mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-08-20 18:09:05 +00:00
GET /api/v3/config/secrets returned config_secrets.json in full to anyone who could reach the port, and this interface has no authentication. Probed against a real rig it produced six populated credential fields: a 40-character GitHub token, a 183-character Home Assistant token, and Jellyfin and weather API keys. This is the second door onto the same credentials; #477 closes the first. Masking the response alone would have been worse than the leak. The only client fetches every secret, edits one field and posts all of them back, and save_raw_file_content replaces the file wholesale -- so a masked GET followed by the client's own save would write the mask over every credential the user had not touched. That is why this was left open when the leak was found; it needs both halves. Read side: mask_all_secret_values(), which already existed for exactly this endpoint -- its docstring names it -- and had never been wired to a call site. It leaves empty values and YOUR_* placeholders alone, so a client can still tell "set" from "not set" without being told the secret. Write side: strip the echoed mask and blanks from the submission, then merge onto what is stored, so "unchanged" means unchanged. The cost is that a secret can no longer be cleared by blanking it; that wants its own affordance, since a control that erases credentials as a side effect of saving an unrelated one is not one. Browser side: the token field is now left empty rather than filled from the response. Filling it with the mask would have stored eight bullet characters as the token the next time the user pressed Save, and filling it with the real value is the thing being fixed. It reports whether a token is saved instead. Verified end to end through the Flask endpoints, not the helpers. Reverting the masking fails the leak tests; reverting the merge fails the preservation tests; both halves are independently guarded. 278 web tests pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01STMbQE4YctTacQXfbYqKuW
83 lines
3.0 KiB
Python
83 lines
3.0 KiB
Python
"""GET /config/secrets must not hand out credentials, and the client's
|
|
read-modify-write cycle must not destroy them.
|
|
|
|
This interface has no authentication. The endpoint returned the whole
|
|
config_secrets.json to anyone who could reach the port; on one rig that was a
|
|
40-character GitHub token, a 183-character Home Assistant token and three API
|
|
keys. Masking it alone is not enough: the only client fetches every secret,
|
|
edits one field and posts all of them back, so the write path has to treat an
|
|
echoed mask as "unchanged".
|
|
"""
|
|
import json
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
sys.path.insert(0, str(Path(__file__).parent))
|
|
|
|
from test_api_v3_secret_roundtrip import env, _on_disk # noqa: F401,E402
|
|
from src.web_interface.secret_helpers import SECRET_MASK # noqa: E402
|
|
|
|
STORED = {
|
|
"github": {"api_token": "ghp_" + "x" * 36},
|
|
"ledmatrix-weather": {"api_key": "w" * 32},
|
|
"incoming-packages": {"ha_token": "h" * 183},
|
|
"unset-plugin": {"api_key": ""},
|
|
"placeholder-plugin": {"api_key": "YOUR_API_KEY_HERE"},
|
|
}
|
|
|
|
|
|
def _seed(env):
|
|
env.secrets_file.write_text(json.dumps(STORED))
|
|
|
|
|
|
def _get(env):
|
|
r = env.client.get("/api/v3/config/secrets")
|
|
assert r.status_code == 200, r.get_data(as_text=True)[:200]
|
|
return r.get_json()["data"]
|
|
|
|
|
|
def test_no_credential_leaves_the_process(env):
|
|
_seed(env)
|
|
body = json.dumps(_get(env))
|
|
for secret in ("ghp_" + "x" * 36, "w" * 32, "h" * 183):
|
|
assert secret not in body, "endpoint returned a stored credential"
|
|
|
|
|
|
def test_set_and_unset_remain_distinguishable(env):
|
|
_seed(env)
|
|
data = _get(env)
|
|
assert data["github"]["api_token"] == SECRET_MASK
|
|
assert data["unset-plugin"]["api_key"] == ""
|
|
assert data["placeholder-plugin"]["api_key"] == "YOUR_API_KEY_HERE"
|
|
|
|
|
|
def test_the_clients_read_modify_write_preserves_every_other_secret(env):
|
|
"""What the GitHub-token save button actually does."""
|
|
_seed(env)
|
|
secrets = _get(env) # everything arrives masked
|
|
secrets["github"]["api_token"] = "ghp_" + "n" * 36 # user changes one
|
|
r = env.client.post("/api/v3/config/raw/secrets", json=secrets)
|
|
assert r.status_code == 200, r.get_data(as_text=True)[:200]
|
|
|
|
on_disk = _on_disk(env.secrets_file)
|
|
assert on_disk["github"]["api_token"] == "ghp_" + "n" * 36, "new token not saved"
|
|
assert on_disk["ledmatrix-weather"]["api_key"] == "w" * 32
|
|
assert on_disk["incoming-packages"]["ha_token"] == "h" * 183
|
|
|
|
|
|
def test_a_mask_echoed_back_is_never_stored(env):
|
|
_seed(env)
|
|
env.client.post("/api/v3/config/raw/secrets", json=_get(env))
|
|
on_disk = _on_disk(env.secrets_file)
|
|
assert SECRET_MASK not in json.dumps(on_disk), "the mask was stored as a secret"
|
|
assert on_disk["github"]["api_token"] == "ghp_" + "x" * 36
|
|
|
|
|
|
def test_a_brand_new_secret_can_still_be_added(env):
|
|
_seed(env)
|
|
env.client.post("/api/v3/config/raw/secrets",
|
|
json={"new-plugin": {"api_key": "brand-new"}})
|
|
on_disk = _on_disk(env.secrets_file)
|
|
assert on_disk["new-plugin"]["api_key"] == "brand-new"
|
|
assert on_disk["github"]["api_token"] == "ghp_" + "x" * 36
|