diff --git a/backend/app/services/github_restore.py b/backend/app/services/github_restore.py index 881714b17..74ddcbce0 100644 --- a/backend/app/services/github_restore.py +++ b/backend/app/services/github_restore.py @@ -72,8 +72,13 @@ _KPROFILE_PATH_RE = re.compile(r"^kprofiles/([^/]+)/([^/]+)\.json$") # contain them, and a restore must not resurrect a stale credential. _SENSITIVE_SETTING_KEYS = {"bambu_cloud_token", "auth_secret_key"} -# Belt-and-braces for the same reason: any key that looks like a secret is -# skipped even if it isn't in the explicit denylist above. +# The primary refusal, not a backstop for the set above. The collector filters +# exactly bambu_cloud_token and auth_secret_key, so every other credential — +# mqtt_password, ldap_bind_password, ha_token, prometheus_token — is present in +# a current backup and is skipped only because its key matches a hint here. +# _COMPANION_CREDENTIALS sits downstream of that: it withholds a toggle when the +# credential it needs was refused, so shortening this tuple would both write a +# stale credential and quietly make that rule inert. _SECRET_KEY_HINTS = ("token", "secret", "password", "access_code", "api_key", "passphrase") # Settings the MQTT relay reads only when it is (re)configured, so restoring the diff --git a/backend/tests/unit/test_github_restore.py b/backend/tests/unit/test_github_restore.py index 1cb96ee39..d2099a039 100644 --- a/backend/tests/unit/test_github_restore.py +++ b/backend/tests/unit/test_github_restore.py @@ -125,8 +125,9 @@ class TestSettingKeyBlocklist: Carving it out would also be a live hole rather than a tidy-up: an attacker-authored ``settings/app_settings.json`` could then get a ``*token*``-named row written simply by choosing that name. This - blocklist's whole job is belt-and-braces, so a name-shaped exception to - it is exactly the wrong shape of fix. + The hints are the primary refusal for every credential the collector + does not filter, so a name-shaped exception to them is exactly the wrong + shape of fix. """ assert _is_blocked_setting_key("ha_token_from_env") is True