secret

package
v1.49.63 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 4, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package secret recognizes strings that are credentials rather than identifiers.

It exists so that exactly one list of credential markers backs every guard in the system: the Go check on the provisioning path (models/organization), and the SQL backstop trigger below the ORM (db). A credential caught by one gate but not the other is the bug this package is shaped to prevent — so the SQL is generated from these same values rather than written twice.

Index

Constants

This section is empty.

Variables

View Source
var Blank = []rune{
	0x00A0,
	0x00AD,
	0x180E,
	0x200B,
	0x200C,
	0x200D,
	0x200E,
	0x200F,
	0x2028,
	0x2029,
	0x202F,
	0x205F,
	0x2060,
	0x3000,
	0xFEFF,
}

Blank are runes stripped before matching. They carry no identifier meaning but do break a naive prefix test: a zero-width space or a BOM in front of "sk-" defeats an anchored match, and a non-breaking space is not removed by trimming in SQL (Postgres btrim strips ASCII space only). They are removed everywhere in the string, not just at the ends, so an interior insertion cannot split a marker either.

Written as escapes, never as literals: these runes are invisible, and source that renders identically to different bytes cannot be reviewed.

Stripping is used only to decide; the original string is never rewritten.

View Source
var Prefixes = []string{

	"sk-",
	"hk-",

	"sk_",
	"pk_",
	"rk_",
	"whsec_",

	"bearer ",

	"eyj",
}

Prefixes are the markers that identify a string as a credential rather than an organization slug. Matching is on the normalized form (see Normalize), so each entry is lowercase.

Membership is decided by SHAPE, never by whether a marker still opens a door. These values arrive on the untrusted X-Org-Id header, and one that is not refused is persisted as a tenant row — a credential-shaped string in plaintext, plus one Organization per distinct value. Stripe's pk_ is publishable and authenticates nothing; it is on the list for that reason alone, and a marker is dropped only when no such string can still be typed.

Real org identifiers are slugs ("hanzo", "adnexus"), UUIDs, or numeric ids. Matching is prefix-based and every marker ends in a separator ("-", "_", " ") that a slug cannot contain, so no real name collides: "skunkworks" and "hkust" do not start with "sk-"/"hk-". The lone exception is "eyj", the base64 of a JWT header '{"' — a bare token pasted as a tenant.

Functions

func Like

func Like(name string) bool

Like reports whether name is a credential rather than an organization identifier.

Any code that provisions a tenant from an untrusted, gateway-supplied name MUST reject these first: otherwise a caller who presents a raw key as their bearer causes the key to be persisted as an org name and tenant id, leaking the secret into the datastore (incident 2026-07-02).

func Normalize

func Normalize(name string) string

Normalize reduces a name to the form the markers are matched against: Blank runes removed, surrounding whitespace trimmed, lowercased.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL