Skip to content

feat(detect): recursive type detection for nested credential structures #24

Description

@f3rdy

Problem

detect-types inspects only the top-level structure of vault entries. Entries like Jenkins credential stores contain deeply nested structures with explicit type fields in sub-objects, but detection doesn't reach them.

Example structure (redacted)

vault_jenkins_credentials:
  global:
    credentials:
      - type: gitLabApiTokenImpl
        id: "..."
        apiToken: "..."
      - type: usernamePassword
        id: "..."
        username: "..."
        password: "..."
      - type: string
        id: "..."
        secret: "..."
      - type: azure
        id: "..."
        subscriptionId: "..."
        clientId: "..."
        clientSecret: "..."
  domains:
    - name: "..."
      credentials:
        - type: usernamePassword
          ...

Current detection classifies this as usernamePassword (medium) based on the key name pattern — missing the rich type information already present in the sub-objects.

Expected behavior

  • Recognize nested credential container patterns (*.credentials[])
  • Read explicit type fields from sub-objects
  • Report a summary of contained credential types, e.g.:
    vault_jenkins_credentials  → credentialStore (high)
      contains: 6x usernamePassword, 4x string, 1x gitLabApiTokenImpl, 1x azure
    
  • Support Jenkins-style structures (global.credentials, domains[].credentials)

Context

This pattern comes from Ansible roles that manage Jenkins credentials via JCasC (Jenkins Configuration as Code). The vault entry mirrors the Jenkins credential domain hierarchy.

Acceptance criteria

  • Recursive inspection of vault entries
  • Detect credentials[] list patterns with typed sub-objects
  • New container type (e.g. credentialStore) for entries with multiple nested credentials
  • Sub-type summary in detect-types output
  • Privacy: only structural metadata used, no secret values

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions