guide: wire GitHub PATs + Stripe keys into the guided worklist
GitHub PATs and Stripe secret keys have no scriptable rotation API (GitHub's create-token API was removed in 2020; Stripe has no create-key endpoint), so they belong in the guided change-password layer, not as Rotators. But they arrive from the env/file scanner as generic Source="env" tokens with no host, so the worklist showed them as "manual — no web page". Recognise them by their well-known PUBLIC value prefixes (ghp_/gho_/ghs_/ github_pat_/…, sk_live_/sk_test_/rk_live_/…) at scan time and record a non-secret Meta["service"] hint — a fixed service NAME, never the secret bytes. discover.ServiceForSecret does the detection; env.go attaches it for generic tokens, file.go before Store wipes the buffer. links.HostFor consults the hint and maps github→github.com / stripe→stripe.com, so the curated change-password URLs (already in the table) now light up for these credentials. Leak-safe (service name is derived from a public prefix, not the secret) and verified by the existing assertNoLeak checks. go build/vet clean; full suite 179 tests pass. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -89,10 +89,15 @@ func (f *fileScanner) harvest(v *vault.Vault, path, root string) (Credential, bo
|
||||
}
|
||||
|
||||
kind := classifyContent(b) // inspect bytes BEFORE Store wipes them
|
||||
svc := ServiceForSecret(b) // recognise provider prefix BEFORE Store wipes them
|
||||
rel, e := filepath.Rel(root, path)
|
||||
if e != nil {
|
||||
rel = filepath.Base(path)
|
||||
}
|
||||
var meta map[string]string
|
||||
if svc != "" {
|
||||
meta = map[string]string{MetaService: svc}
|
||||
}
|
||||
// Identity is the relative path (non-secret, never the contents). We do NOT
|
||||
// prefix the scanner name here — StorePath already prepends the source
|
||||
// segment, so a "file / " prefix would double it to imported/file/file/<rel>.
|
||||
@@ -103,6 +108,7 @@ func (f *fileScanner) harvest(v *vault.Vault, path, root string) (Credential, bo
|
||||
Location: path,
|
||||
Modified: info.ModTime(),
|
||||
Secret: v.Store(b), // copies into locked mem, wipes b
|
||||
Meta: meta,
|
||||
}, true
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user