Skip to content

sec(api): remove APIKeySecretURL/DeploymentAWSAccountID from unauthenticated responses (closes #633) - #796

Merged
cristim merged 2 commits into
feat/multicloud-web-frontendfrom
fix/633-from-bucket-c
Jun 6, 2026
Merged

cristim merged 2 commits into
feat/multicloud-web-frontendfrom
fix/633-from-bucket-c

Conversation

@cristim

@cristim cristim commented May 28, 2026

Copy link
Copy Markdown
Member

Summary

  • Leak sites closed: APIKeySecretURL and DeploymentAWSAccountID were both populated in getPublicInfo (internal/api/handler_dashboard.go:346-372) and included in PublicInfoResponse (internal/api/types.go:463-464), which is served on the unauthenticated GET /api/info endpoint.
  • Fix: Stripped both fields from PublicInfoResponse and getPublicInfo. Added a new DeploymentInfoResponse type and getDeploymentInfo handler. Registered GET /api/info/deployment with AuthUser in the router.
  • Frontend: approval-details.ts (post-login context, used deployment_aws_account_id from /api/info) updated to call the new authenticated getDeploymentInfo(). app.ts first-time setup no longer passes api_key_secret_url as a hint (the field no longer exists on the public response; deployers can find the secret in the AWS console directly).

Changed files

File Change
internal/api/types.go Strip APIKeySecretURL/DeploymentAWSAccountID from PublicInfoResponse; add DeploymentInfoResponse
internal/api/handler_dashboard.go getPublicInfo no longer populates the two fields; new getDeploymentInfo handler
internal/api/router.go Register GET /api/info/deployment (AuthUser); add getDeploymentInfoHandler shim
internal/api/openapi.yaml Update PublicInfoResponse schema; add DeploymentInfoResponse + /api/info/deployment spec
internal/api/handler_dashboard_test.go Update existing tests; add TestHandler_getDeploymentInfo; add regression test asserting JSON body of /api/info never contains the two sensitive keys
frontend/src/api/types.ts Strip fields from PublicInfo; add DeploymentInfo interface
frontend/src/api/auth.ts Add getDeploymentInfo() function calling /api/info/deployment with auth headers
frontend/src/api/index.ts Export getDeploymentInfo and DeploymentInfo type
frontend/src/approval-details.ts Call getDeploymentInfo() instead of getPublicInfo() for deployment_aws_account_id
frontend/src/app.ts Drop api_key_secret_url hint from unauthenticated bootstrap
frontend/src/__tests__/api.test.ts Update getPublicInfo test; add getDeploymentInfo tests

Regression test scope

TestHandler_getPublicInfo/no_sensitive_fields_in_unauthenticated_response_(#633): JSON-marshals the PublicInfoResponse returned by getPublicInfo and asserts the wire representation contains neither api_key_secret_url nor deployment_aws_account_id. Catches future re-additions via embedded structs or interface{} workarounds that the compile-time type guard would miss.

TestHandler_getDeploymentInfo: covers ARN parsing (valid/invalid/empty), URL construction, and correct struct fields.

Frontend api.test.ts: updated getPublicInfo test asserts no sensitive fields appear; new getDeploymentInfo tests cover happy-path and error fallback.

Notes

No consumer needed api_key_secret_url on the unauthenticated path for a functional flow — it was only a convenience hint in the admin setup modal, and the modal still works without it (the apiKeyHint parameter is optional).

Closes #633

@cristim cristim added triaged Item has been triaged priority/p2 Backlog-worthy severity/medium Moderate harm urgency/this-sprint Within the current sprint impact/internal Team-internal only effort/s Hours type/security Security finding labels May 28, 2026
@coderabbitai

coderabbitai Bot commented May 28, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@cristim, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 21 minutes and 46 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: c08c0d03-ebfc-4bff-bf44-064d2913bab2

📥 Commits

Reviewing files that changed from the base of the PR and between 80c20d2 and 435b3c4.

📒 Files selected for processing (11)
  • frontend/src/__tests__/api.test.ts
  • frontend/src/api/auth.ts
  • frontend/src/api/index.ts
  • frontend/src/api/types.ts
  • frontend/src/app.ts
  • frontend/src/approval-details.ts
  • internal/api/handler_dashboard.go
  • internal/api/handler_dashboard_test.go
  • internal/api/openapi.yaml
  • internal/api/router.go
  • internal/api/types.go
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/633-from-bucket-c

Comment @coderabbitai help to get the list of available commands and usage tips.

@cristim

cristim commented May 28, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented May 28, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented May 30, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented May 30, 2026

Copy link
Copy Markdown
Contributor

Rate Limit Exceeded

@cristim have exceeded the limit for the number of chat messages per hour. Please wait 54 minutes and 22 seconds before sending another message.

cristim added 2 commits June 1, 2026 19:17
…633)

Both fields exposed the AWS account ID + Secrets Manager ARN path to
unauthenticated callers via GET /api/info (AuthPublic).

- Strip both fields from PublicInfoResponse and getPublicInfo
- Add DeploymentInfoResponse + getDeploymentInfo handler
- Register GET /api/info/deployment with AuthUser
- Frontend: approval-details.ts calls getDeploymentInfo (post-login);
  app.ts first-time setup no longer passes the removed hint
- Regression test: JSON-marshals /api/info response and asserts neither
  sensitive key appears on the wire
…tions

PublicInfo no longer includes api_key_secret_url or deployment_aws_account_id
(moved to DeploymentInfo by #633). The direct cast to Record<string,unknown>
therefore fails TS2352. Cast through unknown first to satisfy the type checker
while preserving the runtime assertion that these fields are absent.
@cristim
cristim force-pushed the fix/633-from-bucket-c branch from 75ba483 to 435b3c4 Compare June 1, 2026 17:22
@cristim

cristim commented Jun 4, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 4, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jun 5, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim

cristim commented Jun 5, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@cristim

cristim commented Jun 5, 2026

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cristim
cristim merged commit cbdc4be into feat/multicloud-web-frontend Jun 6, 2026
5 checks passed
@cristim
cristim deleted the fix/633-from-bucket-c branch June 6, 2026 07:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/internal Team-internal only priority/p2 Backlog-worthy severity/medium Moderate harm triaged Item has been triaged type/security Security finding urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant