forked from mirrors/kingfisher
39 lines
1 KiB
YAML
39 lines
1 KiB
YAML
rules:
|
|
- name: Nx Cloud Access Token
|
|
id: kingfisher.nxcloud.1
|
|
pattern: |
|
|
(?xi)
|
|
\b
|
|
nx[_-]?cloud[_-]?token
|
|
(?:.|[\n\r]){0,16}?
|
|
[=:"'\s]
|
|
['"]*
|
|
(
|
|
[A-Za-z0-9+/]{60,80}={0,2}
|
|
)
|
|
['"\s]
|
|
pattern_requirements:
|
|
min_digits: 4
|
|
min_uppercase: 4
|
|
min_entropy: 3.5
|
|
confidence: high
|
|
examples:
|
|
- "nx_cloud_token = \"UDM4ZGY4NWUtZDU4ZS01Z2I4LWNkZWUtYjcyMTAzN2RjOGI0fHJlYWQtd3JpdGU=\""
|
|
- "NX_CLOUD_TOKEN=VEN5ZWY5NmYtZTY5Zi02aGM5LWRlZmYtYzgzMjE0OGVkOWM1fHJlYWQtb25seQ==\n"
|
|
references:
|
|
- https://nx.dev/ci/recipes/security/personal-access-tokens
|
|
validation:
|
|
type: Http
|
|
content:
|
|
request:
|
|
method: GET
|
|
url: https://api.nx.app/nx-cloud/user
|
|
headers:
|
|
Authorization: "Bearer {{ TOKEN }}"
|
|
response_matcher:
|
|
- report_response: true
|
|
- type: StatusMatch
|
|
status: [200]
|
|
- type: StatusMatch
|
|
status: [401, 403]
|
|
negative: true
|