#!/usr/bin/env bash set -uo pipefail # CASAN Plan-16 SEC-27 (X-02) — strip control/ANSI chars from log output. # # Log messages carry attacker-influenced data (action names, tool-output snippets). # A raw ESC/CSI sequence can rewrite a reviewer's terminal; a raw CR/LF can inject a # fake log line. casan_log now strips control chars (keeping tab). Proves the ESC # byte and embedded newlines are removed while the visible text survives. # # Deterministic; no model/network. SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)" PASS=0; FAIL=0 pass() { echo "PASS: $1"; PASS=$((PASS + 1)); } fail() { echo "FAIL: $1"; FAIL=$((FAIL + 1)); } echo "===== Plan-16 SEC-27: log control-char stripping =====" # shellcheck source=/dev/null source "$PROJECT_ROOT/.specify/scripts/bash/casan-log.sh" PAYLOAD="$(printf 'start\033[31mRED\033[0m\nFAKE [ERROR] injected-audit-line')" OUT="$(casan_log error test "$PAYLOAD" 2>&1)" if printf '%s' "$OUT" | od -An -c | grep -q '033'; then fail "ESC byte survived into the log (terminal-escape injection)" else pass "ESC byte stripped from log output" fi LINES="$(printf '%s\n' "$OUT" | grep -c .)" [[ "$LINES" -eq 1 ]] \ && pass "embedded newline stripped — no injected second log line" \ || fail "log emitted $LINES lines (newline injection)" printf '%s' "$OUT" | grep -q "start" && printf '%s' "$OUT" | grep -q "RED" \ && pass "visible text preserved (only control bytes removed)" \ || fail "visible text lost" echo "" echo "===== SEC-27 SUMMARY: PASS=$PASS FAIL=$FAIL =====" [[ "$FAIL" -eq 0 ]] || exit 1