-
Notifications
You must be signed in to change notification settings - Fork 51
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
support multiple encoded blocks #127
base: master
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The only thing I wonder about is garbage. It will silently ignore parts in strings like blaENC[...]
.
method = 'PKCS7' | ||
end | ||
|
||
encodes = val.scan(/ENC\[.*?\]/) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why .*?
as a regex? The ?
doesn't make sense to me. Also wondering why you don't drop the ENC part via groups:
[1] pry(main)> 'ENC[PKCS7,aGVsbG8sf&IHdvcmxk==]'.scan(/ENC\[(.+)\]/)
=> [["PKCS7,aGVsbG8sf&IHdvcmxk=="]]
encodes = val.scan(/ENC\[.*?\]/) | |
encodes = val.scan(/ENC\[(.*)\]/) |
You can even already do the splitting here:
encodes = val.scan(/ENC\[.*?\]/) | |
encodes = val.scan(/ENC\[([^,]+),?(.+)?\]/) |
Note I made the last part optional so you can still detect an invalid format.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The ?
didn't really make sense to me either but it seemed appropriate since that's what hiera-eyaml uses.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good point. Looks like it was introduced in voxpupuli/hiera-eyaml@169ae64 where it previously was value.start_with?('ENC[')
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm all for improving it and my preference would be to do a scan once but I didn't find something that works
encodes = val.scan(/ENC\[([^,]+),?(.+)?\]/)
This fails the tests. Take the example ENC[KMS,aGVsbG8sIdGHdvcmxk==]ENC[KMS,aGVsbG8sIdGHdvcmxk==]
Gives us these match groups.
1. | KMS
2. | aGVsbG8sIdGHdvcmxk==]ENC[KMS,aGVsbG8sIdGHdvcmxk==
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This works for me:
data = 'ENC[KMS,aGVsbG8sIdGHdvcmxk==]ENC[KMS,aGVsbG8sIdGHdvcmxk==]'
data.scan(/ENC\[([^,]+),?([^\]]+)?\]/)
Returns [["KMS", "aGVsbG8sIdGHdvcmxk=="], ["KMS", "aGVsbG8sIdGHdvcmxk=="]]
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Following-up your conversation about the question mark ?
in the REGEX, it seems that we can remove it right from the upstream project, here is the PR to the change:
Thanks!
I still think #127 (comment) is a comment that hasn't been answered. |
Housekeeping: what is the status on this? :) |
With KMS you have to split materials you wish to encode into 4096 blocks.
hiera-eyaml supports this but puppet-syntax thinks it's a problem.
I've changed the behavior of the check_eyaml_blob code and added some tests.