Skip to content

Slack webhook detector misses uppercase hostnames #1139

Description

@bcdonadio

Observed behavior: The bundled slack-webhook-url detector does not match a synthetic Slack webhook URL when the hostname is uppercase (HOOKS.SLACK.COM), although the otherwise identical lowercase hostname matches. DNS hostnames are case-insensitive.

Expected behavior: Hostname case should not allow a Slack webhook credential to escape this detector, while path/token case semantics remain correct.

Root cause: The generated rule uses lowercase hooks.slack.com and flags: "". This behavior is present before PR #791 and is independent of that PR's hostname wildcard correction. Any eventual remedy should avoid indiscriminately making case-sensitive URL paths or tokens case-insensitive.

How to reproduce: At commit 24a7b4cad300f7b514adf5c69bda9f5a57fb1de6, load GITLEAKS_PATTERNS from src/generated-patterns.ts, select id === "slack-webhook-url", compile new RegExp(rule.regex, rule.flags), and test "https://" + host + "/services/" + "a".repeat(43) with host values hooks.slack.com and HOOKS.SLACK.COM. The lowercase result is true and uppercase false. The token is synthetic.

Context: Discovered during independent Opus planning review for #791. Tracked separately from its two-rule literal-dot repair, outside the current frozen Bug campaign inventory. No change to flags is authorized in #791.

Environment:

  • Agent: Codex (Astra owner; Opus 5 reviewer)
  • Connector: CLI
  • OS: Fedora Linux
  • Node: 25.9.0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    High

    Effort

    None yet

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions