Files

34 lines
1.0 KiB
Python

"""Specialized security tests for authorization header and secret redaction (SEC-006)."""
import os
from src.runtime.observability.structured_logger import SanitizedJsonLogger
def test_secret_redaction_in_text():
os.environ["GROQ_API_KEY"] = "gsk_supersecretkey12345"
logger_inst = SanitizedJsonLogger()
raw_message = "Error calling Groq: key gsk_supersecretkey12345 is unauthorized"
sanitized = logger_inst.sanitize_text(raw_message)
assert "gsk_supersecretkey12345" not in sanitized
assert "[REDACTED_SECRET]" in sanitized
def test_secret_redaction_in_dictionary():
logger_inst = SanitizedJsonLogger()
data = {
"user": "admin",
"authorization": "Bearer secret_token_xyz",
"nested": {
"api_key": "another_secret",
"safe_field": "value",
},
}
sanitized = logger_inst.sanitize_dict(data)
assert sanitized["authorization"] == "[REDACTED_SECRET]"
assert sanitized["nested"]["api_key"] == "[REDACTED_SECRET]"
assert sanitized["nested"]["safe_field"] == "value"