Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Extend algoliaadminkey with additional checks #3459

Merged
merged 3 commits into from
Oct 24, 2024

Conversation

0x2b3bfa0
Copy link
Contributor

@0x2b3bfa0 0x2b3bfa0 commented Oct 17, 2024

Description

This pull request adds verification for other kinds of sensitive Algolia API keys apart from Admin keys, as per https://www.secjuice.com/api-misconfiguration-data-breach.

This pull reques also enhances the detection of Algolia keys by looking also for Algolia DocSearch keywords and option names on the official libraries (example).

Checklist

  • Tests passing (make test-community)?
  • Lint passing (make lint this requires golangci-lint)?

@zricethezav
Copy link
Collaborator

@0x2b3bfa0 that blog is from 2020. Did you test this locally? Do you have a screenshot of the integration test passing with a valid credential?

@0x2b3bfa0

This comment was marked as outdated.

@0x2b3bfa0
Copy link
Contributor Author

0x2b3bfa0 commented Oct 19, 2024

@zricethezav, locally everything seems to work "fine" now; I wonder if continuous integration will agree. 🤞🏼

@0x2b3bfa0 0x2b3bfa0 mentioned this pull request Oct 21, 2024
2 tasks
@0x2b3bfa0 0x2b3bfa0 changed the title Extend algoliaadminkey with ACL checks Extend algoliaadminkey with additional checks Oct 21, 2024
@0x2b3bfa0
Copy link
Contributor Author

@zricethezav, I've consolidated #3458 into this pull request and made sure all tests pass.

@zricethezav zricethezav merged commit 9cf0a4c into trufflesecurity:main Oct 24, 2024
13 checks passed
@0x2b3bfa0 0x2b3bfa0 deleted the 0x2b3bfa0-patch-1 branch October 24, 2024 19:22
abmussani added a commit to abmussani/trufflehog that referenced this pull request Oct 30, 2024
* main: (76 commits)
  update aws descriptions (trufflesecurity#3529)
  enforce timeout on circleci test (trufflesecurity#3528)
  rm snifftest (trufflesecurity#3527)
  Redact more source credentials (trufflesecurity#3526)
  Create global log redaction capability (trufflesecurity#3522)
  Adding basic "what is trufflehog" to the readme (trufflesecurity#3514)
  Handle custom detector response and include in extra data (trufflesecurity#3411)
  fix: fixed validation logic for `calendarific` (trufflesecurity#3480)
  fix(deps): update github.com/tailscale/depaware digest to 3d7f3b3 (trufflesecurity#3518)
  Move DecoderType into ResultWithMetadata trufflesecurity#3502
  Addeded 403 account block status code handling for gitlab (trufflesecurity#3471)
  updated gcpapplicationdefaultcredentials detector results with RawV2 (trufflesecurity#3499)
  fix(deps): update module github.com/brianvoe/gofakeit/v7 to v7.1.1 (trufflesecurity#3512)
  fix(deps): update module github.com/schollz/progressbar/v3 to v3.17.0 (trufflesecurity#3510)
  fix(deps): update module cloud.google.com/go/secretmanager to v1.14.2 (trufflesecurity#3498)
  Adds a logging section in the contributing guidelines (trufflesecurity#3509)
  fix: fixed verifcation pattern logic for `bulksms` (trufflesecurity#3478)
  Extend `algoliaadminkey` with additional checks (trufflesecurity#3459)
  fix(deps): update module google.golang.org/api to v0.203.0 (trufflesecurity#3497)
  fix: added correct api endpoint for verification & logic for Aeroworkflow (trufflesecurity#3435)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

2 participants