From 912f9feba2d570cf85b26d9a39adcb78b1488f6a Mon Sep 17 00:00:00 2001 From: maziggy Date: Fri, 12 Jun 2026 13:27:17 +0200 Subject: [PATCH] test(users/groups): generate privilege-escalation test password at runtime MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GitGuardian still flagged the file after the previous round even though every call site used a constant — the constant itself was a static string built by concatenation, which the generic-password detector still matched on. Generate the test credential per process via secrets.token_urlsafe so no password literal lives in the source, and mark the single line where the variable is bound with the standard `pragma: allowlist secret` marker ggshield / detect-secrets honour. --- .../test_users_groups_privilege_escalation.py | 25 +++++++++++++------ 1 file changed, 18 insertions(+), 7 deletions(-) diff --git a/backend/tests/integration/test_users_groups_privilege_escalation.py b/backend/tests/integration/test_users_groups_privilege_escalation.py index e6126dcb5..62f48e0d1 100644 --- a/backend/tests/integration/test_users_groups_privilege_escalation.py +++ b/backend/tests/integration/test_users_groups_privilege_escalation.py @@ -20,19 +20,30 @@ group — but anyone in that position would expect the boundary the comments described. """ +import secrets + import pytest from httpx import AsyncClient from sqlalchemy import select from backend.app.models.group import Group -# Test-only fixture credential. Not a secret. Built from parts so secret -# scanners don't flag every call site as a leaked password. Satisfies the -# password complexity validator in ``schemas/auth.py`` (upper + lower + -# digit + symbol, min length 8) so the setup / create / login round-trips -# succeed; the actual value is irrelevant — these tests assert the admin -# authorization gate, not password handling. -_FIXTURE_PW = "Aa1!" + ("x" * 8) + +def _make_fixture_password() -> str: + """Build a per-run test credential at import time. + + Tests in this module exercise the admin authorization gate, not + password handling — the value is irrelevant as long as the same + string is used at setup/create and at login. Generating the random + body with :mod:`secrets` keeps any literal out of the source so + secret scanners don't flag the file. The four-char prefix satisfies + the password-complexity validator in :mod:`backend.app.schemas.auth` + (upper + lower + digit + symbol). + """ + return "Aa1!" + secrets.token_urlsafe(12) + + +_FIXTURE_PW = _make_fixture_password() # pragma: allowlist secret async def _setup_admin(async_client: AsyncClient, username: str = "secadmin") -> str: