Conversation
The Akamai (.edgerc) and Pipedream config files are built by joining `key = value` lines, so a line break in an item field would start a new key or section in the generated file. Trim surrounding whitespace from each value, then return an error if a line break remains. These files are read by INI parsers without escape syntax, so quoting or escaping (as done for MySQL in 1Password#672) would not be read back correctly, and valid credentials never contain line breaks. The parsers already ignore surrounding whitespace, so trimming keeps a stray leading or trailing newline, such as from a paste, working as before. The error names the field but never includes its value.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
The Akamai (
.edgerc) and Pipedream (~/.config/pipedream/config) provisioners build their INI config files by joiningkey = valuelines. If an item field contains a line break, the rest of the value is written as its own line, which the CLI then reads as an extra key or a new section. The generated file no longer matches what's stored in 1Password.This change hardens both provisioners:
Why reject instead of escape
#672 fixed the same class of problem for MySQL by quoting and escaping values, because MySQL's option-file parser decodes
\nback into a newline. The parsers that read these files have no such escape syntax, so an escaped value would be read back with a literal backslash and fail to authenticate:EDGERC, loads.edgercwithgopkg.in/ini.v1using default options.go-ini's only unescape options cover\"and\#/\;; nothing decodes\n..edgercwithconfigparser, whose file format has no escape sequences.Parsing
host = "abc\nfoo"with each one:Valid Akamai and Pipedream credentials never contain line breaks, so rejecting them loses nothing.
Type of change
Related Issue(s)
How To Test
Unit tests
go test ./plugins/akamai/ ./plugins/pipedream/New table-driven tests cover:
\n,\r\n, spaces and tabs, which produce output byte-identical to the clean valueThe existing provisioner fixture tests confirm that normal credentials produce the same file as before.
See the problem with the Pipedream CLI
This uses a throwaway config directory and a dead proxy, so it doesn't touch your real config and makes no network requests. Requires
pd(install).In the second run,
pdfindsotheras a real profile and tries to authenticate with the injected key. The dead proxy blocks the request. The item's Org ID also ends up under[other]instead of the default profile.With this change, the plugin returns
line breaks are not allowed in the Pipedream "API Key" fieldinstead of writing the file.Changelog
The Akamai and Pipedream plugins now refuse to write credential values containing line breaks into their generated config files.