check-safety/check_envreads.go
Alex Dunmow cd88c808b0 initial: standalone check-safety module hoisted from CMS
Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.

This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
  blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
  install-safety-checker targets

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:04:02 +08:00

45 lines
1.3 KiB
Go

package main
import "fmt"
func init() {
register(Check{
Seq: 10,
ID: "1",
Title: "Secret env var reads outside config.Load()",
Run: func(ctx *ScanContext, rep *Reporter) {
// Check 1: Secret env var reads
fmt.Println("=== Check 1: Secret env var reads outside config.Load() ===")
var envViolations []envViolation
for _, target := range ctx.backendTargets {
for _, v := range checkEnvReads(target.root) {
v.file = prefixDisplayPath(target.display, v.file)
envViolations = append(envViolations, v)
}
}
for _, target := range ctx.pluginTargets {
for _, v := range checkEnvReads(target.root) {
v.file = prefixDisplayPath(target.display, v.file)
envViolations = append(envViolations, v)
}
}
if len(envViolations) > 0 {
for _, v := range envViolations {
fmt.Printf(" FAIL: %s:%d — os.Getenv(%q)\n", v.file, v.line, v.envVar)
}
fmt.Printf("\n %d violation(s). Secrets must flow through Config → DI.\n", len(envViolations))
rep.Fail()
} else {
fmt.Printf(" OK: No secret env var reads outside config.Load()")
if len(ctx.pluginTargets) > 0 {
fmt.Printf(" (%d plugin roots scanned)", len(ctx.pluginTargets))
}
fmt.Println()
printPerTargetOKLines(pluginTargetLabels(ctx.pluginTargets))
}
fmt.Println()
},
})
}