fix(security): reject invalid optional bundle values
This commit is contained in:
@@ -55,3 +55,5 @@ outside Compose and mount only the bundle.
|
|||||||
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
|
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
|
||||||
than being orphaned by `exec`.
|
than being orphaned by `exec`.
|
||||||
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
|
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
|
||||||
|
- Optional key lookup distinguishes an absent key from an invalid value; present malformed
|
||||||
|
credentials now stop entrypoint startup instead of being silently ignored.
|
||||||
|
|||||||
@@ -85,7 +85,7 @@ read_bundle_secret() {
|
|||||||
END { if (!found) exit 5 }
|
END { if (!found) exit 5 }
|
||||||
' "$bundle_path") || {
|
' "$bundle_path") || {
|
||||||
echo "$bundle_key is unavailable in secret bundle" >&2
|
echo "$bundle_key is unavailable in secret bundle" >&2
|
||||||
return 2
|
return 3
|
||||||
}
|
}
|
||||||
if [ -z "$value" ] || printf '%s' "$value" | LC_ALL=C grep -q '[[:space:]]'; then
|
if [ -z "$value" ] || printf '%s' "$value" | LC_ALL=C grep -q '[[:space:]]'; then
|
||||||
echo "$bundle_key must contain no whitespace" >&2
|
echo "$bundle_key must contain no whitespace" >&2
|
||||||
|
|||||||
@@ -58,8 +58,12 @@ if [ -n "$bundle" ]; then
|
|||||||
load_bundle_env() {
|
load_bundle_env() {
|
||||||
env_name=$1
|
env_name=$1
|
||||||
key=$2
|
key=$2
|
||||||
value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null || true)
|
if value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null); then
|
||||||
if [ -n "$value" ]; then export "$env_name=$value"; fi
|
export "$env_name=$value"
|
||||||
|
else
|
||||||
|
status=$?
|
||||||
|
[ "$status" -eq 3 ] || { echo "secret bundle contains an invalid $key value" >&2; exit 2; }
|
||||||
|
fi
|
||||||
}
|
}
|
||||||
load_bundle_env THT_DWH_API_KEY THT_DWH_API_KEY
|
load_bundle_env THT_DWH_API_KEY THT_DWH_API_KEY
|
||||||
load_bundle_env THT_VEC_API_KEY THT_VEC_API_KEY
|
load_bundle_env THT_VEC_API_KEY THT_VEC_API_KEY
|
||||||
@@ -75,11 +79,13 @@ if [ -n "$bundle" ]; then
|
|||||||
materialize_password() {
|
materialize_password() {
|
||||||
env_name=$1
|
env_name=$1
|
||||||
key=$2
|
key=$2
|
||||||
value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null || true)
|
if value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null); then
|
||||||
if [ -n "$value" ]; then
|
|
||||||
file="$secret_tmp_dir/$key"
|
file="$secret_tmp_dir/$key"
|
||||||
printf '%s' "$value" >"$file"
|
printf '%s' "$value" >"$file"
|
||||||
export "$env_name=$file"
|
export "$env_name=$file"
|
||||||
|
else
|
||||||
|
status=$?
|
||||||
|
[ "$status" -eq 3 ] || { echo "secret bundle contains an invalid $key value" >&2; exit 2; }
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
materialize_password THT_VECTOR_BOOTSTRAP_PASSWORD_FILE THT_VECTOR_BOOTSTRAP_PASSWORD
|
materialize_password THT_VECTOR_BOOTSTRAP_PASSWORD_FILE THT_VECTOR_BOOTSTRAP_PASSWORD
|
||||||
|
|||||||
Reference in New Issue
Block a user