Rework PR #15 per security review SEC-14-R1: the client no longer carries an API token. js/newsletter-config.js ships only the non-secret endpoint, enforced https-only at config load time via validateEndpoint() (mirroring the protocol allowlist in js/reading-list.js); js/newsletter.js POSTs email-only with no Authorization header. Failure paths keep the single user-safe message that never leaks token, endpoint, status, or raw body; success still shows the confirmation. CI gains a gitleaks step that fails on any secret hit; README documents the server-side token, the residual signup-abuse risk, and the authoritative server-side validation follow-up.
31 lines
886 B
YAML
31 lines
886 B
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
test:
|
|
name: Run tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Run test suite
|
|
run: npm test
|
|
|
|
gitleaks:
|
|
name: Secret scan (gitleaks)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Install gitleaks
|
|
run: |
|
|
curl -sSfL https://github.com/gitleaks/gitleaks/releases/download/v8.18.4/gitleaks_8.18.4_linux_x64.tar.gz -o gitleaks.tar.gz
|
|
tar -xzf gitleaks.tar.gz gitleaks
|
|
# `gitleaks detect` exits non-zero on any finding, so this step fails the
|
|
# build on any secret hit. `--no-git` scans the checked-out tree only;
|
|
# `--redact` masks matched secrets in the log output.
|
|
- name: Run gitleaks (fail on any hit)
|
|
run: ./gitleaks detect --source . --no-git --redact -v
|