Repository navigation
route-git-token: gate the token, and record 1.5.0's entries - #45
Merged
Merged
Conversation
Every other input that lands in a gitconfig key was charset-validated; the token, which is embedded in the same key, was not. A newline in it wrote a line of its own into $GITHUB_ENV — an arbitrary environment variable for every later step in the job — and `::add-mask::` covered only the first line, printing the rest to the log. The gate runs before the mask and before any use, and its error never echoes the value. The charset covers what forges issue (GitHub ghs_/github_pat_, GitLab glpat-, Bitbucket, base64url JWTs) and excludes what would break the URL the token is embedded in.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
route-git-tokenvalidates host, username and path against a charset before they reach a gitconfig key, with the comment that those gates keep injection structurally impossible. The token lands in the same key, and it was not validated. Reproduced against the merged script:A newline in the token writes a line of its own into
$GITHUB_ENV, which becomes an environment variable for every later step in the job, and::add-mask::masks only the first line so the payload reaches the log. A trailing newline from a pasted secret hits the same path by accident.The gate now runs before the mask and before any use, and its error never echoes the value. The charset accepts what forges actually issue — verified against
ghs_…,github_pat_…,glpat-…and a base64url JWT — and rejects whitespace plus the characters that would break the URL. The selftest gains the negative control and asserts that a refused token leaves the two good entries untouched.