Files
trufflehog/pkg/sources/github/connector.go
Cody Rose f26b502c2e Auth GitHub in Init (#3131)
The GitHub source currently applies its authentication configuration as the first step of enumeration. This is incompatible with both targeted scans and scan job reports, and also means that authentication logic has to be duplicated into the validation flow. This PR moves it into Init so that it's available to targeted scans and, eventually, unit-specific scans. This also allows us to remove the copy of the old logic that was in Validate.

As part of the work I've also cleaned up the integration test suite. (Several of them were apparently disabled back when they ran on every push, but now that we're not doing that, we can re-enable them.)
2024-08-05 15:13:29 -04:00

40 lines
1.3 KiB
Go

package github
import (
"fmt"
gogit "github.com/go-git/go-git/v5"
"github.com/google/go-github/v63/github"
"github.com/trufflesecurity/trufflehog/v3/pkg/context"
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/sourcespb"
)
const cloudEndpoint = "https://api.github.com"
type connector interface {
// APIClient returns a configured GitHub client that can be used for GitHub API operations.
APIClient() *github.Client
// Clone clones a repository using the configured authentication information.
Clone(ctx context.Context, repoURL string) (string, *gogit.Repository, error)
}
func newConnector(source *Source) (connector, error) {
apiEndpoint := source.conn.Endpoint
if apiEndpoint == "" || endsWithGithub.MatchString(apiEndpoint) {
apiEndpoint = cloudEndpoint
}
switch cred := source.conn.GetCredential().(type) {
case *sourcespb.GitHub_GithubApp:
return newAppConnector(apiEndpoint, cred.GithubApp)
case *sourcespb.GitHub_BasicAuth:
return newBasicAuthConnector(apiEndpoint, cred.BasicAuth)
case *sourcespb.GitHub_Token:
return newTokenConnector(apiEndpoint, cred.Token, source.handleRateLimit)
case *sourcespb.GitHub_Unauthenticated:
return newUnauthenticatedConnector(apiEndpoint)
default:
return nil, fmt.Errorf("unknown connection type")
}
}