mirror of
https://github.com/superdesigndev/treg.git
synced 2026-10-02 03:24:35 +08:00
Three CI findings, three different kinds of problem. gitleaks flagged a Fernet key hardcoded in e2e-server.sh. That one is real: it encrypts only a throwaway local e2e.db and prod reads TREG_SECRET_KEY from the environment, so the blast radius is a local database — but a committed key is a committed key. treg-dev-server hardcodes one because its database persists and a new key would orphan stored secrets; this harness deletes its database between runs, so it now generates a fresh key per run and needs no constant at all. The other two were the same fixture: a Stripe-shaped string in a test whose whole job is to prove such strings get masked. Now reuses the placeholder .gitleaks.toml already allowlists for that exact purpose, so a test about masking secrets stops tripping the secret scanner and the allowlist stops growing a line per test. CodeQL flagged the JWT alternative as polynomial on uncontrolled data, and it was right — the alternative was written for argv and round 2 moved it onto PROVIDER response bodies. Measured on 'eyJ' repeated: 1.1ms at 2KB, 4.2ms at 4KB, 17ms at 8KB — quadratic, attacker-triggerable, on the request path, once per failed call. Anchoring with \b leaves one start position instead of one every three characters, and a possessive quantifier removes backtracking within an attempt (it cannot change what matches: the class excludes '.', so the run always ends at the first one). Unmeasurable at every size after, and real JWTs still mask. Fixed in the argv rule too — same shape, same exposure. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
46 lines
2.0 KiB
Bash
Executable File
46 lines
2.0 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Start an ISOLATED e2e server for this worktree. Deliberately not `treg-dev-server`: that one
|
|
# pkills every `python -m treg`, and another session already has one running against the main
|
|
# checkout. Own port, own database, nothing shared.
|
|
set -euo pipefail
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
PORT="${PORT:-18795}"
|
|
LOG=/tmp/treg-e2e.log
|
|
|
|
case "${1:-start}" in
|
|
# Kill by PORT, not by a pattern: TREG_E2E_MARKER is an environment variable and never appears in
|
|
# argv, so `pkill -f` silently matched nothing and left an orphan holding the database open — which
|
|
# then showed up as "attempt to write a readonly database" after the file was replaced underneath it.
|
|
stop)
|
|
pids="$(lsof -ti :"$PORT" 2>/dev/null || true)"
|
|
if [ -n "$pids" ]; then kill $pids 2>/dev/null || true; sleep 2; echo "stopped ($pids)"; else echo "wasn't running"; fi
|
|
exit 0 ;;
|
|
logs) exec tail -f "$LOG"; ;;
|
|
esac
|
|
|
|
# Real provider keys, so a real upstream answers with a real error body — the whole point of e2e.
|
|
set -a; . "$HERE/.env"; set +a
|
|
|
|
# A FRESH Fernet key per run, generated here rather than written into the file. `treg-dev-server`
|
|
# hardcodes one because its database persists and a new key would orphan every stored secret; this
|
|
# harness deletes its database between runs, so it has no such need — and a committed key is a
|
|
# committed key, whatever it unlocks. (gitleaks flagged the hardcoded one, correctly.)
|
|
SECRET_KEY="$(uv run --frozen --directory "$HERE" python -c \
|
|
'from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())')"
|
|
|
|
PORT="$PORT" \
|
|
TREG_E2E_MARKER=1 \
|
|
TREG_DATABASE_URL="sqlite+aiosqlite:///$HERE/e2e.db" \
|
|
TREG_SECRET_KEY="$SECRET_KEY" \
|
|
TREG_ADMIN_TOKEN="E2E-ADMIN-TOKEN" \
|
|
nohup uv run --frozen --directory "$HERE" python -m treg > "$LOG" 2>&1 &
|
|
|
|
for _ in $(seq 1 60); do
|
|
if grep -q "Application startup complete" "$LOG" 2>/dev/null; then
|
|
echo "e2e server up on http://127.0.0.1:$PORT (db $HERE/e2e.db, log $LOG)"
|
|
exit 0
|
|
fi
|
|
sleep 1
|
|
done
|
|
echo "did not start within 60s" >&2; tail -20 "$LOG" >&2; exit 1
|