fix(02): scan leftover passwords and redact secrets in diffs (WR-04)
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -405,7 +405,7 @@ func TestScrubShortIDsLeavePaginationAndIPv4Literal(t *testing.T) {
|
||||
}
|
||||
store.Set("id:album", "1")
|
||||
step := Step{
|
||||
ID: "page",
|
||||
ID: "page",
|
||||
Request: Request{Method: http.MethodGet, Path: "/albums/1"},
|
||||
Response: Response{
|
||||
Status: 200,
|
||||
@@ -424,6 +424,54 @@ func TestScrubShortIDsLeavePaginationAndIPv4Literal(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestScrubRejectsUnknownPasswordKeepsAllowlist(t *testing.T) {
|
||||
store, err := OpenStore("")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
allowed := Step{
|
||||
ID: "login",
|
||||
Request: Request{Method: http.MethodPost, Path: "/login", Body: Body(`{"email":"alice@parity.test","password":"parity-alice-pass"}`)},
|
||||
Response: Response{Status: 200, Body: Body(`{"ok":true}`)},
|
||||
}
|
||||
if err := ScrubStep(store, &allowed); err != nil {
|
||||
t.Fatalf("allow-listed test password: %v", err)
|
||||
}
|
||||
leaked := Step{
|
||||
ID: "login",
|
||||
Request: Request{Method: http.MethodPost, Path: "/login", Body: Body(`{"email":"alice@parity.test","password":"hunter2-live"}`)},
|
||||
Response: Response{Status: 200, Body: Body(`{"ok":true}`)},
|
||||
}
|
||||
if err := ScrubStep(store, &leaked); err == nil || !strings.Contains(err.Error(), "password") {
|
||||
t.Fatalf("unknown password: %v", err)
|
||||
}
|
||||
opaque := Step{
|
||||
ID: "tok",
|
||||
Response: Response{Status: 200, Body: Body(`{"access_token":"not-a-jwt-but-secret"}`)},
|
||||
}
|
||||
if err := ScrubStep(store, &opaque); err == nil || !strings.Contains(err.Error(), "access_token") {
|
||||
t.Fatalf("opaque access_token: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestMismatchErrorRedactsJWT(t *testing.T) {
|
||||
err := &MismatchError{Result: Result{Steps: []StepResult{{
|
||||
ID: "t",
|
||||
Diffs: []Diff{{
|
||||
Path: "$.token",
|
||||
Expected: testJWT,
|
||||
Actual: testJWT + "x",
|
||||
}},
|
||||
}}}}
|
||||
msg := err.Error()
|
||||
if strings.Contains(msg, "eyJ") {
|
||||
t.Fatalf("mismatch leaked jwt: %s", msg)
|
||||
}
|
||||
if !strings.Contains(msg, "<redacted-jwt>") {
|
||||
t.Fatalf("expected redaction: %s", msg)
|
||||
}
|
||||
}
|
||||
|
||||
func TestScrubFormFieldDespiteSubstringSecrets(t *testing.T) {
|
||||
store, err := OpenStore("")
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user