Skip to content

fix(security): load client-leak patterns from org secret, fail closed - #13

Draft
RevealUIStudio wants to merge 1 commit into
masterfrom
fix/client-leak-secret-patterns
Draft

RevealUIStudio wants to merge 1 commit into
masterfrom
fix/client-leak-secret-patterns

Conversation

@RevealUIStudio

Copy link
Copy Markdown
Owner

Summary

The client / prospect name leak scanner no longer stores its detection list in the public tree. scripts/check-client-leaks.sh loads the literal pattern list at runtime from CLIENT_LEAK_PATTERNS (multiline, one tag|literal|reason line per pattern). Behavior stays the same once that secret holds the previous lines.

.github/workflows/check-client-leaks.yml passes client_leak_patterns: ${{ secrets.CLIENT_LEAK_PATTERNS }} into the pinned shared action RevealUIStudio/.github/.github/actions/check-client-leaks@8ea1ca5697dfc1f2041aac1368a9dd6d241121ab. The job name stays Client / prospect name leak scan.

Fail closed:

  • In CI (CI=true or GITHUB_ACTIONS=true), an empty or missing CLIENT_LEAK_PATTERNS exits non-zero and names that secret.
  • Locally, a gitignored .client-name-watchlist.local file is an optional fallback. If neither source is present, the script prints a warning and exits 2.

The scanner no longer excludes itself. This repo has no .gitleaks.issues.toml and no workflow consumes one, so there were no committed name rules to relocate. The previous exclusion of that filename was dropped with the self-exclusion. Unrelated gitleaks rules were not present.

CI on this PR is expected to fail closed until the org secret CLIENT_LEAK_PATTERNS exists and is visible to this repo. The old values remain in git history. No history rewrite; that is accepted.

Adding coverage: add the line to the CLIENT_LEAK_PATTERNS org secret, never to a committed file.

Open in Web Open in Cursor 

Co-authored-by: Joshua Vaughn <founder@revealui.com>

@RevealUIStudio RevealUIStudio left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security soft review: PASS. P0=0 P1=0.

  • The literal pattern list is removed from the scanner. No added line, the title, the body or the commit message carries any of it.
  • The workflow passes secrets.CLIENT_LEAK_PATTERNS into the pinned composite. The job name Client / prospect name leak scan is unchanged and still triggers on master.
  • Fails closed in CI when the secret is empty. The local fallback .client-name-watchlist.local is gitignored.
  • The failing leak-scan check is expected until the org secret is visible to this repo. The updates.yml failure is pre-existing on master.

This fixes the tip exposure that #12 introduced on master. Stays draft. No merge until the owner confirms the org secret. Security does not merge, undraft, or promote.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants