fix(02): scan leftover passwords and redact secrets in diffs (WR-04)

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 14:43:01 +02:00
parent d3d202e0e2
commit 0ac9dc45d0
4 changed files with 114 additions and 10 deletions

View File

@@ -405,7 +405,7 @@ func TestScrubShortIDsLeavePaginationAndIPv4Literal(t *testing.T) {
}
store.Set("id:album", "1")
step := Step{
ID: "page",
ID: "page",
Request: Request{Method: http.MethodGet, Path: "/albums/1"},
Response: Response{
Status: 200,
@@ -424,6 +424,54 @@ func TestScrubShortIDsLeavePaginationAndIPv4Literal(t *testing.T) {
}
}
func TestScrubRejectsUnknownPasswordKeepsAllowlist(t *testing.T) {
store, err := OpenStore("")
if err != nil {
t.Fatal(err)
}
allowed := Step{
ID: "login",
Request: Request{Method: http.MethodPost, Path: "/login", Body: Body(`{"email":"alice@parity.test","password":"parity-alice-pass"}`)},
Response: Response{Status: 200, Body: Body(`{"ok":true}`)},
}
if err := ScrubStep(store, &allowed); err != nil {
t.Fatalf("allow-listed test password: %v", err)
}
leaked := Step{
ID: "login",
Request: Request{Method: http.MethodPost, Path: "/login", Body: Body(`{"email":"alice@parity.test","password":"hunter2-live"}`)},
Response: Response{Status: 200, Body: Body(`{"ok":true}`)},
}
if err := ScrubStep(store, &leaked); err == nil || !strings.Contains(err.Error(), "password") {
t.Fatalf("unknown password: %v", err)
}
opaque := Step{
ID: "tok",
Response: Response{Status: 200, Body: Body(`{"access_token":"not-a-jwt-but-secret"}`)},
}
if err := ScrubStep(store, &opaque); err == nil || !strings.Contains(err.Error(), "access_token") {
t.Fatalf("opaque access_token: %v", err)
}
}
func TestMismatchErrorRedactsJWT(t *testing.T) {
err := &MismatchError{Result: Result{Steps: []StepResult{{
ID: "t",
Diffs: []Diff{{
Path: "$.token",
Expected: testJWT,
Actual: testJWT + "x",
}},
}}}}
msg := err.Error()
if strings.Contains(msg, "eyJ") {
t.Fatalf("mismatch leaked jwt: %s", msg)
}
if !strings.Contains(msg, "<redacted-jwt>") {
t.Fatalf("expected redaction: %s", msg)
}
}
func TestScrubFormFieldDespiteSubstringSecrets(t *testing.T) {
store, err := OpenStore("")
if err != nil {