diff --git a/CHANGELOG.md b/CHANGELOG.md index fa41a33..8fb51d6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,16 @@ Notable changes to the Evomedia.net Token Savers. ## Unreleased +### Changed +- **The sanitization denylist moved to `tests/sanitization-patterns.psd1`**, + so the test suite here and the publisher in the private toolkit read one + list instead of keeping two. They had two, and they disagreed: the + publisher's scan looked only for secrets, while these rules are about + identity — internal project names, product domains, private-only script + names, operator paths. It therefore reported "clean" on files this suite + rejects. No rule changed; only where they live. + + ### Changed - **`zdeploy` verification picks its channel on every retry, and never asks the bare IP** — the check used to choose its channel once, before the wait diff --git a/CHANGELOG.txt b/CHANGELOG.txt index 49b5c99..f870e39 100644 --- a/CHANGELOG.txt +++ b/CHANGELOG.txt @@ -9,6 +9,16 @@ Notable changes to the Evomedia.net Token Savers. Unreleased ---------- +Changed +- The sanitization denylist moved to tests/sanitization-patterns.psd1, so + the test suite here and the publisher in the private toolkit read one + list instead of keeping two. They had two, and they disagreed: the + publisher's scan looked only for secrets, while these rules are about + identity - internal project names, product domains, private-only script + names, operator paths. It therefore reported "clean" on files this suite + rejects. No rule changed; only where they live. + + Changed - zdeploy verification picks its channel on every retry, and never asks the bare IP - the check used to choose its channel once, before the wait diff --git a/tests/Sanitization.Tests.ps1 b/tests/Sanitization.Tests.ps1 index 111e99f..a29552e 100644 --- a/tests/Sanitization.Tests.ps1 +++ b/tests/Sanitization.Tests.ps1 @@ -40,31 +40,18 @@ BeforeAll { } ) - # name -> what it is, so a failure explains itself - # pattern -> regex, case-insensitive - # Kept narrow on purpose: "evomedia.net" alone is legitimate here (the - # attribution header and the repo URL), so only the drive path and specific - # internal hosts are matched. - $script:Denied = @( - @{ Name = 'private project name'; Pattern = '\b(EvoCivilCode|EvoPlatform|DocketMail|SmartPlant\w*|ProvenSheet|evoehs|evoproven|evoaicc|evolocate|evoplatform)\b' } - @{ Name = 'private product domain'; Pattern = '\b(smartplantehs\.com|provensheet\.com|evoehs\.com|civilcode\.evomedia\.net|dashboard\.evomedia\.net|webmail\.evomedia\.net|mail-admin\.evomedia\.net|docketmail\.evomedia\.net|cardiff\.evomedia\.net|platform\.evomedia\.net|ai\.evomedia\.net|git\.evomedia\.net|analytics\.evomedia\.net)\b' } - @{ Name = 'private-only script'; Pattern = '\b(register_civilcode|register_docketmail|sp_seed_demo_prod|zpublish_stats|zcoverage|zmerge|zpull|zresume|swag_set_owner|provision_demo|apply_platform_config_fixes)\b' } - @{ Name = 'local drive path'; Pattern = '[A-Za-z]:\\\\?evomedia\.net' } - @{ Name = 'operator home path'; Pattern = '/home/ubuntu/' } - @{ Name = 'real pem key name'; Pattern = 'evomedia-prod\.pem' } - # RFC 5737 reserves 203.0.113.0/24 for documentation - that one is the - # correct placeholder and must stay allowed, as are loopback and the - # private ranges. Anything else that looks like a public IPv4 literal is - # suspect. - # - # The boundaries are [\d.] rather than \d on purpose: this toolkit's own - # 5-segment version (v1.0.0.0.14) contains "0.0.0.14", which a plain - # digit boundary happily reads as an address. Refusing a match that - # touches another dot rules out every version string without weakening - # detection of a real address, which is always delimited by whitespace - # or quotes. - @{ Name = 'non-documentation IP'; Pattern = '(? +@{ + Denied = @( + @{ Name = 'private project name'; Pattern = '\b(EvoCivilCode|EvoPlatform|DocketMail|SmartPlant\w*|ProvenSheet|evoehs|evoproven|evoaicc|evolocate|evoplatform)\b' } + @{ Name = 'private product domain'; Pattern = '\b(smartplantehs\.com|provensheet\.com|evoehs\.com|civilcode\.evomedia\.net|dashboard\.evomedia\.net|webmail\.evomedia\.net|mail-admin\.evomedia\.net|docketmail\.evomedia\.net|cardiff\.evomedia\.net|platform\.evomedia\.net|ai\.evomedia\.net|git\.evomedia\.net|analytics\.evomedia\.net)\b' } + @{ Name = 'private-only script'; Pattern = '\b(register_civilcode|register_docketmail|sp_seed_demo_prod|zpublish_stats|zcoverage|zmerge|zpull|zresume|swag_set_owner|provision_demo|apply_platform_config_fixes)\b' } + @{ Name = 'local drive path'; Pattern = '[A-Za-z]:\\\\?evomedia\.net' } + @{ Name = 'operator home path'; Pattern = '/home/ubuntu/' } + @{ Name = 'real pem key name'; Pattern = 'evomedia-prod\.pem' } + # RFC 5737 reserves 203.0.113.0/24 for documentation - that one is the + # correct placeholder and must stay allowed, as are loopback and the + # private ranges. Anything else that looks like a public IPv4 literal is + # suspect. + # + # The boundaries are [\d.] rather than \d on purpose: this toolkit's own + # 5-segment version (v1.0.0.0.14) contains "0.0.0.14", which a plain + # digit boundary happily reads as an address. Refusing a match that + # touches another dot rules out every version string without weakening + # detection of a real address, which is always delimited by whitespace + # or quotes. + @{ Name = 'non-documentation IP'; Pattern = '(?