Skip to content

fix: remove hardcoded secret in discovery.vars.js.default (CWE-798) - #2383

Merged
thostetler merged 1 commit into
adsabs:masterfrom
anupamme:fix-repo-bumblebee-multi-agent-cwe-798-src-config-discovery-vars-js-default
Oct 1, 2026
Merged

thostetler merged 1 commit into
adsabs:masterfrom
anupamme:fix-repo-bumblebee-multi-agent-cwe-798-src-config-discovery-vars-js-default

Conversation

@anupamme

Copy link
Copy Markdown
Contributor

The discovery.vars.js.default configuration file contains hardcoded API keys and OAuth client credentials exposed to clients. The ORCID OAuth client ID (APP-P5ANJTQRRTMA6GXZ) and API endpoint configuration are embedded in client-side JavaScript. While reCAPTCHA site keys are designed to be public, the pattern of embedding credentials creates risk of accidental exposure of sensitive keys. The empty fingerprintApiKey field indicates a pattern that could lead to future credential exposure. The affected code is src/config/discovery.vars.js.default:42. This change is the fix I would apply.

Reference: CWE-798

What changed

  • src/config/discovery.vars.js.default

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.

Regression test

The security boundary is maintained under adversarial input

Test
const { expect } = require('chai');

describe("Configuration must not expose sensitive hardcoded credentials", () => {
  const config = require('../../src/config/discovery.vars.js.default');

  const sensitivePatterns = [
    { name: 'OAuth client ID pattern', pattern: /^APP-[A-Z0-9]{16}$/ },
    { name: 'Non-empty API key field', field: 'fingerprintApiKey', check: (v) => v !== '' },
    { name: 'Production endpoint exposure', pattern: /amazonaws\.com/ }
  ];

  it("must not contain hardcoded OAuth client credentials", () => {
    expect(config.orcidClientId).to.not.match(/^APP-[A-Z0-9]{16}$/, 
      'Hardcoded OAuth client ID pattern detected - use environment variable instead');
  });

  it("must not expose internal API endpoints", () => {
    expect(config.orcidApiEndpoint).to.not.match(/amazonaws\.com/,
      'Internal AWS endpoint exposed in client config');
  });

  it("must use environment variables for injectable secrets", () => {
    const hasHardcodedSecret = config.fingerprintApiKey && 
      !config.fingerprintApiKey.startsWith('${') &&
      config.fingerprintApiKey !== '';
    expect(hasHardcodedSecret).to.be.false;
  });
});}

Automated security fix by OrbisAI Security

@thostetler thostetler left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, thanks for the contribution

@thostetler
thostetler merged commit 6c3f38a into adsabs:master Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants