mirror of
https://github.com/warmbly/warmbly.git
synced 2026-10-05 08:02:14 +00:00
* feat: let the backend, consumer and tracking service fetch their own MaxMind databases from GEODB_URL and TRACKING_SCANNER_ASN_DB_URL, reading the archive shape from the content so a permalink tar.gz, a gzipped mmdb and a bare mmdb all work, never replacing a file already at the path, opening the bytes before installing them so a licence-key error page cannot become the database forever, skipping the AppleDouble sidecars a macOS tar writes ahead of the real file, and treating both URLs as secrets because the permalink carries the licence key * feat: drop the trailing blank line cargo fmt --check rejects at the end of tracking/src/asndb.rs * feat: stream the downloaded ASN archive instead of decompressing it whole, sizing each buffer from the gzip footer and the tar header so the member is allocated exactly once, which drops the peak of unwrapping a permalink tar.gz from 38 MB to 11.9 MB, essentially the database itself * feat: stop the MaxMind licence key reaching the logs through net/http's and reqwest's own error text, which both print the URL they were given and so defeated the redaction beside them, drop userinfo as well as the query when redacting, refuse plain http for a URL carrying a credential and refuse an https-to-http redirect, and apply the size cap to the decoded database rather than the compressed transfer so a gzip bomb cannot fill the disk * feat: strip basic-auth userinfo as well as the query when the tracking service redacts its database URL, parsing it rather than cutting at the first question mark so where a credential sits is the URL library's problem and not a guess
49 lines
1.5 KiB
Go
49 lines
1.5 KiB
Go
package instanceconfig
|
|
|
|
import (
|
|
"crypto/sha256"
|
|
"encoding/hex"
|
|
"strings"
|
|
)
|
|
|
|
// sensitiveMarkers make redaction structural rather than per-field: a new
|
|
// variable is protected by its name, not by someone remembering to list it.
|
|
var sensitiveMarkers = []string{"SECRET", "PASSWORD", "KEY", "TOKEN", "DSN", "_PASS"}
|
|
|
|
// sensitiveKeys are URLs that carry a credential inline and match no marker:
|
|
// the connection strings routinely hold user:password, and MaxMind's database
|
|
// permalink holds the account's licence key in its query string.
|
|
var sensitiveKeys = map[string]bool{
|
|
"PRIMARY_DB": true,
|
|
"REDIS": true,
|
|
"NATS_URL": true,
|
|
"SCHEMA_REGISTRY_URL": true,
|
|
"GEODB_URL": true,
|
|
"TRACKING_SCANNER_ASN_DB_URL": true,
|
|
}
|
|
|
|
// Sensitive reports whether a variable's value must never be returned.
|
|
func Sensitive(key string) bool {
|
|
if sensitiveKeys[key] {
|
|
return true
|
|
}
|
|
upper := strings.ToUpper(key)
|
|
for _, marker := range sensitiveMarkers {
|
|
if strings.Contains(upper, marker) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
// Fingerprint is the first 4 hex characters of SHA-256 of a value, empty when
|
|
// the value is unset. It exists so an operator can confirm the backend and the
|
|
// realtime service hold the same AUTH_SECRET without either being disclosed.
|
|
func Fingerprint(value string) string {
|
|
if value == "" {
|
|
return ""
|
|
}
|
|
sum := sha256.Sum256([]byte(value))
|
|
return hex.EncodeToString(sum[:])[:4]
|
|
}
|