Harden common third party enricher edge cases

Reject oversized logo responses instead of silently truncating them,
which could persist corrupt image bytes as a valid logo.

Tighten ownership substring matching with a length-ratio guard so a
short label root no longer attributes unrelated domains to a vendor.

Render the worker confidence threshold when set to zero by testing
against nil, so an explicit "accept all" value is not dropped by Helm's
falsy-numeric truthiness.

Sanitize and bound per-agent error text before persisting it to the
enrichment metadata column to avoid leaking unbounded internal detail.

Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
Émile Ré
2026-06-11 18:54:28 +02:00
parent 08ff9277e7
commit d226a8be9a
4 changed files with 42 additions and 10 deletions

View File

@@ -167,10 +167,11 @@ func exactLabelMatch(label string, vendorLabels []string) bool {
return slices.Contains(vendorLabels, label)
}
// relatedLabelMatch reports whether label is the same as, contains, or is
// contained by any vendor label. Substring matches require the shorter
// string to be at least minLabelOverlap characters to avoid spurious hits
// on very short labels.
// relatedLabelMatch reports whether label is the same as, or shares a
// dominant root with, any vendor label. A substring match requires the
// shorter label to be at least minLabelOverlap characters AND to cover at
// least half of the longer label, so a short root (e.g. "meta") no longer
// attributes an unrelated domain (e.g. "metallica") to the vendor.
func relatedLabelMatch(label string, vendorLabels []string) bool {
for _, vl := range vendorLabels {
if label == vl {
@@ -182,7 +183,15 @@ func relatedLabelMatch(label string, vendorLabels []string) bool {
shorter, longer = longer, shorter
}
if len(shorter) >= minLabelOverlap && strings.Contains(longer, shorter) {
if len(shorter) < minLabelOverlap {
continue
}
if len(shorter)*2 < len(longer) {
continue
}
if strings.Contains(longer, shorter) {
return true
}
}