Module: Ace::Hitl::Lifecycle::Kinds

Defined in:
lib/ace/hitl/lifecycle/kinds.rb

Overview

Request kinds and the secret/OTP answer gates (port of the migrated kind model; spec 8wm.t.y21 §4).

Constant Summary collapse

ALL =
%w[
  text choice confirm secret review
  question decision verification otp
].freeze
SECRET =
%w[otp].freeze
REQUEST_ID =
/\A[A-Za-z0-9_-]{6,64}\z/
WORK_ID =
/\AW[0-9]+\z/
ATTEMPT_ID =
/\AA-[0-9a-f]{24}\z/
SAFE_LABEL =
/\A[A-Za-z0-9_. -]{1,48}\z/
OTP_ANSWER =
/\A[0-9]{6}\z/
SECRET_SHAPED =

Secret-shape scrubbing: tokens that must never enter a non-OTP answer or a channel message.

Regexp.new(
  "(?:github_pat_[A-Za-z0-9_]+|gh[pousr]_[A-Za-z0-9]+|" \
  "sk-[A-Za-z0-9_-]{20,}|-----BEGIN [A-Z ]+PRIVATE KEY-----|" \
  "\\b(?:otp|token|secret|password)\\s*[:=]\\s*\\S+|" \
  "\\b[0-9]{6}\\b)",
  Regexp::IGNORECASE
).freeze

Class Method Summary collapse

Class Method Details

.check_answer!(kind, answer) ⇒ Object

The deliver/consume answer gate (port of check_answer): OTP answers must be exactly six ASCII digits; every other kind rejects secret-shaped content before persistence.



43
44
45
46
47
48
49
50
51
52
# File 'lib/ace/hitl/lifecycle/kinds.rb', line 43

def check_answer!(kind, answer)
  if secret?(kind)
    unless OTP_ANSWER.match?(answer)
      raise AnswerError, "OTP answer must be exactly six ASCII digits"
    end
  elsif SECRET_SHAPED.match?(answer)
    raise AnswerError, "secret-shaped content is forbidden in HITL answers"
  end
  nil
end

.secret?(kind) ⇒ Boolean

Returns:

  • (Boolean)


32
33
34
# File 'lib/ace/hitl/lifecycle/kinds.rb', line 32

def secret?(kind)
  SECRET.include?(kind.to_s)
end

.valid?(kind) ⇒ Boolean

Returns:

  • (Boolean)


36
37
38
# File 'lib/ace/hitl/lifecycle/kinds.rb', line 36

def valid?(kind)
  ALL.include?(kind.to_s)
end