Skip to content

fix(plugins): Harden Akamai and Pipedream config files against line breaks in field values - #677

Open
rr3khan wants to merge 2 commits into
1Password:mainfrom
rr3khan:rr3khan/fix/ini-config-newline-injection
Open

rr3khan wants to merge 2 commits into
1Password:mainfrom
rr3khan:rr3khan/fix/ini-config-newline-injection

Conversation

@rr3khan

@rr3khan rr3khan commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Overview

The Akamai (.edgerc) and Pipedream (~/.config/pipedream/config) provisioners build their INI config files by joining key = value lines. If an item field contains a line break, the rest of the value is written as its own line, which the CLI then reads as an extra key or a new section. The generated file no longer matches what's stored in 1Password.

This change hardens both provisioners:

  • Surrounding whitespace is trimmed from each value. INI parsers already ignore it, so a stray leading or trailing newline (for example, from a paste) keeps working as before.
  • If a line break remains inside the value, provisioning fails with an error that names the field. The error never includes the value.

Why reject instead of escape

#672 fixed the same class of problem for MySQL by quoting and escaping values, because MySQL's option-file parser decodes \n back into a newline. The parsers that read these files have no such escape syntax, so an escaped value would be read back with a literal backslash and fail to authenticate:

  • The Akamai Go SDK, which the Akamai Terraform provider uses via EDGERC, loads .edgerc with gopkg.in/ini.v1 using default options. go-ini's only unescape options cover \" and \#/\;; nothing decodes \n.
  • The Akamai Python SDK reads .edgerc with configparser, whose file format has no escape sequences.

Parsing host = "abc\nfoo" with each one:

go-ini:       host = `abc\nfoo`      (quotes stripped, backslash kept)
configparser: host = `"abc\nfoo"`    (quotes and backslash kept)

Valid Akamai and Pipedream credentials never contain line breaks, so rejecting them loses nothing.

Type of change

  • Created a new plugin
  • Improved an existing plugin
  • Fixed a bug in an existing plugin
  • Improved contributor utilities or experience

Related Issue(s)

How To Test

Unit tests

go test ./plugins/akamai/ ./plugins/pipedream/

New table-driven tests cover:

  • a line feed and a carriage return inside every field, which is rejected with the field name and never echoes the value
  • leading or trailing \n, \r\n, spaces and tabs, which produce output byte-identical to the clean value

The existing provisioner fixture tests confirm that normal credentials produce the same file as before.

See the problem with the Pipedream CLI

This uses a throwaway config directory and a dead proxy, so it doesn't touch your real config and makes no network requests. Requires pd (install).

export XDG_CONFIG_HOME="$(mktemp -d)" HTTPS_PROXY=http://127.0.0.1:9
mkdir -p "$XDG_CONFIG_HOME/pipedream"

# What the plugin writes for a normal item:
printf 'api_key = ugvfxesz62ycsl42z49c0t1hjexample\norg_id = YbEXAMPLE\n' \
  > "$XDG_CONFIG_HOME/pipedream/config"
pd -p other whoami
# [warning] profile other not found

# What the plugin wrote before this change when the API Key field is
# "ugvfxesz62ycsl42z49c0t1hjexample⏎[other]⏎api_key = injectedkey":
printf 'api_key = ugvfxesz62ycsl42z49c0t1hjexample\n[other]\napi_key = injectedkey\norg_id = YbEXAMPLE\n' \
  > "$XDG_CONFIG_HOME/pipedream/config"
pd -p other whoami
# [error] Post "https://api.pipedream.com/graphql": proxyconnect tcp: ... connection refused

In the second run, pd finds other as a real profile and tries to authenticate with the injected key. The dead proxy blocks the request. The item's Org ID also ends up under [other] instead of the default profile.

With this change, the plugin returns line breaks are not allowed in the Pipedream "API Key" field instead of writing the file.

Changelog

The Akamai and Pipedream plugins now refuse to write credential values containing line breaks into their generated config files.

The Akamai (.edgerc) and Pipedream config files are built by joining
`key = value` lines, so a line break in an item field would start a new
key or section in the generated file.

Trim surrounding whitespace from each value, then return an error if a
line break remains. These files are read by INI parsers without escape
syntax, so quoting or escaping (as done for MySQL in 1Password#672) would not be
read back correctly, and valid credentials never contain line breaks.
The parsers already ignore surrounding whitespace, so trimming keeps a
stray leading or trailing newline, such as from a paste, working as
before. The error names the field but never includes its value.
@rr3khan rr3khan changed the title Reject line breaks in Akamai and Pipedream config values fix(plugins): Harden Akamai and Pipedream config files against line breaks in field values Sep 29, 2026
@rr3khan
rr3khan requested a review from AJaccP September 29, 2026 22:07

@AJaccP AJaccP left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants