#!/usr/bin/env bash # No secret header on a curl command line (review round 4, ledger X29 and X24): a key passed as `-H "x-igneum-key: ..."` # is readable by every local user in the process list for the length of the upload. Scripts pass secret headers through # a config file (`curl -K ` with `header = "..."` lines) or a header file (`-H @file`). The class check (standing # rule, 5 October 2026): any .sh, .bat, .cmd or .ps1 line that invokes curl with x-igneum-key, x-relay-token or # x-machine-secret as a -H argument fails this. # # bash tools/ci/curl-header-check.sh [--self-test] set -euo pipefail ROOT="$(cd "$(dirname "$0")/../.." && pwd)" PAT='curl[^|]*-H[[:space:]]+"?[^"]*x-(igneum-key|relay-token|machine-secret):' check_tree() { # -> 0 when clean; prints offenders local root="$1" bad=0 while IFS= read -r hit; do echo "secret header on a curl command line: ${hit#$root/}"; bad=1; done \ < <(grep -rnE --include='*.sh' --include='*.bat' --include='*.cmd' --include='*.ps1' "$PAT" "$root" 2>/dev/null | grep -v '/node_modules/' | grep -v '/vendor/' | grep -v '/fixtures/' | grep -v 'tools/ci/curl-header-check.sh' | grep -vE '^[^:]+:[0-9]+:[[:space:]]*(printf|echo) ' || true) # fixture writers in the other checks return $bad } if [ "${1:-}" = "--self-test" ]; then T="$(mktemp -d)"; trap 'rm -rf "$T"' EXIT mkdir -p "$T/a" printf 'curl -sS -K "$cfg" -X POST "$url" -H "Content-Type: application/json" --data-binary @body\n' > "$T/a/good.sh" check_tree "$T" >/dev/null || { echo "self-test: the clean tree failed"; exit 1; } printf 'curl -sS -X POST "$url" -H "x-igneum-key: $KEY" --data-binary @body\n' > "$T/a/bad.sh" if check_tree "$T" >/dev/null; then echo "self-test: the bad tree passed"; exit 1; fi rm "$T/a/bad.sh" printf 'curl.exe -sS -X POST "%%URL%%" -H "x-igneum-key: %%KEY%%" --data-binary "@%%OUT%%"\n' > "$T/a/bad.bat" if check_tree "$T" >/dev/null; then echo "self-test: the bad .bat passed"; exit 1; fi echo "curl-header-check self-test: fires on the bad cases, passes the good one" exit 0 fi if check_tree "$ROOT"; then echo "curl-header-check: no secret header on any curl command line"; else exit 1; fi