So lanes can discover what the lockbox holds without opening it (Super Admin 50 request). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
65 lines
2.4 KiB
Python
65 lines
2.4 KiB
Python
"""lockbox-names: headings + labels + resolvable, NEVER a value or prose after a label."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import os
|
|
import subprocess
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[2]
|
|
V1 = "Qm7xT2vLp9RkZw4HnB8dYc3S" # synthetic values
|
|
V2 = "other-fake-value-1234567890"
|
|
V3 = "dup-one-aaaaaaaaaaaaaaaa"
|
|
V4 = "dup-two-bbbbbbbbbbbbbbbb"
|
|
PROSE = "ZZPROSEZZ-not-for-printing"
|
|
|
|
|
|
def make(tmp_path):
|
|
r = tmp_path / "kit"
|
|
(r / "secrets" / "x").mkdir(parents=True)
|
|
(r / "ACCESS_LOCKBOX.md").write_text(
|
|
"# LOCKBOX\n\n## 🔷 AZURE signing (added 10-01)\n"
|
|
f"- **Tenant:** {PROSE} lives in the portal\n"
|
|
f"- **`AZURE_CLIENT_ID`**: `{V1}`\n"
|
|
f"- **Secret (AZURE_CLIENT_SECRET):** `{V2}`\n"
|
|
"## GOOGLE oauth\n"
|
|
f"GOOGLE_OAUTH_CLIENT_ID={V2}\n"
|
|
f"- **`DUP_KEY`**: `{V3}`\n- **`DUP_KEY`**: `{V4}`\n"
|
|
f"## stray\n**{V1}** is a heading-like bold that is secret shaped? no, just label\n")
|
|
(r / "secrets" / "x" / "a.env").write_text(f"FILE_KEY={V1}\n")
|
|
subprocess.run(["git", "init", "-q", "-b", "main"], cwd=r, check=True)
|
|
return r
|
|
|
|
|
|
def run(r, *args):
|
|
e = {**os.environ, "LOCKBOX_REPO": str(r), "LOCKBOX_REF": "WORKTREE"}
|
|
p = subprocess.run([sys.executable, str(ROOT / "scripts" / "lockbox_names.py"), *args],
|
|
capture_output=True, text=True, env=e)
|
|
return p.returncode, p.stdout + p.stderr
|
|
|
|
|
|
def test_lists_labels_and_resolvable_without_values_or_prose(tmp_path):
|
|
r = make(tmp_path)
|
|
rc, out = run(r, "AZURE|GOOGLE|FILE|DUP")
|
|
assert rc == 0
|
|
assert "AZURE signing (added 10-01) | AZURE_CLIENT_ID | md | yes" in out
|
|
assert "| GOOGLE_OAUTH_CLIENT_ID | env | yes" in out
|
|
assert "| FILE_KEY | file | yes" in out
|
|
assert "| DUP_KEY | md | dup" in out
|
|
# a prose label is listed but never resolvable, and nothing after the label leaks
|
|
assert "| Tenant: " not in out or "| Tenant" in out
|
|
assert "| label | no" in out
|
|
for secret in (V1, V2, V3, V4, PROSE, "lives in the portal"):
|
|
assert secret not in out
|
|
for i in range(0, len(secret) - 7):
|
|
assert secret[i:i + 8] not in out
|
|
|
|
|
|
def test_filter_and_bad_regex(tmp_path):
|
|
r = make(tmp_path)
|
|
rc, out = run(r, "NOSUCHTHING")
|
|
assert rc == 0 and "0 entries" in out
|
|
rc, out = run(r, "(")
|
|
assert rc == 2 and "bad regex" in out
|