Skip to content

Zero an over-limit credential blob in the Windows store [patch] - #181

Merged
matt-edmondson merged 1 commit into
mainfrom
fix/165-scrub-oversize-windows-blob
Oct 5, 2026
Merged

matt-edmondson merged 1 commit into
mainfrom
fix/165-scrub-oversize-windows-blob

Conversation

@matt-edmondson

Copy link
Copy Markdown
Contributor

Fixes #165

What changed

WindowsCredentialStore.Save checked the 2560-byte CredentialBlob limit before entering its try { … } finally { Zero(blob); }, so an oversize credential (e.g. a long JWT or PAT) was rejected with its serialized plaintext left on the managed heap unscrubbed.

Rather than only moving the check inside the store's try, the check now lives in a shared helper, NativeSecretBuffer.CopyWithinLimit(byte[] source, int maxLength, string storeName). It takes ownership of the serialized bytes, throws CredentialStoreException when they exceed the limit, otherwise copies them into a NativeSecretBuffer, and zeroes the managed copy in a finally on every path. This follows the pattern OfCredential already uses: the scrubbing sequence sits where the tests can reach it on every OS, not in a store body that only runs on Windows.

The exception message is unchanged ("Credential exceeds the Windows Credential Manager blob size limit of 2560 bytes (was N).") because the store passes its own Name.

Tests

  • SecretScrubbingTests.CopyWithinLimitRejectsAnOversizeSourceAndStillZeroesIt checks that the throw still happens and that the source buffer is all zeros afterwards. This covers the issue's stronger acceptance criterion: the scrub is observed directly.
  • CopyWithinLimitCopiesASourceAtTheLimitAndZeroesTheManagedCopy and CopyWithinLimitRejectsANullSource cover the success path and the null-argument path.
  • NativeStoreScrubbingWiringTests.TheWindowsStoreChecksItsBlobLimitInsideTheScrubbing pins WindowsCredentialStore.Save to the helper with the existing IL scan.

Verified the test catches the bug: with only the WindowsCredentialStore.cs change reverted, TheWindowsStoreChecksItsBlobLimitInsideTheScrubbing fails. With the change in place, the full suite passes on Linux: 68 passed, 0 failed, 5 skipped. The skips are the existing native-store tests, which report Inconclusive because libsecret is not available in this environment.

🤖 Generated with Claude Code

https://claude.ai/code/session_018fjR4mduqAKqmuCXhfcCbx


Generated by Claude Code

WindowsCredentialStore.Save checked the 2560-byte blob limit before its
try/finally, so an oversize credential was rejected with its serialized
plaintext left on the managed heap unscrubbed. The check now lives in
NativeSecretBuffer.CopyWithinLimit, which zeroes the managed copy on every
path, rejection included, and runs under test on every operating system.

Fixes #165

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018fjR4mduqAKqmuCXhfcCbx
Comment thread CredentialCache/Storage/WindowsCredentialStore.cs
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Windows Save leaves the serialized plaintext credential unscrubbed when it exceeds the 2560-byte blob limit

1 participant