feat: finish Pi and workspace management updates

This commit is contained in:
2026-08-16 14:19:32 +02:00
parent 7651b63cea
commit 351361f72f
20 changed files with 2276 additions and 149 deletions
+6
View File
@@ -122,6 +122,12 @@ func extractSecretValues(contents []byte) ([]string, error) {
if whole != "" {
values = append(values, whole)
}
// PEM files (including OpenSSH private keys) can contain base64 lines that look
// like dotenv assignments. Keep the complete document opaque instead of trying
// to parse it as a dotenv bundle.
if bytes.HasPrefix(trimmed, []byte("-----BEGIN ")) {
return values, nil
}
if trimmed[0] == '{' || trimmed[0] == '[' {
var document any
@@ -105,6 +105,26 @@ func TestSecretValuesFromFilesRedactsEveryDotenvBundleValue(t *testing.T) {
}
}
func TestSecretValuesFromFilesAcceptsOpenSSHPrivateKey(t *testing.T) {
t.Parallel()
secretFile := filepath.Join(physicalTempDir(t), "git-ssh-key")
contents := "-----BEGIN OPENSSH PRIVATE KEY-----\n" +
"ZmFrZS1rZXktcGF5bG9hZA==\n" +
"-----END OPENSSH PRIVATE KEY-----\n"
if err := os.WriteFile(secretFile, []byte(contents), 0o600); err != nil {
t.Fatal(err)
}
secrets, err := SecretValuesFromFiles([]string{secretFile})
if err != nil {
t.Fatalf("SecretValuesFromFiles() error = %v, want OpenSSH key accepted", err)
}
if len(secrets) == 0 {
t.Fatal("SecretValuesFromFiles() returned no values for OpenSSH key")
}
}
func TestSanitizeRecognizesQuotedCredentialKeys(t *testing.T) {
t.Parallel()