chore(security): scrub dead admin token from doc + add gitleaks db-URL rule #161

Merged
gmackie merged 1 commit from chore/security-scrub-token-gitleaks into main 2026-07-30 05:04:41 +00:00
Owner

Final hygiene from the leaked-credential incident (both items are cleanup — no live exposure; the credentials involved are already dead).

1. Scrub the dead admin token from a committed doc

docs/plans/2026-05-06-forgejo-sync.md embedded a Forgejo admin token in a setup example. Verified dead (HTTP 401 against the Forgejo API), so no server-side revocation is needed — replaced the literal token with $FORGEJO_ADMIN_TOKEN. (The other leaked token, from the old .git/config remote URL, is also dead and already removed from the URL.)

2. Add a gitleaks rule for DB connection strings

gitleaks's default rules do not match URL-form DB credentials (postgres://user:PASSWORD@host) — that gap is exactly how the owner password sat in two committed wrangler.toml files undetected. New .gitleaks.toml:

  • [extend] useDefault = true + a db-connection-string-inline-password rule (postgres/mysql/redis/mongodb).
  • Allowlist for placeholders / env-vars (<password>, password, ${VAR}, $VAR) so examples don't false-positive.
  • Documents the color.ui = always gotcha that silently makes gitleaks scan zero commits.

Verified: real leaked strings FLAGGED, placeholder/env-var forms allowlisted; TOML parses.

🤖 Generated with Claude Code

Final hygiene from the leaked-credential incident (both items are cleanup — no live exposure; the credentials involved are already dead). ## 1. Scrub the dead admin token from a committed doc `docs/plans/2026-05-06-forgejo-sync.md` embedded a Forgejo admin token in a setup example. **Verified dead** (HTTP 401 against the Forgejo API), so no server-side revocation is needed — replaced the literal token with `$FORGEJO_ADMIN_TOKEN`. (The other leaked token, from the old `.git/config` remote URL, is also dead and already removed from the URL.) ## 2. Add a gitleaks rule for DB connection strings gitleaks's default rules do **not** match URL-form DB credentials (`postgres://user:PASSWORD@host`) — that gap is exactly how the owner password sat in two committed `wrangler.toml` files undetected. New `.gitleaks.toml`: - `[extend] useDefault = true` + a `db-connection-string-inline-password` rule (postgres/mysql/redis/mongodb). - Allowlist for placeholders / env-vars (`<password>`, `password`, `${VAR}`, `$VAR`) so examples don't false-positive. - Documents the `color.ui = always` gotcha that silently makes gitleaks scan zero commits. Verified: real leaked strings FLAGGED, placeholder/env-var forms allowlisted; TOML parses. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
chore(security): scrub dead admin token from doc + add gitleaks db-URL rule
All checks were successful
forgegraph/ci CI passed
CI / ci (pull_request) Successful in 6m42s
ea243e509e
gmackie deleted branch chore/security-scrub-token-gitleaks 2026-07-30 05:04:41 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!161
No description provided.