Handle no such host errors for Algolia Detector (#4264)
This commit is contained in:
@@ -3,14 +3,18 @@ package algoliaadminkey
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"slices"
|
"slices"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
|
"github.com/trufflesecurity/trufflehog/v3/pkg/cache/simple"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
|
logContext "github.com/trufflesecurity/trufflehog/v3/pkg/context"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
)
|
)
|
||||||
@@ -28,6 +32,10 @@ var (
|
|||||||
// Make sure that your group is surrounded in boundary characters such as below to reduce false positives.
|
// Make sure that your group is surrounded in boundary characters such as below to reduce false positives.
|
||||||
idPat = regexp.MustCompile(detectors.PrefixRegex([]string{"algolia", "docsearch", "appId"}) + `\b([A-Z0-9]{10})\b`)
|
idPat = regexp.MustCompile(detectors.PrefixRegex([]string{"algolia", "docsearch", "appId"}) + `\b([A-Z0-9]{10})\b`)
|
||||||
keyPat = regexp.MustCompile(detectors.PrefixRegex([]string{"algolia", "docsearch", "apiKey"}) + `\b([a-zA-Z0-9]{32})\b`)
|
keyPat = regexp.MustCompile(detectors.PrefixRegex([]string{"algolia", "docsearch", "apiKey"}) + `\b([a-zA-Z0-9]{32})\b`)
|
||||||
|
|
||||||
|
invalidHosts = simple.NewCache[struct{}]()
|
||||||
|
|
||||||
|
errNoHost = errors.New("no such host")
|
||||||
)
|
)
|
||||||
|
|
||||||
// Keywords are used for efficiently pre-filtering chunks.
|
// Keywords are used for efficiently pre-filtering chunks.
|
||||||
@@ -38,6 +46,7 @@ func (s Scanner) Keywords() []string {
|
|||||||
|
|
||||||
// FromData will find and optionally verify AlgoliaAdminKey secrets in a given set of bytes.
|
// FromData will find and optionally verify AlgoliaAdminKey secrets in a given set of bytes.
|
||||||
func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (results []detectors.Result, err error) {
|
func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (results []detectors.Result, err error) {
|
||||||
|
logger := logContext.AddLogger(ctx).Logger().WithName("algoliaadminkey")
|
||||||
dataStr := string(data)
|
dataStr := string(data)
|
||||||
|
|
||||||
// Deduplicate matches.
|
// Deduplicate matches.
|
||||||
@@ -59,6 +68,12 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
// Test matches.
|
// Test matches.
|
||||||
for key := range keyMatches {
|
for key := range keyMatches {
|
||||||
for id := range idMatches {
|
for id := range idMatches {
|
||||||
|
if invalidHosts.Exists(id) {
|
||||||
|
logger.V(3).Info("Skipping application id: no such host", "host", id)
|
||||||
|
delete(idMatches, id)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
r := detectors.Result{
|
r := detectors.Result{
|
||||||
DetectorType: detectorspb.DetectorType_AlgoliaAdminKey,
|
DetectorType: detectorspb.DetectorType_AlgoliaAdminKey,
|
||||||
Raw: []byte(key),
|
Raw: []byte(key),
|
||||||
@@ -70,8 +85,15 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
isVerified, extraData, verificationErr := verifyMatch(ctx, id, key)
|
isVerified, extraData, verificationErr := verifyMatch(ctx, id, key)
|
||||||
r.Verified = isVerified
|
r.Verified = isVerified
|
||||||
r.ExtraData = extraData
|
r.ExtraData = extraData
|
||||||
|
if verificationErr != nil {
|
||||||
|
if errors.Is(verificationErr, errNoHost) {
|
||||||
|
invalidHosts.Set(id, struct{}{})
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
|
||||||
r.SetVerificationError(verificationErr, key)
|
r.SetVerificationError(verificationErr, key)
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
results = append(results, r)
|
results = append(results, r)
|
||||||
if r.Verified {
|
if r.Verified {
|
||||||
@@ -101,6 +123,11 @@ func verifyMatch(ctx context.Context, appId, apiKey string) (bool, map[string]st
|
|||||||
|
|
||||||
res, err := client.Do(req)
|
res, err := client.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
// lookup xyz.algolia.net: no such host
|
||||||
|
if strings.Contains(err.Error(), "no such host") {
|
||||||
|
return false, nil, errNoHost
|
||||||
|
}
|
||||||
|
|
||||||
return false, nil, err
|
return false, nil, err
|
||||||
}
|
}
|
||||||
defer func() {
|
defer func() {
|
||||||
|
|||||||
Reference in New Issue
Block a user