Skip to content

Feature/server detection - #95

Open
VanDelinea wants to merge 14 commits into
mainfrom
feature/server-detection
Open

Feature/server detection#95
VanDelinea wants to merge 14 commits into
mainfrom
feature/server-detection

Conversation

@VanDelinea

@VanDelinea VanDelinea commented Jun 23, 2026

Copy link
Copy Markdown
  • New process-scoped, thread-safe cache keyed by normalized base_url — detection fires at most once per base_url per process instead of on every Authorizer/SecretServer construction.
  • Only successful probes are cached; failures re-probe on the next call.
  • Explicit server_type override available for callers that don't need auto-detection.
  • Health-check validation tightened: requires a 2xx response and an exact "healthy" match (JSON Healthy: true or literal text) instead of a loose substring check, so an unhealthy or non-2xx response can no longer be mistaken for a pass.

VanDelinea and others added 3 commits June 8, 2026 12:13
Authorizer now memoizes the /api/v1/healthcheck + /health probe result in a
process-scoped, thread-safe class cache keyed by normalized base_url, so
detection fires once per base_url per process instead of on every authorizer
construction. Closes the unauthenticated-probe burst that the Delinea Platform
WAF rate-limits to 403 under Ansible token-auth lookups.

- successes only are cached; detection failures re-probe
- per-instance _server_type still set on cache hit (SecretServer + _refresh read it)
- adds first offline unit tests (tests/test_server_detection_cache.py)

Addresses 728859
@snyk-io

snyk-io Bot commented Jun 23, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

VanDelinea and others added 3 commits July 23, 2026 13:18
Clears CVE-2026-25645 (requests) and CVE-2026-44431/44432 (urllib3) per
work item 741117. The fixed releases require Python >= 3.10.

- requirements.txt: requests==2.34.2, urllib3==2.7.0
- pyproject.toml: requires-python >=3.10, requests floor >= 2.34.2
- tox.ini / run_tests.yml: matrix trimmed to 3.10-3.12
- README: minimum Python 3.10

BREAKING: drops Python 3.8/3.9 support (both EOL) and raises the
published requests floor for downstream consumers.
…rllib3-bump

🛡️ bump requests 2.34.2 & urllib3 2.7.0; drop Python 3.8/3.9
VanDelinea and others added 5 commits August 6, 2026 17:22
…, attach response to errors, 🧪 add offline security tests

security review remediation, phase 1 (DevPlan.md)
==

- every http call now passes an explicit timeout via DEFAULT_REQUEST_TIMEOUT;
  the folder and lookup calls had none and could hang a consumer forever
- oauth2 grant now refreshes up to 300s before expiry; the drift sign was
  inverted so expired tokens were reused for up to 300s past expiry
- SecretServerError keeps the server response (error.response works now);
  a 4xx json body without message/error keys no longer masks the failure
  with UnboundLocalError
- example masks the password value instead of printing it
- new offline test suite covers timeout coverage on every request path,
  refresh boundary behavior, and error plumbing; no live credentials needed
…n, sanitize error bodies, validate vault redirect, 🧪 add offline security tests

security review remediation, phase 2 (DevPlan.md)
==

- warn (UserWarning) when base_url is not https; credentials and bearer
  tokens would otherwise travel in plaintext with no signal to the caller.
  strict rejection is deferred to v3.0 to avoid breaking localhost/lab setups
- health-check probing now requires a 2xx status and an exact "healthy"
  match instead of a substring check; the old check matched "Unhealthy" and
  ignored the http status entirely
- exception messages no longer echo raw response bodies; the secrets
  endpoint omits the body outright, other endpoints get a capped, clearly
  truncated excerpt
- the platform vault-broker redirect url is now required to be a valid
  https url before any token is sent to it
- SecretServerError now passes its message through to Exception.__init__,
  so str(error) is populated instead of always empty
- new offline test suite covers all four fixes; existing FakeResponse
  fixtures updated with .ok/.status_code/.text to match the tightened
  health-check contract
…lease to pypi trusted publishing, align tox deps with pinned requirements

security review remediation, phase 3 (DevPlan.md)
==

- every workflow now declares least-privilege permissions at the top level;
  the lint job (needs to push auto-fix commits and publish check results)
  and the release job (needs the oidc token) grant themselves only what they
  actually use
- pypa/gh-action-pypi-publish was pinned to the mutable release/v1 branch,
  the only unpinned action in the repo; now pinned to the v1.14.2 commit sha
- release.yml drops the long-lived PYPI_API_TOKEN in favor of PyPI Trusted
  Publishing (OIDC) -- requires a trusted publisher to be configured for
  this repo/workflow on pypi.org before the next tag push; keep the repo
  secret until that is confirmed working
- tox.ini and lint.yml now install the versions pinned in requirements.txt
  (black==26.5.1, flit==3.12.0, and the full pinned set via -r
  requirements.txt) instead of floating latest, so CI exercises what
  consumers actually get
…SECURITY.md, 🚀 split runtime/dev deps and pin pip

- token refresh now locked and utc-aware; mutable default args removed
- fixed get_folder_json crash on bare call, itemValue returning a Response
  object instead of text, and an unvalidated non-numeric secrets count
- requirements.txt split into runtime-only pins with a new
  requirements-dev.txt for build/test tooling; pip>=26.2 pinned there and
  in release.yml (transitive via flit; CVE-2026-8643 and others)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants