Enforce public rate limits in production config
This commit is contained in:
parent
da19893b36
commit
07f96a6070
|
|
@ -131,6 +131,35 @@ valid_nonempty_csv() {
|
||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
|
valid_public_rate_limit_policy() {
|
||||||
|
local json=$1
|
||||||
|
|
||||||
|
command -v jq >/dev/null 2>&1 || return 1
|
||||||
|
|
||||||
|
printf '%s' "$json" | jq -e '
|
||||||
|
type == "object" and
|
||||||
|
length > 0 and
|
||||||
|
([
|
||||||
|
"registration_email",
|
||||||
|
"registration_ip",
|
||||||
|
"magic_link_email",
|
||||||
|
"magic_link_ip",
|
||||||
|
"password_login_email",
|
||||||
|
"password_login_ip",
|
||||||
|
"email_change_email",
|
||||||
|
"email_change_ip",
|
||||||
|
"support_request",
|
||||||
|
"support_request_ip",
|
||||||
|
"content_removal_notice",
|
||||||
|
"content_removal_notice_ip"
|
||||||
|
] | all(. as $action |
|
||||||
|
($json[$action] | type == "object") and
|
||||||
|
($json[$action].limit | type == "number" and floor == . and . > 0) and
|
||||||
|
($json[$action].window_seconds | type == "number" and floor == . and . > 0)
|
||||||
|
))
|
||||||
|
' --argjson json "$json" >/dev/null 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
failures=0
|
failures=0
|
||||||
warnings=0
|
warnings=0
|
||||||
|
|
||||||
|
|
@ -202,6 +231,17 @@ else
|
||||||
missing "support inbox" "SUPPORT_INBOX_ADDRESS"
|
missing "support inbox" "SUPPORT_INBOX_ADDRESS"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
rate_limit_policies_json=$(value RATE_LIMIT_POLICIES_JSON)
|
||||||
|
if [[ "$deployment_env" == test && "$rate_limit_policies_json" == "{}" ]]; then
|
||||||
|
local_only "public rate limits" "all shared counters are disabled for this isolated test deployment"
|
||||||
|
elif [[ -z "$rate_limit_policies_json" ]]; then
|
||||||
|
missing "public rate limits" "RATE_LIMIT_POLICIES_JSON"
|
||||||
|
elif valid_public_rate_limit_policy "$rate_limit_policies_json"; then
|
||||||
|
ready "public rate limits" "authentication and anonymous-intake policies are enabled"
|
||||||
|
else
|
||||||
|
invalid "public rate limits" "required public policies are missing, malformed, or disabled"
|
||||||
|
fi
|
||||||
|
|
||||||
if all_empty GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then
|
if all_empty GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then
|
||||||
missing "Google sign-in" "GOOGLE_OAUTH_CLIENT_ID and GOOGLE_OAUTH_CLIENT_SECRET"
|
missing "Google sign-in" "GOOGLE_OAUTH_CLIENT_ID and GOOGLE_OAUTH_CLIENT_SECRET"
|
||||||
elif all_set GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then
|
elif all_set GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then
|
||||||
|
|
|
||||||
|
|
@ -671,6 +671,20 @@ grep -Fx 'GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS=quality-production-android-client' \
|
||||||
"$production_env" >/dev/null
|
"$production_env" >/dev/null
|
||||||
./scripts/validate-production-env.sh "$production_env" help.test >/dev/null
|
./scripts/validate-production-env.sh "$production_env" help.test >/dev/null
|
||||||
./scripts/check-environment-readiness.sh "$production_env" --require-release >/dev/null
|
./scripts/check-environment-readiness.sh "$production_env" --require-release >/dev/null
|
||||||
|
disabled_rate_limits_env="$scan_dir/production.disabled-rate-limits.env"
|
||||||
|
cp "$production_env" "$disabled_rate_limits_env"
|
||||||
|
sed -i 's|^RATE_LIMIT_POLICIES_JSON=.*|RATE_LIMIT_POLICIES_JSON={}|' \
|
||||||
|
"$disabled_rate_limits_env"
|
||||||
|
if ./scripts/validate-production-env.sh \
|
||||||
|
"$disabled_rate_limits_env" help.test >/dev/null 2>&1; then
|
||||||
|
echo "Production validation accepted disabled shared rate limits." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if ./scripts/check-environment-readiness.sh \
|
||||||
|
"$disabled_rate_limits_env" --require-release >/dev/null 2>&1; then
|
||||||
