Scan staged workspace snapshots for secrets
This commit is contained in:
@@ -64,6 +64,30 @@ class ExecutionSnapshotTests(unittest.TestCase):
|
||||
with self.subTest(path=path), self.assertRaises(ValueError):
|
||||
self.stage([path])
|
||||
|
||||
def test_rejects_credentials_embedded_in_ordinary_source_files(self) -> None:
|
||||
source = self.root / "src" / "settings.py"
|
||||
source.write_text(
|
||||
'api_key = "abcDEF0123456789_secret_value"\n', encoding="utf-8"
|
||||
)
|
||||
with self.assertRaisesRegex(ValueError, "يحتوي على مفتاح"):
|
||||
self.stage(["src/settings.py"])
|
||||
|
||||
source.write_text(
|
||||
'GROQ_API_KEY = "gsk_12345678901234567890123456789012"\n',
|
||||
encoding="utf-8",
|
||||
)
|
||||
with self.assertRaisesRegex(ValueError, "يحتوي على مفتاح"):
|
||||
self.stage(["src/settings.py"])
|
||||
|
||||
def test_allows_obvious_environment_placeholder(self) -> None:
|
||||
source = self.root / "src" / "settings.py"
|
||||
source.write_text('api_key = "your_api_key_here"\n', encoding="utf-8")
|
||||
staged = self.stage(["src/settings.py"])
|
||||
try:
|
||||
self.assertTrue((staged.root / "src" / "settings.py").is_file())
|
||||
finally:
|
||||
staged.close()
|
||||
|
||||
def test_rejects_duplicate_empty_and_unallowlisted_workspace(self) -> None:
|
||||
for paths in ([], ["src/main.py", "src/main.py"]):
|
||||
with self.subTest(paths=paths), self.assertRaises(ValueError):
|
||||
|
||||
Reference in New Issue
Block a user