Small fixes

This commit is contained in:
Daniel Inge
2023-09-01 23:08:38 +01:00
parent 4adb2a623e
commit 011507b8e0
3 changed files with 54 additions and 55 deletions
+1
View File
@@ -57,3 +57,4 @@ yarn-error.log*
# Infisical init # Infisical init
.infisical.json .infisical.json
.vscode
@@ -4,7 +4,7 @@ import { tmpdir } from "os";
import { join } from "path" import { join } from "path"
import { SecretMatch } from "./types"; import { SecretMatch } from "./types";
export async function scanFullContentAndGetFindings(octokit: any, installationId: number, repositoryFullName: string): Promise<SecretMatch[]> { export async function scanFullRepoContentAndGetFindings(octokit: any, installationId: number, repositoryFullName: string): Promise<SecretMatch[]> {
const tempFolder = await createTempFolder(); const tempFolder = await createTempFolder();
const findingsPath = join(tempFolder, "findings.json"); const findingsPath = join(tempFolder, "findings.json");
const repoPath = join(tempFolder, "repo.git") const repoPath = join(tempFolder, "repo.git")
@@ -5,7 +5,7 @@ import { sendMail } from "../../helpers";
import GitRisks from "../../ee/models/gitRisks"; import GitRisks from "../../ee/models/gitRisks";
import { MembershipOrg, User } from "../../models"; import { MembershipOrg, User } from "../../models";
import { ADMIN, OWNER } from "../../variables"; import { ADMIN, OWNER } from "../../variables";
import { convertKeysToLowercase, scanFullContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper"; import { convertKeysToLowercase, scanFullRepoContentAndGetFindings } from "../../ee/services/GithubSecretScanning/helper";
import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config"; import { getSecretScanningGitAppId, getSecretScanningPrivateKey } from "../../config";
import { SecretMatch } from "../../ee/services/GithubSecretScanning/types"; import { SecretMatch } from "../../ee/services/GithubSecretScanning/types";
@@ -22,72 +22,70 @@ type TScanPushEventQueueDetails = {
githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback) => { githubFullRepositorySecretScan.process(async (job: Job, done: Queue.DoneCallback) => {
const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data const { organizationId, repository, installationId }: TScanPushEventQueueDetails = job.data
const octokit = new ProbotOctokit({ try {
auth: { const octokit = new ProbotOctokit({
appId: await getSecretScanningGitAppId(), auth: {
privateKey: await getSecretScanningPrivateKey(), appId: await getSecretScanningGitAppId(),
installationId: installationId privateKey: await getSecretScanningPrivateKey(),
}, installationId: installationId
}); },
try { });
const findings : SecretMatch[] = await scanFullContentAndGetFindings(octokit, installationId, repository.fullName) const findings : SecretMatch[] = await scanFullRepoContentAndGetFindings(octokit, installationId, repository.fullName)
for (const finding of findings) {
for (const finding of findings) { await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint},
await GitRisks.findOneAndUpdate({ fingerprint: finding.Fingerprint}, {
{
...convertKeysToLowercase(finding), ...convertKeysToLowercase(finding),
installationId: installationId, installationId: installationId,
organization: organizationId, organization: organizationId,
repositoryFullName: repository.fullName, repositoryFullName: repository.fullName,
repositoryId: repository.id repositoryId: repository.id
}, { }, {
upsert: true upsert: true
}).lean() }).lean()
}
// get emails of admins
const adminsOfWork = await MembershipOrg.find({
organization: organizationId,
$or: [
{ role: OWNER },
{ role: ADMIN }
]
}).lean()
const userEmails = await User.find({
_id: {
$in: [adminsOfWork.map(orgMembership => orgMembership.user)]
} }
}).select("email").lean()
const usersToNotify = userEmails.map(userObject => userObject.email) // get emails of admins
const adminsOfWork = await MembershipOrg.find({
organization: organizationId,
$or: [
{ role: OWNER },
{ role: ADMIN }
]
}).lean()
if (findings.length) { const userEmails = await User.find({
await sendMail({ _id: {
template: "historicalSecretLeakIncident.handlebars", $in: [adminsOfWork.map(orgMembership => orgMembership.user)]
subjectLine: `Incident alert: leaked secrets found in Github repository ${repository.fullName}`,
recipients: usersToNotify,
substitutions: {
numberOfSecrets: findings.length,
} }
}); }).select("email").lean()
}
const postHogClient = await TelemetryService.getPostHogClient(); const usersToNotify = userEmails.map(userObject => userObject.email)
if (postHogClient) {
postHogClient.capture({ if (findings.length) {
event: "historical cloud secret scan", await sendMail({
distinctId: repository.fullName, template: "historicalSecretLeakIncident.handlebars",
properties: { subjectLine: `Incident alert: leaked secrets found in Github repository ${repository.fullName}`,
numberOfRisksFound: findings.length, recipients: usersToNotify,
} substitutions: {
}); numberOfSecrets: findings.length,
} }
done(null, findings) });
} catch (error) { }
const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) {
postHogClient.capture({
event: "historical cloud secret scan",
distinctId: repository.fullName,
properties: {
numberOfRisksFound: findings.length,
}
});
}
done(null, findings)
} catch (error) {
done(new Error(`gitHubHistoricalScanning.process: an error occurred ${error}`), null) done(new Error(`gitHubHistoricalScanning.process: an error occurred ${error}`), null)
} }
}) })
export const scanGithubFullRepoForSecretLeaks = (pushEventPayload: TScanPushEventQueueDetails) => { export const scanGithubFullRepoForSecretLeaks = (pushEventPayload: TScanPushEventQueueDetails) => {