Address gosec findings

Mostly handling unhandled errors appropriately.
If logging to STDERR fails, we panic. Added #nosec
comments to findings we are OK with.
This commit is contained in:
Nick Meves
2020-08-09 07:55:39 -07:00
parent 7b21f53aad
commit 65c228394f
16 changed files with 155 additions and 41 deletions
+16 -8
View File
@@ -1,7 +1,7 @@
package basic
import (
"crypto/sha1"
"crypto/sha1" // #nosec G505
"encoding/base64"
"encoding/csv"
"fmt"
@@ -29,11 +29,16 @@ type sha1Pass string
// NewHTPasswdValidator constructs an httpasswd based validator from the file
// at the path given.
func NewHTPasswdValidator(path string) (Validator, error) {
r, err := os.Open(path)
r, err := os.Open(path) // #nosec G304
if err != nil {
return nil, fmt.Errorf("could not open htpasswd file: %v", err)
}
defer r.Close()
defer func(c io.Closer) {
cerr := c.Close()
if cerr != nil {
logger.Fatalf("error closing the htpasswd file: %v", cerr)
}
}(r)
return newHtpasswd(r)
}
@@ -83,13 +88,16 @@ func (h *htpasswdMap) Validate(user string, password string) bool {
return false
}
switch real := realPassword.(type) {
switch rp := realPassword.(type) {
case sha1Pass:
d := sha1.New()
d.Write([]byte(password))
return string(real) == base64.StdEncoding.EncodeToString(d.Sum(nil))
d := sha1.New() // #nosec G401
_, err := d.Write([]byte(password))
if err != nil {
return false
}
return string(rp) == base64.StdEncoding.EncodeToString(d.Sum(nil))
case bcryptPass:
return bcrypt.CompareHashAndPassword([]byte(real), []byte(password)) == nil
return bcrypt.CompareHashAndPassword([]byte(rp), []byte(password)) == nil
default:
return false
}