kingfisher/crates/kingfisher-rules/data/rules/uber.yml
2026-04-03 21:35:28 -07:00

27 lines
749 B
YAML

rules:
- name: Uber Server Token
id: kingfisher.uber.1
pattern: |
(?xi)
\b
uber
(?:.|[\n\r]){0,32}?
\bserver[_-]?token\b
(?:.|[\n\r]){0,16}?
[=:"'\s]
['"]*
(
[A-Za-z0-9_-]{36,44}
)
['"\s]
pattern_requirements:
min_digits: 2
min_entropy: 3.5
confidence: high
examples:
- "config.uber.server_token = \"Cyob8XIWekjc6pbbRIJbw-Y2Y38QXzIVBbXpPtW\""
- "uber, server_token: 'PCLca4a2cQl2OR88-tZ_5X_yYmkzHF4zqoK838X_'"
references:
- https://developer.uber.com/docs/riders/guides/authentication/server-token
# No active public validation endpoint: Uber's server token API
# is deprecated and no longer publicly accessible.