mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
test(users/groups): generate privilege-escalation test password at runtime
GitGuardian still flagged the file after the previous round even though every call site used a constant — the constant itself was a static string built by concatenation, which the generic-password detector still matched on. Generate the test credential per process via secrets.token_urlsafe so no password literal lives in the source, and mark the single line where the variable is bound with the standard `pragma: allowlist secret` marker ggshield / detect-secrets honour.
This commit is contained in:
@@ -20,19 +20,30 @@ group — but anyone in that position would expect the boundary the
|
||||
comments described.
|
||||
"""
|
||||
|
||||
import secrets
|
||||
|
||||
import pytest
|
||||
from httpx import AsyncClient
|
||||
from sqlalchemy import select
|
||||
|
||||
from backend.app.models.group import Group
|
||||
|
||||
# Test-only fixture credential. Not a secret. Built from parts so secret
|
||||
# scanners don't flag every call site as a leaked password. Satisfies the
|
||||
# password complexity validator in ``schemas/auth.py`` (upper + lower +
|
||||
# digit + symbol, min length 8) so the setup / create / login round-trips
|
||||
# succeed; the actual value is irrelevant — these tests assert the admin
|
||||
# authorization gate, not password handling.
|
||||
_FIXTURE_PW = "Aa1!" + ("x" * 8)
|
||||
|
||||
def _make_fixture_password() -> str:
|
||||
"""Build a per-run test credential at import time.
|
||||
|
||||
Tests in this module exercise the admin authorization gate, not
|
||||
password handling — the value is irrelevant as long as the same
|
||||
string is used at setup/create and at login. Generating the random
|
||||
body with :mod:`secrets` keeps any literal out of the source so
|
||||
secret scanners don't flag the file. The four-char prefix satisfies
|
||||
the password-complexity validator in :mod:`backend.app.schemas.auth`
|
||||
(upper + lower + digit + symbol).
|
||||
"""
|
||||
return "Aa1!" + secrets.token_urlsafe(12)
|
||||
|
||||
|
||||
_FIXTURE_PW = _make_fixture_password() # pragma: allowlist secret
|
||||
|
||||
|
||||
async def _setup_admin(async_client: AsyncClient, username: str = "secadmin") -> str:
|
||||
|
||||
Reference in New Issue
Block a user