62 lines
2.3 KiB
Python
62 lines
2.3 KiB
Python
from pathlib import Path
|
|
import sys
|
|
import unittest
|
|
from unittest import mock
|
|
|
|
import pandas as pd
|
|
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
APP_DIR = ROOT / 'app'
|
|
sys.path.insert(0, str(APP_DIR))
|
|
|
|
import dashboard
|
|
from scanner_db import extract_redacted_secret
|
|
|
|
|
|
class DashboardSecretGuardTests(unittest.TestCase):
|
|
def test_raw_only_finding_never_populates_redacted_column_with_raw(self):
|
|
self.assertEqual(
|
|
extract_redacted_secret({'Raw': 'raw-secret-value'}),
|
|
'***REDACTED***',
|
|
)
|
|
|
|
def test_historical_unmasked_redacted_value_is_masked_before_render(self):
|
|
frame = pd.DataFrame([{'redacted_secret': 'historical-raw-secret', 'detector_name': 'OpenAI'}])
|
|
with mock.patch.object(dashboard.st, 'dataframe') as render:
|
|
dashboard.display_df(frame)
|
|
rendered = render.call_args.args[0]
|
|
self.assertEqual(rendered.iloc[0]['redacted_secret'], '***REDACTED***')
|
|
self.assertNotIn('historical-raw-secret', rendered.to_string())
|
|
|
|
def test_historical_endpoint_credentials_are_removed_before_render(self):
|
|
sentinels = (
|
|
'DASHBOARD-URL-USER-SENTINEL',
|
|
'DASHBOARD-URL-PASSWORD-SENTINEL',
|
|
'DASHBOARD-API-KEY-SENTINEL',
|
|
'DASHBOARD-TOKEN-SENTINEL',
|
|
'DASHBOARD-QUERY-PASSWORD-SENTINEL',
|
|
)
|
|
contaminated = (
|
|
f'https://{sentinels[0]}:{sentinels[1]}@normal.openai.azure.com:443/openai/deployments/demo'
|
|
f'?api_key={sentinels[2]}&token={sentinels[3]}&password={sentinels[4]}#private'
|
|
)
|
|
normal = 'https://normal.openai.azure.com/openai/deployments/ordinary'
|
|
frame = pd.DataFrame([
|
|
{'endpoint': contaminated, 'detector_name': 'OpenAI'},
|
|
{'endpoint': normal, 'detector_name': 'AzureOpenAI'},
|
|
])
|
|
with mock.patch.object(dashboard.st, 'dataframe') as render:
|
|
dashboard.display_df(frame)
|
|
rendered = render.call_args.args[0]
|
|
self.assertEqual(
|
|
rendered.iloc[0]['endpoint'],
|
|
'https://normal.openai.azure.com:443/openai/deployments/demo',
|
|
)
|
|
self.assertEqual(rendered.iloc[1]['endpoint'], normal)
|
|
self.assertTrue(all(sentinel not in rendered.to_string() for sentinel in sentinels))
|
|
|
|
|
|
if __name__ == '__main__':
|
|
unittest.main()
|