feat: add input validation for user secret env names and file paths (#24103)

Adds backend validation for user secret environment variable names and file paths.

Env name validation enforces POSIX naming rules and blocks a deliberately aggressive denylist of reserved names and prefixes. The denylist errs on the side of blocking too much since it's easier to remove entries later than to add them after users have created conflicting secrets.

File path validation requires paths to start with ~/ or /.
This commit is contained in:
Zach
2026-04-08 17:02:33 -06:00
committed by GitHub
parent 9b91af8ab7
commit 7caef4987f
3 changed files with 388 additions and 0 deletions
+14
View File
@@ -8081,6 +8081,20 @@ export interface UserSecret {
readonly updated_at: string;
}
// From codersdk/usersecretvalidation.go
/**
* UserSecretEnvValidationOptions controls deployment-aware behavior
* in environment variable name validation.
*/
export interface UserSecretEnvValidationOptions {
/**
* AIGatewayEnabled indicates that the deployment has AI Gateway
* configured. When true, AI Gateway environment variables
* (OPENAI_API_KEY, etc.) are reserved to prevent conflicts.
*/
readonly AIGatewayEnabled: boolean;
}
// From codersdk/users.go
export type UserStatus = "active" | "dormant" | "suspended";