Skip to content

route-git-token: gate the token, and record 1.5.0's entries - #45

Merged
gronke merged 1 commit into
mainfrom
changelog-1-5-0
Aug 3, 2026
Merged

gronke merged 1 commit into
mainfrom
changelog-1-5-0

Conversation

@gronke

@gronke gronke commented Aug 3, 2026

Copy link
Copy Markdown
Owner

route-git-token validates host, username and path against a charset before they reach a gitconfig key, with the comment that those gates keep injection structurally impossible. The token lands in the same key, and it was not validated. Reproduced against the merged script:

$ ROUTE_TOKEN="$(printf 'ghs_abc\nNODE_OPTIONS=--require /tmp/pwn')" bash route.sh
::add-mask::ghs_abc
NODE_OPTIONS=--require /tmp/pwn          # <- printed to the log, unmasked

# and in $GITHUB_ENV:
GIT_CONFIG_KEY_0=url.https://x-access-token:ghs_abc
NODE_OPTIONS=--require /tmp/pwn@github.com/octo/.insteadOf

A newline in the token writes a line of its own into $GITHUB_ENV, which becomes an environment variable for every later step in the job, and ::add-mask:: masks only the first line so the payload reaches the log. A trailing newline from a pasted secret hits the same path by accident.

The gate now runs before the mask and before any use, and its error never echoes the value. The charset accepts what forges actually issue — verified against ghs_…, github_pat_…, glpat-… and a base64url JWT — and rejects whitespace plus the characters that would break the URL. The selftest gains the negative control and asserts that a refused token leaves the two good entries untouched.

Every other input that lands in a gitconfig key was charset-validated; the token, which is embedded in the same key, was not.
A newline in it wrote a line of its own into $GITHUB_ENV — an arbitrary environment variable for every later step in the job — and `::add-mask::` covered only the first line, printing the rest to the log.
The gate runs before the mask and before any use, and its error never echoes the value.
The charset covers what forges issue (GitHub ghs_/github_pat_, GitLab glpat-, Bitbucket, base64url JWTs) and excludes what would break the URL the token is embedded in.
@gronke
gronke merged commit 67ed45d into main Aug 3, 2026
20 checks passed
@gronke
gronke deleted the changelog-1-5-0 branch August 3, 2026 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant