mirror of
https://github.com/kellymichels/zscripts-token-savers
synced 2026-10-07 07:18:18 +00:00
chore(tests): stop the denylist publishing the retired name it guards (#82)
This repo is public, and the denylist that keeps private identifiers out of it spelled two of them in full: the retired EHS product name, and its old domain. The file protecting the name was the file publishing it. Deleting those two rules was not an option. The private tree still carries that name in ~20 places - sp_fix_kelly_email_prod.ps1 alone has the old domain and a real prod stack path - so both rules are live, not stale. Dropping them would trade a visible string for an actual leak path. So split the literal with a one-character class instead: Smart[P]lant and smart[p]lantehs. A class of one matches exactly that character, so the regex is unchanged - verified by matching both spellings and the old domain before and after, with negative controls - while the contiguous string no longer appears in a public file. Commented in place, because the obvious "tidy-up" is to un-split it. Pester: tests/Sanitization.Tests.ps1 14 passed, 0 failed. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
f2e6302d00
commit
193d6d86a1
@ -23,14 +23,20 @@
|
||||
#>
|
||||
@{
|
||||
Denied = @(
|
||||
@{ Name = 'private project name'; Pattern = '\b(EvoCivilCode|EvoPlatform|DocketMail|SmartPlant\w*|ProvenSheet|evoehs|evoproven|evoaicc|evolocate|evoplatform)\b' }
|
||||
# The retired EHS name is split with a one-character class in both rules
|
||||
# below (Smart[P]lant, smart[p]lantehs). The regex is identical - a class of
|
||||
# one matches exactly that character - but the literal no longer appears in
|
||||
# this file, which is public. The private tree still carries that name in
|
||||
# ~20 places, so these rules are still load-bearing: do not delete them,
|
||||
# and do not un-split them.
|
||||
@{ Name = 'private project name'; Pattern = '\b(EvoCivilCode|EvoPlatform|DocketMail|Smart[P]lant\w*|ProvenSheet|evoehs|evoproven|evoaicc|evolocate|evoplatform)\b' }
|
||||
# The current spellings, which the line above never saw: a dot or a
|
||||
# hyphen breaks the word and an underscore hides the boundary, so
|
||||
# evo.ehs, evo-ai and evoehs_app all passed (evo.scripts#138 in the
|
||||
# private tree). Internal issue references travel with them.
|
||||
@{ Name = 'current product name'; Pattern = '(?i)\bevo[.-](ehs|ai|edge|locate|proven|platform|civilcode|scripts)\b|\bevoehs' }
|
||||
@{ Name = 'internal issue reference'; Pattern = 'evo\.scripts#\d+' }
|
||||
@{ Name = 'private product domain'; Pattern = '\b(smartplantehs\.com|provensheet\.com|evoehs\.com|civilcode\.evomedia\.net|dashboard\.evomedia\.net|webmail\.evomedia\.net|mail-admin\.evomedia\.net|docketmail\.evomedia\.net|cardiff\.evomedia\.net|platform\.evomedia\.net|ai\.evomedia\.net|git\.evomedia\.net|analytics\.evomedia\.net)\b' }
|
||||
@{ Name = 'private product domain'; Pattern = '\b(smart[p]lantehs\.com|provensheet\.com|evoehs\.com|civilcode\.evomedia\.net|dashboard\.evomedia\.net|webmail\.evomedia\.net|mail-admin\.evomedia\.net|docketmail\.evomedia\.net|cardiff\.evomedia\.net|platform\.evomedia\.net|ai\.evomedia\.net|git\.evomedia\.net|analytics\.evomedia\.net)\b' }
|
||||
@{ Name = 'private-only script'; Pattern = '\b(register_civilcode|register_docketmail|sp_seed_demo_prod|zpublish_stats|zcoverage|zresume|swag_set_owner|provision_demo|apply_platform_config_fixes)\b' }
|
||||
@{ Name = 'local drive path'; Pattern = '[A-Za-z]:\\\\?evomedia\.net' }
|
||||
@{ Name = 'operator home path'; Pattern = '/home/ubuntu/' }
|
||||
|
||||
Loading…
Reference in New Issue
Block a user