# runtime/entrypoints/leak.entrypoint.ts

> 76 lines of code and 13 definitions.

Tree: Bane's Lab Content
Language: typescript
Layer: runtime
Canonical: https://banes-lab.com/anatomy/content#file-content-runtime-entrypoints-leak-entrypoint-ts
Source text: https://banes-lab.com/source/content/runtime/entrypoints/leak.entrypoint.ts.txt

Listed in [runtime/entrypoints](https://banes-lab.com/api/source/content/runtime/entrypoints.md), after [runtime/entrypoints/inventory.entrypoint.ts](https://banes-lab.com/source/content/runtime/entrypoints/inventory.entrypoint.ts.md) and before [runtime/entrypoints/link.entrypoint.ts](https://banes-lab.com/source/content/runtime/entrypoints/link.entrypoint.ts.md).

## Definitions

- `validate` (lexical_declaration, line 54)
- `derive` (lexical_declaration, line 37)
- `argv` (lexical_declaration, line 31)
- `inventory` (lexical_declaration, line 38)
- `seeds` (lexical_declaration, line 42)
- `target` (lexical_declaration, line 47)
- `leaks` (lexical_declaration, line 55)
- `graphs` (lexical_declaration, line 59)
- `roots` (lexical_declaration, line 63)
- `findings` (lexical_declaration, line 64)
- `payload` (lexical_declaration, line 66)
- `scan` (lexical_declaration, line 73)
- `machine` (lexical_declaration, line 74)

## Contained in

- [runtime/entrypoints](https://banes-lab.com/anatomy/content/folder-content-runtime-entrypoints.md)

## Uses

- [core/loaders/inventory.loader.ts](https://banes-lab.com/source/content/core/loaders/inventory.loader.ts.md)
- [core/loaders/leak.loader.ts](https://banes-lab.com/source/content/core/loaders/leak.loader.ts.md)
- [core/loaders/leak.output.loader.ts](https://banes-lab.com/source/content/core/loaders/leak.output.loader.ts.md)
- [core/loaders/seed.loader.ts](https://banes-lab.com/source/content/core/loaders/seed.loader.ts.md)
- [core/persistence/report.persistence.ts](https://banes-lab.com/source/content/core/persistence/report.persistence.ts.md)
- [core/reporters/derivation.reporter.ts](https://banes-lab.com/source/content/core/reporters/derivation.reporter.ts.md)
- [core/validators/leak.validator.ts](https://banes-lab.com/source/content/core/validators/leak.validator.ts.md)

## Enforces

- [Privacy by Design](https://banes-lab.com/records/architecture/privacy-by-design.md)

## Detector for

- [Personal Data Oversharing](https://banes-lab.com/records/architecture/personal-data-oversharing.md)

## Linked from

- [core/loaders](https://banes-lab.com/anatomy/content/folder-content-core-loaders.md)
- [core/persistence](https://banes-lab.com/anatomy/content/folder-content-core-persistence.md)
- [core/reporters](https://banes-lab.com/anatomy/content/folder-content-core-reporters.md)
- [core/validators](https://banes-lab.com/anatomy/content/folder-content-core-validators.md)

## Source

```typescript
import {
    CLEAN_LEAKS,
    NO_GRAPHS,
    NO_INVENTORY,
    NO_LEAK_SET,
    NO_SEEDS,
    SOURCES_SUFFIX,
    TOKENS_SUFFIX,
    WROTE,
} from "#configuration/strings/derivation.strings";
import { DERIVE_DESCRIBE, LEAK_SUMMARY } from "#configuration/strings/contract.strings";
import { DERIVE_FLAG, PRIVATE_ALLOWANCES, PRIVATE_TERMS } from "#configuration/constants/leak.constants";
import { conclude, refuse, say } from "#core/reporters/derivation.reporter";
import { deriveLeakSet, leakTarget, readLeakSet, workspaceRoots } from "#core/loaders/leak.loader";
import { hasFlag, resolveArgv } from "@govlab/argv";
import { inventoryTarget, readInventory } from "#core/loaders/inventory.loader";
import { machinePaths, publishedPaths, readPublished } from "#core/loaders/leak.output.loader";
import { readSeeds, seedsTarget } from "#core/loaders/seed.loader";
import { validatePayload, validatePublished } from "#core/validators/leak.validator";
import type { Finding } from "#types/derivation.types";
import { LEAK_COMMAND } from "#configuration/constants/contract.constants";
import { PAYLOAD_MISSING } from "#configuration/strings/coverage.strings";
import { defineCheck } from "@govlab/context/check";
import { loadContentGraphs } from "#core/loaders/coverage.loader";
import { persistJson } from "#core/persistence/report.persistence";
import { privateTermScanner } from "#core/matchers/leak.matcher";
import { readPagePayload } from "#core/loaders/payload.loader";

defineCheck({ detects: ["architecture:personal-data-oversharing"], enforces: ["architecture:privacy-by-design"] });

const argv = resolveArgv({
    command: LEAK_COMMAND,
    flags: [{ describe: DERIVE_DESCRIBE, name: DERIVE_FLAG, takesValue: false }],
    summary: LEAK_SUMMARY,
});

const derive = async function derive(): Promise<void> {
    const inventory = readInventory();
    if (inventory === null) {
        refuse(`${NO_INVENTORY}${inventoryTarget()}`);
    }
    const seeds = readSeeds();
    if (seeds === null) {
        refuse(`${NO_SEEDS}${seedsTarget()}`);
    }
    const leaks = deriveLeakSet(inventory, seeds);
    const target = leakTarget();
    await persistJson(target, leaks);
    say(
        `${WROTE}${target}: ${String(leaks.tokens.length)}${TOKENS_SUFFIX}${String(leaks.sources.length)}${SOURCES_SUFFIX}`,
    );
};

const validate = async function validate(): Promise<void> {
    const leaks = readLeakSet();
    if (leaks === null) {
        refuse(`${NO_LEAK_SET}${leakTarget()}`);
    }
    const graphs = await loadContentGraphs();
    if (graphs.length === 0) {
        say(NO_GRAPHS);
    }
    const roots = workspaceRoots();
    const findings: Finding[] = [];
    for (const graph of graphs) {
        const payload = readPagePayload(graph.page);
        if (payload === null) {
            findings.push({ file: graph.page, message: `${PAYLOAD_MISSING}${graph.page}` });
            continue;
        }
        findings.push(...validatePayload(payload, leaks, roots));
    }
    const scan = privateTermScanner(PRIVATE_TERMS, PRIVATE_ALLOWANCES);
    const machine = machinePaths();
    for (const path of publishedPaths()) {
        findings.push(...validatePublished(readPublished(path), scan, machine));
    }
    conclude(LEAK_COMMAND, findings, CLEAN_LEAKS);
};

await (hasFlag(argv, DERIVE_FLAG) ? derive() : validate());
```
