Commit c6cdd75
committed
feat(config): block sensitive env overrides by suffix and add tests
- Add suffix-based, case-insensitive filter for sensitive env vars in `zainod/src/config.rs`:
- Deny leaf keys ending with: `password`, `secret`, `token`, `cookie`, `private_key`.
- Pre-filter `ZAINO_*` vars and pass sanitized map via `Environment::source(Some(filtered_env))` with `try_parsing(true)`.
- Keep non-sensitive fields overridable (e.g., `cookie_dir`, `tls_cert_path`, `tls_key_path`).
- Add tests in `zainod/tests/config.rs`:
- `test_env_unknown_non_sensitive_key_is_ignored`
- `test_env_unknown_sensitive_key_is_ignored`
- `test_env_validator_password_is_ignored` (env does not override default)1 parent 2358167 commit c6cdd75
2 files changed
Lines changed: 83 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
23 | 34 | | |
24 | 35 | | |
25 | 36 | | |
| |||
397 | 408 | | |
398 | 409 | | |
399 | 410 | | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
400 | 433 | | |
401 | 434 | | |
402 | 435 | | |
403 | 436 | | |
404 | 437 | | |
405 | 438 | | |
406 | | - | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
407 | 444 | | |
408 | 445 | | |
409 | 446 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
451 | 451 | | |
452 | 452 | | |
453 | 453 | | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
0 commit comments