fix(redact): correct test comments on entropy-layer miss reasoning · Entire
fix(redact): correct test comments on entropy-layer miss reasoning
fa1d633→main· suhaanthayyil·4d ago·2 files·+13 added/-10 removed
Changes
2
cmd/entire/cli/integration_test
- Msupabase_secret_redaction_test.go+5/-4
redact
- Mredact_test.go+8/-6
22 unmodified lines
23
24
25
26
27
28
29
26
27
28
29
30
31
32
33
22 unmodified lines
// methodology),
// - a sb_publishable_ key (public by design) is NOT over-redacted.
//
// Every sb_secret_ occurrence is placed so the surrounding token is
// low-entropy (quoted or in prose), which the entropy layer (threshold 4.5)
// and the composite betterleaks Supabase rule both miss — so redaction here is
// attributable to the deterministic provider-prefix layer added for this fix.
// Every sb_secret_ occurrence uses a low-entropy synthetic token, which the
// entropy layer (threshold 4.5) misses regardless of quoting or surrounding
// prose, and no *.supabase.co URL is co-present, so the composite betterleaks
// Supabase rule does not fire either — so redaction here is attributable to
// the deterministic provider-prefix layer added for this fix.
func TestSupabaseSecretRedaction_FullHookFlow(t *testing.T) {
// Hook subprocesses share settings/env; do not run in parallel.
// The sb_secret_ / sb_publishable_ prefixes are assembled from fragments so
Mcmd/entire/cli/integration_test/supabase_secret_redaction_test.go+5/-4
381 unmodified lines
382
383
384
385
386
387
385
386
387
388
389
390
391
36 unmodified lines
428
429
430
430
431
432
431
432
433
434
435
436
437
381 unmodified lines
want: "service_role key: REDACTED",
},
{
// Canonical .env form. The surrounding quotes break the token so the
// entropy layer sees only the low-entropy secret and misses it,
// isolating the deterministic provider layer.
// Canonical .env form. The chosen token value is low-entropy
// (quoting has no effect on secretPattern matching), so the
// entropy layer misses it, isolating the deterministic provider
// layer.
name: "sb_secret_ in env-style double-quoted assignment",
input: `SUPABASE_SERVICE_ROLE_KEY="` + secret + `"`,
want: `SUPABASE_SERVICE_ROLE_KEY="REDACTED"`,
36 unmodified lines
assertStringRedactionCases(t, []stringRedactionCase{
{
// Quoted so the entropy layer sees only the low-entropy publishable
// value (which it does not flag), proving the provider layer itself
// does not target publishable keys.
// The publishable fixture is low-entropy (quoting has no effect on
// secretPattern matching), so the entropy layer does not flag it,
// proving the provider layer itself does not target publishable
// keys.
name: "publishable key is not targeted by the provider layer",
input: `NEXT_PUBLIC_SUPABASE_KEY="` + publishable + `"`,
want: `NEXT_PUBLIC_SUPABASE_KEY="` + publishable + `"`,