2.3 KiB
2.3 KiB
Why
Public Postman collections and environments are a high-signal source for leaked API credentials because they often preserve request auth settings, headers, variables, and example payloads close to real API usage. The existing scanner already supports multi-source discovery, queues, TruffleHog filesystem scans, token rotation, and observability, so adding Postman can reuse the current architecture while expanding coverage beyond repositories, packages, containers, and HuggingFace Spaces.
What Changes
- Add a new
postmansource that discovers, queues, scans, and records Postman collection/environment artifacts. - Seed Postman targets from GitHub code search using public
*.postman_collection.jsonand*.postman_environment.jsonfiles. - Support a one-time backfill mode that scans up to the GitHub Search API result limit per query while filtering out artifacts older than a configured age window.
- Support a daily tail mode that fetches recently indexed pages and stops early when all targets on consecutive pages are already known.
- Use the configured GitHub auth pool for Postman discovery, rotating across tokens and sleeping when all tokens are rate-limited.
- Add durable Postman artifact caching so targets discovered from GitHub, npm, and PyPI can be scanned after temporary extraction directories are removed.
- Harvest Postman artifacts from npm and PyPI packages during existing package extraction flows and enqueue them into the shared Postman queue.
- Add Postman-aware result enrichment that classifies credentials using TruffleHog findings plus Postman auth/header/query/body/environment context.
Capabilities
New Capabilities
postman-source: Discovery, queueing, scanning, caching, and enrichment for Postman collection and environment artifacts.
Modified Capabilities
- None.
Impact
- Affected scanner paths:
app/scanner.py,app/console_runner.py,app/scanner_db.py,app/dashboard.py, andapp/config.yaml. - Adds runtime files under
runtime/queues/fortodo_postman.txtandchecked_postman.txt. - Adds durable artifact storage under a runtime Postman cache directory.
- Uses existing GitHub auth pools from
secrets.yaml; no new secret format is required for GitHub discovery. - Uses existing TruffleHog filesystem scanning and keychecker follow-up flows; no breaking changes to current sources are expected.