sourcecases

package
v0.54.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package sourcecases generates the source strings the DT-0C property test feeds to every command path that takes a source: every scheme the CLI knows, in lower, upper and mixed case, bare and wrapped in another scheme, with a generated secret in each position a parser can read as userinfo or a user can put one: userinfo (with and without a user name), a token standing alone as the user name, the position a parser misreads as userinfo ("alice:42/secret@"), a token or a user name that holds a slash (so no colon or "@" comes before a slash), userinfo after a UNC start ("\\alice:secret@"), the query string and the fragment.

The secrets are generated, not typed, so a test that finds one in an output has found a real leak and not a coincidence with a fixed word. Generation is deterministic: the same call returns the same cases.

Index

Constants

This section is empty.

Variables

View Source
var Schemes = []string{"sqlite", "ingitdb", "postgres", "postgresql", "http", "https", "openvaultdb"}

Schemes are the schemes the CLI knows: everything Parse dispatches, and the postgresql alias.

Functions

func Leaks

func Leaks(c Case, texts ...string) []string

Leaks returns the secrets of c found in texts: a whole secret, or any run of four or more letters and digits of it (so a password cut at a space or a slash and leaked in part still counts).

func WithoutGeneratedIdentifiers

func WithoutGeneratedIdentifiers(text string) string

WithoutGeneratedIdentifiers returns text with every UUID, RFC 3339 timestamp and long hexadecimal digest replaced by a space. Read a file a program wrote through it before calling Leaks: those identifiers are random or time-based, so a run of four or more characters of a generated secret (all eight digits of a digits-only password, five hexadecimal letters of a short one) appears in one now and then by chance, and none is made from a source string.

Types

type Case

type Case struct {
	// Name is unique across All.
	Name string
	// Source is the string given to the command.
	Source string
	// Secrets are the literals Source holds that must never appear in an output.
	Secrets []string
	// Style says what the secret looks like ("with spaces", "digits only", ...).
	Style string
	// Position says where the secret is ("userinfo", "query", ...).
	Position string
	// Wrapped is true when Source is a URL inside another scheme's URL.
	Wrapped bool
}

Case is one source string a user could type.

func All

func All() []Case

All returns every case.

func CommandCases

func CommandCases() []Case

CommandCases returns the cases a command-level test runs: the styles that stress the readers most (spaces, an "@", digits before a slash, digits only, a plain word, a token), so the many command runs stay quick.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL