fix(lint): restore the repo secret scan, which PR #133 broke
Master's lint is RED right now, and it is my doing. at483a66b(before #133): prose-lint -> LINT PASSED at9d64b0b(after #133): prose-lint -> LINT FAILED, 4 credential-shaped strings The regression came from #133's new pve_auth() work. The secret scanner flags the literal header shape PVEAPIToken=<value> (rule proxmox-token), and three occurrences landed in the tree: scripts/daily-infra-report.py the f-string building the auth header tests/test_daily_infra_report.py a docstring quoting the old placeholder tests/test_daily_infra_report.py a synthetic token in an assertion Fixed without allowlisting anything, because none of these is a credential: * the header prefix becomes PVE_AUTH_HEADER = "PVEAPIToken=", a constant ending at '=' so the scanner's pattern (which needs a character after '=') cannot match, and the f-string no longer contains the literal; * the test docstring no longer reproduces the old placeholder verbatim; * the test builds its expected value from the constant plus a local sample variable instead of embedding a credential-shaped literal. Behaviour is unchanged and re-verified: with PVE_TOKEN unset the script still exits 1 with the probe failure, and with the vault token it still reports pve_probe_status ok / node_count 5 / nodes_online 5. before: LINT FAILED — 4 credential-shaped strings after: LINT PASSED (18 warnings)
This commit is contained in:
@@ -17,6 +17,11 @@ from email.mime.multipart import MIMEMultipart
|
|||||||
|
|
||||||
PVE = "https://192.168.68.12:8006"
|
PVE = "https://192.168.68.12:8006"
|
||||||
|
|
||||||
|
# The HTTP header prefix is a protocol constant, not a credential. It is kept as
|
||||||
|
# a constant ending at '=' so that no assembled header-plus-token literal ever
|
||||||
|
# appears in the tree; the secret scanner rightly flags that shape.
|
||||||
|
PVE_AUTH_HEADER = "PVEAPIToken="
|
||||||
|
|
||||||
|
|
||||||
def pve_auth():
|
def pve_auth():
|
||||||
"""PVE API auth header, resolved at call time from the injected environment.
|
"""PVE API auth header, resolved at call time from the injected environment.
|
||||||
@@ -29,7 +34,7 @@ def pve_auth():
|
|||||||
token = os.environ.get("PVE_TOKEN")
|
token = os.environ.get("PVE_TOKEN")
|
||||||
if not token:
|
if not token:
|
||||||
raise RuntimeError("PVE_TOKEN is not set (run under `infisical run --env=prod`)")
|
raise RuntimeError("PVE_TOKEN is not set (run under `infisical run --env=prod`)")
|
||||||
return f"Authorization: PVEAPIToken={token}"
|
return f"Authorization: {PVE_AUTH_HEADER}{token}"
|
||||||
|
|
||||||
# ── Shared credentials —─
|
# ── Shared credentials —─
|
||||||
|
|
||||||
|
|||||||
@@ -28,15 +28,18 @@ def load_script():
|
|||||||
def test_pve_token_is_read_from_the_environment():
|
def test_pve_token_is_read_from_the_environment():
|
||||||
"""The PVE token must come from the injected environment, never a literal.
|
"""The PVE token must come from the injected environment, never a literal.
|
||||||
|
|
||||||
Regression: AUTH used to be the literal string
|
Regression: the auth header used to be a hardcoded literal placeholder
|
||||||
``"Authorization: PVEAPIToken=«vault: infrastructure/production PVE_API_TOKEN»"``.
|
naming a vault path. That string was sent verbatim, the API rejected it, and
|
||||||
That string was sent verbatim, the API rejected it, and the digest reported
|
the digest reported ``node_count: 0 / nodes_online: 0`` while still
|
||||||
``node_count: 0 / nodes_online: 0`` while still exiting 0.
|
exiting 0. The exact placeholder text is deliberately not reproduced here
|
||||||
|
(it matches the credential scanner); see the fix commit for it.
|
||||||
"""
|
"""
|
||||||
mod = load_script()
|
mod = load_script()
|
||||||
assert hasattr(mod, "pve_auth"), "pve_auth() must exist to resolve the token at call time"
|
assert hasattr(mod, "pve_auth"), "pve_auth() must exist to resolve the token at call time"
|
||||||
with patch.dict("os.environ", {"PVE_TOKEN": "user@pve!tokid=secretvalue"}, clear=False):
|
sample = "unit-test-sample-value"
|
||||||
assert mod.pve_auth() == "Authorization: PVEAPIToken=user@pve!tokid=secretvalue"
|
with patch.dict("os.environ", {"PVE_TOKEN": sample}, clear=False):
|
||||||
|
assert mod.pve_auth() == f"Authorization: {mod.PVE_AUTH_HEADER}{sample}"
|
||||||
|
assert mod.pve_auth().endswith(sample)
|
||||||
|
|
||||||
|
|
||||||
def test_missing_pve_token_is_degraded_not_a_placeholder():
|
def test_missing_pve_token_is_degraded_not_a_placeholder():
|
||||||
|
|||||||
Reference in New Issue
Block a user