fix(detectors/posthog): widen phx_ key body to {43,48} (#5133)

PostHog personal API keys now use a 48-char body (52 total with phx_),
while the detector only matched the legacy 43-char body (47 total).
Widen the regex to {43,48} and add a 48-char pattern test case.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
matt
2026-07-23 12:17:18 -04:00
committed by GitHub
co-authored by Cursor
parent a2ef4f51a5
commit 05a583290b
2 changed files with 7 additions and 1 deletions
+1 -1
View File
@@ -21,7 +21,7 @@ var (
client = common.SaneHttpClient()
// Make sure that your group is surrounded in boundary characters such as below to reduce false positives.
keyPat = regexp.MustCompile(`\b(phx_[a-zA-Z0-9_]{43})\b`)
keyPat = regexp.MustCompile(`\b(phx_[a-zA-Z0-9_]{43,48})\b`)
)
// Keywords are used for efficiently pre-filtering chunks.
+6
View File
@@ -13,6 +13,7 @@ import (
var (
validPattern = "phx_C1rP9fnAtEFJvb0IYCFdeQhar2WdwUFBYHJym1F_Zqr"
validPattern48 = "phx_C1rP9fnAtEFJvb0IYCFdeQhar2WdwUFBYHJym1F_ZqrAbcde"
invalidPattern = "phx_C1rP9fnAtEFJvb0IYCF?eQhar2WdwUFBYHJym1F_Zqr"
keyword = "posthog"
)
@@ -30,6 +31,11 @@ func TestAppPosthog_Pattern(t *testing.T) {
input: fmt.Sprintf("%s token = '%s'", keyword, validPattern),
want: []string{validPattern},
},
{
name: "valid pattern 48 chars - with keyword posthog",
input: fmt.Sprintf("%s token = '%s'", keyword, validPattern48),
want: []string{validPattern48},
},
{
name: "invalid pattern",
input: fmt.Sprintf("%s = '%s'", keyword, invalidPattern),