Repository navigation
Redact credentials from logged URLs, VEX product ids and hosted Composer locks - #1026
Draft
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Draft
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Mikola Lysenko (mikolalysenko) wants to merge 3 commits into
Conversation
Add utils::redact, the one place a URL is made safe to show: userinfo, the Socket grant-token path level (the level before the patch uuid under /patch/ or /patch-registry/) and secret query values become <redacted>. Route every emission through it: - VendorWarning::new redacts its detail, so the vendor_prebuilt_downloaded advisory (8 hand-written copies, now one VerifiedArchive:: downloaded_warning builder) no longer puts the grant URL into --json events and --verbose output; - registry_fetch::download and maven_repo::fetch_registry_bytes errors (GOPROXY / .npmrc / mirror userinfo, reqwest's own error text); - api::client debug_log, network_error_detail and the artifact not-found / still-building / non-http errors; - telemetry::sanitize_error_message; patch_fetch_failed now reports the uuid field only when the identifier is a uuid, not a CVE, purl or private package name. Consolidation: redirect::redact_grant_token (1 caller, vlt preflight) is deleted and the caller routed through redact_urls_in; the userinfo-safe host extractor hosted::guidance::url_host and the upstream/uv.rs copy are replaced by utils::redact::url_host. A ratchet test pins the download advisory to its single builder. Audit B26. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
remote_url_to_purl fell back to the raw origin URL for any host other than github.com / gitlab.com / bitbucket.org and for any non owner/repo path (a GitLab subgroup), so a CI clone's https://gitlab-ci-token:<job token>@host/... or https://<PAT>@host/... was published verbatim in the OpenVEX document. The fallback now goes through utils::redact::strip_url_credentials (userinfo and secret query parameters dropped); an ssh login name (ssh://git@host/...) and scp-like remotes stay as they were, so existing product ids do not move. Audit B21. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Composer copies a repository's options (http.header auth tokens, ssl client certificates, http.proxy) into every lock entry it resolves from it as transport-options, and applies them to that entry's dist download. The hosted rewrite retargeted dist.url to the patch host but kept transport-options, so every composer install sent the private repository's credentials to the hosted patch server. The origin-bound entry members are now one list, formats::composer::ORIGIN_BOUND_ENTRY_KEYS (source, transport-options), used by both backends: the vendored rewrite_lock_entry (which already dropped both by hand) and the hosted apply_dist_edit, which now drops each member, re-scanning between removals so adjacent members never leave a dangling comma, and widens the recorded edit to cover every changed byte so the ledger's fragment revert restores them. A new warning, redirect_composer_transport_options_removed, says so. New golden case composer-lock/transport-options (plus its vex-discover golden entry) and a unit test over five member layouts. Fixes #399. Audit B02. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Architecture audit, credential leaks:
B02 / Hosted Composer rewrite keeps the entry's transport-options, so Composer sends a private repository's auth headers to the hosted patch URL #399: the hosted Composer rewrite pointed
dist.urlat the patch host but kept the entry'stransport-options. Composer copies a repository'soptions(http.headerauth tokens,sslclient certificates,http.proxy) into each lock entry and applies them to that entry's dist download, so everycomposer installsent the private registry's credentials to the hosted patch server. The vendored backend already dropped the key, but with its own hand-written list.B26: grant tokens and URL userinfo reached
--jsonevents, CI logs, debug output and telemetry:vendor_prebuilt_downloadedadvisories quoted the grant URL;registry_fetch::downloadand the Maven fetch errors quoted GOPROXY,.npmrcand mirror URLs, reqwest's error text included;client.rsdebug lines and artifact errors quoted grant URLs;telemetry::sanitize_error_messageonly replaced$HOME, andpatch_fetch_failed.uuidcarried whatever identifier the user passed (CVE, purl, private package name).redirect::redact_grant_tokenhad a single caller.B21: the VEX product
@idfell back to the raw git origin URL for unknown hosts and GitLab subgroups, sohttps://gitlab-ci-token:<token>@…andhttps://<PAT>@…were published in the OpenVEX document.Change
New
utils::redactis the one redactor.redact_url/redact_urls_inreplace userinfo, the Socket grant-token level (the path level before the patch uuid under/patch/or/patch-registry/) and secret query values with<redacted>.strip_url_credentialsis the identifier form, andurl_hostis the userinfo-safe host.Each emission point now goes through it:
VendorWarning::new(every vendor advisory);registry_fetch::downloadandmaven_repo::fetch_registry_bytes;api::client'sdebug_log,network_error_detailand artifact errors;telemetry::sanitize_error_message.patch_fetch_failednow sendsuuidonly when the identifier is a uuid.VEX: a remote that falls back to the URL is stripped of credentials first. An ssh login name (
ssh://git@host/…) and scp-like remotes are kept, so existing product ids don't change.Composer:
formats::composer::ORIGIN_BOUND_ENTRY_KEYS(source,transport-options) is shared by the vendoredrewrite_lock_entryand the hostedapply_dist_edit.redirect_composer_transport_options_removed, documented in docs/testing/composer-compatibility.md.Duplicate copies deleted
vendor_prebuilt_downloadedadvisory buildersVerifiedArchive::downloaded_warning, pinned by a ratchet test)redirect::redact_grant_tokenwith 1 caller;hosted::guidance::url_host's userinfo strip)utils::redact)hosted::guidance::url_host,patch/redirect/upstream/uv.rs)source-only plan)Testing
Run on macOS:
cargo test -p socket-patch-core --lib: 5585 passed, 2 failed. After regenerating the vex-discover golden for the new fixture,vex::discover::testing::goldenpasses. The other failure,utils::digest::tests::production_digests_go_through_the_helpers, fails on main too: it namescrawlers/gradle_cache.rs,patch/jvm_jar.rsandpatch/sidecars/maven.rs, none of which this PR touches.cargo test -p socket-patch-core --test redirect_golden --test upstream_restore_goldenpassed, including the newcomposer-lock/transport-optionscase and its round-trip restore.cargo test -p socket-patch-clipassed forin_process_redirect,hosted_memory_engine,hosted_memory_parity,e2e_vex,covgap_commands_vex,in_process_vendor,scan_vendor_e2e,e2e_vendored_production,e2e_hosted_productionande2e_embedded_vex.cargo clippy -p socket-patch-core --all-targets -- -D warningsreports only lints that already fail on main under the local toolchain:maven_repo.rs:2514andnuget_feed.rs:2005(empty line after doc comment) andpython_crawler.rs:2734(unusedunix_default). There are no lints in changed code. The samepython_crawlerlint stops the CLI clippy build.utils::redactunit tests and the ratchet;telemetryURL redaction and uuid-only field;vex::product::remote_url_credentials_never_reach_the_product_id;formats::composer::source::transport_options_are_dropped_with_source_in_any_layout;composer-lock/transport-options.Deferred
composer-lock-members.ts) has to port thetransport-optionsdrop to stay byte-identical. The shared goldencomposer-lock/transport-optionswill fail there until it does.RewriteWarninggoes through the redactor: they are built as struct literals at about 180 sites. Most already quote onlyurl_host. The Gradle/sbt guidance snippets embed the repository URL on purpose, because the user is meant to paste it. A CLI-envelope-level choke point needs a decision about those snippets.update/release.rskeeps its own reqwest-basedurl_host, which normalizes ports differently.pkg:gitlabwith a namespace) are not done. The fallback is now credential-free.--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704, Decide: warn on and then remove scan --apply/--vendor, and whether --vex stays embedded #966, Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615, Decide: where patch API calls go when a token is set but the org slug can't be resolved #648).🤖 Generated with Claude Code