mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 07:27:43 +00:00
93 lines
2.5 KiB
Go
93 lines
2.5 KiB
Go
// MIT License
|
|
|
|
// Copyright (c) 2019 Zachary Rice
|
|
|
|
// Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
// of this software and associated documentation files (the "Software"), to deal
|
|
// in the Software without restriction, including without limitation the rights
|
|
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
// copies of the Software, and to permit persons to whom the Software is
|
|
// furnished to do so, subject to the following conditions:
|
|
|
|
// The above copyright notice and this permission notice shall be included in all
|
|
// copies or substantial portions of the Software.
|
|
|
|
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
// SOFTWARE.
|
|
|
|
package report
|
|
|
|
import (
|
|
"math"
|
|
"strings"
|
|
)
|
|
|
|
// Finding contains information about strings that
|
|
// have been captured by a tree-sitter query.
|
|
type Finding struct {
|
|
// Rule is the name of the rule that was matched
|
|
RuleID string
|
|
Description string
|
|
|
|
StartLine int
|
|
EndLine int
|
|
StartColumn int
|
|
EndColumn int
|
|
|
|
Line string `json:"-"`
|
|
|
|
Match string
|
|
|
|
// Secret contains the full content of what is matched in
|
|
// the tree-sitter query.
|
|
Secret string
|
|
|
|
// File is the name of the file containing the finding
|
|
File string
|
|
SymlinkFile string
|
|
Commit string
|
|
Link string `json:",omitempty"`
|
|
|
|
// Entropy is the shannon entropy of Value
|
|
Entropy float32
|
|
|
|
Author string
|
|
Email string
|
|
Date string
|
|
Message string
|
|
Tags []string
|
|
|
|
// unique identifier
|
|
Fingerprint string
|
|
}
|
|
|
|
// Redact removes sensitive information from a finding.
|
|
func (f *Finding) Redact(percent uint) {
|
|
secret := maskSecret(f.Secret, percent)
|
|
if percent >= 100 {
|
|
secret = "REDACTED"
|
|
}
|
|
f.Line = strings.Replace(f.Line, f.Secret, secret, -1)
|
|
f.Match = strings.Replace(f.Match, f.Secret, secret, -1)
|
|
f.Secret = secret
|
|
}
|
|
|
|
func maskSecret(secret string, percent uint) string {
|
|
if percent > 100 {
|
|
percent = 100
|
|
}
|
|
len := float64(len(secret))
|
|
if len <= 0 {
|
|
return secret
|
|
}
|
|
prc := float64(100 - percent)
|
|
lth := int64(math.RoundToEven(len * prc / float64(100)))
|
|
|
|
return secret[:lth] + "..."
|
|
}
|