Files
monlet/server/tests/test_redaction.py
2026-05-27 10:01:59 +04:00

48 lines
1.2 KiB
Python

from monlet_server.redaction import redact
def test_redact_authorization_header_full_value():
# Per security.md the entire Authorization value is redacted.
assert redact("Authorization: Bearer abcdef123") == "Authorization: ***"
def test_redact_bearer_outside_header():
assert redact("token sent as Bearer abcdef123 to peer") == "token sent as Bearer *** to peer"
def test_redact_token_kv():
out = redact('token="abc123secret"')
assert "abc123secret" not in out
assert "***" in out
def test_redact_password_kv():
out = redact("password=qwerty12345")
assert "qwerty12345" not in out
def test_redact_authorization_header_value():
out = redact("authorization: deadbeefcafe")
assert "deadbeefcafe" not in out
assert "***" in out
def test_redact_cookie_header():
out = redact("Cookie: session=abc; user=u1")
assert "abc" not in out
assert "***" in out
def test_redact_set_cookie_header():
out = redact("Set-Cookie: sid=verysecret123; Path=/")
assert "verysecret123" not in out
def test_redact_credential_env():
out = redact("MY_CREDENTIAL=topsecret")
assert "topsecret" not in out
def test_none_passthrough():
assert redact(None) is None