Documentation
¶
Overview ¶
Package sourcecases generates the source strings the DT-0C property test feeds to every command path that takes a source: every scheme the CLI knows, in lower, upper and mixed case, bare and wrapped in another scheme, with a generated secret in each position a parser can read as userinfo or a user can put one: userinfo (with and without a user name), a token standing alone as the user name, the position a parser misreads as userinfo ("alice:42/secret@"), a token or a user name that holds a slash (so no colon or "@" comes before a slash), userinfo after a UNC start ("\\alice:secret@"), a user name with a slash after a UNC start, a token as the user name straight after a UNC start and after a UNC start and one more separator (a backslash or a slash), a second URL written after an explicit path start ("/" or "./") that holds the userinfo, the query string and the fragment.
The secrets are generated, not typed, so a test that finds one in an output has found a real leak and not a coincidence with a fixed word. Generation is deterministic: the same call returns the same cases.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var Schemes = []string{"sqlite", "ingitdb", "postgres", "postgresql", "http", "https", "openvaultdb"}
Schemes are the schemes the CLI knows: everything Parse dispatches, and the postgresql alias.
Functions ¶
func Leaks ¶
Leaks returns the secrets of c found in texts: a whole secret, or any run of four or more letters and digits of it (so a password cut at a space or a slash and leaked in part still counts).
func WithoutGeneratedIdentifiers ¶
WithoutGeneratedIdentifiers returns text with every UUID, RFC 3339 timestamp and long hexadecimal digest replaced by a space. Read a file a program wrote through it before calling Leaks: those identifiers are random or time-based, so a run of four or more characters of a generated secret (all eight digits of a digits-only password, five hexadecimal letters of a short one) appears in one now and then by chance, and none is made from a source string.
Types ¶
type Case ¶
type Case struct {
// Name is unique across All.
Name string
// Source is the string given to the command.
Source string
// Secrets are the literals Source holds that must never appear in an output.
Secrets []string
// Style says what the secret looks like ("with spaces", "digits only", ...).
Style string
// Position says where the secret is ("userinfo", "query", ...).
Position string
// Wrapped is true when Source is a URL inside another scheme's URL.
Wrapped bool
}
Case is one source string a user could type.
func CommandCases ¶
func CommandCases() []Case
CommandCases returns the cases a command-level test runs: the styles that stress the readers most (spaces, an "@", digits before a slash, digits only, a plain word, a token), so the many command runs stay quick.
type UnsafeIdentifier ¶ added in v0.54.4
type UnsafeIdentifier struct {
// Name says what the text is.
Name string
// ID is the text, as it stands after the request's own decoding.
ID string
}
UnsafeIdentifier is a text a client can send where an environment, a catalog or another ID belongs that must never reach a file path: it would leave the folder the ID names a child of, name an absolute path, or be read differently by a layer that decodes it once more.
func UnsafeHosts ¶ added in v0.55.1
func UnsafeHosts() []UnsafeIdentifier
UnsafeHosts returns the texts that a check of the host of a db server must refuse: the unsafe identifiers (but the name of 129 letters, which is a host name), the shapes that are not a host (a space, user information, a path, a zone) and a host over the 253 characters a name can have.
func UnsafeIdentifiers ¶ added in v0.54.4
func UnsafeIdentifiers() []UnsafeIdentifier
UnsafeIdentifiers returns the texts that a path-bound ID check must refuse: the parent and the current directory, a traversal, an absolute path, a path separator of either kind, a drive path, a NUL, a separator that is still percent-encoded after one decoding, a hidden name, a home directory, an empty text and one over the length limit.
func UnsafePathIdentifiers ¶ added in v0.55.1
func UnsafePathIdentifiers() []UnsafeIdentifier
UnsafePathIdentifiers returns the texts that a check of an ID made of folders (a recordset definition, a folder path) must refuse: every unsafe identifier but the text that is a valid path of two plain names, and the paths whose own folders are unsafe, empty or both.