Anchor streaming destination schema patterns to whole strings
What does this MR do and why?
JSON schema pattern constraints in the audit event streaming config schemas were anchored with ^/$. json_schemer compiles a pattern with its default regexp_resolver of "ruby", so those bind to line boundaries — a value only had to match on one of its lines, leaving anything after a newline unvalidated. "validbucket\nevil" was accepted for bucketName.
Anchors the four affected fields with \A/\z:
| Schema | Field |
|---|---|
| aws | accessKeyXid, bucketName |
| gcp | googleProjectIdName, logIdName |
awsRegion was already fixed in !249803 (merged).
Deliberate choices
The AWS and GCP schema validations are now skipped while config is untouched. Tightening a pattern can reject a value an existing row already stores, and the schema validation re-ran on every save — so such a destination could not be renamed or even deactivated (Activatable#deactivate! is update!(active: false)). Any change to config still revalidates the whole config, so a rejected value cannot be introduced. This mirrors the existing guard in config_is_properly_formatted and the gating applied to awsRegion.
The HTTP schema is left alone. Its url pattern has no closing anchor at all and its header value pattern is a three-branch alternation; both need semantic decisions rather than a mechanical change. Worth a follow-up — the header value is the highest injection risk of the set.
References
- Closes #613422 (closed)
- Origin: !249803 (merged)
Screenshots or screen recordings
No UI change.
How to set up and validate locally
d = build(:audit_events_group_external_streaming_destination, :aws)
d.config = d.config.merge('bucketName' => "validbucket\nevil")
d.valid? # => false (was true before this change)bundle exec rspec \
ee/spec/models/audit_events/group/external_streaming_destination_spec.rb \
ee/spec/models/audit_events/instance/external_streaming_destination_spec.rbMR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.