42 lines
1.4 KiB
Python
42 lines
1.4 KiB
Python
|
|
import json
|
||
|
|
|
||
|
|
from secrets_engine.evidence import EvidenceWriter, _scrub
|
||
|
|
from secrets_engine.redact import looks_secret, redact_text
|
||
|
|
|
||
|
|
|
||
|
|
def test_redact_known_token_shapes():
|
||
|
|
assert "npm_" not in redact_text("token=npm_abcdEFGH12345678abcd")
|
||
|
|
assert "REDACTED" in redact_text("token=npm_abcdEFGH12345678abcd")
|
||
|
|
assert "ghp_" not in redact_text("ghp_0123456789abcdef0123")
|
||
|
|
|
||
|
|
|
||
|
|
def test_redact_extra_literal():
|
||
|
|
out = redact_text("the value is hunter2hunter2", extra=["hunter2hunter2"])
|
||
|
|
assert "hunter2" not in out
|
||
|
|
|
||
|
|
|
||
|
|
def test_looks_secret():
|
||
|
|
assert looks_secret("npm_token")
|
||
|
|
assert looks_secret("API_KEY")
|
||
|
|
assert not looks_secret("path")
|
||
|
|
|
||
|
|
|
||
|
|
def test_scrub_drops_secret_keys_and_redacts():
|
||
|
|
scrubbed = _scrub({"token": "npm_realvalue123456789", "path": "a/b", "note": "ghp_0123456789abcdef0123"})
|
||
|
|
assert scrubbed["token"].startswith("<omitted")
|
||
|
|
assert scrubbed["path"] == "a/b"
|
||
|
|
assert "ghp_" not in scrubbed["note"]
|
||
|
|
|
||
|
|
|
||
|
|
def test_evidence_record_has_no_value(tmp_path):
|
||
|
|
w = EvidenceWriter(evidence_dir=tmp_path, hub_url="") # hub disabled
|
||
|
|
rec = w.record(
|
||
|
|
"provision", result="from-file", catalog_id="lane", stage="prod",
|
||
|
|
detail={"field": "npm_token", "value": "npm_shouldnotappear123"},
|
||
|
|
)
|
||
|
|
blob = json.dumps(rec)
|
||
|
|
assert "npm_shouldnotappear123" not in blob
|
||
|
|
# written to disk too
|
||
|
|
files = list(tmp_path.glob("evidence-*.jsonl"))
|
||
|
|
assert files and "npm_shouldnotappear123" not in files[0].read_text()
|