Files
osmedeus/internal/executor/sudo_scan.go
T
j3ssie bd1434739e feat: add sudo authentication support with keepalive and variable renames
- Add sudo_auth() function for TTY prompts and credential management with optional 4-minute keepalive loop
- Add --sudo-aware CLI flag to detect workflows with sudo commands and offer authentication guidance
- Add sudo step scanner to detect sudo usage across all step types (bash, parallel, foreach) and nested structures
- Add parse_url_file() function to batch-process URLs with format directives, supporting bare IPs and CIDR notation
- Add portscan test data with realistic nmap JSONL samples
- Rename {{Workspace}} to {{TargetSpace}} in function examples for clarity
- Add sudo E2E tests covering tip message, flag acceptance, and non-sudo workflows
2026-02-16 23:46:33 +07:00

82 lines
1.8 KiB
Go

package executor
import (
"strings"
"github.com/j3ssie/osmedeus/v5/internal/core"
)
// scanStepsForSudo returns true if any step (or nested step) contains
// a command that invokes sudo.
func scanStepsForSudo(steps []core.Step) bool {
for i := range steps {
if stepContainsSudo(&steps[i]) {
return true
}
}
return false
}
// stepContainsSudo checks a single step and its nested children
// for sudo command usage.
func stepContainsSudo(step *core.Step) bool {
// Check direct command fields
if containsSudoCommand(step.Command) {
return true
}
for _, cmd := range step.Commands {
if containsSudoCommand(cmd) {
return true
}
}
for _, cmd := range step.ParallelCommands {
if containsSudoCommand(cmd) {
return true
}
}
// Check parallel nested steps
if len(step.ParallelSteps) > 0 && scanStepsForSudo(step.ParallelSteps) {
return true
}
// Check foreach nested step
if step.Step != nil && stepContainsSudo(step.Step) {
return true
}
return false
}
// containsSudoCommand detects "sudo " at word boundaries — start of string
// or after a pipe/semicolon/ampersand/whitespace. This avoids false
// positives on words like "pseudo" or "sudoku".
func containsSudoCommand(cmd string) bool {
if cmd == "" {
return false
}
// Check if the command starts with "sudo "
if strings.HasPrefix(cmd, "sudo ") {
return true
}
// Check for sudo after common shell separators: |, ;, &&, ||, `, $(
// We look for any of these chars followed by optional whitespace and "sudo "
for i := 0; i < len(cmd)-5; i++ {
c := cmd[i]
if c == '|' || c == ';' || c == '&' || c == '`' || c == '(' {
// Skip whitespace after the separator
j := i + 1
for j < len(cmd) && (cmd[j] == ' ' || cmd[j] == '\t') {
j++
}
if strings.HasPrefix(cmd[j:], "sudo ") {
return true
}
}
}
return false
}