplaceAllString(text, "${1}[REDACTED]")
@@ -29,13 +33,21 @@ func Sanitize(text string, secretValues []string) string {
// SecretValuesFromFiles reads non-empty secret-file contents without exposing them to callers.
func SecretValuesFromFiles(paths []string) ([]string, error) {
if len(paths) > maxSecretSourceFiles {
return nil, errors.New("declared secret file could not be read")
}
values := make([]string, 0, len(paths))
seen := make(map[string]struct{})
var totalBytes int64
for _, path := range paths {
value, err := readSecretFile(path)
value, size, err := readSecretFile(path)
if err != nil {
return nil, err
}
totalBytes += size
if totalBytes > maxSecretSourceBytes {
return nil, errors.New("declared secret file could not be read")
}
if value != "" {
if _, exists := seen[value]; exists {
continue
@@ -47,10 +59,10 @@ func SecretValuesFromFiles(paths []string) ([]string, error) {
return values, nil
}
func readSecretFile(path string) (string, error) {
func readSecretFile(path string) (string, int64, error) {
contents, err := safeio.ReadCanonicalRegular(path, maxSecretFileBytes)
if err != nil {
return "", errors.New("declared secret file could not be read")
return "", 0, errors.New("declared secret file could not be read")
}
return strings.TrimRight(string(contents), "\r\n"), nil
return strings.TrimRight(string(contents), "\r\n"), int64(len(contents)), nil
}