Quest 44 - Secret Scanner
Quest 44: Secret Scanner
easy 15-20 minutes🎯 Learning Objectives
- Identify common secret patterns (API keys, passwords, tokens) in source code
- Understand why hardcoded secrets are a critical security vulnerability
- Build a scanner that detects secrets using regex pattern matching
- Recognize AI-generated code that may accidentally embed test secrets
📖 Concept: Hardcoded Secrets — The Silent Killer
ในทุกๆ วัน มี API keys, passwords, และ tokens ถูก commit ขึ้น GitHub อย่างไม่ตั้งใจ สิ่งเหล่านี้เรียกว่า “hardcoded secrets” — ข้อมูลลับที่ถูกฝังไว้ใน source code แทนที่จะอยู่ใน environment variables หรือ secrets manager
ปัญหาคือ: เมื่อคุณ commit secret ขึ้น public repository แม้จะลบ commit แล้ว ก็ยังอยู่ใน git history — และ bots ที่เฝ้าดู GitHub อยู่ตลอด 24/7 จะ discover ได้ภายในไม่กี่นาที
// ❌ ห้ามทำ — hardcoded API keyconst apiKey = 'sk-abc123def456ghi789';
// ❌ ห้ามทำ — hardcoded database passwordconst dbPassword = 'super_secret_password_123';
// ✅ ถูกต้อง — ใช้ environment variableconst apiKey = process.env.API_KEY;const dbPassword = process.env.DB_PASSWORD;Think of secrets like house keys: you wouldn’t tape your house key to the front door. Don’t tape your API keys to your source code.
⚙️ How It Works
Common Secret Patterns
Secrets มักจะมีรูปแบบเฉพาะที่สามารถ detect ได้ด้วย regex:
| Secret Type | Pattern Example | Regex Hint |
|---|---|---|
| AWS Access Key | AKIAIOSFODNN7EXAMPLE | Starts with AKIA |
| API Key | sk-abc123..., api_key=... | Prefixes like sk-, api_key= |
| Password in code | password = "...", passwd: "..." | Keywords + assignment |
| Private Key | -----BEGIN RSA PRIVATE KEY----- | PEM format headers |
| JWT Token | eyJhbGci... | Starts with eyJ (base64) |
The Scanner Strategy
1. Read source code line by line ↓2. Match each line against known secret patterns ↓3. Filter out false positives (test files, comments, placeholders) ↓4. Return list of detected secrets with type and location💡 Example: Secret Scanner in Action
function scanSecrets(code) { const patterns = [ { type: 'AWS Key', regex: /AKIA[0-9A-Z]{16}/g }, { type: 'API Key', regex: /(?:api[_-]?key|apikey)\s*[:=]\s*['"][^'"]{8,}['"]/gi }, { type: 'Password', regex: /(?:password|passwd|pwd)\s*[:=]\s*['"][^'"]{4,}['"]/gi }, { type: 'Private Key', regex: /-----BEGIN.*PRIVATE KEY-----/g }, { type: 'JWT Token', regex: /eyJ[A-Za-z0-9_-]{20,}\.eyJ[A-Za-z0-9_-]{20,}/g }, { type: 'Generic Secret', regex: /(?:secret|token)\s*[:=]\s*['"][^'"]{8,}['"]/gi }, ];
const detections = []; const lines = code.split('\n');
for (let i = 0; i < lines.length; i++) { for (const { type, regex } of patterns) { const matches = lines[i].match(regex); if (matches) { detections.push({ line: i + 1, type, value: matches[0], }); } } }
return detections;}Key insight: A good secret scanner needs multiple patterns because different providers use different key formats. AWS keys look different from GitHub tokens, which look different from generic passwords.
⚠️ Common Mistakes
Mistake 1: Only checking for “password”
“I’ll just search for the word ‘password’” → Secrets come in many forms: API keys, tokens, connection strings, private keys. A comprehensive scanner needs multiple patterns.
Mistake 2: Flagging test data as secrets
“The scanner found ‘test123’ in the test file” → Distinguish between real secrets in production code and placeholder values in test files. Use context (file path, variable naming) to reduce false positives.
Mistake 3: Missing encoded secrets
“The secret is base64 encoded, so it doesn’t look like a password” → Attackers often encode secrets to avoid detection. Check for base64 patterns and common encoding schemes.
Mistake 4: Not scanning comments
“Comments aren’t executable code” → Developers sometimes paste secrets in comments as “temporary” notes. These are just as dangerous as secrets in code.
📝 Knowledge Check
📝 Knowledge Check
Q1:ทำไม hardcoded secrets ใน source code ถึงอันตราย?
Q2:AWS Access Key มีรูปแบบใด?
Q3:การ scan secrets ควรตรวจสอบอะไรบ้าง?
🏋️ Quest: Secret Scanner
เขียน secret scanner ที่ตรวจจับ hardcoded credentials ใน source code — AI มักจะ suggestion โค้ดที่ฝัง secrets ไว้ใน example code โดยไม่รู้ตัว!
-
Download ไฟล์เริ่มต้นของ quest:
Terminal window npx bluebeltdojo download quest-44-secret-scannercd quest-44-secret-scanner -
เปิด
problem.jsใน editor ของคุณพร้อมความช่วยเหลือของ AI -
Implement
scanSecrets(code)ที่ตรวจจับ:- API keys (AWS, generic patterns)
- Hardcoded passwords
- Private keys (PEM format)
- JWT tokens
- Return results พร้อม line number, type, และ matched value
-
ตรวจสอบ solution ของคุณ:
Terminal window node test.js
การตรวจสอบ
node test.jsWhen all tests pass, you will see the completion message.
ส่งคำตอบ
When tests pass, submit your solution:
npx bluebeltdojo submitต้องตั้งค่า access code ก่อน:
npx bluebeltdojo setup <code>
คำใบ้
- ใช้ regex patterns ที่แตกต่างกันสำหรับแต่ละ type ของ secret
- นึกถึงรูปแบบที่พบบ่อย:
AKIA...(AWS),sk-...(generic API key),-----BEGIN...(private key) - อย่าลืม return line number เพื่อให้ developer แก้ไขได้ง่าย
- ถ้าติดขัด ลองนึกว่า secrets ของ service ต่างๆ มีรูปแบบยังไง