secretcheck

package
v1.2.9 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 11, 2026 License: MIT Imports: 13 Imported by: 0

Documentation

Overview

Package secretcheck is the harness of the class rule "no secret reaches an error" (docs/SPEC-CI.md, `secrets-never-in-errors`): secret-shaped inputs, a driver that hands them to a function by reflection and reads what came back, and the two-way comparisons of a reviewed table and allowlist with what a walk of the tree finds. internal/ci's TestNoSecretReachesAnError holds the rule over this repository's tree; a tree whose packages this repository cannot import (nova-sprint's) holds it with the same harness. It is test support: only tests import it.

Index

Constants

View Source
const Window = 8

Window is the substring length that counts as the secret reaching a text: eight bytes of it, anywhere.

Variables

View Source
var Shapes = func() []Shape {
	dsnPW := "pwQm4Zt9Xv2LkR7bNc5W"
	urlPW := "pwJt8Hs3Yd6FwP1gUe9A"
	kvPW := "pwVx2Kb7Mn4RtC8hLs3E"
	userPW := "pwGd5Zc9Qa1XvT6mHb2K"
	orToken := "sk-or-v1-" + "Zq7xK2mVd3Wn8Ys5Jc0Tu6Pe1Gf4Ba9Lr2Oi7Hk"
	ghToken := "ghp_" + "Fh6Rj3Ux8Cw1Nb5Ty9Ea2Lv4Mk7Sd0Pq"
	antToken := "sk-ant-api03-" + "Jw4Ct9Bn2Xs7Hy1Rk5Vd8Fe3Zm6Qa0Lg-Uo"
	return []Shape{
		{"dsn-url-unreachable", "postgres://nova:" + dsnPW + "@%2Fnowhere-nova-ci/nova", dsnPW, ""},
		{"dsn-url-malformed", "postgres://nova:" + urlPW + "@db.invalid:notaport/nova", urlPW, ""},
		{"dsn-keyword-malformed", "host=/nowhere-nova-ci user=nova port=notaport password=" + kvPW, kvPW, ""},
		{"url-userinfo", "https://" + "deploy" + ":" + userPW + "@" + "git.invalid" + "/nova.git", userPW, ""},
		{"openrouter-token", orToken, orToken, "sk-or-v1-"},
		{"github-token", ghToken, ghToken, "ghp_"},
		{"anthropic-token", antToken, antToken, "sk-ant-api03-"},
	}
}()

Shapes are the inputs. Every secret holds a marker no other shape, no message of this tree and no path shares.

Functions

func Drive

func Drive(fn any, input string) map[string]string

Drive calls fn with the input in every string parameter and zero values elsewhere, and returns the texts a leak could be in: `error`, `result` (a returned refusal value), `panic` and `log`.

func FunctionName

func FunctionName(fn any) string

FunctionName is the qualified name the runtime gives fn.

func LeakFindings

func LeakFindings(table map[string]any, shapes []Shape) map[string][]string

LeakFindings drives every function in the table with every shape and returns the functions that leak, key -> `<shape>: <where> holds "<window>"`.

func Leaks

func Leaks(secret, public string, texts map[string]string) []string

Leaks is each named text that holds an 8-byte substring of the secret, as `<where> holds "<window>"`, sorted by where.

func OpenerName

func OpenerName(name string) bool

func OpenersIn

func OpenersIn(files []File) map[string]bool

func ParseAllowlist

func ParseAllowlist(raw string) (map[string]string, []string)

ParseAllowlist reads the rows into key -> reason, naming a row with no reason.

func TableFindings

func TableFindings(found map[string]bool, table map[string]any, exempt map[string]string) []string

TableFindings compares what the tree has with the table and the exempt rows, in both directions, and checks each table value is the function its key names.

func TakesString

func TakesString(params *ast.FieldList) bool

TakesString is whether a parameter list holds a string or ...string.

func Verdict

func Verdict(leaks map[string][]string, allowed map[string]string) []string

Verdict compares the leaks with the allowlist, in both directions.

func Windows

func Windows(s, public string) []string

Windows is every 8-byte substring of s that lies after the public prefix: a token's own spelling (sk-or-v1-, ghp_) is not the secret.

Types

type File

type File struct {
	Rel      string
	AST      *ast.File
	Testdata bool
}

OpenersIn is every exported top-level function in the non-test Go of cmd/ and internal/ whose name begins Open, Parse, Dial or New and that takes a string, found by go/ast and keyed `<package directory>.<Name>`. File is one Go file of a tree: its path from the tree's root, its syntax (nil when it did not parse), and whether a directory on its path is named testdata.

type Shape

type Shape struct {
	Name   string
	Input  string
	Secret string
	Public string
}

Shape is one secret-shaped input: the string a function is handed, the secret inside it, and the public prefix of a token whose own spelling is not the secret.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL