From f67d2c97d85c0effb4e4289c0518882b45710c3a Mon Sep 17 00:00:00 2001 From: mptyl Date: Sun, 12 Jul 2026 11:53:15 +0200 Subject: [PATCH] fix(security): reject invalid optional bundle values --- .superpowers/sdd/task-3-report.md | 2 ++ deploy/vector/secret-policy.sh | 2 +- docker/core-entrypoint.sh | 14 ++++++++++---- 3 files changed, 13 insertions(+), 5 deletions(-) diff --git a/.superpowers/sdd/task-3-report.md b/.superpowers/sdd/task-3-report.md index 154f23ad..b6696028 100644 --- a/.superpowers/sdd/task-3-report.md +++ b/.superpowers/sdd/task-3-report.md @@ -55,3 +55,5 @@ outside Compose and mount only the bundle. - Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather than being orphaned by `exec`. - The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader. +- Optional key lookup distinguishes an absent key from an invalid value; present malformed + credentials now stop entrypoint startup instead of being silently ignored. diff --git a/deploy/vector/secret-policy.sh b/deploy/vector/secret-policy.sh index 50c22c34..01de8eab 100755 --- a/deploy/vector/secret-policy.sh +++ b/deploy/vector/secret-policy.sh @@ -85,7 +85,7 @@ read_bundle_secret() { END { if (!found) exit 5 } ' "$bundle_path") || { echo "$bundle_key is unavailable in secret bundle" >&2 - return 2 + return 3 } if [ -z "$value" ] || printf '%s' "$value" | LC_ALL=C grep -q '[[:space:]]'; then echo "$bundle_key must contain no whitespace" >&2 diff --git a/docker/core-entrypoint.sh b/docker/core-entrypoint.sh index 1039e542..a304a7bf 100755 --- a/docker/core-entrypoint.sh +++ b/docker/core-entrypoint.sh @@ -58,8 +58,12 @@ if [ -n "$bundle" ]; then load_bundle_env() { env_name=$1 key=$2 - value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null || true) - if [ -n "$value" ]; then export "$env_name=$value"; fi + if value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null); then + export "$env_name=$value" + else + status=$? + [ "$status" -eq 3 ] || { echo "secret bundle contains an invalid $key value" >&2; exit 2; } + fi } load_bundle_env THT_DWH_API_KEY THT_DWH_API_KEY load_bundle_env THT_VEC_API_KEY THT_VEC_API_KEY @@ -75,11 +79,13 @@ if [ -n "$bundle" ]; then materialize_password() { env_name=$1 key=$2 - value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null || true) - if [ -n "$value" ]; then + if value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null); then file="$secret_tmp_dir/$key" printf '%s' "$value" >"$file" export "$env_name=$file" + else + status=$? + [ "$status" -eq 3 ] || { echo "secret bundle contains an invalid $key value" >&2; exit 2; } fi } materialize_password THT_VECTOR_BOOTSTRAP_PASSWORD_FILE THT_VECTOR_BOOTSTRAP_PASSWORD