20 lines
939 B
JavaScript
20 lines
939 B
JavaScript
import assert from "node:assert/strict";
|
|
import { randomUUID } from "node:crypto";
|
|
import test from "node:test";
|
|
|
|
import { boundedBody, redactHeaders, safeUrl } from "../scripts/m0-spike.mjs";
|
|
|
|
test("export policy redacts credentials and bounds bodies", () => {
|
|
const sensitive = randomUUID();
|
|
assert.deepEqual(redactHeaders({ Cookie: sensitive, Authorization: sensitive, Referer: "https://example.test/private", "Set-Cookie": sensitive, Accept: "*/*" }), {
|
|
accept: "*/*",
|
|
authorization: "[REDACTED]",
|
|
cookie: "[REDACTED]",
|
|
referer: "[REDACTED]",
|
|
"set-cookie": "[REDACTED]",
|
|
});
|
|
assert.equal(safeUrl("https://example.test/path?token=secret"), "https://example.test/path?<redacted>");
|
|
assert.deepEqual(boundedBody("hello", false, 5), { state: "stored", bytes: 5, encoding: "utf8", text: "hello" });
|
|
assert.deepEqual(boundedBody("hello!", false, 5), { state: "omitted", reason: "size_limit", bytes: 6 });
|
|
});
|