"""Specialized security tests for authorization header and secret redaction (SEC-006).""" import os from src.runtime.observability.structured_logger import SanitizedJsonLogger def test_secret_redaction_in_text(): os.environ["GROQ_API_KEY"] = "gsk_supersecretkey12345" logger_inst = SanitizedJsonLogger() raw_message = "Error calling Groq: key gsk_supersecretkey12345 is unauthorized" sanitized = logger_inst.sanitize_text(raw_message) assert "gsk_supersecretkey12345" not in sanitized assert "[REDACTED_SECRET]" in sanitized def test_secret_redaction_in_dictionary(): logger_inst = SanitizedJsonLogger() data = { "user": "admin", "authorization": "Bearer secret_token_xyz", "nested": { "api_key": "another_secret", "safe_field": "value", }, } sanitized = logger_inst.sanitize_dict(data) assert sanitized["authorization"] == "[REDACTED_SECRET]" assert sanitized["nested"]["api_key"] == "[REDACTED_SECRET]" assert sanitized["nested"]["safe_field"] == "value"