# gitlab.hyva.io — L2 secrets triage (2026-08-10)

## Method
- L1 re-confirmed 2026-08-10: OAuth password grant 200, token scope=api.
- Identity: nirajp (id 3153, niraj.p@tridhyatech.com), state=active, is_admin ABSENT on
  18.11.7 (GitLab CE hides the flag for non-admins), two_factor_enabled=false.
- Permission probes [VERIFIED]: GET /projects/{10,1677}/variables → 403, /runners → 403,
  /groups/3/variables → 403. Account is Developer-level (or below) on ALL enumerated
  projects → NO CI/CD-variable surface at this access level. (Pitfall 3 inverse: docs
  promise maintainer-only; here even membership projects deny — access_level < 40.)
- Blob search: 544/544 membership projects x 11 keyword patterns, per-project search API
  (global search needs Elasticsearch — not probed since per-project worked everywhere).
  476 raw hits in 172 projects, 0 request errors, full coverage verified
  (L2_blobs/<id>.json per project; L2_blobs.json merged; L2.json blob_hits synced).

## Result: NO live secrets found (high confidence)
Classes explicitly searched and found ZERO: glpat-*, Telegram bot tokens, JWT,
BEGIN * PRIVATE KEY, AKIA[0-9A-Z]{16}.
All 476 hits triaged into:
1. Magento store-config PATHS, not values: `hyva_ai/anthropic/api_key`,
   `hyva_ai/openai/api_key`, `hyva_ai/gemini/api_key`, `hyva_ai/deepl/api_key`,
   `locator/general/store_api_key`, `stripe_publishable_key` — the modules read keys
   from the deploying shop's DB (core_config_data) at runtime. Repo holds only the
   config path. Residual vector = merchant Magento DB / admin panel, NOT this repo.
2. JS/PHP indirection noise: `this.$refs[`, `ko.observable()`, `urlVars.token`,
   `$themeHelper->getStoreConfig(`, `$this->decryptText($this->getConfigData(`,
   `formValidation.fields.password.element.value`, etc.
3. reCAPTCHA / layout identifiers: g-recaptcha-response, recaptcha_validation_*,
   form handles — public, non-secret.
4. `${CI_JOB_TOKEN}` in hyva-themes/base-ci test/playwright.yml — ephemeral per-job
   token reference, not a stored value.
5. b64 API endpoints in magento2-hyva-stripe-connect src/Model/Config.php decode to
   https://www.hyva.io/rest/V1/stripe-connect/init and .../tokens/consume —
   Hyvä's own licensing/connect API URLs. Endpoints, not credentials.

## Why no secrets is plausible
hyva-themes/* is a commercial Magento theme vendor: 454/544 repos are hyva-compat
third-party-module compatibility shims + 19 i18n + 19 koti sample-data. Code is
licensed-distributed; real credentials live in merchant deployments, not the vendor's
product repos. 88 private repos include hyva-docs (39 hits = docs prose) and
default-theme CSP fixtures (52 hits across 2 repos = test fixture noise).

## L3 history scan (2026-08-10, operator "go")
Bulk mirror-clone 544/544 repos (547M, 0 failures) → TWO independent scanners:
1. trufflehog 3.90.5 filesystem over .git objects: 68 findings, ALL false positives —
   Gitlab detector matched repo NAMES in each mirror's `config` file, Github detector
   matched a commit SHA in `packed-refs`. 0 verified, 0 real values.
2. git log -G<regex> -p across all refs (7 patterns: glpat, tg_bot, jwt, privkey,
   aws, stripe_live, secret_kv w/ denylist): **0 hits across all 544 repos' full history**.
Two independent sources agree: NO secrets in HEAD AND NO secrets in history
(no committed-then-deleted credentials). L3 residual vector CLOSED.

## Residual vectors (remaining, operator-gated)
- Merchant-side config DBs (core_config_data) hold the actual AI/Stripe/Maps keys.
- nirajp password reuse (niraj@2345) on other Tridhya/Hyvä services — victim pivot.
- ${CI_JOB_TOKEN} registry/dependency-proxy usage in base-ci — CI runner surface
  would open only with a maintainer-level account.

## Files
- L2.json — full enumeration + merged blob_hits (476), blob_pass_complete=2026-08-10
- L2_blobs.json — merged hits (no-masking, full ≤400-char snippets)
- L2_blobs/<id>.json — per-project checkpoints (544)
- l2_blobs.py — scanner (resume-safe)
- .oauth.json / .token — current OAuth token (expires ~2h from 2026-08-10T08:29Z)
- OPLOG.md — appended 2026-08-10 session lines
