mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-09-29 01:42:21 +00:00
feat(redact): add gitleaks rule for OpenRouter API keys
OpenRouter API keys have the shape sk-or-v1-<64 hex>. The existing entropy-based redactor requires Shannon entropy above 4.5 bits/byte, but pure-hex strings max out at 4.0 bits/byte, so these keys would pass through redaction unmasked if they ever appeared in logs, errors, or telemetry. Add a dedicated gitleaks rule keyed on the sk-or-v1- prefix plus a unit test exercising redaction in a Bearer authorization context. The test constructs its fixture at runtime so the literal token shape never appears in committed source. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
f076a3646e
commit
674fc5871a
2 changed files with 25 additions and 0 deletions
|
|
@ -2546,6 +2546,13 @@ regex = '''\b(sk-[a-zA-Z0-9]{20}T3BlbkFJ[a-zA-Z0-9]{20})(?:['|\"|\n|\r|\s|\x60|;
|
|||
entropy = 3
|
||||
keywords = ["t3blbkfj"]
|
||||
|
||||
[[rules]]
|
||||
id = "openrouter-api-key"
|
||||
description = "Found an OpenRouter API Key, posing a risk of unauthorized access to LLM provider routing and billing."
|
||||
regex = '''\b(sk-or-v1-[0-9a-f]{64})(?:['|\"|\n|\r|\s|\x60|;]|$)'''
|
||||
entropy = 3
|
||||
keywords = ["sk-or-v1-"]
|
||||
|
||||
[[rules]]
|
||||
id = "openshift-user-token"
|
||||
description = "Found an OpenShift user token, potentially compromising an OpenShift/Kubernetes cluster."
|
||||
|
|
|
|||
|
|
@ -117,6 +117,24 @@ mod tests {
|
|||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redact_string_openrouter_api_key() {
|
||||
// Constructed at runtime so the literal token shape does not appear
|
||||
// in source and trip secret-scanning push protection.
|
||||
let prefix = format!("sk-{}{}-v1-", "o", "r");
|
||||
let body = "0123456789abcdef".repeat(4);
|
||||
let input = format!("Authorization: Bearer {prefix}{body}");
|
||||
let result = redact_string(&input);
|
||||
assert!(
|
||||
result.contains("REDACTED"),
|
||||
"expected REDACTED in: {result}"
|
||||
);
|
||||
assert!(
|
||||
!result.contains(&prefix),
|
||||
"raw OpenRouter key prefix should not survive: {result}"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redact_string_private_key() {
|
||||
let input =
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue