Files
treg/e2e-server.sh
Jason ZhouandClaude Opus 5 3e902adf78 fix(ci): stop committing a real key, and make the JWT rule linear on provider data
Three CI findings, three different kinds of problem.

gitleaks flagged a Fernet key hardcoded in e2e-server.sh. That one is real: it
encrypts only a throwaway local e2e.db and prod reads TREG_SECRET_KEY from the
environment, so the blast radius is a local database — but a committed key is a
committed key. treg-dev-server hardcodes one because its database persists and a
new key would orphan stored secrets; this harness deletes its database between
runs, so it now generates a fresh key per run and needs no constant at all.

The other two were the same fixture: a Stripe-shaped string in a test whose whole
job is to prove such strings get masked. Now reuses the placeholder .gitleaks.toml
already allowlists for that exact purpose, so a test about masking secrets stops
tripping the secret scanner and the allowlist stops growing a line per test.

CodeQL flagged the JWT alternative as polynomial on uncontrolled data, and it was
right — the alternative was written for argv and round 2 moved it onto PROVIDER
response bodies. Measured on 'eyJ' repeated: 1.1ms at 2KB, 4.2ms at 4KB, 17ms at
8KB — quadratic, attacker-triggerable, on the request path, once per failed call.
Anchoring with \b leaves one start position instead of one every three characters,
and a possessive quantifier removes backtracking within an attempt (it cannot
change what matches: the class excludes '.', so the run always ends at the first
one). Unmeasurable at every size after, and real JWTs still mask. Fixed in the argv
rule too — same shape, same exposure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-17 19:39:57 +10:00

46 lines
2.0 KiB
Bash
Executable File

#!/usr/bin/env bash
# Start an ISOLATED e2e server for this worktree. Deliberately not `treg-dev-server`: that one
# pkills every `python -m treg`, and another session already has one running against the main
# checkout. Own port, own database, nothing shared.
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
PORT="${PORT:-18795}"
LOG=/tmp/treg-e2e.log
case "${1:-start}" in
# Kill by PORT, not by a pattern: TREG_E2E_MARKER is an environment variable and never appears in
# argv, so `pkill -f` silently matched nothing and left an orphan holding the database open — which
# then showed up as "attempt to write a readonly database" after the file was replaced underneath it.
stop)
pids="$(lsof -ti :"$PORT" 2>/dev/null || true)"
if [ -n "$pids" ]; then kill $pids 2>/dev/null || true; sleep 2; echo "stopped ($pids)"; else echo "wasn't running"; fi
exit 0 ;;
logs) exec tail -f "$LOG"; ;;
esac
# Real provider keys, so a real upstream answers with a real error body — the whole point of e2e.
set -a; . "$HERE/.env"; set +a
# A FRESH Fernet key per run, generated here rather than written into the file. `treg-dev-server`
# hardcodes one because its database persists and a new key would orphan every stored secret; this
# harness deletes its database between runs, so it has no such need — and a committed key is a
# committed key, whatever it unlocks. (gitleaks flagged the hardcoded one, correctly.)
SECRET_KEY="$(uv run --frozen --directory "$HERE" python -c \
'from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())')"
PORT="$PORT" \
TREG_E2E_MARKER=1 \
TREG_DATABASE_URL="sqlite+aiosqlite:///$HERE/e2e.db" \
TREG_SECRET_KEY="$SECRET_KEY" \
TREG_ADMIN_TOKEN="E2E-ADMIN-TOKEN" \
nohup uv run --frozen --directory "$HERE" python -m treg > "$LOG" 2>&1 &
for _ in $(seq 1 60); do
if grep -q "Application startup complete" "$LOG" 2>/dev/null; then
echo "e2e server up on http://127.0.0.1:$PORT (db $HERE/e2e.db, log $LOG)"
exit 0
fi
sleep 1
done
echo "did not start within 60s" >&2; tail -20 "$LOG" >&2; exit 1