Skip to content

Commit 2a9f7de

Browse files
committed
fix(auth): reject empty HMAC keys so authsign cannot fail open
New() accepted an empty hex-decoded key (literal "", unset env:, or whitespace-only file:). HMAC-SHA256 with a zero-length key still produces a verifiable token, so a misconfigured remote auth provider would treat unauthenticated authsign requests as valid. Reject empty keys after env/file resolution and after hex decode. Signed-off-by: Sasha Mitchell <sash.t.mitchell@gmail.com>
1 parent e429e72 commit 2a9f7de

2 files changed

Lines changed: 32 additions & 0 deletions

File tree

‎auth/auth.go‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,21 +50,36 @@ func New(key string, ad []byte) (*Standard, error) {
5050
switch splitKey[0] {
5151
case "env":
5252
key = os.Getenv(splitKey[1])
53+
if key == "" {
54+
return nil, fmt.Errorf("auth key environment variable %q is unset or empty", splitKey[1])
55+
}
5356
case "file":
5457
data, err := os.ReadFile(splitKey[1])
5558
if err != nil {
5659
return nil, err
5760
}
5861
key = strings.TrimSpace(string(data))
62+
if key == "" {
63+
return nil, fmt.Errorf("auth key file %q is empty", splitKey[1])
64+
}
5965
default:
6066
return nil, fmt.Errorf("unknown key prefix: %s", splitKey[0])
6167
}
6268
}
6369

70+
if key == "" {
71+
return nil, fmt.Errorf("auth key must not be empty")
72+
}
73+
6474
keyBytes, err := hex.DecodeString(key)
6575
if err != nil {
6676
return nil, err
6777
}
78+
if len(keyBytes) == 0 {
79+
// hex.DecodeString("") succeeds with a zero-length key; reject so HMAC
80+
// auth cannot fail open when a secret is missing/misconfigured.
81+
return nil, fmt.Errorf("auth key must not be empty")
82+
}
6883

6984
return &Standard{keyBytes, ad}, nil
7085
}

‎auth/auth_test.go‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,23 @@ func TestNew(t *testing.T) {
1919
t.Fatal("expected failure with improperly-hex-encoded key")
2020
}
2121

22+
if _, err := New("", nil); err == nil {
23+
t.Fatal("expected failure with empty key")
24+
}
25+
26+
t.Setenv("CFSSL_AUTH_EMPTY", "")
27+
if _, err := New("env:CFSSL_AUTH_EMPTY", nil); err == nil {
28+
t.Fatal("expected failure with empty env key")
29+
}
30+
31+
emptyFile := t.TempDir() + "/empty.key"
32+
if err := os.WriteFile(emptyFile, []byte(" \n"), 0o600); err != nil {
33+
t.Fatalf("%v", err)
34+
}
35+
if _, err := New("file:"+emptyFile, nil); err == nil {
36+
t.Fatal("expected failure with empty file key")
37+
}
38+
2239
testProvider, err = New(testKey, nil)
2340
if err != nil {
2441
t.Fatalf("%v", err)

0 commit comments

Comments
 (0)