fix adjacent creds

This commit is contained in:
Cody Rose
2024-01-12 14:20:12 -05:00
parent dd0ca2f93f
commit 9eb4e735b3
2 changed files with 36 additions and 30 deletions
+7 -7
View File
@@ -36,8 +36,7 @@ func (s Scanner) Keywords() []string {
func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) ([]detectors.Result, error) {
var results []detectors.Result
var pgURLs []url.URL
pgURLs = append(pgURLs, findUriMatches(string(data)))
pgURLs := findUriMatches(string(data))
pgURLs = append(pgURLs, findComponentMatches(verify, string(data))...)
for _, pgURL := range pgURLs {
@@ -80,18 +79,19 @@ func getDeadlineInSeconds(ctx context.Context) int {
return int(duration.Seconds())
}
func findUriMatches(dataStr string) url.URL {
var pgURL url.URL
for _, uri := range uriPattern.FindAllString(dataStr, -1) {
func findUriMatches(dataStr string) []url.URL {
var results []url.URL
all := uriPattern.FindAllString(dataStr, -1)
for _, uri := range all {
pgURL, err := url.Parse(uri)
if err != nil {
continue
}
if pgURL.User != nil {
return *pgURL
results = append(results, *pgURL)
}
}
return pgURL
return results
}
// check if postgres is running
+29 -23
View File
@@ -98,29 +98,6 @@ func TestPostgres_FromChunk(t *testing.T) {
},
wantErr: false,
},
{
name: "found with single line credentials next to invalid credentials, verified",
s: Scanner{},
args: func() args {
ctx, cancel := context.WithTimeout(context.Background(), 3*time.Second)
defer cancel()
return args{
ctx: ctx,
data: []byte(fmt.Sprintf(`
postgresql://user:[email protected]:5432/mydb?sslmode=disable
postgresql://%s:%s@%s:%s/postgres`,
postgresUser, postgresPass, postgresHost, postgresPort)),
verify: true,
}
}(),
want: []detectors.Result{
{
DetectorType: detectorspb.DetectorType_Postgres,
Verified: true,
},
},
wantErr: false,
},
{
name: "found with json credentials, verified",
s: Scanner{},
@@ -268,6 +245,35 @@ func TestPostgres_FromChunk(t *testing.T) {
}(),
wantErr: false,
},
{
name: "verified credentials next to bad host credentials",
s: Scanner{},
args: func() args {
ctx, cancel := context.WithTimeout(context.Background(), 3*time.Second)
defer cancel()
return args{
ctx: ctx,
data: []byte(fmt.Sprintf(`
postgresql://user:[email protected]:5432/mydb?sslmode=disable
postgresql://%s:%s@%s:%s/postgres`,
postgresUser, postgresPass, postgresHost, postgresPort)),
verify: true,
}
}(),
want: func() []detectors.Result {
first := detectors.Result{
DetectorType: detectorspb.DetectorType_Postgres,
Verified: false,
}
first.SetVerificationError(errors.New("i/o timeout"))
second := detectors.Result{
DetectorType: detectorspb.DetectorType_Postgres,
Verified: true,
}
return []detectors.Result{first, second}
}(),
wantErr: false,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {