diff --git a/pkg/detectors/alchemy/alchemy.go b/pkg/detectors/alchemy/alchemy.go index e32fd4449..eb8b12dda 100644 --- a/pkg/detectors/alchemy/alchemy.go +++ b/pkg/detectors/alchemy/alchemy.go @@ -85,15 +85,15 @@ func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, _ = res.Body.Close() }() - if res.StatusCode >= 200 && res.StatusCode < 300 { + switch res.StatusCode { + case http.StatusOK: // If the endpoint returns useful information, we can return it as a map. return true, nil, nil - } else if res.StatusCode == 401 { + case http.StatusUnauthorized: // The secret is determinately not verified (nothing to do) return false, nil, nil - } else { - err = fmt.Errorf("unexpected HTTP response status %d", res.StatusCode) - return false, nil, err + default: + return false, nil, fmt.Errorf("unexpected HTTP response status %d", res.StatusCode) } } diff --git a/pkg/detectors/ldap/ldap.go b/pkg/detectors/ldap/ldap.go index b4619fa4c..fb8ebad83 100644 --- a/pkg/detectors/ldap/ldap.go +++ b/pkg/detectors/ldap/ldap.go @@ -4,13 +4,14 @@ import ( "context" "crypto/tls" "fmt" - regexp "github.com/wasilibs/go-re2" "net" "net/url" "strings" "time" "github.com/go-ldap/ldap/v3" + regexp "github.com/wasilibs/go-re2" + "github.com/trufflesecurity/trufflehog/v3/pkg/detectors" "github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb" ) @@ -151,16 +152,17 @@ func verifyLDAP(username, password string, ldapURL *url.URL) error { return l.Bind(username, password) case "ldaps": // TLS dial - l, err := ldap.DialTLS("tcp", uri, &tls.Config{InsecureSkipVerify: true}) + l, err := ldap.DialURL(uri, ldap.DialWithTLSConfig(&tls.Config{InsecureSkipVerify: true})) if err != nil { return err } defer l.Close() // TLS verify return l.Bind(username, password) + default: + return fmt.Errorf("unknown ldap scheme %q", ldapURL.Scheme) } - return fmt.Errorf("unknown ldap scheme %q", ldapURL.Scheme) } func (s Scanner) Type() detectorspb.DetectorType {