| 1 | package secrets |
| 2 | |
| 3 | import ( |
| 4 | "encoding/json" |
| 5 | "strings" |
| 6 | "testing" |
| 7 | "unicode/utf8" |
| 8 | ) |
| 9 | |
| 10 | func TestRedactJSONPreservesStructureAndCounters(t *testing.T) { |
| 11 | input := []byte(`{"token_count":9007199254740993,"api_key":"a secret with spaces","nested":[{"output":"TOKEN=这是很长的中文测试凭证内容\nCookie: sid=abc; secure\npassword=\"escape-me\""}],"empty":[],"flag":true}`) |
| 12 | got, err := RedactJSON(input) |
| 13 | if err != nil || !json.Valid(got) || !utf8.Valid(got) { |
| 14 | t.Fatalf("invalid diagnostic JSON: %q, %v", got, err) |
| 15 | } |
| 16 | for _, secret := range []string{"a secret with spaces", "escape-me", "sid=abc", "这是很长的中文测试凭证内容"} { |
| 17 | if strings.Contains(string(got), secret) { |
| 18 | t.Fatalf("diagnostic leaked %q", secret) |
| 19 | } |
| 20 | } |
| 21 | for _, preserved := range []string{`"token_count":9007199254740993`, `"empty":[]`, `"flag":true`} { |
| 22 | if !strings.Contains(string(got), preserved) { |
| 23 | t.Fatalf("lost structural value %s: %s", preserved, got) |
| 24 | } |
| 25 | } |
| 26 | } |
| 27 | |
| 28 | func TestRedactJSONRejectsInvalidDocument(t *testing.T) { |
| 29 | for _, input := range []string{`{} {}`, `{"broken":`, `not json`} { |
| 30 | if _, err := RedactJSON([]byte(input)); err == nil { |
| 31 | t.Fatalf("accepted invalid document %q", input) |
| 32 | } |
| 33 | } |
| 34 | } |
| 35 |