|
echo "Environment readiness accepted disabled shared rate limits." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
if PRODUCTION_CODEX_SESSION_ID=00000000-0000-0000-0000-000000000001 \
|
if PRODUCTION_CODEX_SESSION_ID=00000000-0000-0000-0000-000000000001 \
|
||||||
PRODUCTION_WNH_FIREBASE_APPLICATION_ID=1:987654321:android:quality \
|
PRODUCTION_WNH_FIREBASE_APPLICATION_ID=1:987654321:android:quality \
|
||||||
PRODUCTION_WNH_FIREBASE_API_KEY=quality-public-client-key \
|
PRODUCTION_WNH_FIREBASE_API_KEY=quality-public-client-key \
|
||||||
|
|
|
||||||
|
|
@ -92,6 +92,38 @@ valid_nonempty_csv() {
|
||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
|
valid_public_rate_limit_policy() {
|
||||||
|
local json=$1
|
||||||
|
|
||||||
|
command -v jq >/dev/null 2>&1 || {
|
||||||
|
echo "Required command is unavailable for rate-limit validation: jq" >&2
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
printf '%s' "$json" | jq -e '
|
||||||
|
type == "object" and
|
||||||
|
length > 0 and
|
||||||
|
([
|
||||||
|
"registration_email",
|
||||||
|
"registration_ip",
|
||||||
|
"magic_link_email",
|
||||||
|
"magic_link_ip",
|
||||||
|
"password_login_email",
|
||||||
|
"password_login_ip",
|
||||||
|
"email_change_email",
|
||||||
|
"email_change_ip",
|
||||||
|
"support_request",
|
||||||
|
"support_request_ip",
|
||||||
|
"content_removal_notice",
|
||||||
|
"content_removal_notice_ip"
|
||||||
|
] | all(. as $action |
|
||||||
|
($json[$action] | type == "object") and
|
||||||
|
($json[$action].limit | type == "number" and floor == . and . > 0) and
|
||||||
|
($json[$action].window_seconds | type == "number" and floor == . and . > 0)
|
||||||
|
))
|
||||||
|
' --argjson json "$json" >/dev/null 2>&1
|
||||||
|
}
|
||||||
|
|
||||||
reject_marker() {
|
reject_marker() {
|
||||||
local key=$1
|
local key=$1
|
||||||
local value=$2
|
local value=$2
|
||||||
|
|
@ -145,6 +177,7 @@ smtp_tls=$(optional_value SMTP_TLS)
|
||||||
smtp_ssl=$(optional_value SMTP_SSL)
|
smtp_ssl=$(optional_value SMTP_SSL)
|
||||||
email_from_address=$(require_value EMAIL_FROM_ADDRESS)
|
email_from_address=$(require_value EMAIL_FROM_ADDRESS)
|
||||||
support_inbox_address=$(optional_value SUPPORT_INBOX_ADDRESS)
|
support_inbox_address=$(optional_value SUPPORT_INBOX_ADDRESS)
|
||||||
|
rate_limit_policies_json=$(require_value RATE_LIMIT_POLICIES_JSON)
|
||||||
google_oauth_client_id=$(optional_value GOOGLE_OAUTH_CLIENT_ID)
|
google_oauth_client_id=$(optional_value GOOGLE_OAUTH_CLIENT_ID)
|
||||||
google_oauth_client_secret=$(optional_value GOOGLE_OAUTH_CLIENT_SECRET)
|
google_oauth_client_secret=$(optional_value GOOGLE_OAUTH_CLIENT_SECRET)
|
||||||
google_oauth_authorized_party_ids=$(optional_value GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS)
|
google_oauth_authorized_party_ids=$(optional_value GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS)
|
||||||
|
|
@ -374,6 +407,11 @@ if [[ -n "$support_inbox_address" &&
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
valid_public_rate_limit_policy "$rate_limit_policies_json" || {
|
||||||
|
echo "RATE_LIMIT_POLICIES_JSON must enable every documented public authentication and intake policy with positive integer limit and window_seconds values; {} is reserved for isolated tests." >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
if [[ -n "$google_oauth_client_id" || -n "$google_oauth_client_secret" ]]; then
|
if [[ -n "$google_oauth_client_id" || -n "$google_oauth_client_secret" ]]; then
|
||||||
[[ -n "$google_oauth_client_id" && -n "$google_oauth_client_secret" ]] || {
|
[[ -n "$google_oauth_client_id" && -n "$google_oauth_client_secret" ]] || {
|
||||||
echo "Google OAuth client ID and secret must either both be set or both be empty." >&2
|
echo "Google OAuth client ID and secret must either both be set or both be empty." >&2
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user