diff --git a/pkg/detectors/jdbc/jdbc.go b/pkg/detectors/jdbc/jdbc.go index 8edb48a33..d11c22260 100644 --- a/pkg/detectors/jdbc/jdbc.go +++ b/pkg/detectors/jdbc/jdbc.go @@ -50,7 +50,7 @@ var _ detectors.Detector = (*Scanner)(nil) var _ detectors.CustomFalsePositiveChecker = (*Scanner)(nil) var ( - keyPat = regexp.MustCompile(`(?i)jdbc:[\w]{3,10}:[^\s"']{0,512}`) + keyPat = regexp.MustCompile(`(?i)jdbc:[\w]{3,10}:[^\s"'<>,(){}[\]&]{10,512}`) ) // Keywords are used for efficiently pre-filtering chunks. diff --git a/pkg/detectors/jdbc/jdbc_test.go b/pkg/detectors/jdbc/jdbc_test.go index fd1a27c5c..f05ccb64c 100644 --- a/pkg/detectors/jdbc/jdbc_test.go +++ b/pkg/detectors/jdbc/jdbc_test.go @@ -2,7 +2,6 @@ package jdbc import ( "context" - "fmt" "os" "testing" @@ -12,12 +11,6 @@ import ( "github.com/trufflesecurity/trufflehog/v3/pkg/engine/ahocorasick" ) -var ( - validPattern = "jdbc:mysql:localhost:3306/mydatabase" - invalidPattern = "jdbc:my?ql:localhost:3306/my database" - keyword = "jdbc" -) - func TestJdbc_Pattern(t *testing.T) { d := Scanner{} ahoCorasickCore := ahocorasick.NewAhoCorasickCore([]detectors.Detector{d}) @@ -27,14 +20,73 @@ func TestJdbc_Pattern(t *testing.T) { want []string }{ { - name: "valid pattern", - input: fmt.Sprintf("%s token = '%s'", keyword, validPattern), - want: []string{validPattern}, + // examples from: https://github.com/trufflesecurity/trufflehog/issues/3704 + name: "valid patterns", + input: ` + + + + + postgresql + true + org.postgresql.Driver + jdbc:postgresql://localhost:5432/postgres + jdbc:sqlserver: + jdbc:postgresql://#{uri.host}#{uri.path}?user=#{uri.user} + postgresql://postgres:postgres@:5432 + jdbc:mysql:localhost:3306/mydatabase + jdbc:sqlserver://x.x.x.x:1433;databaseName=MY-DB;user=MY-USER;password=MY-PASSWORD;encrypt=false + jdbc:sqlserver://localhost:1433;databaseName=AdventureWorks + $ProjectFileDir$ + + + + `, + want: []string{ + "jdbc:postgresql://localhost:5432/postgres", + "jdbc:mysql:localhost:3306/mydatabase", + "jdbc:sqlserver://x.x.x.x:1433;databaseName=MY-DB;user=MY-USER;password=MY-PASSWORD;encrypt=false", + "jdbc:sqlserver://localhost:1433;databaseName=AdventureWorks", + }, }, { - name: "invalid pattern", - input: fmt.Sprintf("%s = '%s'", keyword, invalidPattern), - want: []string{}, + name: "valid pattern - true positives", + input: ` + { + "detector": "jdbc", + "potential_matches": [ + "jdbc:postgresql://localhost:5432/mydb", + "jdbc:mysql://user:pass@host:3306/db?param=1", + "jdbc:sqlite:/data/test.db", + "jdbc:oracle:thin:@host:1521:db", + "jdbc:mysql://host:3306/db,other_param", + "jdbc:db2://host:50000/db?param=1" + ] + }`, + want: []string{ + "jdbc:postgresql://localhost:5432/mydb", + "jdbc:mysql://user:pass@host:3306/db?param=1", + "jdbc:sqlite:/data/test.db", + "jdbc:oracle:thin:@host:1521:db", + "jdbc:mysql://host:3306/db", + "jdbc:db2://host:50000/db?param=1", + }, + }, + { + name: "invalid pattern - false positives", + input: ` + { + "detector": "jdbc", + "false_positives": [ + "jdbc:xyz:short", + "somejdbc:mysql://host/db", + "jdbc:invalid_driver:test", + "jdbc:mysql://host/db>next", + "adjdbc:mysql://host/db", + "jdbc:my?ql:localhost:3306/my database" + ] + }`, + want: []string{}, }, }