mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-30 16:19:21 +00:00
Add WASM sandbox secure API extension
Extends the WASM sandbox with HTTP API capabilities, secrets management, tool aliasing, and leak detection. Key security principle: WASM never sees credentials, injection happens at host boundary. New modules: - secrets: AES-256-GCM encrypted storage with HKDF key derivation - leak_detector: Aho-Corasick + regex pattern matching for secret exfiltration - capabilities: Extended capability system (HTTP, ToolInvoke, Secrets) - allowlist: HTTP endpoint validation with glob patterns - credential_injector: Host-boundary credential injection - rate_limiter: Sliding window per-tool rate limiting - storage: WASM binary storage with BLAKE3 integrity verification Leak detection happens at two points: 1. Before HTTP request (prevents exfiltration via URL/headers/body) 2. After response (prevents exposure in outputs returned to WASM) Co-Authored-By: Claude Opus 4.5 <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.5
parent
45bbfa026d
commit
32bfd24154
@@ -0,0 +1,66 @@
|
||||
//! Secrets management for secure credential storage and injection.
|
||||
//!
|
||||
//! This module provides:
|
||||
//! - AES-256-GCM encrypted secret storage
|
||||
//! - Per-secret key derivation (HKDF-SHA256)
|
||||
//! - PostgreSQL persistence
|
||||
//! - Access control for WASM tools
|
||||
//!
|
||||
//! # Security Model
|
||||
//!
|
||||
//! ```text
|
||||
//! ┌─────────────────────────────────────────────────────────────────────────────┐
|
||||
//! │ Secret Lifecycle │
|
||||
//! │ │
|
||||
//! │ User stores secret ──► Encrypt with AES-256-GCM ──► Store in PostgreSQL │
|
||||
//! │ (per-secret key via HKDF) │
|
||||
//! │ │
|
||||
//! │ WASM requests HTTP ──► Host checks allowlist ──► Decrypt secret ──► │
|
||||
//! │ & allowed_secrets (in memory only) │
|
||||
//! │ │ │
|
||||
//! │ ▼ │
|
||||
//! │ Inject into request ──► Execute HTTP call │
|
||||
//! │ (WASM never sees value) │
|
||||
//! │ │ │
|
||||
//! │ ▼ │
|
||||
//! │ Leak detector scans ──► Return response to WASM │
|
||||
//! │ response for secrets │
|
||||
//! └─────────────────────────────────────────────────────────────────────────────┘
|
||||
//! ```
|
||||
//!
|
||||
//! # Example
|
||||
//!
|
||||
//! ```ignore
|
||||
//! use near_agent::secrets::{SecretsStore, PostgresSecretsStore, SecretsCrypto, CreateSecretParams};
|
||||
//! use secrecy::SecretString;
|
||||
//!
|
||||
//! // Initialize crypto with master key from environment
|
||||
//! let master_key = SecretString::from(std::env::var("SECRETS_MASTER_KEY")?);
|
||||
//! let crypto = Arc::new(SecretsCrypto::new(master_key)?);
|
||||
//!
|
||||
//! // Create store
|
||||
//! let store = PostgresSecretsStore::new(pool, crypto);
|
||||
//!
|
||||
//! // Store a secret
|
||||
//! store.create("user_123", CreateSecretParams::new("openai_key", "sk-...")).await?;
|
||||
//!
|
||||
//! // Check if secret exists (WASM can call this)
|
||||
//! let exists = store.exists("user_123", "openai_key").await?;
|
||||
//!
|
||||
//! // Decrypt for injection (host boundary only)
|
||||
//! let decrypted = store.get_decrypted("user_123", "openai_key").await?;
|
||||
//! ```
|
||||
|
||||
mod crypto;
|
||||
mod store;
|
||||
mod types;
|
||||
|
||||
pub use crypto::SecretsCrypto;
|
||||
pub use store::{PostgresSecretsStore, SecretsStore};
|
||||
pub use types::{
|
||||
CreateSecretParams, CredentialLocation, CredentialMapping, DecryptedSecret, Secret,
|
||||
SecretError, SecretRef,
|
||||
};
|
||||
|
||||
#[cfg(test)]
|
||||
pub use store::testing::InMemorySecretsStore;
|
||||
Reference in New Issue
Block a user