fix(detectors/harness): allow underscore in PAT account segment (#5153)
Lint / golangci-lint (push) Waiting to run
Lint / man-page-staleness (push) Waiting to run
Lint / semgrep (push) Waiting to run
Lint / checksecretparts (push) Waiting to run
Scan for secrets / test (push) Waiting to run
Test / test (push) Waiting to run
Test / test-community (push) Waiting to run
Release / mark-latest (push) Canceled after 0s
Release / Release (push) Canceled after 0s
Lint / golangci-lint (push) Waiting to run
Lint / man-page-staleness (push) Waiting to run
Lint / semgrep (push) Waiting to run
Lint / checksecretparts (push) Waiting to run
Scan for secrets / test (push) Waiting to run
Test / test (push) Waiting to run
Test / test-community (push) Waiting to run
Release / mark-latest (push) Canceled after 0s
Release / Release (push) Canceled after 0s
Harness PAT tokens can include underscores in the 22-character account segment; widen the detector regex so live keys are found during scans. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
@@ -32,7 +32,7 @@ var _ detectors.Detector = (*Scanner)(nil)
|
|||||||
var (
|
var (
|
||||||
defaultClient = common.SaneHttpClient()
|
defaultClient = common.SaneHttpClient()
|
||||||
|
|
||||||
keyPat = regexp.MustCompile(detectors.PrefixRegex([]string{"harness"}) + `\b(pat\.[A-Za-z0-9]{22}\.[0-9a-f]{24}\.[A-Za-z0-9]{20})\b`)
|
keyPat = regexp.MustCompile(detectors.PrefixRegex([]string{"harness"}) + `\b(pat\.[A-Za-z0-9_]{22}\.[0-9a-f]{24}\.[A-Za-z0-9]{20})\b`)
|
||||||
)
|
)
|
||||||
|
|
||||||
func (s Scanner) getClient() *http.Client {
|
func (s Scanner) getClient() *http.Client {
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import (
|
|||||||
|
|
||||||
var (
|
var (
|
||||||
validKey = "pat.4oXWHvYFRNOGLVpFTZGGTA.68077fc826afe36865614d58.2fFEmr57WO3zPmev3jze"
|
validKey = "pat.4oXWHvYFRNOGLVpFTZGGTA.68077fc826afe36865614d58.2fFEmr57WO3zPmev3jze"
|
||||||
|
validKeyWithUnderscore = "pat.YDfcEm2LT_OUZrFZv1WVlg.6a4f91eb79dfb04b036caf48.FrDL8MGzpMygCMzZv1Kq"
|
||||||
validKeyWithoutKeyword = `API Key Token: pat.4oXWHvYFRNOGLVpFTZGGTA.68077fc826afe36865614d58.2fFEmr57WO3zPmev3jze
|
validKeyWithoutKeyword = `API Key Token: pat.4oXWHvYFRNOGLVpFTZGGTA.68077fc826afe36865614d58.2fFEmr57WO3zPmev3jze
|
||||||
url |https://api.harness.io/`
|
url |https://api.harness.io/`
|
||||||
invalidKey = "pat.4oXWHvYFRNOGLVpFTZGGTA.6807c5bed9599c324f6368ce.usCT2fzvADwSoXzXc"
|
invalidKey = "pat.4oXWHvYFRNOGLVpFTZGGTA.6807c5bed9599c324f6368ce.usCT2fzvADwSoXzXc"
|
||||||
@@ -31,6 +32,11 @@ func TestHarness_Pattern(t *testing.T) {
|
|||||||
input: fmt.Sprintf("%s token = '%s'", keyword, validKey),
|
input: fmt.Sprintf("%s token = '%s'", keyword, validKey),
|
||||||
want: []string{validKey},
|
want: []string{validKey},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "valid pattern with underscore in account segment",
|
||||||
|
input: fmt.Sprintf("%s = '%s'", keyword, validKeyWithUnderscore),
|
||||||
|
want: []string{validKeyWithUnderscore},
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: "valid pattern - no keyword",
|
name: "valid pattern - no keyword",
|
||||||
input: fmt.Sprintf("token = '%s'", validKeyWithoutKeyword),
|
input: fmt.Sprintf("token = '%s'", validKeyWithoutKeyword),
|
||||||
|
|||||||
Reference in New Issue
Block a user