fix: harden evidence secret file handoff

This commit is contained in:
2026-08-09 19:27:52 +02:00
parent e50aad7e41
commit 3b9681a63a
4 changed files with 83 additions and 24 deletions
@@ -223,6 +223,37 @@ def test_signed_http_rejects_reordered_extra_mismatch_userinfo_and_duplicate_pro
assert_no_canaries(caught.value)
def test_s3_rejects_inline_credentials_and_never_discloses_them(tmp_path):
path = write_config(tmp_path, {
"type": "s3", "bucket": "clinical-evidence",
"access_key": ACCESS_CANARY,
"secret_key": SECRET_CANARY,
"session_token": TOKEN_CANARY,
})
with pytest.raises(ConfigError) as caught:
load_config(path)
assert "file" in str(caught.value).lower()
assert_no_canaries(caught.value)
assert_no_canaries("".join(traceback.format_exception(caught.value)))
def test_s3_scalar_secret_files_are_bounded(tmp_path):
access = tmp_path / "oversized-access-key"
access.write_bytes(b"A" * (64 * 1024 + 1))
secret = tmp_path / "secret-key"
secret.write_text("bounded-secret")
path = write_config(tmp_path, {
"type": "s3", "bucket": "clinical-evidence",
"access_key_file": str(access), "secret_key_file": str(secret),
})
with pytest.raises(ConfigError) as caught:
load_config(path)
assert "secret file" in str(caught.value).lower()
assert "bounded-secret" not in str(caught.value)
def test_s3_ambient_and_static_file_credentials_are_secret_typed(tmp_path):
ambient = load_config(write_config(tmp_path, {
"type": "s3", "bucket": "clinical-evidence", "prefix": "published/",