test(agent-team): assemble PEM test data at runtime (avoid gitleaks FP)
The no-write-token detector's test fixtures + a doc comment contained contiguous '-----BEGIN ... PRIVATE KEY-----' literals that tripped the repo's gitleaks pre-push backstop (a false positive on a secret-DETECTOR's own test data). Build the PEM markers at runtime so the source carries no contiguous literal; the runtime values are still full PEM blocks (what the detector under test sees). No behavior change; 39 no-write-token tests pass.
This commit is contained in:
parent
00c51192c8
commit
ee97a69154
2 changed files with 19 additions and 13 deletions
|
|
@ -125,8 +125,8 @@ def scan_environ(environ: Mapping[str, str], *, app_id: str | None = None) -> li
|
|||
for name, value in environ.items():
|
||||
# The PEM private-key VALUE check and the configured App-id VALUE check
|
||||
# are NOT name-exempt: the App's private key exported under a benign name
|
||||
# (e.g. GH_APP_KEY=-----BEGIN RSA PRIVATE KEY-----...) and the configured
|
||||
# App id parked in any var are both forbidden material, even in an
|
||||
# (e.g. GH_APP_KEY set to a "BEGIN ... PRIVATE KEY" PEM block) and the
|
||||
# configured App id parked in any var are both forbidden material, even in an
|
||||
# otherwise read-only/allowlisted var. Check them up front, before the
|
||||
# allowlist short-circuits the name/token-prefix heuristics.
|
||||
if value and _PRIVATE_KEY_RE.search(value):
|
||||
|
|
|
|||
|
|
@ -24,18 +24,24 @@ _SCRIPT_PATH = (
|
|||
)
|
||||
|
||||
# A sample PEM private key header for each algorithm the design calls out. We
|
||||
# assert the regex covers RSA / EC / OPENSSH (and a bare PKCS#8 block).
|
||||
# assert the regex covers RSA / EC / OPENSSH (and a bare PKCS#8 block). The PEM
|
||||
# markers are ASSEMBLED at runtime (not written as contiguous literals) so this
|
||||
# test data does not itself trip the repo's gitleaks pre-push backstop — the
|
||||
# values are still full PEM blocks at runtime, which is what the detector sees.
|
||||
_BEGIN = "-----BEGIN "
|
||||
_END = "-----END "
|
||||
_PEM_BODY = "\nMIIB...redacted...\n"
|
||||
_RSA_KEY = (
|
||||
"-----BEGIN RSA PRIVATE KEY-----" + _PEM_BODY + "-----END RSA PRIVATE KEY-----"
|
||||
)
|
||||
_EC_KEY = "-----BEGIN EC PRIVATE KEY-----" + _PEM_BODY + "-----END EC PRIVATE KEY-----"
|
||||
_OPENSSH_KEY = (
|
||||
"-----BEGIN OPENSSH PRIVATE KEY-----"
|
||||
+ _PEM_BODY
|
||||
+ "-----END OPENSSH PRIVATE KEY-----"
|
||||
)
|
||||
_PKCS8_KEY = "-----BEGIN PRIVATE KEY-----" + _PEM_BODY + "-----END PRIVATE KEY-----"
|
||||
|
||||
|
||||
def _pem(alg: str) -> str:
|
||||
label = f"{alg} PRIVATE KEY-----" if alg else "PRIVATE KEY-----"
|
||||
return f"{_BEGIN}{label}{_PEM_BODY}{_END}{label}"
|
||||
|
||||
|
||||
_RSA_KEY = _pem("RSA")
|
||||
_EC_KEY = _pem("EC")
|
||||
_OPENSSH_KEY = _pem("OPENSSH")
|
||||
_PKCS8_KEY = _pem("")
|
||||
|
||||
|
||||
def _load_script() -> ModuleType:
|
||||
|
|
|
|||
Reference in a new issue