Documentation
¶
Overview ¶
Package secretcheck is the harness of the class rule "no secret reaches an error" (docs/SPEC-CI.md, `secrets-never-in-errors`): secret-shaped inputs, a driver that hands them to a function by reflection and reads what came back, and the two-way comparisons of a reviewed table and allowlist with what a walk of the tree finds. internal/ci's TestNoSecretReachesAnError holds the rule over this repository's tree; a tree whose packages this repository cannot import (nova-sprint's) holds it with the same harness. It is test support: only tests import it.
Index ¶
- Constants
- Variables
- func Drive(fn any, input string) map[string]string
- func FunctionName(fn any) string
- func LeakFindings(table map[string]any, shapes []Shape) map[string][]string
- func Leaks(secret, public string, texts map[string]string) []string
- func OpenerName(name string) bool
- func OpenersIn(files []File) map[string]bool
- func ParseAllowlist(raw string) (map[string]string, []string)
- func TableFindings(found map[string]bool, table map[string]any, exempt map[string]string) []string
- func TakesString(params *ast.FieldList) bool
- func Verdict(leaks map[string][]string, allowed map[string]string) []string
- func Windows(s, public string) []string
- type File
- type Shape
Constants ¶
const Window = 8
Window is the substring length that counts as the secret reaching a text: eight bytes of it, anywhere.
Variables ¶
var Shapes = func() []Shape { dsnPW := "pwQm4Zt9Xv2LkR7bNc5W" urlPW := "pwJt8Hs3Yd6FwP1gUe9A" kvPW := "pwVx2Kb7Mn4RtC8hLs3E" userPW := "pwGd5Zc9Qa1XvT6mHb2K" orToken := "sk-or-v1-" + "Zq7xK2mVd3Wn8Ys5Jc0Tu6Pe1Gf4Ba9Lr2Oi7Hk" ghToken := "ghp_" + "Fh6Rj3Ux8Cw1Nb5Ty9Ea2Lv4Mk7Sd0Pq" antToken := "sk-ant-api03-" + "Jw4Ct9Bn2Xs7Hy1Rk5Vd8Fe3Zm6Qa0Lg-Uo" return []Shape{ {"dsn-url-unreachable", "postgres://nova:" + dsnPW + "@%2Fnowhere-nova-ci/nova", dsnPW, ""}, {"dsn-url-malformed", "postgres://nova:" + urlPW + "@db.invalid:notaport/nova", urlPW, ""}, {"dsn-keyword-malformed", "host=/nowhere-nova-ci user=nova port=notaport password=" + kvPW, kvPW, ""}, {"url-userinfo", "https://" + "deploy" + ":" + userPW + "@" + "git.invalid" + "/nova.git", userPW, ""}, {"openrouter-token", orToken, orToken, "sk-or-v1-"}, {"github-token", ghToken, ghToken, "ghp_"}, {"anthropic-token", antToken, antToken, "sk-ant-api03-"}, } }()
Shapes are the inputs. Every secret holds a marker no other shape, no message of this tree and no path shares.
Functions ¶
func Drive ¶
Drive calls fn with the input in every string parameter and zero values elsewhere, and returns the texts a leak could be in: `error`, `result` (a returned refusal value), `panic` and `log`.
func FunctionName ¶
FunctionName is the qualified name the runtime gives fn.
func LeakFindings ¶
LeakFindings drives every function in the table with every shape and returns the functions that leak, key -> `<shape>: <where> holds "<window>"`.
func Leaks ¶
Leaks is each named text that holds an 8-byte substring of the secret, as `<where> holds "<window>"`, sorted by where.
func OpenerName ¶
func ParseAllowlist ¶
ParseAllowlist reads the rows into key -> reason, naming a row with no reason.
func TableFindings ¶
TableFindings compares what the tree has with the table and the exempt rows, in both directions, and checks each table value is the function its key names.
func TakesString ¶
TakesString is whether a parameter list holds a string or ...string.
Types ¶
type File ¶
OpenersIn is every exported top-level function in the non-test Go of cmd/ and internal/ whose name begins Open, Parse, Dial or New and that takes a string, found by go/ast and keyed `<package directory>.<Name>`. File is one Go file of a tree: its path from the tree's root, its syntax (nil when it did not parse), and whether a directory on its path is named testdata.