Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 54/100
- Issue-Typ
- Bug
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- javascript, rust
- Bereich
- cli, documentation, security
Rechercherichtung
Start with preflight_yarn_berry_hosted and rewrite_yarn_berry in crates/socket-patch-core/src/patch/redirect/mod.rs, then review CLI_CONTRACT.md and the supplied cold-cache Yarn Berry reproduction. Compare scoped, unscoped, environment-token, and npmAlwaysAuth cases; done means hosted patch requests do not silently receive registry credentials, with the relevant behavior documented in docs/ecosystems.md and docs/testing/yarn-berry-compatibility.md.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled Yarn Berry (2+) bug-hunt routine (ledger #305).
Summary
On yarn berry, hosted mode pins a patched dependency as <name>@npm:<v>::__archiveUrl=<hosted tgz> (crates/socket-patch-core/src/patch/redirect/mod.rs:3459). Yarn handles that locator with its npm fetcher, so it attaches the npm registry's credentials to the request, even though the request goes to the hosted patch server and not to the registry. These cases all send Authorization: Bearer <npm token> to the patch host:
- any scoped package (
@scope/name) when annpmAuthTokenis configured. Yarn uses best-effort auth for scoped idents, sonpmAlwaysAuthisn't needed. That covers the top-levelnpmAuthTokenin.yarnrc.yml, theYARN_NPM_AUTH_TOKENenv var that CI commonly sets, andnpmScopes.<scope>.npmAuthToken; - every hosted package, scoped or not, when
npmAlwaysAuth: trueis set. That's the usual setup for Artifactory / Nexus / GitHub Packages proxies.
Impact
- A private-registry or npm publish token is disclosed to
patch.socket.dev(or to any--patch-server-urlhost) on every cold-cache install of a hosted-patched package. CI is affected on every run. The user never configured that host to receive the token, and nothing in the docs mentions it. - npm, pnpm and yarn classic scope registry auth to the registry's host, so this is berry-specific. It comes from the locator form that hosted mode picks.
- Scoped packages (
@babel/*,@types/*,@isaacs/*…) are a large share of the patchable npm surface.
Repro (Linux, yarn 4.12.0 / 4.18.1 / 4.0.2; mock patch API logging the Authorization header on the tarball route)
mkdir proj && cd proj
echo '{"name":"app","version":"1.0.0","private":true,"dependencies":{"@isaacs/string-locale-compare":"1.1.0","left-pad":"1.3.0"}}' > package.json
printf 'nodeLinker: node-modules\nenableGlobalCache: false\n' > .yarnrc.yml
yarn install
socket-patch scan --json --yes --api-url http://127.0.0.1:18080 --org test-org --api-token fake # hosted (default): redirected 2
# fresh checkout, cold cache:
mkdir ../fresh && cp package.json yarn.lock ../fresh/ && cd ../fresh
printf 'nodeLinker: node-modules\nenableGlobalCache: false\nunsafeHttpWhitelist:\n - "127.0.0.1"\n' > .yarnrc.yml
YARN_NPM_AUTH_TOKEN=ENV-CI-TOKEN YARN_GLOBAL_FOLDER=$(mktemp -d) yarn install --immutable
What the patch host received:
GET /patch/npm/@isaacs/string-locale-compare/1.1.0/<token>/<uuid>/…tgz Authorization: Bearer ENV-CI-TOKEN
GET /patch/npm/left-pad/1.3.0/<token>/<uuid>/left-pad-1.3.0.tgz Authorization: (none)
With npmAuthToken: "ALWAYS-TOKEN" and npmAlwaysAuth: true in .yarnrc.yml, both requests carry Bearer ALWAYS-TOKEN. The installs themselves succeed and get the patched bytes.
Expected vs actual
- Expected: a hosted redirect shouldn't cause installs to disclose registry credentials to a host the user never set up for them. The CLI contract already holds hosted fetches to this standard elsewhere: the vlt artifact probe is specified as "no
Authorization" (CLI_CONTRACT.md,redirect_vlt_artifact_unverifiable). If the berry locator form can't avoid it, hosted mode should at least detect a configurednpmAuthToken/npmAlwaysAuth(.yarnrc.yml, env) and warn or refuse, and docs/ecosystems.md "yarn berry" plus docs/testing/yarn-berry-compatibility.md should document it. - Actual: the token is sent silently, and the run reports plain success.
Matrix
| OS | yarn | scoped + npmAuthToken / YARN_NPM_AUTH_TOKEN |
scoped + npmScopes token |
unscoped + npmAuthToken |
any + npmAlwaysAuth: true |
|---|---|---|---|---|---|
| Linux | 4.0.2 (bare-hex lock) | sent (env) | untested | — | untested |
| Linux | 4.12.0 | sent | untested | not sent | sent |
| Linux | 4.18.1 (lock version: 10) |
sent (rc and env) | sent | not sent | sent |
| macOS / Windows | — | untested. The behaviour is in yarn's JS fetcher (npmHttpUtils.get takes auth from the configured registry, not from the URL origin), so it shouldn't depend on the OS |
Yarn 2/3 aren't reachable: hosted mode refuses cacheKey 7/8.
First bad: main 2463257. Release 4.0.0 writes the same ::__archiveUrl= locator for berry, so it should behave the same; I didn't re-run the token capture against it.
Suspect code
crates/socket-patch-core/src/patch/redirect/mod.rs:3459: the{fname}@npm:{}::__archiveUrl={}resolution written byrewrite_yarn_berry(line 3238). There's no gate on registry auth config next to the other berry project gates inpreflight_yarn_berry_hosted(around line 3195).
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 18 Std. 4 Min.
- Gemergte PRs (30 T.)
- 70
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
agent:triaged bug bughunt pm:composer priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
SocketDev/socket-patch#515 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#464 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#433 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:uv priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
SocketDev/socket-patch#408 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#370 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
discover: `sudo RTK_DISABLED=$VAR …` is not detected as a bypass when `sudo` is a transparent prefixOffenarea:cli bug good first issue priority:medium
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
rtk-ai/rtk#4412 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
skill:code-review
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
component:sight
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
agentic-os-org/ANOLISA#4115 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
rivet-dev/rivet#5819 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
A-io-database bug needs triage python
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
Maintainer antworten meist innerhalb von 1 Tag