zscripts-token-savers/tests/Sanitization.Tests.ps1
Kelly Michels 4ebb596176
chore(mirror): mirror tagOnDeploy and the zstart gitPull fix, and stop publishing current product names (#72)
The mirror carries the tagOnDeploy feature, its tests, and the zstart
gitPull fix from the private tree. Twelve published references to
current product names and internal issue numbers are reworded
generically, the denylist learns the current spellings (a dot or hyphen
broke the word, an underscore hid the boundary), and planted cases prove
the suite now sees them. CHECKSUMS.txt regenerated.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-08 13:40:45 -05:00

124 lines
5.8 KiB
PowerShell

# Evomedia.net Token Savers — https://github.com/evomedia-net/evo.zscripts
# Created by Kelly Michels · dev@evomedia.net
# Licensed under the MIT License. See LICENSE.
# Sanitization.Tests.ps1 — this repo is public and must stay standalone.
#
# WHY THIS EXISTS
# ---------------
# The toolkit is developed in a private checkout and copied here. Twice in three
# days a wholesale copy landed carrying environment-specific detail: real
# project names, internal hostnames, host disk figures, and references to
# scripts that exist only in the private copy. Each time it was caught by a
# human reading the diff, which is exactly the control that fails when a diff is
# 280 lines of good work with three bad words buried in it.
#
# So it is a test. A copy that reintroduces private detail turns the suite red
# at the moment it happens rather than at review.
#
# WHAT IT CANNOT DO
# -----------------
# This is a denylist, so it proves the absence of KNOWN patterns, not the
# absence of secrets. It is a regression net for a specific recurring mistake -
# not a substitute for reading what you publish. Add a pattern whenever a new
# private identifier appears; the cost of a stale entry is zero.
BeforeAll {
$script:RepoRoot = Split-Path -Parent $PSScriptRoot
# Scanned: everything a reader of the published repo can see. Skipped:
# .git (history is out of scope here), releases/ (published zips are
# immutable by policy - rewriting one would break its checksum), and this
# file, which necessarily contains every pattern it looks for.
$script:Scanned = @(
Get-ChildItem -LiteralPath $script:RepoRoot -Recurse -File |
Where-Object {
$_.Extension -in @('.ps1', '.cmd', '.md', '.txt', '.json', '.bats', '.sh') -and
$_.FullName -notlike '*\.git\*' -and
$_.FullName -notlike '*\releases\*' -and
$_.Name -ne 'Sanitization.Tests.ps1'
}
)
# The rules live in sanitization-patterns.psd1, not here, so the
# publisher in the private tree can read the SAME list. It used to keep
# its own, narrower one - secrets only, no identity rules - and therefore
# reported "clean" on files this suite rejects (evo.scripts#106).
$patternFile = Join-Path $PSScriptRoot 'sanitization-patterns.psd1'
if (-not (Test-Path -LiteralPath $patternFile)) {
throw "sanitization-patterns.psd1 is missing - the denylist has no source."
}
$script:Denied = (Import-PowerShellDataFile -LiteralPath $patternFile).Denied
if (-not $script:Denied -or $script:Denied.Count -eq 0) {
throw "sanitization-patterns.psd1 defined no rules - refusing to pass vacuously."
}
function Get-Hits {
param([string]$Pattern)
$hits = @()
foreach ($f in $script:Scanned) {
$m = Select-String -LiteralPath $f.FullName -Pattern $Pattern -AllMatches -ErrorAction SilentlyContinue
foreach ($line in $m) {
$rel = $line.Path.Substring($script:RepoRoot.Length).TrimStart('\')
$hits += "$rel`:$($line.LineNumber): $($line.Line.Trim())"
}
}
return $hits
}
}
Describe "public repo carries no private detail" {
It "finds files to scan at all" {
# Guards the guard: a bad filter here would make every test below pass
# vacuously, which is worse than no test.
$script:Scanned.Count | Should -BeGreaterThan 30
}
It "contains no <Name>" -ForEach @(
@{ Name = 'private project name' }
@{ Name = 'private product domain' }
@{ Name = 'private-only script' }
@{ Name = 'local drive path' }
@{ Name = 'operator home path' }
@{ Name = 'real pem key name' }
@{ Name = 'non-documentation IP' }
) {
$rule = $script:Denied | Where-Object { $_.Name -eq $Name }
$hits = Get-Hits -Pattern $rule.Pattern
$hits | Should -BeNullOrEmpty -Because "these look like private detail copied in from the internal toolkit:`n$($hits -join "`n")"
}
It "catches the current spelling <Sample>" -ForEach @(
@{ Rule = 'current product name'; Sample = 'evo.ehs answers build_version' }
@{ Rule = 'current product name'; Sample = 'evo-ai answers version on /health' }
@{ Rule = 'current product name'; Sample = 'upstream evoehs_app:80' }
@{ Rule = 'internal issue reference'; Sample = 'see evo.scripts#101 for the trap' }
) {
# The rename went past the old pattern: the dot and the hyphen break
# the word and the underscore hides the boundary, so a suite that ran
# green was trusted on a tree that named the fleet.
$pattern = ($script:Denied | Where-Object { $_.Name -eq $Rule }).Pattern
$pattern | Should -Not -BeNullOrEmpty
($Sample -match $pattern) | Should -BeTrue
}
It "still allows this repo's own name" {
$pattern = ($script:Denied | Where-Object { $_.Name -eq 'current product name' }).Pattern
('https://github.com/evomedia-net/evo.zscripts' -match $pattern) | Should -BeFalse
}
It "still detects a planted violation" {
# Mutation check. Without this the suite passes just as happily when the
# patterns are broken as when the repo is clean - the failure mode that
# makes a denylist worthless.
$probe = Join-Path ([IO.Path]::GetTempPath()) ("sanitize-probe-" + [guid]::NewGuid().ToString("N") + ".ps1")
try {
Set-Content -LiteralPath $probe -Value '# deploy target /home/ubuntu/stack/example' -Encoding UTF8
$found = Select-String -LiteralPath $probe -Pattern ($script:Denied | Where-Object { $_.Name -eq 'operator home path' }).Pattern
$found | Should -Not -BeNullOrEmpty
}
finally { Remove-Item -LiteralPath $probe -Force -ErrorAction SilentlyContinue }
}
}