fix(SEC-33,SEC-34): address code review — missed docs, key-id guard comment, test consolidation
Same-commit docs rule (were missed in the prior commit): - docs/GalaxyRepository.md: SnapshotCachePath now documents the per-OS derived default and the GalaxyRepositoryOptionsValidator rooting/validity enforcement. - A2-galaxyrepository-adoption-handoff.md: correct the now-inaccurate NSSM caveat (SnapshotCachePath override is optional, not required; blank seeds a rooted host default, no silent no-op) and repoint the option-validation item at the new GalaxyRepositoryOptionsValidator. SEC-34 guard confirmed and documented: TryParseKeyId's '_' split cannot truncate a key id because both — and the only — gateway key-creation paths (ApiKeyAdminCommandLineParser.IsValidKeyId, DashboardApiKeyManagementService.ValidateKeyId) restrict key ids to IsAsciiLetterOrDigit || '.' || '-', and key ids are never library-generated. Added a citing comment; no behavior change. Test consolidation: moved the three host-start SqlitePath overrides into TestHostEnvironmentInitializer (per-process temp store, mirroring Secrets__SqlitePath) so future host-start tests auto-cover.
This commit is contained in:
@@ -205,6 +205,14 @@ public sealed class CachingApiKeyVerifier : IApiKeyVerifier, IApiKeyCacheInvalid
|
||||
// Parses the key id out of a "Bearer mxgw_<keyId>_<secret>" header without any store access —
|
||||
// the same split the authorization interceptor does. Returns null for a header this cache cannot
|
||||
// attribute to a key id (in which case the generation race-guard is simply not applied).
|
||||
//
|
||||
// Correctness of the SEC-34 generation guard rests on parts[1] being the FULL key id: the '_'
|
||||
// split would truncate a key id that itself contained '_', silently disarming the guard for that
|
||||
// key. This is safe because '_' is the token's field delimiter and both — and the only — key
|
||||
// creation paths in the gateway forbid it: ApiKeyAdminCommandLineParser.IsValidKeyId and
|
||||
// DashboardApiKeyManagementService.ValidateKeyId each restrict a key id to
|
||||
// char.IsAsciiLetterOrDigit || '.' || '-'. Key ids are never library-generated, so no path can
|
||||
// mint one containing '_'.
|
||||
private static string? TryParseKeyId(string? authorizationHeader)
|
||||
{
|
||||
if (string.IsNullOrEmpty(authorizationHeader))
|
||||
|
||||
Reference in New Issue
Block a user