Check the staged diff for credentials before push commits
`push` runs `git add --all .`, so anything lying in the project gets committed, and with `mirror = true` it reaches a public server in the same breath. It is the one action in mgsh that cannot be undone: a deleted server repository comes back from an archive, a published credential does not. The staged diff is now scanned before the commit is made -- private keys, GitHub/GitLab/Slack/AWS/PyPI tokens, and credential-shaped assignments -- and a hit is shown with file and line before asking whether to continue. Declining leaves the changes staged but uncommitted, so removing the file and adding a .gitignore entry is all it takes. The hard part is not detection but silence. A scanner that cries wolf gets answered with a reflexive "y" and stops being a safety net, so values that are plainly environment references, dotted identifiers, constant names, template slots or masked stand-ins are filtered out. A test scans mgsh's own README and mgshrc.example -- both full of credential-shaped text -- and fails if either would trip the check. It caught the documentation for this very feature, which is why the README describes the sample output instead of reproducing it. For a line that legitimately looks like a credential there is `mgsh:allow`, which suppresses that one line; `secretscan = off` turns the check off entirely. Only an explicit "off" does that -- a typo in the setting leaves the safety net in place, which is what the new falsy() is for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -38,6 +38,7 @@ type Config struct {
|
||||
RemoteType string // "gitea"|"github"|"gitlab" (auto-detected when empty)
|
||||
RemoteVis string // visibility of created repos: "private" (default)|"public"
|
||||
Mirror string // truthy -> `push` also mirrors via `pushremote`
|
||||
SecretScan string // falsy -> `push` skips the credential scan
|
||||
Remotes []RemoteTarget
|
||||
RemoteNames string // "remotes": explicit, ordered subset of targets to use
|
||||
}
|
||||
@@ -370,6 +371,7 @@ func applyConfig(c *Config, m map[string]string) {
|
||||
set("remotevisibility", &c.RemoteVis)
|
||||
set("remotes", &c.RemoteNames)
|
||||
set("mirror", &c.Mirror)
|
||||
set("secretscan", &c.SecretScan)
|
||||
applyRemoteTargets(c, m)
|
||||
}
|
||||
|
||||
@@ -443,4 +445,5 @@ func applyEnv(c *Config) {
|
||||
env("MGSH_REMOTEVISIBILITY", &c.RemoteVis)
|
||||
env("MGSH_REMOTES", &c.RemoteNames)
|
||||
env("MGSH_MIRROR", &c.Mirror)
|
||||
env("MGSH_SECRETSCAN", &c.SecretScan)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user