Scan staged workspace snapshots for secrets

This commit is contained in:
Hamza Ayed
2026-10-03 13:00:28 +03:00
parent 3fa456698e
commit fbbfa3a2d4
3 changed files with 58 additions and 1 deletions
@@ -64,6 +64,30 @@ class ExecutionSnapshotTests(unittest.TestCase):
with self.subTest(path=path), self.assertRaises(ValueError):
self.stage([path])
def test_rejects_credentials_embedded_in_ordinary_source_files(self) -> None:
source = self.root / "src" / "settings.py"
source.write_text(
'api_key = "abcDEF0123456789_secret_value"\n', encoding="utf-8"
)
with self.assertRaisesRegex(ValueError, "يحتوي على مفتاح"):
self.stage(["src/settings.py"])
source.write_text(
'GROQ_API_KEY = "gsk_12345678901234567890123456789012"\n',
encoding="utf-8",
)
with self.assertRaisesRegex(ValueError, "يحتوي على مفتاح"):
self.stage(["src/settings.py"])
def test_allows_obvious_environment_placeholder(self) -> None:
source = self.root / "src" / "settings.py"
source.write_text('api_key = "your_api_key_here"\n', encoding="utf-8")
staged = self.stage(["src/settings.py"])
try:
self.assertTrue((staged.root / "src" / "settings.py").is_file())
finally:
staged.close()
def test_rejects_duplicate_empty_and_unallowlisted_workspace(self) -> None:
for paths in ([], ["src/main.py", "src/main.py"]):
with self.subTest(paths=paths), self.assertRaises(ValueError):