Remove 'enroll diff --enforce' option. Tighten yaml data re: handlers - use listen: instead of notify:
This commit is contained in:
parent
e9d7d74445
commit
903125976d
15 changed files with 851 additions and 1288 deletions
|
|
@ -72,3 +72,90 @@ def test_password_keyword_no_false_positives():
|
|||
b"compression = gzip\n",
|
||||
]:
|
||||
assert pol._content_deny_reason("/etc/app.conf", data) is None, data
|
||||
|
||||
|
||||
def test_block_comment_open_cannot_mask_private_key():
|
||||
"""Security regression: a line beginning with ``/*`` must not put the content
|
||||
scanner into a runaway block-comment state that hides later real secrets.
|
||||
|
||||
Previously, any line starting with ``/*`` suppressed scanning of every
|
||||
subsequent line until a ``*/`` appeared. An unterminated (or hostile) block
|
||||
open therefore masked a PEM private key / password in an arbitrary config
|
||||
file (one not covered by a path deny-glob)."""
|
||||
pol = IgnorePolicy(dangerous=False)
|
||||
leaking = [
|
||||
# leading /* with no closing */ masking a PEM private key
|
||||
b"/* app config\n"
|
||||
b"tls_key = -----BEGIN PRIVATE KEY-----\n"
|
||||
b"MIIBVw...\n"
|
||||
b"-----END PRIVATE KEY-----\n",
|
||||
# leading /* masking an assignment-style password
|
||||
b"/* app config\npassword = realSecret123\n",
|
||||
# unterminated block masking an age secret key
|
||||
b"/* doc\nAGE-SECRET-KEY-1ABCDEF0123456789\n",
|
||||
# inline open+close then a secret on the same line
|
||||
b"/* note */ password = realSecret123\n",
|
||||
]
|
||||
for data in leaking:
|
||||
assert (
|
||||
pol._content_deny_reason("/etc/app/app.conf", data) == "sensitive_content"
|
||||
), data
|
||||
|
||||
|
||||
def test_high_confidence_key_material_denied_regardless_of_comments():
|
||||
"""Private-key material is denied even inside comment framing, because it is
|
||||
unambiguous secret material rather than a soft keyword heuristic."""
|
||||
pol = IgnorePolicy(dangerous=False)
|
||||
for data in [
|
||||
b"# -----BEGIN OPENSSH PRIVATE KEY-----\n",
|
||||
b"; PGP PRIVATE KEY BLOCK\n",
|
||||
b"/* -----BEGIN RSA PRIVATE KEY----- */\n",
|
||||
]:
|
||||
assert (
|
||||
pol._content_deny_reason("/etc/app/app.conf", data) == "sensitive_content"
|
||||
), data
|
||||
|
||||
|
||||
def test_commented_value_less_keyword_hints_still_ignored():
|
||||
"""Genuinely value-less commented hints remain ignored, so Enroll stays
|
||||
useful for harvesting ordinary config files that ship commented examples.
|
||||
|
||||
Only a bare credential *word* with no assigned value is tolerated in a
|
||||
comment; a populated commented assignment is treated as a real (disabled)
|
||||
secret -- see test_commented_out_credential_values_require_dangerous."""
|
||||
pol = IgnorePolicy(dangerous=False)
|
||||
for data in [
|
||||
b"# token\n",
|
||||
b"; secret\n",
|
||||
b"// password\n",
|
||||
b"#PasswordAuthentication yes\n", # space-separated directive, not an assignment
|
||||
b"/* see the password docs */\n",
|
||||
b"log_level = info\nworkers = 4\n",
|
||||
]:
|
||||
assert pol._content_deny_reason("/etc/app/app.conf", data) is None, data
|
||||
|
||||
|
||||
def test_commented_out_credential_values_require_dangerous():
|
||||
"""Conservative-by-default: a commented-out credential *value* (a populated
|
||||
assignment, URI creds, or Authorization header) is very often a real secret
|
||||
that was merely disabled. Such a file is refused in safe mode and requires
|
||||
--dangerous, regardless of comment style or block-comment framing."""
|
||||
safe = IgnorePolicy(dangerous=False)
|
||||
dangerous = IgnorePolicy(dangerous=True)
|
||||
commented_real_secrets = [
|
||||
b"# password = realProductionPass\n",
|
||||
b"; auth_token = abc123secret\n",
|
||||
b"// client_secret: deadbeef\n",
|
||||
b"/* password = changeme123 */\n",
|
||||
b"/*\n api_key = AKIA0123\n*/\nlisten = 8080\n",
|
||||
b"# DATABASE_URL=postgres://user:pass@host/db\n",
|
||||
b"# -----BEGIN OPENSSH PRIVATE KEY-----\n",
|
||||
b"/*\nAuthorization: Bearer eyJabc\n*/\n",
|
||||
]
|
||||
for data in commented_real_secrets:
|
||||
# Refused in safe mode...
|
||||
assert (
|
||||
safe._content_deny_reason("/etc/app/app.conf", data) == "sensitive_content"
|
||||
), data
|
||||
# ...but --dangerous still collects it (operator's explicit choice).
|
||||
assert dangerous._content_deny_reason("/etc/app/app.conf", data) is None, data
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue