fix: harden evidence secret file handoff
This commit is contained in:
@@ -223,6 +223,37 @@ def test_signed_http_rejects_reordered_extra_mismatch_userinfo_and_duplicate_pro
|
||||
assert_no_canaries(caught.value)
|
||||
|
||||
|
||||
def test_s3_rejects_inline_credentials_and_never_discloses_them(tmp_path):
|
||||
path = write_config(tmp_path, {
|
||||
"type": "s3", "bucket": "clinical-evidence",
|
||||
"access_key": ACCESS_CANARY,
|
||||
"secret_key": SECRET_CANARY,
|
||||
"session_token": TOKEN_CANARY,
|
||||
})
|
||||
|
||||
with pytest.raises(ConfigError) as caught:
|
||||
load_config(path)
|
||||
assert "file" in str(caught.value).lower()
|
||||
assert_no_canaries(caught.value)
|
||||
assert_no_canaries("".join(traceback.format_exception(caught.value)))
|
||||
|
||||
|
||||
def test_s3_scalar_secret_files_are_bounded(tmp_path):
|
||||
access = tmp_path / "oversized-access-key"
|
||||
access.write_bytes(b"A" * (64 * 1024 + 1))
|
||||
secret = tmp_path / "secret-key"
|
||||
secret.write_text("bounded-secret")
|
||||
path = write_config(tmp_path, {
|
||||
"type": "s3", "bucket": "clinical-evidence",
|
||||
"access_key_file": str(access), "secret_key_file": str(secret),
|
||||
})
|
||||
|
||||
with pytest.raises(ConfigError) as caught:
|
||||
load_config(path)
|
||||
assert "secret file" in str(caught.value).lower()
|
||||
assert "bounded-secret" not in str(caught.value)
|
||||
|
||||
|
||||
def test_s3_ambient_and_static_file_credentials_are_secret_typed(tmp_path):
|
||||
ambient = load_config(write_config(tmp_path, {
|
||||
"type": "s3", "bucket": "clinical-evidence", "prefix": "published/",
|
||||
|
||||
Reference in New Issue
Block a user