zscripts-token-savers/tests/Sanitization.Tests.ps1
Kelly Michels b26be3cd2a
chore: write the site name as evomedia.net, lowercase (#92)
* chore: write the site name as evomedia.net, lowercase

The name is a domain and is written as one. Script headers, the README,
CHANGELOG and elevator pitch, their .txt twins, and the site page --
matching the same sweep in the private evo.scripts so the mirror does not
drift.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore: refresh CHECKSUMS.txt for the lowercase sweep

Every script's header changed, so every hash did. The repo's own
Checksums test caught it -- which is what it is for.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-22 13:40:03 -05:00

124 lines
5.8 KiB
PowerShell

# evomedia.net Token Savers — https://github.com/evomedia-net/evo.zscripts
# Created by Kelly Michels · dev@evomedia.net
# Licensed under the MIT License. See LICENSE.
# Sanitization.Tests.ps1 — this repo is public and must stay standalone.
#
# WHY THIS EXISTS
# ---------------
# The toolkit is developed in a private checkout and copied here. Twice in three
# days a wholesale copy landed carrying environment-specific detail: real
# project names, internal hostnames, host disk figures, and references to
# scripts that exist only in the private copy. Each time it was caught by a
# human reading the diff, which is exactly the control that fails when a diff is
# 280 lines of good work with three bad words buried in it.
#
# So it is a test. A copy that reintroduces private detail turns the suite red
# at the moment it happens rather than at review.
#
# WHAT IT CANNOT DO
# -----------------
# This is a denylist, so it proves the absence of KNOWN patterns, not the
# absence of secrets. It is a regression net for a specific recurring mistake -
# not a substitute for reading what you publish. Add a pattern whenever a new
# private identifier appears; the cost of a stale entry is zero.
BeforeAll {
$script:RepoRoot = Split-Path -Parent $PSScriptRoot
# Scanned: everything a reader of the published repo can see. Skipped:
# .git (history is out of scope here), releases/ (published zips are
# immutable by policy - rewriting one would break its checksum), and this
# file, which necessarily contains every pattern it looks for.
$script:Scanned = @(
Get-ChildItem -LiteralPath $script:RepoRoot -Recurse -File |
Where-Object {
$_.Extension -in @('.ps1', '.cmd', '.md', '.txt', '.json', '.bats', '.sh') -and
$_.FullName -notlike '*\.git\*' -and
$_.FullName -notlike '*\releases\*' -and
$_.Name -ne 'Sanitization.Tests.ps1'
}
)
# The rules live in sanitization-patterns.psd1, not here, so the
# publisher in the private tree can read the SAME list. It used to keep
# its own, narrower one - secrets only, no identity rules - and therefore
# reported "clean" on files this suite rejects (evo.scripts#106).
$patternFile = Join-Path $PSScriptRoot 'sanitization-patterns.psd1'
if (-not (Test-Path -LiteralPath $patternFile)) {
throw "sanitization-patterns.psd1 is missing - the denylist has no source."
}
$script:Denied = (Import-PowerShellDataFile -LiteralPath $patternFile).Denied
if (-not $script:Denied -or $script:Denied.Count -eq 0) {
throw "sanitization-patterns.psd1 defined no rules - refusing to pass vacuously."
}
function Get-Hits {
param([string]$Pattern)
$hits = @()
foreach ($f in $script:Scanned) {
$m = Select-String -LiteralPath $f.FullName -Pattern $Pattern -AllMatches -ErrorAction SilentlyContinue
foreach ($line in $m) {
$rel = $line.Path.Substring($script:RepoRoot.Length).TrimStart('\')
$hits += "$rel`:$($line.LineNumber): $($line.Line.Trim())"
}
}
return $hits
}
}
Describe "public repo carries no private detail" {
It "finds files to scan at all" {
# Guards the guard: a bad filter here would make every test below pass
# vacuously, which is worse than no test.
$script:Scanned.Count | Should -BeGreaterThan 30
}
It "contains no <Name>" -ForEach @(
@{ Name = 'private project name' }
@{ Name = 'private product domain' }
@{ Name = 'private-only script' }
@{ Name = 'local drive path' }
@{ Name = 'operator home path' }
@{ Name = 'real pem key name' }
@{ Name = 'non-documentation IP' }
) {
$rule = $script:Denied | Where-Object { $_.Name -eq $Name }
$hits = Get-Hits -Pattern $rule.Pattern
$hits | Should -BeNullOrEmpty -Because "these look like private detail copied in from the internal toolkit:`n$($hits -join "`n")"
}
It "catches the current spelling <Sample>" -ForEach @(
@{ Rule = 'current product name'; Sample = 'evo.ehs answers build_version' }
@{ Rule = 'current product name'; Sample = 'evo-ai answers version on /health' }
@{ Rule = 'current product name'; Sample = 'upstream evoehs_app:80' }
@{ Rule = 'internal issue reference'; Sample = 'see evo.scripts#101 for the trap' }
) {
# The rename went past the old pattern: the dot and the hyphen break
# the word and the underscore hides the boundary, so a suite that ran
# green was trusted on a tree that named the fleet.
$pattern = ($script:Denied | Where-Object { $_.Name -eq $Rule }).Pattern
$pattern | Should -Not -BeNullOrEmpty
($Sample -match $pattern) | Should -BeTrue
}
It "still allows this repo's own name" {
$pattern = ($script:Denied | Where-Object { $_.Name -eq 'current product name' }).Pattern
('https://github.com/evomedia-net/evo.zscripts' -match $pattern) | Should -BeFalse
}
It "still detects a planted violation" {
# Mutation check. Without this the suite passes just as happily when the
# patterns are broken as when the repo is clean - the failure mode that
# makes a denylist worthless.
$probe = Join-Path ([IO.Path]::GetTempPath()) ("sanitize-probe-" + [guid]::NewGuid().ToString("N") + ".ps1")
try {
Set-Content -LiteralPath $probe -Value '# deploy target /home/ubuntu/stack/example' -Encoding UTF8
$found = Select-String -LiteralPath $probe -Pattern ($script:Denied | Where-Object { $_.Name -eq 'operator home path' }).Pattern
$found | Should -Not -BeNullOrEmpty
}
finally { Remove-Item -LiteralPath $probe -Force -ErrorAction SilentlyContinue }
}
}