Enforce public rate limits in production config

This commit is contained in:
SimpleTest 2026-08-03 21:46:03 +03:00
parent da19893b36
commit 07f96a6070
3 changed files with 92 additions and 0 deletions

View File

@ -131,6 +131,35 @@ valid_nonempty_csv() {
done done
} }
valid_public_rate_limit_policy() {
local json=$1
command -v jq >/dev/null 2>&1 || return 1
printf '%s' "$json" | jq -e '
type == "object" and
length > 0 and
([
"registration_email",
"registration_ip",
"magic_link_email",
"magic_link_ip",
"password_login_email",
"password_login_ip",
"email_change_email",
"email_change_ip",
"support_request",
"support_request_ip",
"content_removal_notice",
"content_removal_notice_ip"
] | all(. as $action |
($json[$action] | type == "object") and
($json[$action].limit | type == "number" and floor == . and . > 0) and
($json[$action].window_seconds | type == "number" and floor == . and . > 0)
))
' --argjson json "$json" >/dev/null 2>&1
}
failures=0 failures=0
warnings=0 warnings=0
@ -202,6 +231,17 @@ else
missing "support inbox" "SUPPORT_INBOX_ADDRESS" missing "support inbox" "SUPPORT_INBOX_ADDRESS"
fi fi
rate_limit_policies_json=$(value RATE_LIMIT_POLICIES_JSON)
if [[ "$deployment_env" == test && "$rate_limit_policies_json" == "{}" ]]; then
local_only "public rate limits" "all shared counters are disabled for this isolated test deployment"
elif [[ -z "$rate_limit_policies_json" ]]; then
missing "public rate limits" "RATE_LIMIT_POLICIES_JSON"
elif valid_public_rate_limit_policy "$rate_limit_policies_json"; then
ready "public rate limits" "authentication and anonymous-intake policies are enabled"
else
invalid "public rate limits" "required public policies are missing, malformed, or disabled"
fi
if all_empty GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then if all_empty GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then
missing "Google sign-in" "GOOGLE_OAUTH_CLIENT_ID and GOOGLE_OAUTH_CLIENT_SECRET" missing "Google sign-in" "GOOGLE_OAUTH_CLIENT_ID and GOOGLE_OAUTH_CLIENT_SECRET"
elif all_set GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then elif all_set GOOGLE_OAUTH_CLIENT_ID GOOGLE_OAUTH_CLIENT_SECRET; then

View File

@ -671,6 +671,20 @@ grep -Fx 'GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS=quality-production-android-client' \
"$production_env" >/dev/null "$production_env" >/dev/null
./scripts/validate-production-env.sh "$production_env" help.test >/dev/null ./scripts/validate-production-env.sh "$production_env" help.test >/dev/null
./scripts/check-environment-readiness.sh "$production_env" --require-release >/dev/null ./scripts/check-environment-readiness.sh "$production_env" --require-release >/dev/null
disabled_rate_limits_env="$scan_dir/production.disabled-rate-limits.env"
cp "$production_env" "$disabled_rate_limits_env"
sed -i 's|^RATE_LIMIT_POLICIES_JSON=.*|RATE_LIMIT_POLICIES_JSON={}|' \
"$disabled_rate_limits_env"
if ./scripts/validate-production-env.sh \
"$disabled_rate_limits_env" help.test >/dev/null 2>&1; then
echo "Production validation accepted disabled shared rate limits." >&2
exit 1
fi
if ./scripts/check-environment-readiness.sh \
"$disabled_rate_limits_env" --require-release >/dev/null 2>&1; then
echo "Environment readiness accepted disabled shared rate limits." >&2
exit 1
fi
if PRODUCTION_CODEX_SESSION_ID=00000000-0000-0000-0000-000000000001 \ if PRODUCTION_CODEX_SESSION_ID=00000000-0000-0000-0000-000000000001 \
PRODUCTION_WNH_FIREBASE_APPLICATION_ID=1:987654321:android:quality \ PRODUCTION_WNH_FIREBASE_APPLICATION_ID=1:987654321:android:quality \
PRODUCTION_WNH_FIREBASE_API_KEY=quality-public-client-key \ PRODUCTION_WNH_FIREBASE_API_KEY=quality-public-client-key \

View File

@ -92,6 +92,38 @@ valid_nonempty_csv() {
done done
} }
valid_public_rate_limit_policy() {
local json=$1
command -v jq >/dev/null 2>&1 || {
echo "Required command is unavailable for rate-limit validation: jq" >&2
return 1
}
printf '%s' "$json" | jq -e '
type == "object" and
length > 0 and
([
"registration_email",
"registration_ip",
"magic_link_email",
"magic_link_ip",
"password_login_email",
"password_login_ip",
"email_change_email",
"email_change_ip",
"support_request",
"support_request_ip",
"content_removal_notice",
"content_removal_notice_ip"
] | all(. as $action |
($json[$action] | type == "object") and
($json[$action].limit | type == "number" and floor == . and . > 0) and
($json[$action].window_seconds | type == "number" and floor == . and . > 0)
))
' --argjson json "$json" >/dev/null 2>&1
}
reject_marker() { reject_marker() {
local key=$1 local key=$1
local value=$2 local value=$2
@ -145,6 +177,7 @@ smtp_tls=$(optional_value SMTP_TLS)
smtp_ssl=$(optional_value SMTP_SSL) smtp_ssl=$(optional_value SMTP_SSL)
email_from_address=$(require_value EMAIL_FROM_ADDRESS) email_from_address=$(require_value EMAIL_FROM_ADDRESS)
support_inbox_address=$(optional_value SUPPORT_INBOX_ADDRESS) support_inbox_address=$(optional_value SUPPORT_INBOX_ADDRESS)
rate_limit_policies_json=$(require_value RATE_LIMIT_POLICIES_JSON)
google_oauth_client_id=$(optional_value GOOGLE_OAUTH_CLIENT_ID) google_oauth_client_id=$(optional_value GOOGLE_OAUTH_CLIENT_ID)
google_oauth_client_secret=$(optional_value GOOGLE_OAUTH_CLIENT_SECRET) google_oauth_client_secret=$(optional_value GOOGLE_OAUTH_CLIENT_SECRET)
google_oauth_authorized_party_ids=$(optional_value GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS) google_oauth_authorized_party_ids=$(optional_value GOOGLE_OAUTH_AUTHORIZED_PARTY_IDS)
@ -374,6 +407,11 @@ if [[ -n "$support_inbox_address" &&
exit 1 exit 1
fi fi
valid_public_rate_limit_policy "$rate_limit_policies_json" || {
echo "RATE_LIMIT_POLICIES_JSON must enable every documented public authentication and intake policy with positive integer limit and window_seconds values; {} is reserved for isolated tests." >&2
exit 1
}
if [[ -n "$google_oauth_client_id" || -n "$google_oauth_client_secret" ]]; then if [[ -n "$google_oauth_client_id" || -n "$google_oauth_client_secret" ]]; then
[[ -n "$google_oauth_client_id" && -n "$google_oauth_client_secret" ]] || { [[ -n "$google_oauth_client_id" && -n "$google_oauth_client_secret" ]] || {
echo "Google OAuth client ID and secret must either both be set or both be empty." >&2 echo "Google OAuth client ID and secret must either both be set or both be empty." >&2