A path is not a secret, and the check said it was
The last failure of the run: `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` reported as "something secret-shaped, which the broker would see". `/` is in the base64 alphabet, so any absolute path of 24 characters or more matched the pattern meant to catch a sealed value. An absolute path is a *reference* to a secret and naming one is the whole design — the mesh delivers a credential as a file and a module says where. Excluded explicitly rather than by loosening the pattern, and checked both ways: a real sealed value and a base64 blob are still flagged, a relative path still is, only an absolute path is passed over. Worth the words in the comment. A check that fires on the right shape for the wrong reason is worse than none — it is the one that gets suppressed, and then it is not there when it is right. It surfaced now because tests in this file share one mesh: the builder was assigned by an earlier test and appears in this one's declaration.
This commit is contained in:
@@ -1787,6 +1787,15 @@ test("the real modules resolve together, and compose a declaration a host accept
|
|||||||
`only ${containers.length} containers; mailu alone is nine`);
|
`only ${containers.length} containers; mailu alone is nine`);
|
||||||
for (const c of containers) {
|
for (const c of containers) {
|
||||||
for (const [key, value] of Object.entries(c.env ?? {})) {
|
for (const [key, value] of Object.entries(c.env ?? {})) {
|
||||||
|
// **An absolute path is a reference to a secret, not a secret**, and naming one is the
|
||||||
|
// whole design: the mesh delivers a credential as a file and a module says where.
|
||||||
|
//
|
||||||
|
// Excluded because `/` is in the base64 alphabet, so any path of 24 characters or more
|
||||||
|
// matched — `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` was reported as a credential
|
||||||
|
// the broker would see. A check that fires on the right shape for the wrong reason is
|
||||||
|
// worse than none: it is the one that gets suppressed, and then it is not there when it
|
||||||
|
// is right.
|
||||||
|
if (String(value).startsWith("/")) continue;
|
||||||
assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/,
|
assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/,
|
||||||
`${c.name} carries something secret-shaped in env.${key}, which the broker would see`);
|
`${c.name} carries something secret-shaped in env.${key}, which the broker would see`);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user