-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fixed uri regex issue #3815
base: main
Are you sure you want to change the base?
fixed uri regex issue #3815
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -23,7 +23,7 @@ var _ detectors.Detector = (*Scanner)(nil) | |
var _ detectors.CustomFalsePositiveChecker = (*Scanner)(nil) | ||
|
||
var ( | ||
keyPat = regexp.MustCompile(`\b(?:https?:)?\/\/[\S]{3,50}:([\S]{3,50})@[-.%\w\/:]+\b`) | ||
keyPat = regexp.MustCompile(`\b(?:https?:)?\/\/[\w-\.]{3,50}:([\w-\.]{3,50})@[-.%\w\/:]+\b`) | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. In my opinion, passwords in URIs can consist of any non-whitespace characters. Using \w limits the match to a specific set of characters, which might exclude valid ones. Are you noticing any detection issues when using \S instead? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. e.g. http://username:p%[email protected]" Will not be detected when using There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Yes, actually as the scenario mentioned in the linked issue, it matches some special chars like |
||
|
||
// TODO: make local addr opt-out | ||
defaultClient = detectors.DetectorHttpClientWithNoLocalAddresses | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -13,6 +13,7 @@ import ( | |
|
||
var ( | ||
validPattern = "https://kaNydBSAodo87dsm9asuiSAFtsd7.com:1234@qYY3SylY7fHP" | ||
validPattern2 = `<p><a href="http://username:[email protected]">http://username:[email protected]</a></p>` | ||
invalidPattern = "https://kaNydBSAodo87dsm9asuiSAFtsd7.com.1234@qYY3SylY7fHP" | ||
keyword = "uri" | ||
) | ||
|
@@ -30,6 +31,11 @@ func TestURI_Pattern(t *testing.T) { | |
input: fmt.Sprintf("%s token = '%s'", keyword, validPattern), | ||
want: []string{validPattern}, | ||
}, | ||
{ | ||
name: "valid pattern - capture two outputs", | ||
input: fmt.Sprintf("%s token = '%s'", keyword, validPattern2), | ||
want: []string{"http://username:[email protected]", "http://username:[email protected]"}, | ||
}, | ||
{ | ||
name: "invalid pattern", | ||
input: fmt.Sprintf("%s = '%s'", keyword, invalidPattern), | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
\S
matches any non-whitespace character, which is very broad. Instead, we are now using\w
, which matches[A-Za-z0-9_]
, and extending it by adding a few special characters to suit our needs.