fix(validation): name the keys in the shared-secret failure
The duplicate-value check strips quotes off the value, then looked the keys back up with grep -F "=$value" while the file stores ="$value" — so the lookup never matched and the failure read "these keys share one value: — a secret should never be reused", naming nothing. A failure report that cannot tell you which keys collided is barely better than no check. Found while confirming the check still holds now that configBackfillAllApps (741edfd) resolves RANDOMIZED<n> during an update as well as an install, which gives a shared placeholder a second way to reach a deployed config. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
998deddb5d
commit
3ed912b5ed
@ -102,12 +102,16 @@ _lpvCheckDeployedSecrets()
|
|||||||
# Two different keys holding one value is what a shared placeholder looks
|
# Two different keys holding one value is what a shared placeholder looks
|
||||||
# like after substitution. Short values are skipped: "true", "admin" and
|
# like after substitution. Short values are skipped: "true", "admin" and
|
||||||
# friends repeat legitimately.
|
# friends repeat legitimately.
|
||||||
|
# The value arrives here unquoted (the sed/tr below strip them) while the
|
||||||
|
# file stores it quoted, so the key lookup has to put the quotes back —
|
||||||
|
# grepping for =<value> against ="<value>" matches nothing and the message
|
||||||
|
# names no keys, which is worse than useless in a failure report.
|
||||||
local v
|
local v
|
||||||
while IFS= read -r v; do
|
while IFS= read -r v; do
|
||||||
[[ ${#v} -ge 12 ]] || continue
|
[[ ${#v} -ge 12 ]] || continue
|
||||||
local keys
|
local keys
|
||||||
keys=$(grep -F "=$v" "$file" | cut -d= -f1 | tr '\n' ' ')
|
keys=$(grep -F "=\"$v\"" "$file" | cut -d= -f1 | tr '\n' ' ')
|
||||||
_lpvFail "$app: these keys share one value: ${keys}— a secret should never be reused."
|
_lpvFail "$app: ${keys}share one value — a generated secret should never be reused."
|
||||||
done < <(grep -oE '^CFG_[A-Z0-9_]+="[^"]{12,}"$' "$file" \
|
done < <(grep -oE '^CFG_[A-Z0-9_]+="[^"]{12,}"$' "$file" \
|
||||||
| sed 's/^[^=]*=//' | tr -d '"' | sort | uniq -d)
|
| sed 's/^[^=]*=//' | tr -d '"' | sort | uniq -d)
|
||||||
}
|
}
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user