34 lines
1.0 KiB
Python
34 lines
1.0 KiB
Python
"""Specialized security tests for authorization header and secret redaction (SEC-006)."""
|
|
|
|
import os
|
|
|
|
from src.runtime.observability.structured_logger import SanitizedJsonLogger
|
|
|
|
|
|
def test_secret_redaction_in_text():
|
|
os.environ["GROQ_API_KEY"] = "gsk_supersecretkey12345"
|
|
logger_inst = SanitizedJsonLogger()
|
|
|
|
raw_message = "Error calling Groq: key gsk_supersecretkey12345 is unauthorized"
|
|
sanitized = logger_inst.sanitize_text(raw_message)
|
|
|
|
assert "gsk_supersecretkey12345" not in sanitized
|
|
assert "[REDACTED_SECRET]" in sanitized
|
|
|
|
|
|
def test_secret_redaction_in_dictionary():
|
|
logger_inst = SanitizedJsonLogger()
|
|
data = {
|
|
"user": "admin",
|
|
"authorization": "Bearer secret_token_xyz",
|
|
"nested": {
|
|
"api_key": "another_secret",
|
|
"safe_field": "value",
|
|
},
|
|
}
|
|
|
|
sanitized = logger_inst.sanitize_dict(data)
|
|
assert sanitized["authorization"] == "[REDACTED_SECRET]"
|
|
assert sanitized["nested"]["api_key"] == "[REDACTED_SECRET]"
|
|
assert sanitized["nested"]["safe_field"] == "value"
|