guide: wire GitHub PATs + Stripe keys into the guided worklist
GitHub PATs and Stripe secret keys have no scriptable rotation API (GitHub's create-token API was removed in 2020; Stripe has no create-key endpoint), so they belong in the guided change-password layer, not as Rotators. But they arrive from the env/file scanner as generic Source="env" tokens with no host, so the worklist showed them as "manual — no web page". Recognise them by their well-known PUBLIC value prefixes (ghp_/gho_/ghs_/ github_pat_/…, sk_live_/sk_test_/rk_live_/…) at scan time and record a non-secret Meta["service"] hint — a fixed service NAME, never the secret bytes. discover.ServiceForSecret does the detection; env.go attaches it for generic tokens, file.go before Store wipes the buffer. links.HostFor consults the hint and maps github→github.com / stripe→stripe.com, so the curated change-password URLs (already in the table) now light up for these credentials. Leak-safe (service name is derived from a public prefix, not the secret) and verified by the existing assertNoLeak checks. go build/vet clean; full suite 179 tests pass. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -54,6 +54,16 @@ var serviceByScanner = map[string]string{
|
||||
"aws": "console.aws.amazon.com",
|
||||
}
|
||||
|
||||
// serviceHost maps a scanner's non-secret service hint (discover.MetaService) to
|
||||
// the web host whose curated page rotates that credential. This is how guided-only
|
||||
// credentials — GitHub PATs and Stripe keys, which have no scriptable rotation API
|
||||
// — get a change-password link even though they arrive from the env/file scanner
|
||||
// with no host of their own.
|
||||
var serviceHost = map[string]string{
|
||||
"github": "github.com",
|
||||
"stripe": "stripe.com",
|
||||
}
|
||||
|
||||
// For returns the best rotation URL for a host.
|
||||
func For(host string) Link {
|
||||
h := normalize(host)
|
||||
@@ -72,6 +82,13 @@ func For(host string) Link {
|
||||
// HostFor derives a web host from a discovered credential, or "" if none applies
|
||||
// (e.g. ssh keys and opaque file/env secrets have no rotation page).
|
||||
func HostFor(c discover.Credential) string {
|
||||
// A scanner-recognised provider (GitHub PAT, Stripe key) carries a non-secret
|
||||
// service hint — the strongest signal, since the value prefix is unambiguous.
|
||||
if svc := c.Meta[discover.MetaService]; svc != "" {
|
||||
if h, ok := serviceHost[svc]; ok {
|
||||
return h
|
||||
}
|
||||
}
|
||||
// "user @ host" identities (git, netrc).
|
||||
if i := strings.LastIndex(c.Identity, " @ "); i >= 0 {
|
||||
if host := strings.TrimSpace(c.Identity[i+3:]); host != "" && host != "default" {
|
||||
|
||||
Reference in New Issue
Block a user