Class: Scryer::Rules::HardcodedBasicAuthRule
- Inherits:
-
Scryer::Rule
- Object
- Scryer::Rule
- Scryer::Rules::HardcodedBasicAuthRule
- Defined in:
- lib/scryer/rules/hardcoded_basic_auth_rule.rb
Overview
Flags http_basic_authenticate_with calls whose password: (or
name:) keyword argument is a plain string literal — a shape
HardcodedSecretRule doesn't cover (that rule only looks at
x = "literal" assignment targets, not keyword-argument values in a
method call).
Constant Summary collapse
- PLACEHOLDER_VALUES =
/\A(x+|0+|change-?me|your[_-]?password|placeholder|example|dummy|fake|test|redacted|\*+)\z/i.freeze
Instance Attribute Summary
Attributes inherited from Scryer::Rule
Instance Method Summary collapse
Methods inherited from Scryer::Rule
Constructor Details
This class inherits a constructor from Scryer::Rule
Instance Method Details
#scan ⇒ Object
16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 |
# File 'lib/scryer/rules/hardcoded_basic_auth_rule.rb', line 16 def scan findings = [] Ast.each_node(sexp) do |node| next unless Ast.tagged?(node, :method_add_arg, :command, :command_call) inner = Ast.tagged?(node, :method_add_arg) ? node[1] : node name_pair = Ast.call_name(inner) next unless name_pair && name_pair[1] == "http_basic_authenticate_with" args = Ast.call_arguments(node) password_value = Ast.plain_string_value(Ast.keyword_arg(args, "password")) next unless password_value && !password_value.strip.empty? && !PLACEHOLDER_VALUES.match?(password_value.strip) line = Ast.line_of(node) findings << finding( line: line, message: "`http_basic_authenticate_with` is called with a literal `password:` — " \ "anyone with read access to this source (including git history) has the " \ "credential, and it can't be rotated without a code change and deploy.", suggested_fix: "Move the credential out of source: " \ "`http_basic_authenticate_with name: ENV.fetch(\"BASIC_AUTH_USER\"), " \ "password: ENV.fetch(\"BASIC_AUTH_PASSWORD\")` (or Rails encrypted " \ "credentials), and rotate this password since it's likely already " \ "exposed in git history." ) end findings end |