fix(security): reject invalid optional bundle values

This commit is contained in:
2026-07-12 11:53:15 +02:00
parent 449a333365
commit f67d2c97d8
3 changed files with 13 additions and 5 deletions
+2
View File
@@ -55,3 +55,5 @@ outside Compose and mount only the bundle.
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather - Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
than being orphaned by `exec`. than being orphaned by `exec`.
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader. - The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
- Optional key lookup distinguishes an absent key from an invalid value; present malformed
credentials now stop entrypoint startup instead of being silently ignored.
+1 -1
View File
@@ -85,7 +85,7 @@ read_bundle_secret() {
END { if (!found) exit 5 } END { if (!found) exit 5 }
' "$bundle_path") || { ' "$bundle_path") || {
echo "$bundle_key is unavailable in secret bundle" >&2 echo "$bundle_key is unavailable in secret bundle" >&2
return 2 return 3
} }
if [ -z "$value" ] || printf '%s' "$value" | LC_ALL=C grep -q '[[:space:]]'; then if [ -z "$value" ] || printf '%s' "$value" | LC_ALL=C grep -q '[[:space:]]'; then
echo "$bundle_key must contain no whitespace" >&2 echo "$bundle_key must contain no whitespace" >&2
+10 -4
View File
@@ -58,8 +58,12 @@ if [ -n "$bundle" ]; then
load_bundle_env() { load_bundle_env() {
env_name=$1 env_name=$1
key=$2 key=$2
value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null || true) if value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null); then
if [ -n "$value" ]; then export "$env_name=$value"; fi export "$env_name=$value"
else
status=$?
[ "$status" -eq 3 ] || { echo "secret bundle contains an invalid $key value" >&2; exit 2; }
fi
} }
load_bundle_env THT_DWH_API_KEY THT_DWH_API_KEY load_bundle_env THT_DWH_API_KEY THT_DWH_API_KEY
load_bundle_env THT_VEC_API_KEY THT_VEC_API_KEY load_bundle_env THT_VEC_API_KEY THT_VEC_API_KEY
@@ -75,11 +79,13 @@ if [ -n "$bundle" ]; then
materialize_password() { materialize_password() {
env_name=$1 env_name=$1
key=$2 key=$2
value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null || true) if value=$(read_bundle_secret "$bundle" "$key" 2>/dev/null); then
if [ -n "$value" ]; then
file="$secret_tmp_dir/$key" file="$secret_tmp_dir/$key"
printf '%s' "$value" >"$file" printf '%s' "$value" >"$file"
export "$env_name=$file" export "$env_name=$file"
else
status=$?
[ "$status" -eq 3 ] || { echo "secret bundle contains an invalid $key value" >&2; exit 2; }
fi fi
} }
materialize_password THT_VECTOR_BOOTSTRAP_PASSWORD_FILE THT_VECTOR_BOOTSTRAP_PASSWORD materialize_password THT_VECTOR_BOOTSTRAP_PASSWORD_FILE THT_VECTOR_BOOTSTRAP_PASSWORD