Files
trufflehog/pkg/detectors/klaviyo/klaviyo.go
Bri TanandCursor cc90719407 Updating Klaviyo PK new format (#5009)
* updating Klaviyo PK new format

* update Klaviyo test to use valid hex key pattern

The regex was tightened to match hex-only keys, so the test's
validPattern is updated to a valid 34-character hex string.

Co-authored-by: Cursor <[email protected]>

* add test coverage for new Klaviyo key format

Adds a validPatternNew case exercising the pk_XXXXXX_<hex> format
introduced by the regex change.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-06-09 10:13:16 -04:00

119 lines
3.5 KiB
Go

package klaviyo
import (
"context"
"encoding/json"
"fmt"
"net/http"
"strings"
regexp "github.com/wasilibs/go-re2"
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detector_typepb"
)
type Scanner struct {
client *http.Client
}
// Ensure the Scanner satisfies the interface at compile time.
var _ detectors.Detector = (*Scanner)(nil)
var (
defaultClient = common.SaneHttpClient()
// Make sure that your group is surrounded in boundary characters such as below to reduce false positives.
keyPat = regexp.MustCompile(`\b(pk_([0-9a-f]{34}|[A-Za-z0-9]{6}_[0-9a-f]{34}))\b`)
)
// Keywords are used for efficiently pre-filtering chunks.
// Use identifiers in the secret preferably, or the provider name.
func (s Scanner) Keywords() []string {
return []string{"pk_"}
}
type response struct {
Errors []struct {
Id string `json:"id"`
Status int `json:"status"`
Code string `json:"code"`
Title string `json:"title"`
Detail string `json:"detail"`
Source struct {
Pointer string `json:"pointer"`
} `json:"source"`
} `json:"errors"`
}
// FromData will find and optionally verify Klaviyo secrets in a given set of bytes.
func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (results []detectors.Result, err error) {
dataStr := string(data)
matches := keyPat.FindAllStringSubmatch(dataStr, -1)
for _, match := range matches {
resMatch := strings.TrimSpace(match[1])
s1 := detectors.Result{
DetectorType: detector_typepb.DetectorType_Klaviyo,
Raw: []byte(resMatch),
SecretParts: map[string]string{"key": resMatch},
}
if verify {
client := s.client
if client == nil {
client = defaultClient
}
req, err := http.NewRequestWithContext(ctx, "GET", "https://a.klaviyo.com/api/profiles", nil)
if err != nil {
continue
}
req.Header.Set("Revision", "2023-02-22")
req.Header.Set("Authorization", "Klaviyo-API-Key "+resMatch)
res, err := client.Do(req)
if err == nil {
defer func() { _ = res.Body.Close() }()
if res.StatusCode >= 200 && res.StatusCode < 300 {
s1.Verified = true
} else if res.StatusCode == 403 {
var apiResp response
// Klaviyo responds with 403 when the API-key does not have permissions to hit /api/profiles.
// Ensure that the 403 is from Klaviyo: https://developers.klaviyo.com/en/docs/rate_limits_and_error_handling
if err = json.NewDecoder(res.Body).Decode(&apiResp); err == nil {
// valid JSON response
if len(apiResp.Errors) > 0 {
// Thus, the key is verified, but it is up to the user to determine what scopes the key has.
s1.Verified = true
} else {
s1.SetVerificationError(fmt.Errorf("errors expected"), resMatch)
}
} else {
s1.SetVerificationError(fmt.Errorf("unexpected API JSON response"), resMatch)
}
} else if res.StatusCode == 401 {
// The secret is determinately not verified (nothing to do)
} else {
err = fmt.Errorf("unexpected HTTP response status %d", res.StatusCode)
s1.SetVerificationError(err, resMatch)
}
} else {
s1.SetVerificationError(err, resMatch)
}
}
results = append(results, s1)
}
return results, nil
}
func (s Scanner) Type() detector_typepb.DetectorType {
return detector_typepb.DetectorType_Klaviyo
}
func (s Scanner) Description() string {
return "Klaviyo is a marketing automation platform. Klaviyo API keys can be used to access and modify marketing data and configurations."
}