fix(detectors/posthog): widen phx_ key body to {43,48} (#5133)
PostHog personal API keys now use a 48-char body (52 total with phx_),
while the detector only matched the legacy 43-char body (47 total).
Widen the regex to {43,48} and add a 48-char pattern test case.
Co-authored-by: Cursor <[email protected]>
This commit is contained in:
@@ -21,7 +21,7 @@ var (
|
||||
client = common.SaneHttpClient()
|
||||
|
||||
// Make sure that your group is surrounded in boundary characters such as below to reduce false positives.
|
||||
keyPat = regexp.MustCompile(`\b(phx_[a-zA-Z0-9_]{43})\b`)
|
||||
keyPat = regexp.MustCompile(`\b(phx_[a-zA-Z0-9_]{43,48})\b`)
|
||||
)
|
||||
|
||||
// Keywords are used for efficiently pre-filtering chunks.
|
||||
|
||||
@@ -13,6 +13,7 @@ import (
|
||||
|
||||
var (
|
||||
validPattern = "phx_C1rP9fnAtEFJvb0IYCFdeQhar2WdwUFBYHJym1F_Zqr"
|
||||
validPattern48 = "phx_C1rP9fnAtEFJvb0IYCFdeQhar2WdwUFBYHJym1F_ZqrAbcde"
|
||||
invalidPattern = "phx_C1rP9fnAtEFJvb0IYCF?eQhar2WdwUFBYHJym1F_Zqr"
|
||||
keyword = "posthog"
|
||||
)
|
||||
@@ -30,6 +31,11 @@ func TestAppPosthog_Pattern(t *testing.T) {
|
||||
input: fmt.Sprintf("%s token = '%s'", keyword, validPattern),
|
||||
want: []string{validPattern},
|
||||
},
|
||||
{
|
||||
name: "valid pattern 48 chars - with keyword posthog",
|
||||
input: fmt.Sprintf("%s token = '%s'", keyword, validPattern48),
|
||||
want: []string{validPattern48},
|
||||
},
|
||||
{
|
||||
name: "invalid pattern",
|
||||
input: fmt.Sprintf("%s = '%s'", keyword, invalidPattern),
|
||||
|
||||
Reference in New Issue
Block a user