keyhog-verifier
Live credential verification for the KeyHog secret scanner. Takes deduplicated matches, asks the owning service whether each credential is still active, and returns a typed verdict per finding. Also owns the shared SSRF classifier, the per-service rate limiter, and AWS SigV4 request signing that the source crates delegate to rather than forking.
Part of the KeyHog secret scanner.
use is_private_url;
use VerifyConfig;
// One SSRF classifier for the whole fleet. Sources call this instead of
// carrying a local copy, so a loopback or link-local target is refused in
// exactly one place.
assert!;
assert!;
assert!;
// Verification is opt in and configured, never ambient.
let config = default;
let _ = config;
Public entry points
VerificationEngineholds the shared HTTP client, the response cache, and the global and per-service concurrency limits. Build one and reuse it; constructing several defeats the cache and the rate limits.VerificationEngine::verify_alltakesVec<DedupedMatch>and returns oneVerifiedFindingper input group.VerifyConfigcarries every knob that changes network behavior, including TLS posture and proxy handling.proxy_is_activereports the resolved state.ssrf::is_private_urlandis_private_ip_addrare the canonical private and link-local classifiers.rate_limit::get_rate_limiteris the shared limiter.sigv4signs AWS requests.
Failure behavior
A credential that cannot be checked is never reported as inactive. Network failure, rate limiting, and an unreachable service each produce their own verdict, distinct from a service answering that the credential is dead. That distinction is the whole point of the crate: treating an unreachable service as a revoked credential would hide a live secret.
Features
default = ["live"]. Building without live removes the network verification
path; the SSRF, rate limiting, and signing helpers stay available. Verification
never runs unless the caller asks for it.
Documentation
- Verification describes the verdicts and what each one means.
- Hardening and data handling describes what leaves the process during verification.
- API documentation is on docs.rs.