Description
Follow-up to #103. The PR addresses the correctness findings; track these two remaining validation and credential-handling items separately.
Vault login body buffer
json_login_body writes the serialized Kubernetes JWT or AppRole secret_id into a Zeroizing<Vec<u8>> with an initial capacity of 128 bytes. A normal credential can exceed that capacity. If the Vec reallocates while serde_json::to_writer appends bytes, the old allocation may retain credential bytes because Zeroizing only wipes the final allocation it owns.
- Audit the full login-body lifetime, including the
Bytes::copy_from_slice request copy, and state the achievable zeroization guarantee accurately.
- Avoid reallocations during serialization where feasible, or document the remaining exposure and the reason for the chosen approach.
- Cover login bodies larger than 128 bytes in a test.
Live Vault KV v2 check
#103 uses FakeTransport to cover the Vault 1.19 HTTP contract, including 404 and 200 with data.data: null as NotFound. It has no test against a running Vault server.
- Add a repeatable integration test or documented test procedure using a live Vault KV v2 mount and one supported auth method.
- Verify a normal field read and a soft-deleted version against Vault's actual status and response body, including the
NotFound mapping.
- Document how to run the test locally or in CI.
Description
Follow-up to #103. The PR addresses the correctness findings; track these two remaining validation and credential-handling items separately.
Vault login body buffer
json_login_bodywrites the serialized Kubernetes JWT or AppRolesecret_idinto aZeroizing<Vec<u8>>with an initial capacity of 128 bytes. A normal credential can exceed that capacity. If theVecreallocates whileserde_json::to_writerappends bytes, the old allocation may retain credential bytes becauseZeroizingonly wipes the final allocation it owns.Bytes::copy_from_slicerequest copy, and state the achievable zeroization guarantee accurately.Live Vault KV v2 check
#103 uses
FakeTransportto cover the Vault 1.19 HTTP contract, including404and200withdata.data: nullasNotFound. It has no test against a running Vault server.NotFoundmapping.