forgejo-mcp/.gitleaks.toml
Christoph Görn ed5f419195
ci: 🔧 gitleaks: allow placeholder tokens in demo docs
The default `curl-auth-header` rule flags lines like
`Authorization: token invalid_token` in demo markdown files. The
forthcoming demos/multi-tenant-http.md (commit bd08d6147 on the
byteflavour/stateless-token fork branch) demonstrates the "request
with invalid token" path and trips the scan on import.

Add a per-rule allowlist on `curl-auth-header` scoped to:
- path: `demos/.*\.md$`
- secret matches one of: invalid_token, placeholder_token, changeme,
  your(_api)?_token_here (case-insensitive, anchored)

A real-looking token in the same file is still detected by the
`github-pat` rule, verified locally with gitleaks v8.30.1.

Gotcha discovered: gitleaks v8.30.x ignores user-added `[[rules]]`
blocks that appear AFTER any top-level `[[allowlists]]` in the same
file. Per-rule allowlists must come first.

Refs forgejo-mcp-dhd.
2026-05-25 09:29:01 +02:00

32 lines
760 B
TOML

[extend]
useDefault = true
[[rules]]
id = "generic-api-key"
[[rules.allowlists]]
condition = "AND"
paths = ['''(?i).*\.ya?ml$''']
regexes = ['''^Ag[a-zA-Z0-9+/]{500,}={0,2}$''']
[[rules]]
id = "curl-auth-header"
[[rules.allowlists]]
description = "Placeholder tokens in demo docs"
condition = "AND"
paths = ['''demos/.*\.md$''']
regexes = [
'''(?i)^invalid[-_]?token$''',
'''(?i)^placeholder[-_]?token$''',
'''(?i)^changeme$''',
'''(?i)^your[-_](api[-_])?token[-_]here$''',
]
[[allowlists]]
description = "Historical commits with rotated credentials; pre-existing residue, not in current main."
commits = [
"0eac698f002763f5b0b862fc1f919f6d4e4e259d",
"17cf298ea16665599627fe765db6b60766eb9851",
"86351a10cee44caf36979984f42196964189314d",
]