mirror of
https://github.com/kellymichels/zscripts-token-savers
synced 2026-10-07 07:18:18 +00:00
Two things, both prompted by the same incident. STATIC KIND Plain static sites - no build, no container of their own; a shared web container serves them off disk, so shipping the files IS the deploy. Directories are staged to a sibling and swapped in with mv rather than copied in place, because a large media file uploaded in place is served half-written to anyone who requests it mid-copy. The swap is a rename, so the switch is atomic. Skips $JunkDirNames + .github + deploy.skipDirs, matching the docker kind rather than inventing a third convention. SANITIZATION TEST This repo is public and must stay standalone, but the toolkit is developed in a private checkout and copied here. Twice in three days a wholesale copy landed carrying real project names, internal hostnames, host disk figures, and references to scripts that exist only in the private copy. Both times a human reading the diff caught it - the control that fails exactly when a diff is 280 lines of good work with three bad words buried in it. So it is a test now. Seven rules: private project names, private product domains, private-only script names, local drive paths, the operator home path, the real key filename, and any IPv4 outside RFC 5737 documentation space and the private ranges. Two anti-vacuity guards, because a denylist that silently matches nothing is worse than no denylist: one asserts the file scan is non-empty, and one plants a known violation and requires the pattern to find it. The IP rule bounds on [\d.] rather than \d deliberately - this toolkit's own 5-segment version (v1.0.0.0.14) contains "0.0.0.14", which a plain digit boundary reads as an address. Verified against the real unsanitized copy that slipped through: 3 of the 7 rules fire, naming file and line. Tests: 231/231 (222 + 9 new). CHECKSUMS.txt refreshed. |
||
|---|---|---|
| .. | ||
| fixtures | ||
| ArgumentParsing.Tests.ps1 | ||
| Checksums.Tests.ps1 | ||
| Invoke-Coverage.ps1 | ||
| NewProjectArchive.Tests.ps1 | ||
| Sanitization.Tests.ps1 | ||
| ZHelpers.Tests.ps1 | ||