2.1 KiB
2.1 KiB
ADDED Requirements
Requirement: Alternative provider contexts execute independently
The custom detector policy SHALL detect supported Xai and ZAI/GLM credentials when provider context appears either before or after the credential, without requiring both context directions in one input chunk.
Scenario: Provider context appears before the credential
- WHEN an offline scan processes a bounded synthetic credential preceded by its supported provider context
- THEN the policy emits one corresponding custom provider finding
Scenario: Provider context appears after the credential
- WHEN an offline scan processes a bounded synthetic credential followed by its supported provider context
- THEN the policy emits one corresponding custom provider finding
Requirement: Alternative detector names normalize canonically
The scanner MUST normalize all compatibility-only custom detector aliases to the existing canonical Xai or ZaiGLM detector identity before persistence and candidate extraction.
Scenario: Context-after alias is emitted
- WHEN TruffleHog emits
CustomRegexwith a context-after compatibility name inExtraData.name - THEN the scanner retains
CustomRegexas the original detector and exposes the canonical provider detector name downstream
Requirement: Compatibility is tested through the real CLI
The compatibility suite SHALL run the complete configured custom detector policy through an available TruffleHog executable using deterministic synthetic credentials, disabled verification, and disabled update checks.
Scenario: Compatible executable is available
- WHEN a configured Windows or Linux TruffleHog executable scans the compatibility fixtures
- THEN both context directions produce canonical findings and route to the expected keycheck candidate services without network verification
Scenario: Executable is unavailable
- WHEN no TruffleHog executable is available in a general unit-test environment
- THEN the real-CLI test is explicitly skipped while policy-structure and normalization unit tests still execute