Skip to content

Security/review remediation - #98

Merged
VanDelinea merged 4 commits into
feature/server-detectionfrom
security/review_remediation
Aug 12, 2026
Merged

Security/review remediation#98
VanDelinea merged 4 commits into
feature/server-detectionfrom
security/review_remediation

Conversation

@VanDelinea

Copy link
Copy Markdown

No description provided.

…, attach response to errors, 🧪 add offline security tests

security review remediation, phase 1 (DevPlan.md)
==

- every http call now passes an explicit timeout via DEFAULT_REQUEST_TIMEOUT;
  the folder and lookup calls had none and could hang a consumer forever
- oauth2 grant now refreshes up to 300s before expiry; the drift sign was
  inverted so expired tokens were reused for up to 300s past expiry
- SecretServerError keeps the server response (error.response works now);
  a 4xx json body without message/error keys no longer masks the failure
  with UnboundLocalError
- example masks the password value instead of printing it
- new offline test suite covers timeout coverage on every request path,
  refresh boundary behavior, and error plumbing; no live credentials needed
…n, sanitize error bodies, validate vault redirect, 🧪 add offline security tests

security review remediation, phase 2 (DevPlan.md)
==

- warn (UserWarning) when base_url is not https; credentials and bearer
  tokens would otherwise travel in plaintext with no signal to the caller.
  strict rejection is deferred to v3.0 to avoid breaking localhost/lab setups
- health-check probing now requires a 2xx status and an exact "healthy"
  match instead of a substring check; the old check matched "Unhealthy" and
  ignored the http status entirely
- exception messages no longer echo raw response bodies; the secrets
  endpoint omits the body outright, other endpoints get a capped, clearly
  truncated excerpt
- the platform vault-broker redirect url is now required to be a valid
  https url before any token is sent to it
- SecretServerError now passes its message through to Exception.__init__,
  so str(error) is populated instead of always empty
- new offline test suite covers all four fixes; existing FakeResponse
  fixtures updated with .ok/.status_code/.text to match the tightened
  health-check contract
…lease to pypi trusted publishing, align tox deps with pinned requirements

security review remediation, phase 3 (DevPlan.md)
==

- every workflow now declares least-privilege permissions at the top level;
  the lint job (needs to push auto-fix commits and publish check results)
  and the release job (needs the oidc token) grant themselves only what they
  actually use
- pypa/gh-action-pypi-publish was pinned to the mutable release/v1 branch,
  the only unpinned action in the repo; now pinned to the v1.14.2 commit sha
- release.yml drops the long-lived PYPI_API_TOKEN in favor of PyPI Trusted
  Publishing (OIDC) -- requires a trusted publisher to be configured for
  this repo/workflow on pypi.org before the next tag push; keep the repo
  secret until that is confirmed working
- tox.ini and lint.yml now install the versions pinned in requirements.txt
  (black==26.5.1, flit==3.12.0, and the full pinned set via -r
  requirements.txt) instead of floating latest, so CI exercises what
  consumers actually get
…SECURITY.md, 🚀 split runtime/dev deps and pin pip

- token refresh now locked and utc-aware; mutable default args removed
- fixed get_folder_json crash on bare call, itemValue returning a Response
  object instead of text, and an unvalidated non-numeric secrets count
- requirements.txt split into runtime-only pins with a new
  requirements-dev.txt for build/test tooling; pip>=26.2 pinned there and
  in release.yml (transitive via flit; CVE-2026-8643 and others)
@snyk-io

snyk-io Bot commented Aug 12, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@VanDelinea
VanDelinea merged commit a62f6c9 into feature/server-detection Aug 12, 2026
6 checks passed
@VanDelinea
VanDelinea deleted the security/review_remediation branch August 12, 2026 19:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant