Repository navigation
sec(api): remove APIKeySecretURL/DeploymentAWSAccountID from unauthenticated responses (closes #633) - #796
Conversation
|
Warning Review limit reached
More reviews will be available in 21 minutes and 46 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (11)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai full review |
Rate Limit Exceeded
|
…633) Both fields exposed the AWS account ID + Secrets Manager ARN path to unauthenticated callers via GET /api/info (AuthPublic). - Strip both fields from PublicInfoResponse and getPublicInfo - Add DeploymentInfoResponse + getDeploymentInfo handler - Register GET /api/info/deployment with AuthUser - Frontend: approval-details.ts calls getDeploymentInfo (post-login); app.ts first-time setup no longer passes the removed hint - Regression test: JSON-marshals /api/info response and asserts neither sensitive key appears on the wire
…tions PublicInfo no longer includes api_key_secret_url or deployment_aws_account_id (moved to DeploymentInfo by #633). The direct cast to Record<string,unknown> therefore fails TS2352. Cast through unknown first to satisfy the type checker while preserving the runtime assertion that these fields are absent.
75ba483 to
435b3c4
Compare
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Summary
APIKeySecretURLandDeploymentAWSAccountIDwere both populated ingetPublicInfo(internal/api/handler_dashboard.go:346-372) and included inPublicInfoResponse(internal/api/types.go:463-464), which is served on the unauthenticatedGET /api/infoendpoint.PublicInfoResponseandgetPublicInfo. Added a newDeploymentInfoResponsetype andgetDeploymentInfohandler. RegisteredGET /api/info/deploymentwithAuthUserin the router.approval-details.ts(post-login context, useddeployment_aws_account_idfrom/api/info) updated to call the new authenticatedgetDeploymentInfo().app.tsfirst-time setup no longer passesapi_key_secret_urlas a hint (the field no longer exists on the public response; deployers can find the secret in the AWS console directly).Changed files
internal/api/types.goAPIKeySecretURL/DeploymentAWSAccountIDfromPublicInfoResponse; addDeploymentInfoResponseinternal/api/handler_dashboard.gogetPublicInfono longer populates the two fields; newgetDeploymentInfohandlerinternal/api/router.goGET /api/info/deployment(AuthUser); addgetDeploymentInfoHandlershiminternal/api/openapi.yamlPublicInfoResponseschema; addDeploymentInfoResponse+/api/info/deploymentspecinternal/api/handler_dashboard_test.goTestHandler_getDeploymentInfo; add regression test asserting JSON body of/api/infonever contains the two sensitive keysfrontend/src/api/types.tsPublicInfo; addDeploymentInfointerfacefrontend/src/api/auth.tsgetDeploymentInfo()function calling/api/info/deploymentwith auth headersfrontend/src/api/index.tsgetDeploymentInfoandDeploymentInfotypefrontend/src/approval-details.tsgetDeploymentInfo()instead ofgetPublicInfo()fordeployment_aws_account_idfrontend/src/app.tsapi_key_secret_urlhint from unauthenticated bootstrapfrontend/src/__tests__/api.test.tsgetPublicInfotest; addgetDeploymentInfotestsRegression test scope
TestHandler_getPublicInfo/no_sensitive_fields_in_unauthenticated_response_(#633): JSON-marshals thePublicInfoResponsereturned bygetPublicInfoand asserts the wire representation contains neitherapi_key_secret_urlnordeployment_aws_account_id. Catches future re-additions via embedded structs or interface{} workarounds that the compile-time type guard would miss.TestHandler_getDeploymentInfo: covers ARN parsing (valid/invalid/empty), URL construction, and correct struct fields.Frontend
api.test.ts: updatedgetPublicInfotest asserts no sensitive fields appear; newgetDeploymentInfotests cover happy-path and error fallback.Notes
No consumer needed
api_key_secret_urlon the unauthenticated path for a functional flow — it was only a convenience hint in the admin setup modal, and the modal still works without it (theapiKeyHintparameter is optional).Closes #633