Reject invalid secret names before any command builds a path (closes #33)
check / check (push) Successful in 49s
check / check (push) Successful in 49s
`secret rm ..` resolved to the vault directory and deleted the whole vault; `secret rm .` and `secret rm ""` deleted every secret. rm, mv, the version commands, encrypt and decrypt built paths from the name without checking it; import checked it only after reading the source file. vault.ValidateSecretName wraps the existing name rule; its error and README.md state the rule. Each of those commands calls it on the name as given, before building any path; MoveSecret checks both names once, for every form of the move, before switching the current vault. AddSecret, GetSecretVersion and GetSecretObject use it too. The regression test copies two in-memory vaults for each rejected command and requires the exact error and an unchanged state directory. Model: opus-5-5
This commit is contained in:
@@ -25,6 +25,13 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-03: Every command that builds a path from a secret name
|
||||
checks the name first with `vault.ValidateSecretName` and touches
|
||||
nothing when it is invalid: `rm`, `mv` (both names, within a vault
|
||||
and between vaults, before switching the current vault), `import`,
|
||||
`version list`/`promote`/`rm`, `encrypt` and `decrypt`. The error
|
||||
and `README.md` state the naming rule. Before, `secret rm ..` deleted the whole
|
||||
vault and `secret rm .` every secret in it.
|
||||
- 2026-10-02: A plain `docker build .` builds again: the size tests
|
||||
skip a case that needs more locked memory than the process can
|
||||
lock, and run every case under `script/cibuild`. The image stamps the
|
||||
@@ -96,8 +103,7 @@ Bring the repo into policy compliance in one commit:
|
||||
buffer.Bytes() to GPGEncryptFunc and EncryptWithPassphrase.
|
||||
- Race conditions: no file locking in vault/secrets.go:142-176;
|
||||
non-atomic writes can leave the vault inconsistent.
|
||||
- Input validation: dots in secret names risk path traversal
|
||||
(vault/secrets.go:75-99); no maximum secret size (DoS).
|
||||
- Input validation: no maximum secret size (DoS).
|
||||
- Timing attacks: bytes.Equal passphrase compare (cli/init.go:
|
||||
209-216); non-constant-time public key compare (vault.go:95-100).
|
||||
- High priority:
|
||||
|
||||
Reference in New Issue
Block a user