package nvapi import ( "context" "fmt" "io" "net/http" "net/url" "strings" regexp "github.com/wasilibs/go-re2" "github.com/trufflesecurity/trufflehog/v3/pkg/common" "github.com/trufflesecurity/trufflehog/v3/pkg/detectors" "github.com/trufflesecurity/trufflehog/v3/pkg/pb/detector_typepb" ) type Scanner struct { client *http.Client } // Ensure the Scanner satisfies the interface at compile time. var _ detectors.Detector = (*Scanner)(nil) var ( defaultClient = common.SaneHttpClient() // Make sure that your group is surrounded in boundary characters such as below to reduce false positives. keyPat = regexp.MustCompile(`\b(nvapi-[a-zA-Z0-9_-]{64})\b`) ) // Keywords are used for efficiently pre-filtering chunks. // Use identifiers in the secret preferably, or the provider name. func (s Scanner) Keywords() []string { return []string{"nvapi-"} } // FromData will find and optionally verify Nvapi secrets in a given set of bytes. func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (results []detectors.Result, err error) { dataStr := string(data) uniqueMatches := make(map[string]struct{}) for _, match := range keyPat.FindAllStringSubmatch(dataStr, -1) { uniqueMatches[match[1]] = struct{}{} } for match := range uniqueMatches { s1 := detectors.Result{ DetectorType: detector_typepb.DetectorType_NVAPI, Raw: []byte(match), SecretParts: map[string]string{"key": match}, } if verify { client := s.client if client == nil { client = defaultClient } isVerified, extraData, verificationErr := verifyMatch(ctx, client, match) s1.Verified = isVerified s1.ExtraData = extraData s1.SetVerificationError(verificationErr, match) } results = append(results, s1) } return } func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, map[string]string, error) { data := url.Values{} data.Set("credentials", token) req, err := http.NewRequestWithContext(ctx, http.MethodPost, "https://api.ngc.nvidia.com/v3/keys/get-caller-info", strings.NewReader(data.Encode())) if err != nil { return false, nil, err } req.Header.Add("Content-Type", "application/x-www-form-urlencoded") res, err := client.Do(req) if err != nil { return false, nil, err } defer func() { _, _ = io.Copy(io.Discard, res.Body) _ = res.Body.Close() }() switch res.StatusCode { case http.StatusOK: // If the endpoint returns useful information, we can return it as a map. return true, nil, nil case http.StatusUnauthorized: // The secret is determinately not verified (nothing to do) return false, nil, nil default: return false, nil, fmt.Errorf("unexpected HTTP response status %d", res.StatusCode) } } func (s Scanner) Type() detector_typepb.DetectorType { return detector_typepb.DetectorType_NVAPI } func (s Scanner) Description() string { return "NVAPI keys are used to authenticate API requests to NVIDIA's NGC API. They allow access to NVIDIA's NGC API to manage user data and perform actions on behalf of users." }