A staging token in a pull request SEC-118

OpenGit · Hard · Recover · about 35 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened SEC-118 at 11:20SEV-3

Secret scanning flagged PR #412: a depot-auth token in .env.local. The branch was already pushed, and the author has more work staged locally.

The token is a staging credential for depot-west, but it was on the shared remote for half an hour. Anyone who fetched has it.

"Deleting the file in a new commit does not help, it is still in the branch history. And rotate first: once it is out, it is out." (Priya)

The author also has config and client changes that belong in the PR. They must survive the cleanup.

Your task

Rotate the token, then rewrite the PR branch so no commit contains .env.local, ignore it with a narrow rule, keep .env.example tracked, publish the cleaned branch safely, and put a working replacement token in your local .env.local.

On the machine

  • repo/ on feature/depot-token, and the shared remote remote.git
  • bin/depot-auth-admin (rotate, revoke)
  • repo/bin/depot-ping, the smoke test that reads .env.local

Timeline

10:52Branch feature/depot-token pushed with .env.local committed.
11:15Secret scanning flags DEPOT_TOKEN=test-secret-42.
11:20SEC-118: "Treat it as exposed."

Done when

  1. No commit on the PR branch, locally or on origin, contains the token or .env.local, and .env.local is ignored.
  2. The old token is revoked, and your local .env.local holds a working replacement.
  3. .env.example stays tracked with an empty placeholder.
  4. The cleaned branch, with its intended changes, is on origin, and main is untouched.

Hints

Hint 1

Check staged and committed history.

Hint 2

Ignore rules do not remove tracked content.

Hint 3

Remove the token file from the index/history.

Hint 4

Rotate the fixture token and add a narrow ignore rule.

Show the solution

Rotate first (`bin/depot-auth-admin rotate --subject depot-west --revoke test-secret-42`) because the branch was pushed. Remove `.env.local` from the index, add a narrow `/.env.local` ignore rule, and rewrite the PR branch so no commit contains the file (for example `git reset --soft main` and one clean commit). Publish with `git push --force-with-lease`, put the new token in your local `.env.local`, and confirm with `bin/depot-ping`.