Skip to content

test(secrets): Vault login buffer handling and live KV v2 test #132

Description

@araujof

Description

Follow-up to #103. The PR addresses the correctness findings; track these two remaining validation and credential-handling items separately.

Vault login body buffer

json_login_body writes the serialized Kubernetes JWT or AppRole secret_id into a Zeroizing<Vec<u8>> with an initial capacity of 128 bytes. A normal credential can exceed that capacity. If the Vec reallocates while serde_json::to_writer appends bytes, the old allocation may retain credential bytes because Zeroizing only wipes the final allocation it owns.

  • Audit the full login-body lifetime, including the Bytes::copy_from_slice request copy, and state the achievable zeroization guarantee accurately.
  • Avoid reallocations during serialization where feasible, or document the remaining exposure and the reason for the chosen approach.
  • Cover login bodies larger than 128 bytes in a test.

Live Vault KV v2 check

#103 uses FakeTransport to cover the Vault 1.19 HTTP contract, including 404 and 200 with data.data: null as NotFound. It has no test against a running Vault server.

  • Add a repeatable integration test or documented test procedure using a live Vault KV v2 mount and one supported auth method.
  • Verify a normal field read and a soft-deleted version against Vault's actual status and response body, including the NotFound mapping.
  • Document how to run the test locally or in CI.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions